Skip to Content

Lead SOC Engineer

Addis Ababa, Ethiopia

JOB CLASSIFICATION

Job Title: Lead SOC Engineer

Duty Station: Addis Ababa

Employment Type: Full-time

JOB DESCRIPTION

JOB Summary:

The SOC Engineer is responsible for real-time cyber security threat hunting, triage, analysis, and response across all information processing assets. This role owns the configuration and tuning of security controls, serves as the senior technical escalation point within a 16x7x365 Security Operations Center, and drives continuous improvement of the organization's security posture through proactive threat intelligence, incident response, and cross-functional collaboration.

Key responsibilities:

1.  SOC Operations & Escalation Management

• Operate as a SOC subject-matter expert and manage escalations within a 16x7x365 operational model.

• Manage and resolve Level 2 escalations by identifying root causes, documenting findings, and driving issues to closure.

• Serve as the primary technical point of escalation for SOC Level 2 specialists, providing guidance and mentorship.

2.  Threat Hunting, Intelligence & Security Tooling

• Conduct threat intelligence research and proactively hunt for threats across the environment.

• Configure and fine-tune security policies on control devices, including firewalls, WAF, TDF, and ESA.

• Configure, tune, and optimize the security toolset, including SIEM (QRadar) and antivirus/endpoint platforms.

• Maintain and update security tools and technologies to ensure continued effectiveness and currency.

• Identify, deploy, configure, and manage security infrastructure across the organization.

• Ensure cyber security-enabled products and compensating security controls reduce identified risk to an acceptable level.

3.  Incident Response & Reporting

• Respond to security incidents in a timely manner, implementing appropriate measures to contain and mitigate impact.

• Collaborate with company-wide cyber defense staff to validate network security alerts.

• Work with the team on escalations for identification, isolation, mitigation, and reporting of critical incidents.

• Produce detailed reports on network events and activity relevant to cyber defense practices.

• Participate in incident response exercises and drills to test the effectiveness of security measures.

•  Provide advice and input for Disaster Recovery, Contingency, and Continuity of Operations Plans.

4.  Governance, Policy & Advisory

• Develop and implement security policies and procedures to ensure compliance with company and industry standards and regulations.

• Analyze escalations and recommend security solutions and best practices to improve the organization's overall security posture.

• Provide cyber security recommendations to leadership based on significant threats and vulnerabilities.

•Provide guidance and support to other teams and divisions within the organization on security-related matters.

5.  Continuous Improvement & Knowledge Management

• Instill and reinforce industry best practices in incident response, cyber security analysis, knowledge management, and SOC operations.

• Participate in the creation and review of new procedural documentation as assigned.

• Maintain key security performance indicators (KPIs) to ensure proper information security service delivery and continuous improvement.

Key Performance Indicators (KPIs)

• Mean time to detect (MTTD) and mean time to respond (MTTR) for security incidents.

• Volume and resolution quality of Level 2 escalations closed.

• SIEM and control-tooling tuning accuracy (false positive/negative rates).

• Timeliness and completeness of incident and cyber-defense reporting.

• Participation and outcomes of incident response exercises and drills.

JOB Specification

Qualifications

Education:

• Bachelor's degree in Computer Science, Information Security, Information Technology, or a related field.

• Master's degree in a relevant discipline (preferred).

Experience:

• 8+ years of progressive experience in a SOC, threat hunting, or security operations role, including handling escalations in a 24x7 or 16x7 environment.

• Demonstrated experience mentoring and providing technical escalation support to junior analysts.

Certifications (Preferred) – Minimum of 2 certificates is mandatory

· CompTIA Security+ / CySA+.

· GIAC Certified Incident Handler (GCIH).

· Certified Ethical Hacker (CEH).

· Certified Information Systems Security Professional (CISSP).

· SIEM / vendor-specific credentials (e.g., IBM QRadar).

Skills Requirements:

Technical Skills

· Hands-on expertise with SIEM platforms (e.g., IBM QRadar), firewalls, WAF, endpoint protection/antivirus, and related security controls.

· Strong knowledge of incident response methodologies, threat intelligence, and security policy development.

· Familiarity with configuring and tuning TDF and ESA security controls.

Leadership & Soft Skills

· Excellent analytical, documentation, and communication skills, with the ability to advise both technical teams and leadership.

· Ability to mentor and guide Level 2 analysts under pressure during live incidents.

· Strong cross-functional collaboration skills across cyber defense, IT, and business units.

Job Summary


Open Positions
1
Location
Addis Ababa, Ethiopia
Employment Type
Full-Time

More Details:
Time to Answer
2 open days
Process
1 Phone Call
1 Onsite Interview
Days to get an Offer
4 Days after Interview