Technical Lead – SOC Cyber Defense (iOCO0083)

iOCO · Johannesburg, Gauteng

Stop applying one at a time.

JobAlertsZA auto-applies to South African jobs like this one for you, overnight. Upload your CV once — we do the applying.

Start free — we apply for you →

Job Description What you'll do:

  • Define and execute a structured hypothesis-driven threat hunting programme aligned to MITRE ATT&CK TTPs relevant to client industries.
  • Oversee a hunt cadence weekly/monthly with documented hypotheses, datasets queried, findings, and new detections produced.
  • Track hunt effectiveness metrics: hunts executed, TTPs covered, detections created, threats uncovered, dwell time reduction.
  • Drive proactive identification of stealthy, low-signal threats LOLBins, identity abuse, persistence, lateral movement.
  • Ensure hunt outcomes feed back into detection engineering, playbooks, and threat intel for continuous improvement.
  • Govern the detection lifecycle - ideation, development, testing, deployment, tuning, retirement.
  • Reviewing versioned detection library LQL - Logpoint Query Language mapped to MITRE ATT&CK with coverage scoring.
  • Drive measurable improvement in detection coverage % per tactic/technique, per client environment.
  • Drive the Reduction in false positives and alert fatigue signal-to-noise ratio, precision/recall metrics per rule.
  • Ensure detections are tested via purple team / atomic red team / BAS tools before production release.
  • Review detection-as-code practices Python
  • Oversee L1/L2 analyst quality depth of investigation, accuracy of triage, and quality of incident write-ups.
  • Govern incident analysis standards timelines, IOC pivoting, scope determination, attribution where relevant.
  • Ensure root cause analysis RCA and lessons learned are captured and converted into preventative controls.
  • Work with SOC OPS Manager to Maintain playbooks for top threat scenarios ransomware, BEC, identity compromise, data exfiltration.
  • Drive analyst skill uplift through case reviews, mentoring, and structured training paths.
  • Operate a structured CTI capability across strategic, operational, and tactical levels.
  • Track threat actor groups, campaigns, and TTPs relevant to the organisation and client base.
  • Ensure CTI informs risk decisions, vulnerability prioritisation, and board reporting.
  • Monitor geopolitical, regulatory, and industry events that may translate into cyber risk POPIA, sanctions, hacktivism.
  • Track exposure to active campaigns and trigger proactive defensive actions.
  • Maintain real-time situational awareness of the threat landscape – global, regional Africa/SA, and sector-specific.
  • Maintain transparent metrics on detection coverage, hunt outcomes, intel value, and research impact.
  • Provide daily/weekly intel briefings to SOC Manager
  • Govern effective use of GuardSix, EDR WithSecure, email security Mimecast, Zscaler, and supporting platforms for detection and hunting.
  • Ensure log source coverage and data quality required for hunting and analytics
  • Review KOUEBA, identity analytics, and behavioural detections beyond signature-based controls. Align with L3
  • Maintain audit-ready documentation: hunt records, detection change logs, intel reports, research artefacts.
  • Ensure ethical handling of intel, OSINT, and research legal, privacy, and disclosure boundaries respected.
  • Contribute to enterprise risk register with threat-informed risk inputs.
  • Manage and grow a multi-disciplinary team hunters, detection engineers, analysts, intel analysts, researchers.
  • Participate/Facilitate internal purple team exercises, CTFs, and tabletop scenarios to build muscle memory.
  • Contribute to threat-informed reporting to CISO, exec, and clients not just volumes, but business-relevant insight.
  • Translate technical threat data into business risk language impact, likelihood, exposure, recommended action.
  • Provide quarterly threat landscape and defensive posture reviews to leadership and key clients.
  • Partner closely with SOC Operations Manager feed detections/playbooks, Exposure and Vulnerability Management intel-led prioritisation, IR threat context, and GRC risk inputs.
  • Engage with client CISOs and security teams on threat briefings and joint exercises.
  • Drive measurable year-on-year improvement in detection coverage, hunt yield, and intel-driven outcomes.

Your Expertise

  • 8–12+ years' experience in Cybersecurity Operations.
  • 5+ years' experience in Threat Hunting, Detection Engineering, Threat Intelligence, Incident Response, or Advanced SOC Operations.
  • Proven experience leading Threat Hunting, Detection Engineering, CTI, and SOC Analysis teams.
  • Experience operating within enterprise or MSSP security environments.
  • Experience building and managing detection programs mapped to MITRE ATT&CK.
  • Experience developing and tuning SIEM detection use cases.

Experience performing advanced threat investigations involving

  • Identity compromise
  • Ransomware
  • Business Email Compromise BEC
  • Data exfiltration
  • Insider threats
  • Cloud attacks
  • Lateral movement
  • LOLBins and living-off-the-land techniques
  • Experience presenting threat intelligence and security risks to executive leadership and clients.
  • Experience managing threat-informed security programs and continuous improvement initiatives.

Qualifications: Qualification Essential Competency Strong practical experience with:

  • SIEM Platforms e.g Logpoint, Sentinel, Splunk, QRadar, ArcSight
  • EDR/XDR Platforms e.g. WithSecure, CrowdStrike, Defender, SentinelOne
  • SOAR Platforms
  • Vulnerability Management Platforms
  • Identity Security Solutions
  • UEBA Platforms
  • Cloud Security Controls
  • Threat Intelligence Platforms TIP
  • MITRE ATT&CK
  • CIS/NIST Cyber Security Framework
  • Cyber Threat Intelligence Lifecycle
  • Detection Engineering Frameworks
  • Threat Modelling

Qualifications preferred/ knowledge

  • CTIA Certified Threat Intelligence Analyst
  • CREST CRT
  • CREST CCTIM
Auto-apply to this jobView original posting ↗