Job Summary
The SOC Analyst L3 is responsible for providing advanced security monitoring, threat detection, incident response, threat hunting, and security analysis within Afrocentric IP's Security Operations Centre (SOC). The role focuses on investigating and resolving complex and escalated security incidents, conducting proactive threat hunting, improving SOC processes and tooling, and providing technical guidance to Level 1 and Level 2 SOC Analysts.
Key Responsibilities
Advanced Threat Detection & Incident Response
- Lead the investigation, triage, and resolution of complex and escalated security incidents.
- Perform advanced analysis of security alerts, logs, and threat intelligence.
- Coordinate incident response activities, including containment, eradication, and recovery.
- Conduct root cause analysis and document lessons learned from major security incidents.
- Ensure escalated incidents are resolved within agreed service levels.
Threat Hunting & Intelligence
- Conduct proactive threat hunting across client and internal environments.
- Analyse threat intelligence and identify relevant indicators of compromise.
- Develop and recommend new detection rules and security use cases.
- Improve threat detection capabilities using industry frameworks and emerging threat intelligence.
SOC Process & Tooling
- Identify and implement improvements to SOC processes, playbooks, and standard operating procedures.
- Support the configuration, tuning, and optimisation of SIEM and security monitoring platforms.
- Reduce false-positive alert rates through continuous monitoring and rule tuning.
- Develop and maintain incident response runbooks.
- Contribute to the continuous improvement of SOC capabilities.
Mentorship & Reporting
- Mentor and provide technical guidance to L1 and L2 SOC Analysts.
- Review and quality-assure incident investigations and escalation reports.
- Prepare accurate security incident and threat reports.
- Present security findings and recommendations to clients and management.
- Provide technical leadership during high-severity security incidents.
Minimum Requirements
- Diploma or Degree in Information Technology, Cybersecurity, Computer Science, or a related field.
- 5-7 years' experience in a Security Operations Centre or incident response environment.
- At least 2 years' experience operating at an L3 or senior analyst level.
- Proven experience investigating and resolving complex security incidents.
- Strong experience with SIEM, EDR/XDR, and threat intelligence platforms.
- Relevant security certifications such as CompTIA Security+, CySA+, GCIH, GCIA, CEH, or equivalent.
- SANS/GIAC certifications are advantageous.
- Own reliable transport.
- Willingness to participate in an after-hours standby/on-call roster.
Key Competencies
- Advanced Threat Detection & Analysis
- Incident Response
- Threat Hunting
- Threat Intelligence
- SIEM & Security Monitoring
- EDR/XDR
- MITRE ATT&CK
- Security Investigation & Analysis
- Problem Solving
- SOC Process Improvement
- Technical Leadership & Mentorship
- Client & Stakeholder Communication
- Incident Reporting
- Ability to Work Under Pressure
Why Join Afrocentric IP?
Join a forward-thinking team delivering enterprise Information Security, Business Continuity, and Resilience solutions across South Africa. As a SOC Analyst L3, you'll play a key role in protecting client environments, responding to sophisticated cyber threats, improving security operations, and mentoring the next generation of SOC analysts.