Security Operations Support Engineers are responsible for the day to day support, administration, and optimisation of security operations tools and processes. This role combines hands on technical support with incident response assistance and continuous improvement of monitoring capabilities. The engineer works independently on most tasks and collaborates with other engineers on more complex initiatives.

Key Responsibilities

  • Monitor system performance and alert pipelines to ensure reliability
  • Investigate and resolve issues related to security tools and integrations.
  • Perform in-depth analysis of security alerts and escalate when necessary
  • Support and actively participate in incident response activities
  • Develop basic automation/scripts to streamline repetitive operational tasks
  • Collaborate with SOC, IT, and cloud teams to address security gaps
  • Assist with vulnerability management and remediation tracking
  • Maintain and improve technical documentation, runbooks, and processes
  • Contribute to security tool onboarding and integration projects

Required Skills & Qualifications

  • 2–5 years of experience in cybersecurity, SOC, or IT operations
  • Solid understanding of:
    • Networking (TCP/IP, DNS, VPNs, firewalls)
    • Operating systems (Windows and Mac)
    • Security monitoring, logging, and alerting concepts
  • Ability to independently troubleshoot and resolve technical issues
  • Working knowledge of incident response processes

 

Preferred Qualifications

  • Certifications such as are advantages:
    • CompTIA Security+
    • Certified SOC Analyst (CSA)
    • GIAC GSEC or GCIH
  • Experience with platforms like Splunk, Microsoft Sentinel, Elastic Security
  • Familiarity with cloud platforms (AWS, Azure, GCP)

 

Key Competencies

  • Strong troubleshooting and analytical thinking
  • Ability to work independently with minimal supervision
  • Good communication and collaboration skills
  • Attention to detail with a proactive mindset
  • Continuous improvement approach to processes and tooling

 

Working Conditions

  • May include participation in on-call rotations or shift work
  • Hybrid or on-site work environment
  • Occasional after-hours work during incidents or maintenance

 

Success Metrics

  • Reliability and uptime of security tools and data pipelines
  • Reduction in recurring technical issues and alert noise
  • Effective handling and support of security incidents
  • Contribution to automation and operational efficiency
  • Quality and completeness of documentation and runbooks
Employment Type
Full-time
Industry
Information Technology
Job Location
Johannesburg, Bryanston
Working Hours
08:00 - 17:00 (Monday to Friday)
Date posted
May 29, 2026
PDF Export
Open Questionnaire
APPLY NOW