Cyber Security SOC Engineer
Location: Centurion, Gauteng (provisional – to be confirmed)
Positions Available: 5
Salary: Market-related
Employment Type: To be confirmed
Job Overview
We are seeking experienced and technically proficient Cyber Security Security Operations Centre (SOC) Engineers to design, implement, configure, integrate, maintain and optimise enterprise security monitoring and threat detection technologies.
The successful candidates will be responsible for developing and maintaining the technical infrastructure that supports Security Operations Centre operations, including Security Information and Event Management (SIEM) platforms, Endpoint Detection and Response (EDR) solutions, security automation technologies and enterprise log management systems.
This role requires strong hands-on expertise in SOC engineering, SIEM administration, security monitoring architecture, detection engineering, log ingestion, security tool integration and cybersecurity automation.
The ideal candidates will have proven experience implementing and supporting enterprise security monitoring platforms, developing detection capabilities and ensuring that cybersecurity analysts have access to reliable, accurate and actionable security information.
Unlike a SOC Analyst, whose primary responsibility is investigating security alerts, a SOC Engineer focuses on building, configuring, maintaining and improving the security technologies and detection capabilities used by the SOC.
Key Responsibilities
SOC Infrastructure Design and Implementation
- Design, implement, configure and maintain enterprise SOC security monitoring infrastructure.
- Deploy and administer SIEM, EDR, XDR and related security monitoring technologies.
- Develop and maintain scalable security monitoring architectures.
- Configure security event collection, processing, correlation and retention.
- Integrate security monitoring solutions with enterprise infrastructure and cloud platforms.
- Ensure security monitoring technologies remain available, reliable and appropriately secured.
- Support SOC platform upgrades, migrations and infrastructure improvements.
- Implement security monitoring standards and operational procedures.
- Collaborate with SOC analysts, security architects and infrastructure teams to improve monitoring capabilities.
- Identify technical weaknesses in SOC infrastructure and recommend improvements.
SIEM Engineering and Administration
- Install, configure, administer and optimise enterprise SIEM platforms.
- Integrate security logs from servers, endpoints, firewalls, network devices, applications and cloud services.
- Configure log collectors, agents, connectors and data ingestion pipelines.
- Develop and maintain SIEM correlation rules, detection logic and alerting mechanisms.
- Configure security dashboards, reporting and monitoring views.
- Optimise SIEM performance, data ingestion, storage and query efficiency.
- Troubleshoot log collection failures, parsing issues and integration problems.
- Monitor SIEM platform health and availability.
- Implement appropriate access controls and administrative security measures.
- Support SIEM upgrades, platform migrations and configuration management.
Detection Engineering and Security Analytics
- Develop, implement and maintain cybersecurity detection rules and use cases.
- Translate threat intelligence and attacker techniques into actionable detection logic.
- Map security detection capabilities to the MITRE ATT&CK framework.
- Develop detection content for malware, ransomware, credential compromise, privilege escalation and lateral movement.
- Create and optimise SIEM queries and correlation searches.
- Validate detection rules using controlled testing and attack simulations.
- Reduce false positives and improve alert accuracy.
- Identify gaps in security telemetry and detection coverage.
- Collaborate with SOC analysts, threat hunters and incident responders to improve detection effectiveness.
- Maintain detection documentation, testing evidence and version-controlled detection content.
EDR, XDR and Security Tool Integration
- Deploy, configure and maintain enterprise endpoint detection and response technologies.
- Integrate EDR and XDR platforms with SIEM and incident response systems.
- Configure endpoint security policies, monitoring rules and alerting mechanisms.
- Troubleshoot endpoint agent deployment and communication issues.
- Integrate firewalls, intrusion detection systems and other security technologies with SOC monitoring platforms.
- Support network detection and response capabilities.
- Maintain security tool connectivity and integration health.
- Implement appropriate access controls and security configurations.
- Assist with security platform upgrades and technical improvements.
Security Automation and SOAR Engineering
- Design, implement and maintain Security Orchestration, Automation and Response (SOAR) workflows.
- Develop automated incident enrichment, alert triage and investigation processes.
- Integrate SIEM, EDR, threat intelligence and ticketing platforms.
- Develop and maintain incident response automation playbooks.
- Use APIs and scripting to automate repetitive SOC activities.
- Implement automated indicator enrichment and threat intelligence lookups.
- Test and validate security automation workflows.
- Ensure automated response actions include appropriate approvals and safeguards.
- Troubleshoot security automation failures and integration issues.
- Identify opportunities to improve SOC operational efficiency through automation.
Cloud and Hybrid Security Monitoring
- Implement security monitoring across Microsoft Azure, AWS or Google Cloud environments.
- Configure cloud security log collection and event monitoring.
