Technical Lead – SOC Cyber Defense (iOCO0083)
iOCO · Johannesburg, Gauteng
Stop applying one at a time.
JobAlertsZA auto-applies to South African jobs like this one for you, overnight. Upload your CV once — we do the applying.
Start free — we apply for you →Job Description What you'll do:
- Define and execute a structured hypothesis-driven threat hunting programme aligned to MITRE ATT&CK TTPs relevant to client industries.
- Oversee a hunt cadence weekly/monthly with documented hypotheses, datasets queried, findings, and new detections produced.
- Track hunt effectiveness metrics: hunts executed, TTPs covered, detections created, threats uncovered, dwell time reduction.
- Drive proactive identification of stealthy, low-signal threats LOLBins, identity abuse, persistence, lateral movement.
- Ensure hunt outcomes feed back into detection engineering, playbooks, and threat intel for continuous improvement.
- Govern the detection lifecycle - ideation, development, testing, deployment, tuning, retirement.
- Reviewing versioned detection library LQL - Logpoint Query Language mapped to MITRE ATT&CK with coverage scoring.
- Drive measurable improvement in detection coverage % per tactic/technique, per client environment.
- Drive the Reduction in false positives and alert fatigue signal-to-noise ratio, precision/recall metrics per rule.
- Ensure detections are tested via purple team / atomic red team / BAS tools before production release.
- Review detection-as-code practices Python
- Oversee L1/L2 analyst quality depth of investigation, accuracy of triage, and quality of incident write-ups.
- Govern incident analysis standards timelines, IOC pivoting, scope determination, attribution where relevant.
- Ensure root cause analysis RCA and lessons learned are captured and converted into preventative controls.
- Work with SOC OPS Manager to Maintain playbooks for top threat scenarios ransomware, BEC, identity compromise, data exfiltration.
- Drive analyst skill uplift through case reviews, mentoring, and structured training paths.
- Operate a structured CTI capability across strategic, operational, and tactical levels.
- Track threat actor groups, campaigns, and TTPs relevant to the organisation and client base.
- Ensure CTI informs risk decisions, vulnerability prioritisation, and board reporting.
- Monitor geopolitical, regulatory, and industry events that may translate into cyber risk POPIA, sanctions, hacktivism.
- Track exposure to active campaigns and trigger proactive defensive actions.
- Maintain real-time situational awareness of the threat landscape – global, regional Africa/SA, and sector-specific.
- Maintain transparent metrics on detection coverage, hunt outcomes, intel value, and research impact.
- Provide daily/weekly intel briefings to SOC Manager
- Govern effective use of GuardSix, EDR WithSecure, email security Mimecast, Zscaler, and supporting platforms for detection and hunting.
- Ensure log source coverage and data quality required for hunting and analytics
- Review KOUEBA, identity analytics, and behavioural detections beyond signature-based controls. Align with L3
- Maintain audit-ready documentation: hunt records, detection change logs, intel reports, research artefacts.
- Ensure ethical handling of intel, OSINT, and research legal, privacy, and disclosure boundaries respected.
- Contribute to enterprise risk register with threat-informed risk inputs.
- Manage and grow a multi-disciplinary team hunters, detection engineers, analysts, intel analysts, researchers.
- Participate/Facilitate internal purple team exercises, CTFs, and tabletop scenarios to build muscle memory.
- Contribute to threat-informed reporting to CISO, exec, and clients not just volumes, but business-relevant insight.
- Translate technical threat data into business risk language impact, likelihood, exposure, recommended action.
- Provide quarterly threat landscape and defensive posture reviews to leadership and key clients.
- Partner closely with SOC Operations Manager feed detections/playbooks, Exposure and Vulnerability Management intel-led prioritisation, IR threat context, and GRC risk inputs.
- Engage with client CISOs and security teams on threat briefings and joint exercises.
- Drive measurable year-on-year improvement in detection coverage, hunt yield, and intel-driven outcomes.
Your Expertise
- 8–12+ years' experience in Cybersecurity Operations.
- 5+ years' experience in Threat Hunting, Detection Engineering, Threat Intelligence, Incident Response, or Advanced SOC Operations.
- Proven experience leading Threat Hunting, Detection Engineering, CTI, and SOC Analysis teams.
- Experience operating within enterprise or MSSP security environments.
- Experience building and managing detection programs mapped to MITRE ATT&CK.
- Experience developing and tuning SIEM detection use cases.
Experience performing advanced threat investigations involving
- Identity compromise
- Ransomware
- Business Email Compromise BEC
- Data exfiltration
- Insider threats
- Cloud attacks
- Lateral movement
- LOLBins and living-off-the-land techniques
- Experience presenting threat intelligence and security risks to executive leadership and clients.
- Experience managing threat-informed security programs and continuous improvement initiatives.
Qualifications: Qualification Essential Competency Strong practical experience with:
- SIEM Platforms e.g Logpoint, Sentinel, Splunk, QRadar, ArcSight
- EDR/XDR Platforms e.g. WithSecure, CrowdStrike, Defender, SentinelOne
- SOAR Platforms
- Vulnerability Management Platforms
- Identity Security Solutions
- UEBA Platforms
- Cloud Security Controls
- Threat Intelligence Platforms TIP
- MITRE ATT&CK
- CIS/NIST Cyber Security Framework
- Cyber Threat Intelligence Lifecycle
- Detection Engineering Frameworks
- Threat Modelling
Qualifications preferred/ knowledge
- CTIA Certified Threat Intelligence Analyst
- CREST CRT
- CREST CCTIM