Torna ai jobs
ScovaiScovaiJobs
Redherd.io

Redherd.io

SOC Technical Specialist — Intermediate

Johannesburg, ZAIn sedeIndeterminatoTempo pieno500.000 € – 550.000 € / anno

Pubblicato il 2 ott 2026

Questa offerta è pubblicata in EN

SOC Technical Specialist

Location: Johannesburg, South Africa
Employment type: Full-time, permanent
Seniority: Intermediate to senior, two years or more in a SOC or technical security role

At a glance

  • Half analyst, half engineer. You investigate and hunt across client environments, and you also build and maintain the Elastic and Wazuh platforms that monitor them.
  • Hands-on Elastic and Wazuh experience & Linux and Windows administration.
  • Office-based with flexible hours, plus travel to client sites for installations and support.

About RedHerd

RedHerd is a specialist cybersecurity recruitment and advisory firm. We work with consultancies, product companies, vendors and enterprise security teams across South Africa, the UK, Europe and the United States. We are recruiting this position exclusively on behalf of our client. We share their identity with you during qualification, before submitting anything. We never introduce your profile without your knowledge and consent.

About the client

Our client is an established cybersecurity consultancy that delivers offensive security and managed security services to organisations across Southern Africa and beyond. Its client base includes businesses in Portuguese- and French-speaking markets.

The SOC runs on Elastic and Wazuh, and the team deploys and supports those platforms inside client environments as well as monitoring through them.

The role

This seat combines day-to-day SOC work with the engineering that makes the SOC possible. On one side, you monitor, investigate and hunt. On the other, you deploy agents, onboard log sources, tune detections and keep the platforms healthy across client installations.

It suits someone with solid SOC fundamentals who likes working with the technology as much as the alerts. You will work alongside consultants, infrastructure teams and client stakeholders to fix technical problems and widen security visibility.

What it is not. It is not a pure alert-monitoring seat, and it is not a back-office platform job either. You need to be comfortable doing both halves. It is not a people-management position.

What you will do

  • Monitor and triage security alerts, events and cases across client environments.
  • Investigate suspicious activity using endpoint, network, identity, and application telemetry, and decide what is a real threat and what is a false positive.
  • Escalate confirmed and high-risk incidents, and support initial analysis, evidence collection, scoping and containment under approved procedures.
  • Run hypothesis-led threat hunts, mapping findings to MITRE ATT&CK.
  • Deploy, configure and maintain Elastic- and Wazuh-based SOC installations, including Wazuh agents and Elastic data-collection components on Windows and Linux.
  • Onboard log sources, then parse, normalise and validate them so the right telemetry actually arrives.
  • Build and maintain dashboards, alerts, detection rules, decoders and integrations, and tune them to cut noise without hiding real threats.
  • Watch platform health: ingestion, agent connectivity, storage, performance and data availability.
  • Handle upgrades, configuration changes, backups and testing, and troubleshoot across applications, operating systems, networks, certificates, permissions and data pipelines.
  • Support client installations remotely and on site.
  • Write investigation notes, incident timelines, client-facing reports and system documentation, and help improve SOC playbooks and procedures.

What you must bring

At least two years in a SOC, security monitoring, security engineering or closely related technical security role. Treat that as a level, not a ceiling.

  • Hands-on operational experience with both Elastic and Wazuh, in production, client or comparable lab environments.
  • Working knowledge of the Elastic Stack: Elasticsearch, Kibana and ingestion through Elastic Agent, Beats or Logstash.
  • Working knowledge of Wazuh: agent management, rules, decoders, alerting and troubleshooting.
  • Real experience investigating alerts and security events in a SIEM or security analytics platform.
  • Confident administration and troubleshooting on both Linux and Windows.
  • A sound grasp of Windows event logs, Linux system and authentication logs, and endpoint telemetry.
  • Networking fundamentals: TCP/IP, DNS, HTTP/S, firewalls, proxies and common network services.
  • The ability to read raw logs and correlate events across sources.
  • Clear written English for investigation notes and reports.
  • Willingness and ability to travel for client installations and support.
  • Legal eligibility to work in South Africa.