- Integrate cloud security technologies with enterprise SIEM platforms.
- Monitor cloud identity, workloads, applications and infrastructure.
- Configure security monitoring for Microsoft Entra ID and Microsoft 365 environments.
- Support cloud-native threat detection and incident investigation capabilities.
- Develop detection rules for cloud security threats and suspicious activities.
- Ensure appropriate monitoring coverage across hybrid infrastructure.
- Collaborate with cloud engineering and cybersecurity teams to improve cloud security visibility.
SOC Platform Performance and Operational Support
- Monitor SOC infrastructure health, performance and availability.
- Investigate and resolve security monitoring platform failures.
- Maintain system configurations, technical documentation and operational procedures.
- Support disaster recovery and resilience planning for critical SOC technologies.
- Conduct platform health checks, configuration reviews and capacity assessments.
- Support security technology patching and vulnerability remediation.
- Maintain appropriate change management and configuration control processes.
- Provide technical support to SOC analysts and incident response teams.
- Recommend improvements to security monitoring architecture and operational effectiveness.
Security Governance and Compliance
- Ensure SOC engineering practices align with organisational security policies.
- Support security monitoring requirements under ISO 27001, NIST and other applicable frameworks.
- Maintain audit logs, technical documentation and security monitoring evidence.
- Assist with internal and external cybersecurity audits.
- Support data retention, access control and security logging requirements.
- Maintain technical standards for SIEM configuration and security tool integration.
- Recommend improvements to SOC engineering processes and security controls.
- Support continuous improvement of enterprise security monitoring capabilities.
Minimum Requirements
- Relevant diploma or degree in Information Technology, Computer Science, Cybersecurity, Information Security, Network Engineering or a related discipline.
- Typically 3–5 years of relevant hands-on experience in SOC engineering, SIEM engineering, security infrastructure engineering or a closely related cybersecurity specialisation.
- Proven practical experience implementing, configuring or administering enterprise SIEM or security monitoring platforms.
- Strong knowledge of SOC architecture, security event collection and enterprise log management.
- Experience integrating multiple security technologies and log sources into SIEM environments.
- Practical experience developing, configuring or optimising security detection rules and correlation searches.
- Experience with EDR, XDR or related endpoint security technologies.
- Understanding of security event analysis, threat detection and incident response processes.
- Strong knowledge of Windows Server, Linux, Active Directory and enterprise networking.
- Familiarity with cloud security monitoring and hybrid infrastructure environments.
- Experience using scripting or automation to support security operations.
- Understanding of APIs, security tool integration and log ingestion technologies.
- Familiarity with the MITRE ATT&CK framework.
- Experience troubleshooting complex security monitoring and platform integration issues.
- Strong technical documentation, analytical and problem-solving skills.
Technical Skills and Competencies
SIEM Engineering and Administration
Practical experience with one or more of the following platforms:
- Microsoft Sentinel
- Splunk Enterprise Security
- IBM QRadar
- Elastic Security
- ArcSight
- LogRhythm
- Google Security Operations
- Other enterprise SIEM platforms
Relevant technical competencies include:
- SIEM deployment and configuration
- Log ingestion and collection
- Log source onboarding
- Data parsing and normalisation
- Security event correlation
- Detection rule development
- SIEM query optimisation
- SIEM performance tuning
- Platform administration
- SIEM upgrades and migrations
- Security dashboard development
- Log retention and storage management
Detection Engineering
- Security detection use-case development
- MITRE ATT&CK mapping
- Threat-informed detection engineering
- Security correlation rules
- Detection logic testing
- Alert tuning and false-positive reduction
- Indicators of Compromise (IOCs)
- Indicators of Attack (IOAs)
- Threat intelligence integration
- Detection coverage assessment
- Security analytics
- Detection-as-Code principles
- Sigma detection rules
EDR and XDR Technologies
Experience with relevant platforms such as:
- Microsoft Defender for Endpoint
- Microsoft Defender XDR
- CrowdStrike Falcon
- SentinelOne
- Palo Alto Cortex XDR
- Trend Micro endpoint security
- Other enterprise EDR and XDR platforms
Relevant competencies include:
- EDR deployment and administration
- Endpoint telemetry collection
- Endpoint security policy configuration
- EDR integration with SIEM
- Endpoint detection rule management
- Security agent troubleshooting
- Endpoint security monitoring
Security Automation and SOAR
- Security Orchestration, Automation and Response
- Automated incident enrichment
- Security workflow automation
- Automated alert triage
- Incident response playbook development
- API integration
