{"id":1174772,"url":"https://alion.io/job/job-mail-security-operations-centre-soc-engineer","title":"Security Operations Centre (SOC) Engineer","company":{"id":701519,"name":"Job Mail","domain":"jobmail.co.za","url":"https://alion.io/company/job-mail","size_band":null,"is_staffing_agency":true,"is_intermediary":true,"listed_via":null,"ats_vendor":"Schema","truth_index":{"grade":"A","score":94,"open_postings":182,"ghost_share":0.022,"stale_share":0,"repost_share":0.648,"time_to_fill_p50_days":3,"computed_at":"2026-09-24T05:45:00Z"}},"role":"Security","role_family":"Security","seniority":null,"employment_type":"full_time","work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":[],"countries":[],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":24000,"max_usd":62000,"period":"year","method":null,"sample_n":2443},"experience_years_min":null,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Microsoft Defender","optional":false},{"name":"Service Desk","optional":false},{"name":"SLI/SLO/SLA","optional":false}],"status":"closed","first_seen_at":"2026-09-24T11:07:26Z","employer_posted_date":"2026-09-24","last_verified_at":"2026-09-24T16:07:27Z","board_verified":false,"closed_at":"2026-09-24T16:07:27Z","days_open":0,"trust":{"level":"not_scored","repost_count":null,"flags":[],"days_open":0},"description":"Department: Security Operations & 24/7 Support TeamReporting To: Service Delivery Manager / Team Lead - South Africa\n\nRole Overview\nThe SOC Engineer is responsible for security monitoring, incident triage and after-hours first-line service delivery for the company managed service clients.\nThe role combines security operations with managed service delivery, ensuring that security events and technical issues are identified, assessed, documented, progressed and escalated appropriately.\nThe SOC Engineer operates as part of the wider Service Delivery function, working closely with Service Desk Engineers and Service Delivery Management to provide reliable 24/7 support for contracted clients.\nWhat success looks like:\nSecurity alerts are monitored, assessed and responded to appropriately.\nSecurity incidents are accurately identified, documented and escalated.\n24/7 clients receive consistent and professional after-hours support.\nTickets and incidents have clear ownership and progression.\nEscalations contain sufficient technical context to enable efficient resolution.\nSecurity trends, recurring issues and risks are identified and reported.\nCore accountabilities:\nSecurity Monitoring & Incident Detection\nContinuously monitor security tools and alerting platforms.\nReview security alerts and determine appropriate action.\nIdentify suspicious activity and potential threats.\nEscalate security concerns according to defined processes\nSecurity incident triage and response:\nAssess and validate security incidents.\nPerform initial investigation and impact assessment.\nSupport containment activities within agreed processes.\nMaintain accurate incident records and investigation notes.\nEscalate incidents requiring additional expertise or authority.\nAfter-hours 1st line service desk coverage:\nProvide first-line support for contracted 24/7 clients outside standard business hours.\nAnswer, log and categorise incoming requests.\nPerform basic troubleshooting and resolution within agreed capability.\nProgress tickets appropriately and maintain ownership.\nEscalate technical issues to senior engineers where requiredEscalation and handover management:\nFollow defined escalation routes for technical and security issues.\nEnsure escalations contain accurate information, troubleshooting completed and relevant context.\nEngage senior engineers and management when required based on impact or complexity.\nSupport smooth handover between teams.\nSecurity and incident reporting\nMaintain accurate security and service documentation.\nTrack security incidents, trends, and recurring issues.\nContribute to incident reporting and service improvement activities.\nIdentify opportunities to improve monitoring, processes and knowledge sharing.\nKey Performance Indicators (KPIs):\nSecurity and service performance:\nSecurity alerts and tickets responded to within agreed SLA\nAfter-hours client support delivered within agreed SLA\nSecurity incidents progressed within expected timescales\nOwnership and quality:100% of tickets/incidents have clear ownership and next action\nTicket and incident notes meet quality standards\nReduction in avoidable rework or missed information\nEscalation management:Correct escalation of technical and security issues\nQuality of handovers to wider service desk team\nIssues escalated before becoming client-impacting\nSecurity improvement:\nRecurring issues identified and reported\nContribution to security documentation, processes and knowledge sharing\nTeam and capability development:\nCompletion of agreed training and certifications\nDevelopment of technical and security skills\nTechnical requirements\nEssential:\nExperience within an IT support/service desk environment.\nStrong troubleshooting skills.\nUnderstanding of Microsoft environments.\nExperience working with tickets, priorities and SLAs.\nGood written and verbal communication skills.\nInterest in developing security capability\nAdvantageous:\nExposure to:\nMicrosoft Defender\nMicrosoft 365 security\nEndpoint security tools\nFirewalls\nIdentity and access management\nExperience and development\nThe ideal candidate will be a technically strong first-line engineer or junior second-line engineer looking to develop into security operations.\nExperience within an MSP environment is advantageous. Relevant certifications are beneficial but not essential including:\nCompTIA Security +\nMicrosoft SC-900\nMicrosoft SC-200\nMD-102\nMS-102\nCompTIA Network+","description_format":"text","description_chars":4407,"description_truncated":false,"requirements":{"experience_years_min":null,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Incident Response"],"lifecycle":[{"event":"open","at":"2026-09-24T11:07:26Z"},{"event":"close","at":"2026-09-24T16:07:27Z"}],"liveness":null,"pay":null,"html_url":"https://alion.io/job/job-mail-security-operations-centre-soc-engineer","json_url":"https://alion.io/job/job-mail-security-operations-centre-soc-engineer.json","meta":{"generated_at":"2026-09-24T17:15:22Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers"}}