Useful extras

  • Portuguese or French. The client serves businesses in Portuguese- and French-speaking markets.
  • Writing or tuning detections in KQL, Lucene, EQL, Sigma or similar formats.
  • Integrating firewalls, endpoint tools, identity platforms, cloud services and threat-intelligence feeds with a SIEM.
  • Fleet, Elastic Security, Wazuh Indexer, Wazuh Dashboard or clustered deployments.
  • Scripting in Python, PowerShell or Bash.
  • Incident response, digital forensics, malware triage or vulnerability management exposure.
  • Multi-client or managed security service experience, and ticketing or case-management processes.
  • Certifications such as Security+, CySA+, Blue Team Level 1, Elastic certifications, SC-200 or GIAC.
  • A tertiary qualification in IT, computer science, cybersecurity or a related field.

Work arrangement

Johannesburg. Primarily office-based, with flexible working hours.

Travel is required for client installations and support. Onboarding and configuration work happens on site with clients.

Package and development

We will discuss the package during the Clearing Call with RedHerd.

  • Company-provided devices and the professional tooling the role needs.
  • A structured training and certification path.
  • Company-supported learning, lab access and certification exams.
  • Exposure to varied client environments, building both analysis and SOC-engineering skills.

Process and verification

  1. Apply on the job page. Submit a CV and answer all the screening questions. Include a short summary of your hands-on experience with Elastic, Wazuh, Linux, Windows and SOC operations, and a list of your current certifications.
  2. A clearing call with RedHerd to discuss your application, the role, and the package.
  3. Practical technical assessment with the client, role-relevant and run in an authorised environment. It may cover alert investigation, log analysis, detection logic and troubleshooting a controlled SOC installation.
  4. Discussion with the team about your approach and findings.
  5. Reference and background checks before offer. The client runs these itself.

If a profile or CV does not fully describe confidential work, candidates are encouraged to explain their contribution without disclosing sensitive customer or employer information.

Why this role

  • You grow as an analyst and as a SOC engineer at the same time.
  • Real platform ownership across Elastic and Wazuh, not just a login to someone else's SIEM.
  • Varied client environments rather than one estate.
  • A structured training and certification path, with exams and lab access paid for.
  • Company-provided devices and tooling.

Equal opportunity

Applications are considered against the skills, experience, location and verification requirements of the role. RedHerd and our clients are committed to a fair and respectful process and do not discriminate on the basis of any protected characteristic.

Informazioni ruolo

Tipo di lavoro

Tempo pieno

Email

charles.wroth@redherd.io

Skill richieste

Elastic Stack (Elasticsearch, Kibana, Elastic Agent/Beats/Logstash)Wazuh (agent management, rules, decoders, alerting, troubleshooting)SIEM/security analytics alert investigation and triageLinux administration and troubleshootingWindows administration and troubleshootingLog onboarding, parsing, normalisation and validationDetection engineering: build and tune dashboards, alerts, detection rules and decodersThreat hunting and mapping findings to MITRE ATT&CKNetworking fundamentals (TCP/IP, DNS, HTTP/S, firewalls, proxies, common network services)Incident response procedures: escalation, evidence collection, scoping and containmentSOC platform administration and maintenance (ingestion, agent connectivity, storage, performance, upgrades, backups)Scripting (Python, PowerShell or Bash)Integrating security data sources (firewalls, endpoints, identity, cloud services, threat feeds) with a SIEMClear written communication for investigation notes, timelines, client reports and documentation

Offerte simili

wedded.wonderland

Luxury Travel Advisor, Independent Partner, South Africa | Wedded Wonderland

wedded.wonderland

Johannesburg, ZAIn sedeIndeterminatoTempo pieno
3 giorni fa
Redherd.io

Offensive Security Consultant MOZ — Intermediate

Redherd.io

Johannesburg, MZIn sedeIndeterminatoTempo pieno500.000 € – 550.000 € / anno
7 giorni fa
TMA Proactive Partners

Sales Manager – Digital Advertising - Johannesburg

TMA Proactive Partners

Johannesburg, ZAIn sedeIndeterminatoTempo pieno
7 giorni fa
TMA Proactive Partners

Document Controller – Freight/Shipping/Port Operations

TMA Proactive Partners

Johannesburg, ZAIn sedeIndeterminatoTempo pieno
8 giorni fa
Redherd.io

Offensive Security Consultant ZA — Intermediate

Redherd.io

Johannesburg, ZAIn sedeIndeterminatoTempo pieno450.000 € – 500.000 € / anno
10 giorni fa
CS

Account Manager - German Speaking

CodeConnect Staffing

Johannesburg, ZAIn sedeIndeterminatoTempo pieno
11 giorni fa