Technical Lead – SOC Cyber Defense (iOCO0083)

iOCO

Gauteng

On-site

ZAR 1,000,000 - 1,500,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

iOCO in Johannesburg is seeking a senior Cyber Security professional to lead a threat hunting program aligned to MITRE ATT&CK, working with SIEMs, EDR, and threat intel to reduce dwell time and improve detection coverage.

You will mentor analysts, drive purple-team exercises, and ensure risk-informed decisions are communicated to leadership and clients.

This permanent role offers continuous learning and opportunities to influence security across industries.

Qualifications

  • 8–12+ years' experience in Cybersecurity Operations.
  • 5+ years' experience in Threat Hunting, Detection Engineering, Threat Intelligence, Incident Response, or Advanced SOC Operations.
  • Proven experience leading Threat Hunting, Detection Engineering, CTI, and SOC Analysis teams.
  • Experience building and managing detection programs mapped to MITRE ATT&CK.
  • Experience developing and tuning SIEM detection use cases.

Responsibilities

  • Define and execute a structured hypothesis-driven threat hunting programme aligned to MITRE ATTACK TTPs for client industries.
  • Oversee a hunt cadence with documented hypotheses, datasets queried, findings, and new detections produced.
  • Track hunt effectiveness metrics: hunts executed, TTPs covered, detections created, threats uncovered, dwell time reduction.
  • Drive proactive identification of stealthy threats (LOLBins, identity abuse, persistence, lateral movement).
  • Ensure hunt outcomes feed back into detection engineering, playbooks, and threat intel for continuous improvement.
  • Govern the detection lifecycle - ideation, development, testing, deployment, tuning, retirement.

Skills

Threat Hunting
Detection Engineering
Threat Intelligence
Incident Response
SOC Operations
MITRE ATT&CK
SIEM
EDR/XDR
Leadership
Executive Communication

Education

CTIA
CREST CRT
CREST CCTIM

Tools

Logpoint SIEM
Microsoft Sentinel
Splunk
QRadar
ArcSight
WithSecure EDR
CrowdStrike
Microsoft Defender
SentinelOne
SOAR Platforms
Vulnerability Management
Identity Security
UEBA
Cloud Security
TIP
MITRE ATT&CK

Job description

What you'll do:


  • Define and execute a structured hypothesis-driven threat hunting programme aligned to MITRE ATT&CK TTPs relevant to client industries.

  • Oversee a hunt cadence (weekly/monthly) with documented hypotheses, datasets queried, findings, and new detections produced.

  • Track hunt effectiveness metrics: hunts executed, TTPs covered, detections created, threats uncovered, dwell time reduction.

  • Drive proactive identification of stealthy, low-signal threats (LOLBins, identity abuse, persistence, lateral movement).

  • Ensure hunt outcomes feed back into detection engineering, playbooks, and threat intel for continuous improvement.

  • Govern the detection lifecycle - ideation, development, testing, deployment, tuning, retirement.

  • Reviewing versioned detection library (LQL - Logpoint Query Language) mapped to MITRE ATT&CK with coverage scoring.

  • Drive measurable improvement in detection coverage % per tactic/technique, per client environment.

  • Drive the Reduction in false positives and alert fatigue (signal-to-noise ratio, precision/recall metrics per rule).

  • Ensure detections are tested via purple team / atomic red team / BAS tools before production release.

  • Review detection-as-code practices (Python)

  • Oversee L1/L2 analyst quality depth of investigation, accuracy of triage, and quality of incident write-ups.

  • Govern incident analysis standards (timelines, IOC pivoting, scope determination, attribution where relevant).

  • Ensure root cause analysis (RCA) and lessons learned are captured and converted into preventative controls.

  • Work with SOC OPS Manager to Maintain playbooks for top threat scenarios (ransomware, BEC, identity compromise, data exfiltration).

  • Drive analyst skill uplift through case reviews, mentoring, and structured training paths.

  • Operate a structured CTI capability across strategic, operational, and tactical levels.

  • Track threat actor groups, campaigns, and TTPs relevant to the organisation and client base.

  • Ensure CTI informs risk decisions, vulnerability prioritisation, and board reporting.

  • Monitor geopolitical, regulatory, and industry events that may translate into cyber risk (POPIA, sanctions, hacktivism).

  • Track exposure to active campaigns and trigger proactive defensive actions.

  • Maintain real-time situational awareness of the threat landscape – global, regional (Africa/SA), and sector-specific.

  • Maintain transparent metrics on detection coverage, hunt outcomes, intel value, and research impact.

  • Provide daily/weekly intel briefings to SOC Manager

  • Govern effective use of GuardSix, EDR (WithSecure), email security (Mimecast), Zscaler, and supporting platforms for detection and hunting.

  • Ensure log source coverage and data quality required for hunting and analytics

  • Review KOUEBA, identity analytics, and behavioural detections beyond signature-based controls. (Align with L3)

  • Maintain audit-ready documentation: hunt records, detection change logs, intel reports, research artefacts.

  • Ensure ethical handling of intel, OSINT, and research (legal, privacy, and disclosure boundaries respected).

  • Contribute to enterprise risk register with threat-informed risk inputs.

  • Manage and grow a multi-disciplinary team (hunters, detection engineers, analysts, intel analysts, researchers).

