Junior SOC Engineer
Cape Town - South Africa
Job Summary
Junior SOC Engineer Cape Town(Hybrid)
WHO WE ARE
S-RM is a global intelligence and cyber security 2005wevehelped some of the most demanding clients in the world solve some of their toughest information security challenges.
Wevebeen able to do this because of our outstanding to developingsharp curious driven individuals who want to think critically solve complex problems and achieve success.
But we also know that the lives and careers it helps us proud of thiscultureand we invest in our peoples wellbeing learning and ideas every day.
Were excited youre thinking about joining us.
WORKING IN CYBER AT S-RM
Our Cyber Security division is the fastest-growing part of S-RM. Thecyber sector is always evolving and ourAdvisoryManaged Services andIncident Responsepractices arein moredemand than ever.
Werebuilding a team to meet this respond innovate and too hung up on hierarchy or your ideas are good enoughwellempower you to implement best person to talk to a customeryoullget that opportunity regardless of the title in your email signature. And when you need a hand your team will always have your back.
We alsodontbelievetheresa typical cyber security a team of intelligence analysts technical specialists software developers investigators risk managers and find a range of perspectives andexpertiseto help you learn and grow.
If that sounds like your kind of teamwedlike to hear from you.
THE ROLE
AsJuniorSOCEngineer you willwork onthe technical onboarding of MSSP customers andtheircomprehensive security monitoring coverage through log ingestion and detection engineering. The ideal candidate willhaveexpertiseinSOAR automation EDR/ XDRand potentiallySIEM administration log source integration anddetectionrule development. Additionally having experience with customer-facing technical roles data parsing and normalization and threat detection frameworks such as MITRE ATT&CK will get you ahead.
Key Responsibilities
- Customer Onboarding & Integration: You willconductthe technical onboarding of new MSSP customers including scoping log sourcesdeploying collectioninfrastructureandvalidatingend-to-end data flow. This includesmeetingonboarding timelines coordinating with customersuccess team members customerIT teams and ensuring a smooth transition into active monitoring.
- Log Ingestion & Data Engineering: You willhelp toimplement log ingestion pipelines including parsing normalisation andenrichment of diverse log sources. Thismayinclude troubleshooting ingestion failures managing data quality andoptimisingvolume and retention across a multi-tenantarchitecture.
- Detection Engineering: You willhelp todevelop tune andmaintaindetection logic alignedto customer environments and threat landscapes. Thismayinclude reducing false positive ratesandimproving detection fidelity based on analyst feedback and emerging threats.
- Documentation & Standardisation: You will create andmaintainrunbooks integration guides and onboarding playbooks to ensureconsistent repeatable delivery across customer engagements. You willassisttodefine and refine standards for log source coverageparsing schemas and detection rule lifecycle management.
- Collaboration & Support: You will work closely with SOC analysts platform engineers threat intelligence teams and clientsuccess managers to understand customer requirements and deliver monitoring solutions that maximise detection coverage. You willprovide technical support and troubleshooting for ingestion and detection-related issues.
- Contributing to Internal Technical Development Initiatives: When the schedule allows you will have opportunities toparticipatein and contribute to internal technical development initiatives.
WHAT WERE LOOKING FOR
Candidates with the following qualifications and experience are likely to succeedin our Managed Servicespracticeat S-RM.
That said if youdontthink you meetall ofthe criteria below but still are interested in the job please checks every boxwerelooking for candidates that are particularly strong in a fewareas andhave some interest and capabilities in others.
We nurture a culture of equality diversity andinclusionand we are dedicated to developing a workforce that displays a variety of talentsexperiencesand perspectives.Qualifications
- Education: ABachelors or Mastersdegree in a relevant subject (e.g. computer science software engineering systems administration or cybersecurity) or equivalent practical experience. Relevant industry certifications areadvantageous as is demonstrable knowledge such as contributions toopen sourcesoftware or personal projects.
- Experience:1 years of experience inSOC and/or cybersecurity engineering detection engineering data engineering or a similar technical role preferably within an MSSP or managed security operations environment.
Professional Expertise
- Strong problem-solving skills with the ability to troubleshoot complex multi-system issues
- Strong communicationskills particularly in customer-facing and cross-team contexts
- Self-directed with the ability to prioritise tasks and manage workload efficiently across multiple concurrent onboarding engagements
Technical Expertise
- Experience with security tooling such as EDR SIEM and SOAR products
- Experience with log management and data pipeline architectures including familiarity with common log source formats (firewall endpoint cloud identity)
- Someexperience writing detection content using query languages such as KQL SPL or SQL
- Familiarity with the MITRE ATT&CK framework and its application to detection coverage mapping
- Experience with customerfacing activities which could include reporting incident communicationsonboarding or technical integration delivery
Preferred Expertise
- Experience with CI/CD pipelines and Infrastructure as Code (GitHub Actions Terraform Ansible etc.)
- Proficiencyin programming and scripting languages such as Python Go PowerShell and/or Bash
- Experience with detection-as-code workflows and version-controlled rule management
The successful candidate must have permission to work inSouth Africabythe start of their employment.
OUR BENEFITS
We offerthoughtful balanced rewards and supportto help our people do their best work and live their lives outsideitthis includes but is not exhaustive of:
- Holiday 23 days per year increasing to 28 days (1 day for every year you worked at S-RM up
to a maximum of 5 days) in addition to bank holidays
- Gap Cover policy allowing you to bridge the gap between your medical bills and your medical
aid cover.
- Hybrid working and flexible working hours;
- Private pension up to 7% contribution matched by the company
- Life Insurance4X annual salary.
Parental Support:
- Fertility treatment leave 5 daysof leave per cycle of treatment per year;
- Maternity leave26 weeksof full pay followed by 13 weeks of half pay;
- Paternity leave6 weeksof full pay.
Various Health and Medical Benefits including:
- Medical aid with Discovery Health for employee partner and children up to the cost of the Classic
Saverplan (taxable benefit) for you and your family;
- EAPprogrammefor you and your immediate family;
- Free access to the world-famous mindfulness appHeadspace.
To apply for this role pleasesubmitan up-to-date CV through this link: Job Application for Junior SOC Engineer at S-RM
Required Experience:
Junior IC
About Company
Leading cyber security consultancy and intelligence experts delivering intelligence, resilience, and response solutions to clients worldwide.