SOC Analyst L3

Afrocentric IP

South Africa

On-site

ZAR 700,000 - 900,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Afrocentric IP in South Africa seeks a seasoned SOC Analyst L3 to lead advanced threat detection, incident response, and threat hunting within its Security Operations Centre. You will guide L1/L2 analysts, refine runbooks, and engineer proactive defenses across client environments.

The role demands 5–7 years in SOC/IR, strong SIEM/EDR/XDR experience, relevant certifications, and a willingness to work after hours.

Qualifications

  • Diploma or Degree in IT, Cybersecurity, CS or related field.
  • 5-7 years in a SOC or incident response environment.
  • At least 2 years at L3 or senior analyst level.
  • Proven experience investigating and resolving complex security incidents.
  • Strong experience with SIEM, EDR/XDR, and threat intelligence platforms.
  • Security certifications such as CompTIA Security+, CySA+, GCIH, GCIA, CEH, or equivalent.
  • SANS/GIAC certifications are advantageous.
  • Own reliable transport.
  • Willingness to participate in after-hours standby/on-call roster.

Responsibilities

  • Lead investigation, triage, and resolution of complex incidents.
  • Perform advanced analysis of security alerts, logs, and threat intelligence.
  • Coordinate incident response activities, including containment, eradication, and recovery.
  • Conduct root cause analysis and document lessons learned from major security incidents.
  • Ensure escalated incidents are resolved within agreed service levels.
  • Identify and implement improvements to SOC processes and playbooks.
  • Mentor and provide guidance to L1/L2 SOC Analysts.
  • Prepare accurate security incident and threat reports.
  • Present security findings and recommendations to clients and management.

Skills

Advanced threat detection
Incident response
Threat hunting
Security analysis
Mentorship
Client communication
Problem solving

Education

Diploma or Degree in IT / Cybersecurity

Tools

SIEM
EDR/XDR
Threat intelligence platforms

Job description

Job Summary

The SOC Analyst L3 is responsible for providing advanced security monitoring, threat detection, incident response, threat hunting, and security analysis within Afrocentric IP's Security Operations Centre (SOC). The role focuses on investigating and resolving complex and escalated security incidents, conducting proactive threat hunting, improving SOC processes and tooling, and providing technical guidance to Level 1 and Level 2 SOC Analysts.

Key Responsibilities
Advanced Threat Detection & Incident Response
  • Lead the investigation, triage, and resolution of complex and escalated security incidents.
  • Perform advanced analysis of security alerts, logs, and threat intelligence.
  • Coordinate incident response activities, including containment, eradication, and recovery.
  • Conduct root cause analysis and document lessons learned from major security incidents.
  • Ensure escalated incidents are resolved within agreed service levels.
Threat Hunting & Intelligence
  • Conduct proactive threat hunting across client and internal environments.
  • Analyse threat intelligence and identify relevant indicators of compromise.
  • Develop and recommend new detection rules and security use cases.
  • Improve threat detection capabilities using industry frameworks and emerging threat intelligence.
SOC Process & Tooling
  • Identify and implement improvements to SOC processes, playbooks, and standard operating procedures.
  • Support the configuration, tuning, and optimisation of SIEM and security monitoring platforms.
  • Reduce false-positive alert rates through continuous monitoring and rule tuning.
  • Develop and maintain incident response runbooks.
  • Contribute to the continuous improvement of SOC capabilities.
Mentorship & Reporting
  • Mentor and provide technical guidance to L1 and L2 SOC Analysts.
  • Review and quality-assure incident investigations and escalation reports.
  • Prepare accurate security incident and threat reports.
  • Present security findings and recommendations to clients and management.
  • Provide technical leadership during high-severity security incidents.
Minimum Requirements
  • Diploma or Degree in Information Technology, Cybersecurity, Computer Science, or a related field.
  • 5-7 years' experience in a Security Operations Centre or incident response environment.
  • At least 2 years' experience operating at an L3 or senior analyst level.
  • Proven experience investigating and resolving complex security incidents.
  • Strong experience with SIEM, EDR/XDR, and threat intelligence platforms.
  • Relevant security certifications such as CompTIA Security+, CySA+, GCIH, GCIA, CEH, or equivalent.
  • SANS/GIAC certifications are advantageous.
  • Own reliable transport.
  • Willingness to participate in an after-hours standby/on-call roster.
Key Competencies
  • Advanced Threat Detection & Analysis
  • Incident Response
  • Threat Hunting
  • Threat Intelligence
  • SIEM & Security Monitoring
  • EDR/XDR
  • MITRE ATT&CK
  • Security Investigation & Analysis
  • Problem Solving
  • SOC Process Improvement
  • Technical Leadership & Mentorship
  • Client & Stakeholder Communication
  • Incident Reporting
  • Ability to Work Under Pressure
Why Join Afrocentric IP?

Join a forward-thinking team delivering enterprise Information Security, Business Continuity, and Resilience solutions across South Africa. As a SOC Analyst L3, you'll play a key role in protecting client environments, responding to sophisticated cyber threats, improving security operations, and mentoring the next generation of SOC analysts.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

L3 SOC Analyst - Cape Town
L3 SOC Analyst - Cape Town

Integrity360 • Cape Town

On-site
ZAR 600,000 - 800,000
L3 SOC Analyst - Johannesburg
L3 SOC Analyst - Johannesburg

Jobless • Johannesburg

On-site
ZAR 600,000 - 900,000
Senior Security Operations Center (SOC) Analyst
Senior Security Operations Center (SOC) Analyst

Placements24 • Randburg

On-site
ZAR 800,000 - 1,200,000
Competitive salary
Medical, dental, and vision insurance
Training and certifications
+2
Senior SOC Analyst: Lead Incident Response & Hunting
Senior SOC Analyst: Lead Incident Response & Hunting

Afrocentric IP • South Africa

On-site
ZAR 700,000 - 900,000
L2 SOC Analyst – DOL2SOCA
L2 SOC Analyst – DOL2SOCA

Armstrong Appointments • Cape Town

On-site
ZAR 480,000 - 720,000
L2 SOC Analyst - Cape Town or Johannesburg
L2 SOC Analyst - Cape Town or Johannesburg

Integrity360 • Cape Town

On-site
ZAR 420,000 - 600,000
Cyber Security Operations Manager
Cyber Security Operations Manager

Placements24 • Gauteng

On-site
ZAR 900,000 - 1,500,000
Competitive pay with incentives
Health benefits
Security training & development
+2
Information Security Analyst (SOC)
Information Security Analyst (SOC)

Placements24 • Klerksdorp

On-site
ZAR 320,000 - 520,000
Medical benefits
Retirement benefits
Training opportunities
+2
Mid-Level Cyber Security Analyst (SOC)
Mid-Level Cyber Security Analyst (SOC)

60 Degrees • Wes-Kaap

Hybrid
ZAR 350,000 - 650,000
Hybrid work (Cape Town)
International exposure
Career development
Senior Soc Analyst (Soc L4)
Senior Soc Analyst (Soc L4)

Redherd.Io • Johannesburg

Hybrid
ZAR 900,000 - 1,200,000
Medical aid
Gap cover
Provident fund
+4