SOC Lead
2026-07-22T11:37:08+00:00
Apeiro
https://cdn.greatkenyanjobs.com/jsjobsdata/data/employer/comp_10590/logo/Apeiro.jpeg
https://www.apeiro.digital/
FULL_TIME
Orbit Place, 4th Floor, Westlands
Nairobi
Nairobi
00100
Kenya
Healthcare
Computer & IT, Management, Business Operations
2026-08-05T17:00:00+00:00
8
About the role
The SOC Lead is responsible for leading the day-to-day operations of the Security Operations Centre (SOC), ensuring continuous monitoring, detection, investigation, and response to cybersecurity threats across the organization's infrastructure, cloud platforms, networks, and applications. This role provides technical leadership to SOC analysts while driving operational excellence, incident response maturity, security automation, and continuous service improvement.
What you'll do
- Lead and manage 24/7 Security Operations Centre (SOC) activities and operational performance.
- Supervise and mentor L1 and L2 SOC Analysts, providing technical guidance and performance management.
- Ensure timely triage, investigation, escalation, and resolution of security alerts within defined SLAs.
- Monitor and manage enterprise security technologies including SIEM, EDR, Identity Security, Cloud Security, and Network Security solutions.
- Lead the investigation, containment, and remediation of cybersecurity incidents including phishing, malware, ransomware, insider threats, and unauthorized access incidents.
- Develop and enhance threat detection capabilities through continuous improvement of detection rules and correlation logic.
- Manage and optimize security platforms including SIEM, SOAR, EDR, Email Security, Identity Protection, and Vulnerability Management solutions.
- Develop and maintain SOAR playbooks and security automation workflows to improve incident response efficiency.
- Ensure SOC operations comply with organizational security policies, standards, and industry best practices.
- Prepare and present daily, weekly, and monthly SOC operational reports and security metrics.
- Collaborate with Network Engineering, Cloud Engineering, Infrastructure, DevOps, and Service Desk teams to support secure operations.
- Coach, mentor, and develop SOC Analysts through technical training, knowledge sharing, and performance reviews.
What we're looking for
- Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Technology, or a related discipline.
- Minimum of 5 years' experience in Security Operations, Cybersecurity, or Information Security roles.
- Minimum of 2 years' experience leading, mentoring, or supervising SOC analysts or security teams.
- Hands-on experience with enterprise SIEM platforms including Microsoft Sentinel, Splunk, IBM QRadar, or Elastic SIEM.
- Experience with Endpoint Detection and Response (EDR) solutions such as Microsoft Defender, CrowdStrike, or SentinelOne.
- Strong knowledge of network security concepts including TCP/IP, Firewalls, VPNs, IDS/IPS, DNS, and Web Security.
- Proven experience investigating cybersecurity incidents including phishing, malware, insider threats, privilege abuse, and endpoint compromise.
- Working knowledge of cybersecurity frameworks including MITRE ATT&CK, Cyber Kill Chain, and NIST Incident Response Framework.
- Experience with SOAR platforms and security automation workflows.
- Strong analytical, documentation, reporting, and problem-solving skills.
- Excellent leadership, communication, stakeholder management, and team collaboration skills.
Nice to have
- CompTIA Security+ certification.
- Microsoft SC-200 Security Operations Analyst certification.
- Certified Ethical Hacker (CEH) certification.
- GIAC Certified Incident Handler (GCIH) certification.
- Cisco CCNA Security certification.
- ITILĀ® 4 Foundation certification.
- Microsoft Azure Security Engineer Associate (AZ-500) certification.
- Experience working within healthcare, cloud, or other regulated environments.
- Familiarity with information security frameworks and standards including ISO 27001, CIS Controls, NIST Cybersecurity Framework (NIST CSF), and SOC 2.
- Lead and manage 24/7 Security Operations Centre (SOC) activities and operational performance.
- Supervise and mentor L1 and L2 SOC Analysts, providing technical guidance and performance management.
- Ensure timely triage, investigation, escalation, and resolution of security alerts within defined SLAs.
- Monitor and manage enterprise security technologies including SIEM, EDR, Identity Security, Cloud Security, and Network Security solutions.
- Lead the investigation, containment, and remediation of cybersecurity incidents including phishing, malware, ransomware, insider threats, and unauthorized access incidents.
- Develop and enhance threat detection capabilities through continuous improvement of detection rules and correlation logic.
- Manage and optimize security platforms including SIEM, SOAR, EDR, Email Security, Identity Protection, and Vulnerability Management solutions.
- Develop and maintain SOAR playbooks and security automation workflows to improve incident response efficiency.
- Ensure SOC operations comply with organizational security policies, standards, and industry best practices.
- Prepare and present daily, weekly, and monthly SOC operational reports and security metrics.