  • Participate/Facilitate internal purple team exercises, CTFs, and tabletop scenarios to build muscle memory.

  • Contribute to threat-informed reporting to CISO, exec, and clients not just volumes, but business-relevant insight.

  • Translate technical threat data into business risk language (impact, likelihood, exposure, recommended action).

  • Provide quarterly threat landscape and defensive posture reviews to leadership and key clients.

  • Partner closely with SOC Operations Manager (feed detections/playbooks), Exposure and Vulnerability Management (intel-led prioritisation), IR (threat context), and GRC (risk inputs).

  • Engage with client CISOs and security teams on threat briefings and joint exercises.

  • Drive measurable year-on-year improvement in detection coverage, hunt yield, and intel-driven outcomes.


Your Expertise:


  • 8–12+ years' experience in Cybersecurity Operations.

  • 5+ years' experience in Threat Hunting, Detection Engineering, Threat Intelligence, Incident Response, or Advanced SOC Operations.

  • Proven experience leading Threat Hunting, Detection Engineering, CTI, and SOC Analysis teams.

  • Experience operating within enterprise or MSSP security environments.

  • Experience building and managing detection programs mapped to MITRE ATT&CK.

  • Experience developing and tuning SIEM detection use cases.

  • Experience performing advanced threat investigations involving:

    • Identity compromise

    • Ransomware

    • Business Email Compromise (BEC)

    • Data exfiltration

    • Insider threats

    • Cloud attacks

    • Lateral movement

    • LOLBins and living-off-the-land techniques



  • Experience presenting threat intelligence and security risks to executive leadership and clients.

  • Experience managing threat-informed security programs and continuous improvement initiatives.


Qualifications:


  • Qualification Essential Competency

  • Strong practical experience with:

    • SIEM Platforms (e.g Logpoint, Sentinel, Splunk, QRadar, ArcSight)

    • EDR/XDR Platforms (e.g. WithSecure, CrowdStrike, Defender, SentinelOne)

    • SOAR Platforms

    • Vulnerability Management Platforms

    • Identity Security Solutions

    • UEBA Platforms

    • Cloud Security Controls

    • Threat Intelligence Platforms (TIP)

    • MITRE ATT&CK

    • CIS/NIST Cyber Security Framework

    • Cyber Threat Intelligence Lifecycle

    • Detection Engineering Frameworks

    • Threat Modelling



  • Qualifications preferred/ knowledge

    • CTIA (Certified Threat Intelligence Analyst)

    • CREST CRT

    • CREST CCTIM




Other information applicable to the opportunity:


  • Permanent position

  • Location: Johanesburg

  • Physical: Demands Sitting

  • Travel: Own Transport


Why work for us?

Want to work for an organization that solves complex real-world problems with innovative software solutions? At iOCO, we believe anything is possible with modern technology, software, and development expertise. We are continuously pushing the boundaries of innovative solutions across multiple industries using an array of technologies.


You will be part of a consultancy, working with some of the most knowledgeable minds in the industry on interesting solutions across different business domains.


Our culture of continuous learning will ensure that you will have all the opportunities, tools, and support to hone and grow your craft.


By joining IOCO you will have an open invitation to developer inspiring forums. A place where you will be able to connect and learn from and with your peers by sharing ideas, experiences, practices, and solutions.


iOCO is an equal opportunity employer with an obligation to achieve its own unique EE objectives in the context of Employment Equity targets. Therefore, our employment strategy gives primary preference to previously disadvantaged individuals or groups.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Technician (iOCO0126)
Technician (iOCO0126)

iOCO • Gauteng

On-site
ZAR 280,000 - 360,000
Services Manager – Cyber Security (iOCO0082)
Services Manager – Cyber Security (iOCO0082)

iOCO • Gauteng

Hybrid
ZAR 1,200,000 - 1,800,000
BU Admin (iOCO0087)
BU Admin (iOCO0087)

iOCO • Wes-Kaap

On-site
ZAR 260,000 - 380,000
Senior DevOps Engineer (iOCO0047)
Senior DevOps Engineer (iOCO0047)

Ioco • Sandton

Hybrid
ZAR 900,000 - 1,300,000
Strategic Growth Partner (iOCO0118)
Strategic Growth Partner (iOCO0118)

iOCO Limited • Pretoria

On-site
ZAR 600,000 - 900,000
Technician (iOCO0134)
Technician (iOCO0134)

iOCO Limited • Durban

On-site
ZAR 180,000 - 240,000
Solution Architect (iOCO0103)
Solution Architect (iOCO0103)

Ioco • Johannesburg

Hybrid
ZAR 900,000 - 1,500,000
Flexible work arrangements
Professional development
Solution Architect (iOCO0103)
Solution Architect (iOCO0103)

iOCO Limited • Johannesburg

Hybrid
ZAR 900,000 - 1,300,000
Senior Technology Leadership role - Head of Technology (iOCO0132)
Senior Technology Leadership role - Head of Technology (iOCO0132)

iOCO Limited • Cape Town

On-site
ZAR 1,200,000 - 1,800,000
Senior Client Portfolio Manager
Senior Client Portfolio Manager

Ioco • Johannesburg

On-site
ZAR 1,000,000 - 1,600,000