Senior SOC Threat Hunting & Detection Lead

iOCO

Gauteng

On-site

ZAR 1,000,000 - 1,500,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

iOCO in Johannesburg is seeking a senior Cyber Security professional to lead a threat hunting program aligned to MITRE ATT&CK, working with SIEMs, EDR, and threat intel to reduce dwell time and improve detection coverage.

You will mentor analysts, drive purple-team exercises, and ensure risk-informed decisions are communicated to leadership and clients.

This permanent role offers continuous learning and opportunities to influence security across industries.

Qualifications

  • 8–12+ years' experience in Cybersecurity Operations.
  • 5+ years' experience in Threat Hunting, Detection Engineering, Threat Intelligence, Incident Response, or Advanced SOC Operations.
  • Proven experience leading Threat Hunting, Detection Engineering, CTI, and SOC Analysis teams.
  • Experience building and managing detection programs mapped to MITRE ATT&CK.
  • Experience developing and tuning SIEM detection use cases.

Responsibilities

  • Define and execute a structured hypothesis-driven threat hunting programme aligned to MITRE ATTACK TTPs for client industries.
  • Oversee a hunt cadence with documented hypotheses, datasets queried, findings, and new detections produced.
  • Track hunt effectiveness metrics: hunts executed, TTPs covered, detections created, threats uncovered, dwell time reduction.
  • Drive proactive identification of stealthy threats (LOLBins, identity abuse, persistence, lateral movement).
  • Ensure hunt outcomes feed back into detection engineering, playbooks, and threat intel for continuous improvement.
  • Govern the detection lifecycle - ideation, development, testing, deployment, tuning, retirement.

Skills

Threat Hunting
Detection Engineering
Threat Intelligence
Incident Response
SOC Operations
MITRE ATT&CK
SIEM
EDR/XDR
Leadership
Executive Communication

Education

CTIA
CREST CRT
CREST CCTIM

Tools

Logpoint SIEM
Microsoft Sentinel
Splunk
QRadar
ArcSight
WithSecure EDR
CrowdStrike
Microsoft Defender
SentinelOne
SOAR Platforms
Vulnerability Management
Identity Security
UEBA
Cloud Security
TIP
MITRE ATT&CK

Job description

iOCO in Johannesburg is seeking a senior Cyber Security professional to lead a threat hunting program aligned to MITRE ATT&CK, working with SIEMs, EDR, and threat intel to reduce dwell time and improve detection coverage.

You will mentor analysts, drive purple-team exercises, and ensure risk-informed decisions are communicated to leadership and clients.

This permanent role offers continuous learning and opportunities to influence security across industries.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior SOC Analyst – Threat Hunting & Incident Response
Senior SOC Analyst – Threat Hunting & Incident Response

Redherd.Io • Johannesburg

Hybrid
ZAR 900,000 - 1,200,000
Medical aid
Gap cover
Provident fund
+4
Technical Lead – SOC Cyber Defense (iOCO0083)
Technical Lead – SOC Cyber Defense (iOCO0083)

iOCO • Gauteng

On-site
ZAR 1,000,000 - 1,500,000
Senior Cybersecurity Analyst - Threat Intelligence
Senior Cybersecurity Analyst - Threat Intelligence

Placements24 • Cape Town

Hybrid
ZAR 810,000 - 990,000
Salary incentives
Medical benefits
Retirement benefits
+3
Cybersecurity Threat Hunter
Cybersecurity Threat Hunter

Placements24 • Mtubatuba Local Municipality

Hybrid
ZAR 600,000 - 1,000,000
Competitive salary package
Comprehensive medical aid
Retirement savings plans
+2
Senior SOC Analyst: Lead Incident Response & Hunting
Senior SOC Analyst: Lead Incident Response & Hunting

Afrocentric IP • South Africa

On-site
ZAR 700,000 - 900,000
Senior Cybersecurity Analyst - Threat Detection
Senior Cybersecurity Analyst - Threat Detection

Placements24 • Benoni

Hybrid
ZAR 900,000 - 1,200,000
Bonuses
Hybrid work
Health insurance
+2
Remote SOC Lead: Incident Response & Threat Intelligence
Remote SOC Lead: Incident Response & Threat Intelligence

Placements24 • Stellenbosch

Hybrid
ZAR 800,000 - 1,600,000
Remote work
Home office stipend
Bonuses
+1
Senior Cybersecurity Analyst - Threat Detection
Senior Cybersecurity Analyst - Threat Detection

Placements24 • Rustenburg

On-site
ZAR 900,000 - 1,200,000
Hybrid work model
Professional development
Competitive compensation
+1
L2 SOC Analyst: Threat Hunting, IR & Automation
L2 SOC Analyst: Threat Hunting, IR & Automation

Pronel Personnel • Johannesburg

On-site
ZAR 600,000 - 900,000
Cybersecurity Threat Analyst
Cybersecurity Threat Analyst

Placements24 • Pretoria

Hybrid
ZAR 450,000 - 750,000
Remote-first work model
Health, dental, and vision insurance