Technical Lead – SOC Cyber Defense (iOCO0083)
ioco
Johannesburg, Gauteng
Job description
What you'll do:
-
Define and execute a structured hypothesis-driven threat hunting programme aligned to MITRE ATT&CK TTPs relevant to client industries.
-
Oversee a hunt cadence (weekly/monthly) with documented hypotheses, datasets queried, findings, and new detections produced.
-
Track hunt effectiveness metrics: hunts executed, TTPs covered, detections created, threats uncovered, dwell time reduction.
-
Drive proactive identification of stealthy, low-signal threats (LOLBins, identity abuse, persistence, lateral movement).
-
Ensure hunt outcomes feed back into detection engineering, playbooks, and threat intel for continuous improvement.
-
Govern the detection lifecycle - ideation, development, testing, deployment, tuning, retirement.
-
Reviewing versioned detection library (LQL - Logpoint Query Language) mapped to MITRE ATT&CK with coverage scoring.
-
Drive measurable improvement in detection coverage % per tactic/technique, per client environment.
-
Drive the Reduction in false positives and alert fatigue (signal-to-noise ratio, precision/recall metrics per rule).
-
Ensure detections are tested via purple team / atomic red team / BAS tools before production release.
-
Review detection-as-code practices (Python)
-
Oversee L1/L2 analyst quality depth of investigation, accuracy of triage, and quality of incident write-ups.
-
Govern incident analysis standards (timelines, IOC pivoting, scope determination, attribution where relevant).
-
Ensure root cause analysis (RCA) and lessons learned are captured and converted into preventative controls.
-
Work with SOC OPS Manager to Maintain playbooks for top threat scenarios (ransomware, BEC, identity compromise, data exfiltration).
-
Drive analyst skill uplift through case reviews, mentoring, and structured training paths.
-
Operate a structured CTI capability across strategic, operational, and tactical levels.
-
Track threat actor groups, campaigns, and TTPs relevant to the organisation and client base.
-
Ensure CTI informs risk decisions, vulnerability prioritisation, and board reporting.
- Monitor geopolitical, regulatory, and industry events that may translate into cyber risk (POPIA, sanctions, hacktivism).
- Track exposure to active campaigns and trigger proactive defensive actions.
- Maintain real-time situational awareness of the threat landscape – global, regional (Africa/SA), and sector-specific.
- Maintain transparent metrics on detection coverage, hunt outcomes, intel value, and research impact.
-
Provide daily/weekly intel briefings to SOC Manager
-
Govern effective use of GuardSix, EDR (WithSecure), email security (Mimecast), Zscaler, and supporting platforms for detection and hunting.
-
Ensure log source coverage and data quality required for hunting and analytics
-
Review KOUEBA, identity analytics, and behavioural detections beyond signature-based controls. (Align with L3)
-
Maintain audit-ready documentation: hunt records, detection change logs, intel reports, research artefacts.
-
Ensure ethical handling of intel, OSINT, and research (legal, privacy, and disclosure boundaries respected).
-
Contribute to enterprise risk register with threat-informed risk inputs.
-
Manage and grow a multi-disciplinary team (hunters, detection engineers, analysts, intel analysts, researchers).
-
Participate/Facilitate internal purple team exercises, CTFs, and tabletop scenarios to build muscle memory.
-
Contribute to threat-informed reporting to CISO, exec, and clients not just volumes, but business-relevant insight.
-
Translate technical threat data into business risk language (impact, likelihood, exposure, recommended action).
-
Provide quarterly threat landscape and defensive posture reviews to leadership and key clients.
-
Partner closely with SOC Operations Manager (feed detections/playbooks), Exposure and Vulnerability Management (intel-led prioritisation), IR (threat context), and GRC (risk inputs).
-
Engage with client CISOs and security teams on threat briefings and joint exercises.
-
Drive measurable year-on-year improvement in detection coverage, hunt yield, and intel-driven outcomes.
Your Expertise:
-
8–12+ years' experience in Cybersecurity Operations.
-
5+ years' experience in Threat Hunting, Detection Engineering, Threat Intelligence, Incident Response, or Advanced SOC Operations.
-
Proven experience leading Threat Hunting, Detection Engineering, CTI, and SOC Analysis teams.
-
Experience operating within enterprise or MSSP security environments.
-
Experience building and managing detection programs mapped to MITRE ATT&CK.
-
Experience developing and tuning SIEM detection use cases.
-
Experience performing advanced threat investigations involving:
- Identity compromise
- Ransomware
- Business Email Compromise (BEC)
- Data exfiltration
- Insider threats
- Cloud attacks
- Lateral movement
- LOLBins and living-off-the-land techniques
-
Experience presenting threat intelligence and security risks to executive leadership and clients.
-
Experience managing threat-informed security programs and continuous improvement initiatives.
Qualifications:
-
Qualification Essential Competency
-
Strong practical experience with:
- SIEM Platforms (e.g Logpoint, Sentinel, Splunk, QRadar, ArcSight)
- EDR/XDR Platforms (e.g. WithSecure, CrowdStrike, Defender, SentinelOne)
- SOAR Platforms
- Vulnerability Management Platforms
- Identity Security Solutions
- UEBA Platforms
- Cloud Security Controls
- Threat Intelligence Platforms (TIP)
- MITRE ATT&CK
- CIS/NIST Cyber Security Framework
- Cyber Threat Intelligence Lifecycle
- Detection Engineering Frameworks
- Threat Modelling
-
Qualifications preferred/ knowledge
- CTIA (Certified Threat Intelligence Analyst)
- CREST CRT
- CREST CCTIM
Other information applicable to the opportunity:
- Permanent position
- Location: Johanesburg
- Physical: Demands Sitting
- Travel: Own Transport
Why work for us?
Want to work for an organization that solves complex real-world problems with innovative software solutions? At iOCO, we believe anything is possible with modern technology, software, and development expertise. We are continuously pushing the boundaries of innovative solutions across multiple industries using an array of technologies.?
You will be part of a consultancy, working with some of the most knowledgeable minds in the industry on interesting solutions across different business domains.?
Our culture of continuous learning will ensure that you will have all the opportunities, tools, and support to hone and grow your craft.?
By joining IOCO you will have an open invitation to developer inspiring forums. A place where you will be able to connect and learn from and with your peers by sharing ideas, experiences, practices, and solutions.?
iOCO is an equal opportunity employer with an obligation to achieve its own unique EE objectives in the context of Employment Equity targets. Therefore, our employment strategy gives primary preference to previously disadvantaged individuals or groups.
Good to know
How do I apply for this job?
Tap "Apply on Indeed" to open the original listing, where you can read the full description and apply directly. JobsZA never charges you to apply, and you should never pay money to get a job.
Found on Indeed · Posted 3 days ago