Security Incident Manager
Salix Recruitment · Gauteng
Stop applying one at a time.
JobAlertsZA auto-applies to South African jobs like this one for you, overnight. Upload your CV once — we do the applying.
Start free — we apply for you →Are you an experienced cybersecurity professional who thrives when it comes to incident response, threat remediation and strengthening security operations?
Join a globally established organisation with a long-standing reputation for innovation, technology and responsible growth, operating across six continents and multiple industries. With a global footprint, complex operations and a strong focus on digitalisation.
We're looking for a Security Incident Manager to take ownership of the operational response to cybersecurity threats across a complex enterprise environment. This is a hands-on leadership role where you'll coordinate incident remediation, drive vulnerability management and ensure critical security controls remain effective.
You'll work closely with Security Operations, IT Infrastructure, Service Desk, Application Security, DevSecOps and Risk & Compliance teams to make sure threats are identified, contained and resolved quickly and effectively.
If you're ready to take ownership of security incident management and want a role where your expertise can genuinely shape an organisation's security operations, we'd like to hear from you.
Apply now or get in touch for a confidential discussion.
Duties
- Lead the response and remediation of security incidents identified through the Security Operations Centre (SOC).
- Coordinate vulnerability remediation across IT and infrastructure teams, ensuring vulnerabilities are tracked, prioritised and resolved.
- Oversee patch management and validate that remediation activities have been completed effectively.
- Maintain and optimise security controls, including Endpoint Detection & Response (EDR) and network segmentation.
- Develop and maintain incident response playbooks and operational procedures.
- Improve SOC alert-handling, escalation and reporting workflows, with a focus on reducing false positives and improving response efficiency.
- Work with third-party SOC, vulnerability management and security service providers, monitoring their performance against agreed SLAs.
- Support security incident logging, reporting and post-incident reviews.
- Partner with technical and non-technical stakeholders to strengthen the organisation's overall security posture.
- Ensure operational security practices remain aligned with relevant cybersecurity frameworks and compliance requirements.
Job Experience & Skills Required
Qualifications
- Matric (Grade 12)
- Bachelor's degree in Information Security, Computer Science, Information Technology or a related field.
- ISSP | GCIH | CEH | CompTIA Security+ / CySA+
Experience
- 6–10 years' progressive experience in cybersecurity operations, including hands-on incident response and threat remediation.
- Experience working with or managing a Security Operations Centre (SOC) and vulnerability management platforms.
- Strong experience coordinating vulnerability remediation and patch management.
- Practical experience with EDR solutions, endpoint protection and network security controls.
- Experience developing incident response playbooks and operational workflows.
- Exposure to enterprise IT environments, ideally including SAP, Active Directory and hybrid cloud infrastructure.
- Strong understanding of SOC functions, threat detection and vulnerability management.
- Knowledge of cybersecurity frameworks such as NIST and MITRE ATT&CK.
- Excellent communication and stakeholder-management skills, with the ability to remain decisive and analytical under pressure.
Skills & Competencies
- Incident Response & Remediation
- SOC & Threat Detection
- Vulnerability Management
- Security Controls & EDR
- Patch Management
- Incident Response Playbooks & Workflows
- Cybersecurity Frameworks
- Stakeholder & Vendor Management
If you have not had any response in two weeks, please consider the vacancy application unsuccessful. Your profile will be kept on our database for any other suitable roles / positions.