Cyber Risk Incident Manager

Salix Recruitment

Gauteng

On-site

ZAR 900,000 - 1,500,000

Full time

42 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Salix Recruitment is seeking an experienced Cyber Risk Incident Manager for a longstanding South African organisation with a global footprint. You will lead incident response within a SOC environment and drive remediation across IT and security teams.

You will own containment, coordinate vulnerability management, and oversee cross-functional collaboration with DevSecOps, Risk & Compliance, Service Desk and IT Infrastructure to strengthen security resilience.

Qualifications

  • Six to ten years in cybersecurity operations.
  • Hands-on incident response and threat remediation.
  • Experience with SOC, virtual or outsourced SOC.

Responsibilities

  • Lead remediation and resolution of incidents identified by the SOC.
  • Coordinate vulnerability remediation and patch management across IT teams.
  • Track and ensure vulnerabilities are resolved within set timelines.
  • Maintain EDR and network segmentation controls.
  • Develop and maintain incident response playbooks and workflows.
  • Improve SOC alert handling and reporting to reduce false positives.
  • Monitor third-party SOC and security providers against SLAs.
  • Collaborate with IT, Service Desk, DevSecOps, and Risk & Compliance.
  • Verify incident closure and patching work; support audits.

Skills

Incident response leadership
SOC operations
EDR and network security
Threat remediation
Vulnerability management
Patch management
Strong communication

Education

Bachelor’s degree (Info Sec / CS / IT)
Matric (Grade 12)

Tools

SAP
Active Directory
Hybrid Cloud

Job description

We are looking for an experienced Cyber Risk Incident Manager with a strong knowledge in Microsoft house and proven experience within Security Operations Centre environment.

Our client is a 100+ year-old South African organisation with a global footprint operating across complex industrial environments where technology, security and operational resilience are critical to business success. With a strong focus on protecting its digital infrastructure and managing cyber risk, the organisation is continuing to strengthen its cybersecurity capabilities.

Beyond the technical requirements, we need someone who takes ownership when a security incident occurs. You should be decisive under pressure, analytical when assessing threats and comfortable coordinating multiple technical teams towards resolution. You will need to be a strong communicator who can work across SOC, IT Infrastructure, Service Desk, DevSecOps, Risk & Compliance and external security providers, while continuously looking for ways to improve security processes and controls.

This is more than a cybersecurity operations role - it’s an opportunity to take ownership of an organisation’s cyber defence, lead critical incident response and vulnerability remediation, and directly influence its security resilience. If you’re ready to move beyond monitoring threats and take the lead in how they are contained, remediated and prevented, this is your opportunity to make an impact.

Duties:
  • Lead the remediation and resolution of cybersecurity incidents identified by the Security Operations Centre (SOC), ensuring effective containment and recovery.
  • Coordinate vulnerability remediation and patch management across IT and infrastructure teams.
  • Track, prioritise and ensure vulnerabilities are resolved within agreed timelines.
  • Maintain and optimise Endpoint Detection & Response (EDR) and network segmentation controls.
  • Develop and maintain incident response playbooks, procedures and operational workflows.
  • Optimise SOC alert-handling and reporting processes to improve response efficiency and reduce false positives.
  • Monitor and manage the performance of third-party SOC, vulnerability management and security service providers against agreed SLAs.
  • Collaborate with IT Infrastructure, Service Desk, Application Security, DevSecOps and Risk & Compliance teams to strengthen the organisation’s security posture.
  • Verify that security incidents and patching activities have been effectively resolved and completed.
  • Support security audits, regulatory requirements and adherence to recognised cybersecurity frameworks.
Job Experience & Skills Required:
Qualifications:
  • Matric (Grade 12)
  • Bachelor’s degree in information security, Computer Science, Information Technology or a related field
  • Industry-recognised cybersecurity certifications such as CISSP, GCIH, CEH, CompTIA Security+ or CySA+ will be advantageous.
  • Microsoft security certifications such as SC-200, SC-300 or SC-900 will be advantageous.
Experience:
  • 6–10 years’ progressive experience in cybersecurity operations.
  • Hands-on experience in incident response and threat remediation.
  • Proven experience working with or managing a Security Operations Centre (SOC), preferably a virtual or outsourced SOC.
  • Strong experience in vulnerability management, patch management and remediation coordination.
  • Experience maintaining and optimising EDR, endpoint protection and network security controls.
  • Proven ability to develop and implement incident response playbooks and operational workflows.
  • Experience managing or working with third-party security service providers and MSSPs.
  • Exposure to enterprise IT environments, with SAP, Active Directory and hybrid cloud infrastructure experience advantageous.
Skills & Competencies:
  • Strong incident response and remediation leadership skills.
  • In-depth understanding of SOC operations, threat detection and vulnerability management.
  • Strong knowledge of endpoint protection, EDR and network security architecture.
  • Understanding of cybersecurity frameworks such as NIST and MITRE ATT&CK.
  • Strong analytical and problem-solving abilities, with exceptional attention to detail.
  • Ability to remain proactive and decisive under pressure, particularly during security incidents.
  • Strong communication and collaboration skills across technical and non-technical teams.
  • High level of accountability and ownership for operational security outcomes.
  • Continuous improvement mindset with the ability to identify and implement more efficient security processes and controls.
  • Strong technical writing skills, particularly for security procedures, playbooks and response documentation.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Defence & Operations Lead
Security Defence & Operations Lead

Salix Recruitment • Gauteng

On-site
ZAR 1,200,000 - 1,900,000
Security Defence & Operations Lead
Security Defence & Operations Lead

Salix Recruitment • City of Johannesburg Metropolitan Municipality

On-site
ZAR 900,000 - 1,500,000
Cyber Security Operations Manager
Cyber Security Operations Manager

Placements24 • Gauteng

On-site
ZAR 900,000 - 1,500,000
Competitive pay with incentives
Health benefits
Security training & development
+2
Security Defence and Operations Lead
Security Defence and Operations Lead

Network Finance • Randburg

On-site
ZAR 900,000 - 1,500,000
Security Operations Engineer
Security Operations Engineer

Parvana • Cape Town

Hybrid
ZAR 600,000 - 900,000
Security Operations Engineer
Security Operations Engineer

Parvana • South Africa

Hybrid
ZAR 700,000 - 900,000
Hybrid work model
Career development
Senior Security Analyst
Senior Security Analyst

Interfront SOC • Somerset West

Hybrid
ZAR 900,000 - 1,300,000
Hybrid working conditions
Open to people with disabilities
Senior Security Analyst
Senior Security Analyst

Sabenza IT & Recruitment • Cape Town

On-site
ZAR 700,000 - 1,100,000
Senior Security Analyst
Senior Security Analyst

Sabenza IT & Recruitment • Eersterivier

On-site
ZAR 900,000 - 1,500,000
Security Analyst
Security Analyst

Adapt IT Group • Midrand

On-site
ZAR 600,000 - 900,000