Security Operations Centre (SOC) Engineer (Permanent)

Recruit · Western Cape , CPT - CBD · (Market related, Negotiable)

Posted 31 July 2026

Stop applying one at a time.

JobAlertsZA auto-applies to South African jobs like this one for you, overnight. Upload your CV once — we do the applying.

Start free — we apply for you →

Job Title: Security Operations Centre (SOC) Engineer Start Date: 2026-07-31 - 2026-08-30 Vacancy Type: Permanent PE011680 Sectors: Information Technology Location: Western Cape , CPT - CBD Salary: (Market related, Negotiable) Brief: endpoint security tools|firewalls|identity and access management|microsoft 365 security|msp|soc 1st/2nd line|troubleshooting The SOC Engineer is responsible for security monitoring, incident triage and after-hours first-line service delivery for the company managed service clients. The role combines security operations with managed service delivery, ensuring that security events and technical issues are identified, assessed, documented, progressed and escalated appropriately. The SOC Engineer operates as part of the wider Service Delivery function, working closely with Service Desk Engineers and Service Delivery Management to provide reliable 24/7 support for contracted clients. Detail: What success looks like: Security alerts are monitored, assessed and responded to appropriately. Security incidents are accurately identified, documented and escalated. 24/7 clients receive consistent and professional after-hours support. Tickets and incidents have clear ownership and progression. Escalations contain sufficient technical context to enable efficient resolution. Security trends, recurring issues and risks are identified and reported. Core accountabilities: Security Monitoring & Incident Detection Continuously monitor security tools and alerting platforms. Review security alerts and determine appropriate action. Identify suspicious activity and potential threats. Escalate security concerns according to defined processes Security incident triage and response: Assess and validate security incidents. Perform initial investigation and impact assessment. Support containment activities within agreed processes. Maintain accurate incident records and investigation notes. Escalate incidents requiring additional expertise or authority. After-hours 1st line service desk coverage: Provide first-line support for contracted 24/7 clients outside standard business hours. Answer, log and categorise incoming requests. Perform basic troubleshooting and resolution within agreed capability. Progress tickets appropriately and maintain ownership. Escalate technical issues to senior engineers where required Escalation and handover management: Follow defined escalation routes for technical and security issues. Ensure escalations contain accurate information, troubleshooting completed and relevant context. Engage senior engineers and management when required based on impact or complexity. Support smooth handover between teams. Security and incident reporting Maintain accurate security and service documentation. Track security incidents, trends, and recurring issues. Contribute to incident reporting and service improvement activities. Identify opportunities to improve monitoring, processes and knowledge sharing. Key Performance Indicators (KPIs): Security and service performance: Security alerts and tickets responded to within agreed SLA After-hours client support delivered within agreed SLA Security incidents progressed within expected timescales Ownership and quality: 100% of tickets/incidents have clear ownership and next action Ticket and incident notes meet quality standards Reduction in avoidable rework or missed information Escalation management: Correct escalation of technical and security issues Quality of handovers to wider service desk team Issues escalated before becoming client-impacting Security improvement: Recurring issues identified and reported Contribution to security documentation, processes and knowledge sharing Team and capability development: Completion of agreed training and certifications Development of technical and security skills Technical requirements Essential: Experience within an IT support/service desk environment. Strong troubleshooting skills. Understanding of Microsoft environments. Experience working with tickets, priorities and SLAs. Good written and verbal communication skills. Interest in developing security capability Advantageous: Exposure to: Microsoft Defender Microsoft 365 security Endpoint security tools Firewalls Identity and access management Experience and development The ideal candidate will be a technically strong first-line engineer or junior second-line engineer looking to develop into security operations. Experience within an MSP environment is advantageous. Relevant certifications are beneficial but not essential including: CompTIA Security + Microsoft SC-900 Microsoft SC-200 MD-102 MS-102 CompTIA Network+ show more... For more information please contact: Thabisa Apply

Auto-apply to this jobView original posting ↗