Security Defence & Operations Lead

Salix Recruitment

Gauteng

On-site

ZAR 1,200,000 - 1,900,000

Full time

2 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Salix Recruitment is seeking a senior cybersecurity operations leader to join a global organisation. You will own incident response, threat remediation, vulnerability management and security controls across the Enterprise.

You will coordinate with the SOC, IT, risk, compliance and external security providers to protect against threats, reduce risk and improve resilience. The role demands hands-on expertise, calm under pressure and ownership when incidents occur.

Qualifications

  • 6 - 10 years of progressive experience in cybersecurity operations, including hands‑on incident response and threat remediation.
  • Bachelor’s degree in Information Security, Computer Science, Information Technology or a related field.
  • Relevant certifications such as CISSP, GCIH, CEH, CompTIA Security+ or CySA+ are highly relevant.

Responsibilities

  • Lead the remediation and recovery of security incidents identified by the virtual Security Operations Centre (SOC).
  • Coordinate vulnerability management and remediation across IT and infrastructure teams.
  • Drive patch management and ensure vulnerabilities are tracked, prioritised and resolved.
  • Maintain and optimise Endpoint Detection & Response (EDR) and network segmentation controls.
  • Review security incidents, patching activity and remediation effectiveness.
  • Optimise SOC alert handoffs, workflows and reporting to improve response times and reduce false positives.
  • Develop and maintain practical incident response playbooks and operational procedures.
  • Manage and monitor third‑party SOC, vulnerability management and security service providers against agreed SLAs.
  • Support continuous improvement of the organisation’s security controls, processes and operational resilience.
  • Ensure security operations align with relevant security baselines, frameworks and compliance requirements.

Skills

Incident Response
Threat Remediation
SOC Operations
Vulnerability Management
Patch Management
EDR
Security Controls
Network Segmentation
Cybersecurity Frameworks
Stakeholder Management

Education

Bachelor’s degree
Matric (Grade 12)

Tools

Microsoft Defender for Endpoint
Microsoft Sentinel
Microsoft 365 security tools
SC-200
SC-300
SC-900

Job description

Join a global organisation with a diverse and complex technology environment, where cybersecurity is critical to protecting the business and enabling its continued growth.

This is a key role within Group Information Security, responsible for ensuring that cyber threats are identified, contained and remediated quickly, while strengthening the organisation’s security controls and reducing overall cyber risk.

You’ll work closely with the SOC, IT Infrastructure & Operations, Service Desk, DevSecOps, Risk & Compliance teams and external security providers to ensure the organisation remains protected against an evolving threat landscape.

You are a decisive, analytical and hands‑on security professional who stays calm under pressure and takes ownership when incidents occur.

You can translate technical security requirements into practical action, collaborate effectively with both technical and non-technical stakeholders, and continuously look for ways to improve security operations and response capabilities.

Why this opportunity?

This is an opportunity to play a critical role in protecting a large enterprise environment, leading security defence and operations while helping shape stronger incident response, vulnerability management and security controls.

If you have the technical depth, operational leadership and cyber resilience mindset to take ownership of an organisation’s security defence - we want to hear from you.

Duties:
  • Lead the remediation and recovery of security incidents identified by the virtual Security Operations Centre (SOC).
  • Coordinate vulnerability management and remediation across IT and infrastructure teams.
  • Drive patch management and ensure vulnerabilities are tracked, prioritised and resolved.
  • Maintain and optimise Endpoint Detection & Response (EDR) and network segmentation controls.
  • Review security incidents, patching activity and remediation effectiveness.
  • Optimise SOC alert handoffs, workflows and reporting to improve response times and reduce false positives.
  • Develop and maintain practical incident response playbooks and operational procedures.
  • Manage and monitor third‑party SOC, vulnerability management and security service providers against agreed SLAs.
  • Support continuous improvement of the organisation’s security controls, processes and operational resilience.
  • Ensure security operations align with relevant security baselines, frameworks and compliance requirements.
Job Experience & Skills Required:
Qualifications:
  • Matric (Grade 12)
  • Bachelor’s degree in Information Security, Computer Science, Information Technology or a related field.
  • CISSP, GCIH, CEH, CompTIA Security+/CySA+ or relevant Microsoft security certifications are highly relevant.
  • Microsoft SC-200, SC-300 and SC-900, together with experience using Microsoft Defender for Endpoint, Microsoft Sentinel and Microsoft 365 security tools.
Experience:
  • 6 - 10 years of progressive experience in cybersecurity operations, including hands‑on incident response and threat remediation.
Skills & Competencies:
  • Incident Response & Threat Remediation
  • SOC Operations & Threat Detection
  • Vulnerability Management & Remediation
  • Patch Management
  • Endpoint Detection & Response (EDR)
  • Security Controls & Network Segmentation
  • Cybersecurity Frameworks - NIST & MITRE ATT&CK
  • Stakeholder & Third‑Party Security Provider Management
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Associate Information Security Analyst
Senior Associate Information Security Analyst

Recruit-It • Gauteng

On-site
ZAR 900,000 - 1,300,000
L3 SOC Analyst - Cape Town
L3 SOC Analyst - Cape Town

Integrity360 • Cape Town

On-site
ZAR 600,000 - 800,000
L3 SOC Analyst - Johannesburg
L3 SOC Analyst - Johannesburg

Jobless • Johannesburg

On-site
ZAR 600,000 - 900,000
Senior Cybersecurity Engineer - Compliance & Technology
Senior Cybersecurity Engineer - Compliance & Technology

ATS Client • Sandton

On-site
ZAR 900,000 - 1,600,000
IT Security Specialist Talent Pool
IT Security Specialist Talent Pool

Mr Price Group • Durban

On-site
ZAR 600,000 - 800,000
ITSA: Senior Associate Information Security Analyst
ITSA: Senior Associate Information Security Analyst

Recruit-It • Gauteng

On-site
ZAR 700,000 - 1,000,000
IT Security Manager
IT Security Manager

Performit Personnel • Gqeberha

On-site
ZAR 600,000 - 900,000
Security Operations Centre (SOC) Engineer
Security Operations Centre (SOC) Engineer

Recruit-It • Wes-Kaap

On-site
ZAR 180,000 - 240,000
Global Cyber Defense & Incident Response Lead
Global Cyber Defense & Incident Response Lead

Salix Recruitment • Gauteng

On-site
ZAR 1,200,000 - 1,900,000
Information Security Officer
Information Security Officer

Dots Africa • Midrand

On-site
ZAR 600,000 - 800,000
Competitive Compensation
Generous paid time off
Wellness program
+1