Principal Security & Detection Engineer

Integrity360

Johannesburg

Hybrid

ZAR 900,000 - 1,500,000

Full time

35 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Integrity360 is seeking a Principal Security & Detection Engineer to provide senior technical leadership across our Security Operations capability, focusing on detection engineering, security research, SOC automation, threat hunting, and the fraud monitoring platform.

The role combines hands-on security engineering, software development and automation with autonomy, ownership, and collaboration across cross‑functional teams to deliver repeatable, scalable security capabilities.

Qualifications

  • Minimum 3 years of professional experience in cybersecurity, software development, or a combination of both with a strong security focus.
  • Demonstrated experience developing software, automation or security tooling.
  • Strong Python development capability.

Responsibilities

  • Develop and maintain security detections across the technology stack.
  • Execute hypothesis-driven threat hunts and translate attacker TTPs into practical detections.
  • Map capabilities to MITRE ATT&CK and identify coverage gaps.
  • Lead the development of the fraud and abuse monitoring platform.
  • Design analytics, detection logic, and integrations to identify abuse patterns within business applications.
  • Design and develop automation to improve SOC efficiency.
  • Build automated enrichment, investigation, and response workflows (SOAR playbooks).
  • Conduct independent research into emerging threats, vulnerabilities, and attack techniques.

Skills

Python development
Threat hunting
Security monitoring
SIEM
Security automation
Networking knowledge

Education

Relevant degree or diploma

Tools

SIEM platforms
EDR/XDR
SOAR tooling
Security integrations

Job description

Title: Principal Security & Detection Engineer

Job type: Full-Time Permanent

Working arrangement: 3 days a week onsite/hybrid. No

Salary: Negotiable / DOE

About Us

Integrity360 is a leading independent cybersecurity and PCI specialist operating across Europe, Africa, the Caribbean, and North America. The company has office locations in Ireland, the UK, Bulgaria, Italy, Sweden, Spain, Lithuania, Ukraine, Africa, the Caribbean, and Canada, supported by seven Security Operations Centres (SOCs) located in Dublin, Sofia, Madrid, Stockholm, Rome, Johannesburg and Cape Town.

With over 780 employees, including more than 585 dedicated cybersecurity professionals, Integrity360 delivers a full suite of professional, support, and managed security services. These span the complete cyber risk lifecycle, from identification and prevention to detection, response, and recovery. Integrity360 supports over 3000 mid-market and enterprise organisations across sectors including financial services, insurance, government, healthcare, retail, telecommunications, and utilities.

At Integrity360, people come first. We invest heavily in learning, development and progression, fostering a dynamic culture where innovation, collaboration and continuous growth are at the heart of what we do. If you're ready to take your cyber security career to the next level, we’d love to hear from you.

Job Role / Responsibilities

As a Principal Security & Detection Engineer, you will provide senior technical leadership across our Security Operations capability, with a particular focus on detection engineering, security research, SOC automation, threat hunting, and the continued development of our fraud monitoring platform.

This is a highly technical role for an individual who is comfortable operating with a high degree of autonomy and taking ownership of complex technical problems from concept through to implementation.

You will operate as a senior member of the technical leadership team, helping define the direction of our detection and research capabilities while continuing to work hands‑on across security engineering, software development, research and automation.

The ideal candidate is equally comfortable investigating how a new attack technique works, reproducing an exploit in a controlled environment, writing software to automate a security process, developing a new detection, and turning that work into a repeatable capability for the wider SOC.

This is not a traditional SOC monitoring or incident‑response role. The focus is on building and improving the technology, methodologies and intelligence that enable the SOC to operate more effectively.