- Threat intelligence automation
- Ticketing system integration
- Automated security reporting
Experience with platforms such as:
- Microsoft Sentinel automation
- Azure Logic Apps
- Splunk SOAR
- Cortex XSOAR
- Other enterprise security automation platforms
Scripting and Query Languages
- Kusto Query Language (KQL)
- Splunk Search Processing Language (SPL)
- Python
- PowerShell
- Bash
- SQL fundamentals
- REST APIs
- JSON
- YAML
- Regular expressions
- Security automation scripting
Enterprise Infrastructure and Networking
- Windows Server
- Linux
- Microsoft Active Directory
- Microsoft Entra ID
- TCP/IP networking
- DNS
- DHCP
- HTTP/HTTPS
- Firewalls
- IDS/IPS
- VPN technologies
- Network security monitoring
- Syslog
- Windows Event Forwarding
- Enterprise authentication systems
Cloud Security Monitoring
- Microsoft Azure
- Microsoft Sentinel
- Microsoft Defender for Cloud
- Microsoft Defender XDR
- Microsoft Entra ID
- Microsoft 365 security
- AWS CloudTrail
- AWS CloudWatch
- AWS Security Hub
- Amazon GuardDuty
- Google Cloud security logging
- Cloud identity monitoring
- Cloud workload security
- Hybrid infrastructure monitoring
Security Monitoring Architecture
- Enterprise SOC architecture
- Centralised security logging
- Security telemetry pipelines
- Log collectors and forwarders
- Security monitoring scalability
- High availability and resilience
- Security monitoring integration
- Security data retention
- Monitoring platform performance
- SOC infrastructure troubleshooting
Cybersecurity Frameworks and Standards
- MITRE ATT&CK
- NIST Cybersecurity Framework
- NIST SP 800-61 – Incident Response
- ISO/IEC 27001
- CIS Critical Security Controls
- Security logging and monitoring best practices
- Threat detection engineering methodologies
- Enterprise cybersecurity architecture principles
Relevant Certifications (Advantageous)
One or more of the following certifications would be beneficial:
- Microsoft Certified: Security Operations Analyst Associate (SC-200)
- Microsoft Certified: Azure Security Engineer Associate
- Splunk Enterprise Security Certified Admin
- Splunk Core Certified Power User
- IBM QRadar certifications
- Elastic Certified Engineer
- CompTIA Security+
- CompTIA CySA+
- GIAC Security Essentials (GSEC)
- GIAC Certified Incident Handler (GCIH)
- GIAC Certified Intrusion Analyst (GCIA)
- Certified Information Systems Security Professional (CISSP)
- Relevant SIEM, SOAR, EDR, cloud security or detection engineering certifications
Key Personal Attributes
- Strong technical engineering and problem-solving abilities.
- Excellent analytical and troubleshooting skills.
- High attention to detail and configuration accuracy.
- Ability to design and maintain reliable enterprise security monitoring systems.
- Strong understanding of cybersecurity threats and detection technologies.
- Proactive approach to identifying technical weaknesses and improving SOC capabilities.
- Excellent communication and stakeholder engagement skills.
- Ability to collaborate effectively with SOC analysts, incident responders, infrastructure and cloud teams.
- Strong technical documentation and organisational skills.
- Ability to manage multiple engineering priorities and technical projects.
- High levels of confidentiality, accountability and professional integrity.
Application Requirements
Interested candidates should submit an updated CV clearly detailing their practical SOC engineering, SIEM administration, detection engineering and security technology integration experience, together with copies of relevant academic qualifications and professional certifications.
Candidates should specifically highlight:
- SIEM platforms they have personally implemented, configured or administered.
- Enterprise SOC infrastructure and security monitoring environments they have supported.
- Experience onboarding log sources and configuring security event collection.
- Detection rules, correlation searches and security monitoring use cases they have developed.
- EDR, XDR and security monitoring technologies they have deployed or integrated.
- SOAR platforms, automation playbooks and security workflows they have implemented.
- Practical experience with KQL, SPL, Python, PowerShell or other relevant scripting technologies.
- Cloud security monitoring implementations across Azure, AWS or GCP.
- SOC platform migrations, upgrades, performance optimisation or engineering projects.
- Experience integrating firewalls, endpoints, identity systems and cloud services into SIEM platforms.
- The size and complexity of the enterprise security monitoring environments they have supported.
- Relevant SIEM, SOC engineering, cloud security and cybersecurity certifications.
Important: This is a specialist Cyber Security SOC Engineer opportunity requiring demonstrable hands-on experience implementing, configuring, integrating and maintaining enterprise security monitoring technologies. General IT support, basic security monitoring or SOC Analyst experience without substantial security engineering responsibilities will not be sufficient.
Please note: Specific project requirements, remuneration, employment arrangements, shift or on-call expectations and working conditions will be confirmed during the recruitment process. The required engineering seniority level will also be confirmed with the client.