SOC Analyst Level 2
Location: Johannesburg
Employment type: Permanent
Work model: Hybrid, normally three days on-site and two days remote
About Redherd
Redherd is a specialist technical cybersecurity recruitment company supporting organisations across South Africa and international markets. We connect experienced security professionals with technically challenging opportunities across security operations, incident response, offensive security, engineering and security leadership.
About the Client
Our client is an established South African cybersecurity and managed services provider supporting complex enterprise and regulated environments. Its services include security operations, incident response, threat hunting, penetration testing, security engineering and network services.
The company operates within a highly ethical, security-focused environment and places strong emphasis on professional development, technical training and recognised industry certifications. It is ISO 27001 certified and offers employees opportunities to develop their careers across different cybersecurity disciplines.
Role Overview
The SOC Analyst Level 2 will monitor, investigate and respond to security alerts and incidents across enterprise environments.
This is a hands-on, mid-level position for an analyst who can independently investigate common security incidents, correlate information from multiple security tools and determine whether an alert represents genuine malicious activity.
The role includes alert triage, incident classification, threat hunting, escalation, containment support, security reporting and recommending improvements to existing detection capabilities.
Key Responsibilities
- Monitor and investigate security alerts generated by SIEM, endpoint, network and cloud security technologies.
- Triage alerts and determine whether they represent genuine security incidents, suspicious activity or false positives.
- Classify incidents according to severity, business impact and established procedures.
- Conduct initial and intermediate investigations into phishing, malware, unauthorised access, suspicious authentication and other security events.
- Correlate information from multiple security tools, logs and threat‑intelligence sources.
- Identify potentially affected users, systems, applications and data.
- Execute approved containment and remediation actions.
- Escalate complex, high‑severity or unresolved incidents to senior analysts and relevant stakeholders.
- Maintain clear investigation timelines, case notes and supporting evidence.
- Participate in proactive threat‑hunting activities.
- Develop and test threat‑hunting hypotheses under the guidance of senior analysts.
- Identify suspicious activity that may not have triggered an automated security alert.
- Maintain an up‑to‑date understanding of emerging threats, vulnerabilities and attacker techniques.
- Follow established incident‑response playbooks and recommend improvements where required.
- Support tabletop exercises, attack simulations and detection assessments.
- Assist with determining whether simulated attacks generated the expected security alerts.
- Recommend new detection rules and security use cases based on investigation findings.
- Coordinate with security engineers and other technical teams during investigations.
- Contribute to security dashboards, incident metrics and operational reporting.
- Support the production of monthly incident and key risk indicator reports.
- Participate in post‑incident reviews and lessons‑learned activities.
Minimum Requirements
- A relevant three-year diploma or degree.
- At least two years of hands‑on cybersecurity or SOC experience.
- Practical experience investigating and responding to security alerts.
- Experience classifying, documenting and escalating security incidents.
- Working knowledge of incident containment, remediation and recovery processes.
- Experience using SIEM technologies.
- Practical exposure to Microsoft Sentinel.
- Understanding of SOAR technologies and automated response workflows.
- Good understanding of network technologies, protocols and access controls.
- Knowledge of endpoint, network and cloud security technologies.
- Understanding of enterprise IT infrastructure.
- Ability to analyse logs and correlate information from multiple security sources.
- Strong technical investigation and problem‑solving skills.
- Clear written and verbal communication skills.
Advantageous Experience
- Practical threat‑hunting experience.
- Microsoft Azure security environments.
- Kusto Query Language.
- Microsoft Defender security products.
- Threat intelligence platforms and feeds.
- Endpoint detection and response tools.
- Network traffic analysis.
- Detection engineering or security use‑case development.
- Incident‑response playbook development.
- Tabletop exercises and attack simulations.
- Red‑team or purple‑team detection validation.
- Security dashboard and operational reporting.
Personal Attributes
- High levels of honesty, integrity and professional ethics.
- Comfortable handling sensitive information.
- Customer‑focused and professional in stakeholder interactions.
- Able to prioritise and manage multiple alerts and investigations.
- Self‑motivated and willing to develop technical knowledge.
- Able to apply technical concepts to practical security problems.
- Comfortable asking for guidance and escalating incidents when required.
- Dependable, professional and punctual.
- Able to work effectively as part of a collaborative security team.
Work Arrangement
The position is based in Johannesburg and ordinarily requires three days per week on‑site. Increased on‑site attendance may be required during onboarding, major incidents or when operational requirements demand it.
Candidates must therefore be based in Johannesburg or able to commute reliably to the required work location.
Background Verification
The successful candidate must be willing to complete the background, employment, qualification and related verification checks required for work within sensitive and regulated environments.
Benefits and Development
The employment package includes:
- Medical aid.
- Gap cover.
- Provident fund covering retirement and risk benefits.
- 18 days of annual leave.
- Annual leave increasing to 21 days after three years.
- One birthday leave day during the employee’s birthday month.
- Employer-supported professional development.
- Funding for relevant training, certifications and qualifications.