Advance your career with Jobia Soft Skills & Certificates
Create account, take courses and earn verifiable certificates. Download and add certifications to your profile for better chance of getting hired.
What you'll do:
Define and execute a structured hypothesis-driven threat hunting programme aligned to MITRE ATT&CK TTPs relevant to client industries. Oversee a hunt cadence (weekly/monthly) with documented hypotheses, datasets queried, findings, and new detections produced. Track hunt effectiveness metrics: hunts executed, TTPs covered, detections created, threats uncovered, dwell time reduction. Drive proactive identification of stealthy, low-signal threats (LOLBins, identity abuse, persistence, lateral movement). Ensure hunt outcomes feed back into detection engineering, playbooks, and threat intel for continuous improvement. Govern the detection lifecycle - ideation, development, testing, deployment, tuning, retirement. Reviewing versioned detection library (LQL - Logpoint Query Language) mapped to MITRE ATT&CK with coverage scoring. Drive measurable improvement in detection coverage % per tactic/technique, per client environment. Drive the Reduction in false positives and alert fatigue (signal-to-noise ratio, precision/recall metrics per rule). Ensure detections are tested via purple team / atomic red team / BAS tools before production release. Review detection-as-code practices (Python) Oversee L1/L2 analyst quality depth of investigation, accuracy of triage, and quality of incident write-ups. Govern incident analysis standards (timelines, IOC pivoting, scope determination, attribution where relevant). Ensure root cause analysis (RCA) and lessons learned are captured and converted into preventative controls. Work with SOC OPS Manager to Maintain playbooks for top threat scenarios (ransomware, BEC, identity compromise, data exfiltration). Drive analyst skill uplift through case reviews, mentoring, and structured training paths. Operate a structured CTI capability across strategic, operational, and tactical levels. Track threat actor groups, campaigns, and TTPs relevant to the organisation and client base. Ensure CTI informs risk decisions, vulnerability prioritisation, and board reporting. Monitor geopolitical, regulatory, and industry events that may translate into cyber risk (POPIA, sanctions, hacktivism). Track exposure to active campaigns and trigger proactive defensive actions. Maintain real-time situational awareness of the threat landscape – global, regional (Africa/SA), and sector-specific. Maintain transparent metrics on detection coverage, hunt outcomes, intel value, and research impact. Provide daily/weekly intel briefings to SOC Manager Govern effective use of GuardSix, EDR (WithSecure), email security (Mimecast), Zscaler, and supporting platforms for detection and hunting. Ensure log source coverage and data quality required for hunting and analytics Review KOUEBA, identity analytics, and behavioural detections beyond signature-based controls. (Align with L3) Maintain audit-ready documentation: hunt records, detection change logs, intel reports, research artefacts. Ensure ethical handling of intel, OSINT, and research (legal, privacy, and disclosure boundaries respected). Contribute to enterprise risk register with threat-informed risk inputs. Manage and grow a multi-disciplinary team (hunters, detection engineers, analysts, intel analysts, researchers). Participate/Facilitate internal purple team exercises, CTFs, and tabletop scenarios to build muscle memory. Contribute to threat-informed reporting to CISO, exec, and clients not just volumes, but business-relevant insight. Translate technical threat data into business risk language (impact, likelihood, exposure, recommended action). Provide quarterly threat landscape and defensive posture reviews to leadership and key clients. Partner closely with SOC Operations Manager (feed detections/playbooks), Exposure and Vulnerability Management (intel-led prioritisation), IR (threat context), and GRC (risk inputs). Engage with client CISOs and security teams on threat briefings and joint exercises. Drive measurable year-on-year improvement in detection coverage, hunt yield, and intel-driven outcomes.
8–12+ years' experience in Cybersecurity Operations. 5+ years' experience in Threat Hunting, Detection Engineering, Threat Intelligence, Incident Response, or Advanced SOC Operations. Proven experience leading Threat Hunting, Detection Engineering, CTI, and SOC Analysis teams. Experience operating within enterprise or MSSP security environments. Experience building and managing detection programs mapped to MITRE ATT&CK. Experience developing and tuning SIEM detection use cases.
Identity compromise Ransomware Business Email Compromise (BEC) Data exfiltration Insider threats Cloud attacks Lateral movement LOLBins and living-off-the-land techniques Experience presenting threat intelligence and security risks to executive leadership and clients. Experience managing threat-informed security programs and continuous improvement initiatives.
Qualification Essential Competency
SIEM Platforms (e.g Logpoint, Sentinel, Splunk, QRadar, ArcSight) EDR/XDR Platforms (e.g. WithSecure, CrowdStrike, Defender, SentinelOne) SOAR Platforms Vulnerability Management Platforms Identity Security Solutions UEBA Platforms Cloud Security Controls Threat Intelligence Platforms (TIP)
CIS/NIST Cyber Security Framework Cyber Threat Intelligence Lifecycle Detection Engineering Frameworks Threat Modelling
Qualifications preferred/ knowledge
CTIA (Certified Threat Intelligence Analyst)
Note: Only shortlisted candidates are contacted.
Monthly based
Gauteng
Gauteng
Create account, take courses and earn verifiable certificates. Download and add certifications to your profile for better chance of getting hired.