Key Responsibilities
  • Detection Engineering & Threat Hunting
    • Develop and maintain security detections across the technology stack.
    • Execute hypothesis-driven threat hunts and translate attacker TTPs into practical detections.
    • Map capabilities to MITRE ATT&CK and identify coverage gaps.
  • Fraud Monitoring Platform Development
    • Lead the development of the fraud and abuse monitoring platform.
    • Design analytics, detection logic, and integrations to identify abuse patterns within business applications.
  • Security Automation & SOAR
    • Design and develop automation to improve SOC efficiency.
    • Build automated enrichment, investigation, and response workflows (SOAR playbooks).
  • Security Research & Development
    • Conduct independent research into emerging threats, vulnerabilities, and attack techniques.
    • Reproduce exploits in a controlled environment to validate findings.
Technical Leadership & Autonomy
  • Provide technical leadership and establish standards for engineering activities.
  • Conduct quality reviews and act as a senior technical decision-maker.
  • Operate with a high degree of autonomy, owning projects from concept to implementation.
Technical Environment
  • SIEM
  • EDR/XDR technologies
  • SOAR and security automation
  • Threat hunting
  • Vulnerability research and exploitation
  • Network security and networking technologies
  • Python
  • SQL
  • APIs and system integrations
Required Experience & Skills
  • Minimum 3 years of professional experience in cybersecurity, software development, or a combination of both with a strong security focus.
  • Demonstrated experience developing software, automation or security tooling.
  • Strong Python development capability.
  • Strong understanding of security monitoring and detection engineering.
  • Experience working with SIEM, security analytics and large-scale security telemetry.
  • Experience designing and developing integrations between security platforms and other systems.
  • Strong understanding of networking and network security principles.
  • Ability to translate security research into practical detections, automation or engineering solutions.
  • Strong analytical and problem-solving ability.
  • Excellent technical documentation skills.
  • Ability to work independently with minimal supervision.
  • Demonstrated initiative and a willingness to research unfamiliar technologies and problems.
  • Ability to manage multiple technical projects and prioritise work effectively.
Certifications/Qualifications
  • A relevant degree, diploma or equivalent formal qualification is preferred.
  • However, demonstrated professional experience and technical capability will be considered equally important. Candidates who can demonstrate strong practical cybersecurity or software-development experience without a traditional academic background will be considered.
  • Industry certifications are not a primary requirement for this position. Demonstrated technical ability, initiative, engineering capability and practical experience are more important.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal Security & DevOps Engineer
Principal Security & DevOps Engineer

Integrity360 • Johannesburg

Hybrid
ZAR 1,200,000 - 2,000,000
L3 SOC Analyst - Cape Town
L3 SOC Analyst - Cape Town

Integrity360 • Cape Town

On-site
ZAR 600,000 - 800,000
L3 SOC Analyst - Johannesburg
L3 SOC Analyst - Johannesburg

Jobless • Johannesburg

On-site
ZAR 600,000 - 900,000
L3 SOC Analyst - Johannesburg
L3 SOC Analyst - Johannesburg

Integrity360 • Johannesburg

On-site
ZAR 600,000 - 900,000
Senior Security & Detection Engineer - Threat Hunting
Senior Security & Detection Engineer - Threat Hunting

Integrity360 • Johannesburg

Hybrid
ZAR 900,000 - 1,500,000
Senior Security Analyst
Senior Security Analyst

Interfront SOC • Somerset West

Hybrid
ZAR 900,000 - 1,300,000
Hybrid working conditions
Open to people with disabilities
Hybrid Principal Security & DevOps Engineer
Hybrid Principal Security & DevOps Engineer

Integrity360 • Johannesburg

Hybrid
ZAR 1,200,000 - 2,000,000
Security Defence & Operations Lead
Security Defence & Operations Lead

Salix Recruitment • Gauteng

On-site
ZAR 1,200,000 - 1,900,000
Senior Cybersecurity Engineer - Compliance & Technology
Senior Cybersecurity Engineer - Compliance & Technology

ATS Client • Sandton

On-site
ZAR 900,000 - 1,600,000
Principal Cyber Security Specialist - Blue Team
Principal Cyber Security Specialist - Blue Team

Cyberlogic • Wes-Kaap

Hybrid
ZAR 900,000 - 1,800,000