- Collaborate with Network Engineering, Cloud Engineering, Infrastructure, DevOps, and Service Desk teams to support secure operations.
- Coach, mentor, and develop SOC Analysts through technical training, knowledge sharing, and performance reviews.
- SIEM
- EDR
- SOAR
- Incident Response
- Threat Hunting
- Network Security
- TCP/IP
- Firewalls
- VPN
- IDS/IPS
- DNS
- Web Security
- MITRE ATT&CK
- Cyber Kill Chain
- NIST Incident Response Framework
- Vulnerability Management
- Microsoft Sentinel
- Splunk
- IBM QRadar
- Elastic SIEM
- Microsoft Defender
- CrowdStrike
- SentinelOne
- Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Technology, or a related discipline.
- Minimum of 5 years' experience in Security Operations, Cybersecurity, or Information Security roles.
- Minimum of 2 years' experience leading, mentoring, or supervising SOC analysts or security teams.
- Hands-on experience with enterprise SIEM platforms including Microsoft Sentinel, Splunk, IBM QRadar, or Elastic SIEM.
- Experience with Endpoint Detection and Response (EDR) solutions such as Microsoft Defender, CrowdStrike, or SentinelOne.
- Strong knowledge of network security concepts including TCP/IP, Firewalls, VPNs, IDS/IPS, DNS, and Web Security.
- Proven experience investigating cybersecurity incidents including phishing, malware, insider threats, privilege abuse, and endpoint compromise.
- Working knowledge of cybersecurity frameworks including MITRE ATT&CK, Cyber Kill Chain, and NIST Incident Response Framework.
- Experience with SOAR platforms and security automation workflows.
- Strong analytical, documentation, reporting, and problem-solving skills.
- Excellent leadership, communication, stakeholder management, and team collaboration skills.
JOB-6a60ab6421ef3
Vacancy title:
SOC Lead
[Type: FULL_TIME, Industry: Healthcare, Category: Computer & IT, Management, Business Operations]
Jobs at:
Apeiro
Deadline of this Job:
Wednesday, August 5 2026
Duty Station:
Orbit Place, 4th Floor, Westlands | Nairobi | Nairobi
Summary
Date Posted: Wednesday, July 22 2026, Base Salary: Not Disclosed
Similar Jobs in Kenya
Learn more about Apeiro
Apeiro jobs in Kenya
JOB DETAILS:
About the role
The SOC Lead is responsible for leading the day-to-day operations of the Security Operations Centre (SOC), ensuring continuous monitoring, detection, investigation, and response to cybersecurity threats across the organization's infrastructure, cloud platforms, networks, and applications. This role provides technical leadership to SOC analysts while driving operational excellence, incident response maturity, security automation, and continuous service improvement.
What you'll do
- Lead and manage 24/7 Security Operations Centre (SOC) activities and operational performance.
- Supervise and mentor L1 and L2 SOC Analysts, providing technical guidance and performance management.
- Ensure timely triage, investigation, escalation, and resolution of security alerts within defined SLAs.
- Monitor and manage enterprise security technologies including SIEM, EDR, Identity Security, Cloud Security, and Network Security solutions.
- Lead the investigation, containment, and remediation of cybersecurity incidents including phishing, malware, ransomware, insider threats, and unauthorized access incidents.
- Develop and enhance threat detection capabilities through continuous improvement of detection rules and correlation logic.
- Manage and optimize security platforms including SIEM, SOAR, EDR, Email Security, Identity Protection, and Vulnerability Management solutions.
- Develop and maintain SOAR playbooks and security automation workflows to improve incident response efficiency.
- Ensure SOC operations comply with organizational security policies, standards, and industry best practices.
- Prepare and present daily, weekly, and monthly SOC operational reports and security metrics.
- Collaborate with Network Engineering, Cloud Engineering, Infrastructure, DevOps, and Service Desk teams to support secure operations.
- Coach, mentor, and develop SOC Analysts through technical training, knowledge sharing, and performance reviews.
What we're looking for
- Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Technology, or a related discipline.
- Minimum of 5 years' experience in Security Operations, Cybersecurity, or Information Security roles.
- Minimum of 2 years' experience leading, mentoring, or supervising SOC analysts or security teams.
- Hands-on experience with enterprise SIEM platforms including Microsoft Sentinel, Splunk, IBM QRadar, or Elastic SIEM.
- Experience with Endpoint Detection and Response (EDR) solutions such as Microsoft Defender, CrowdStrike, or SentinelOne.
- Strong knowledge of network security concepts including TCP/IP, Firewalls, VPNs, IDS/IPS, DNS, and Web Security.
- Proven experience investigating cybersecurity incidents including phishing, malware, insider threats, privilege abuse, and endpoint compromise.
- Working knowledge of cybersecurity frameworks including MITRE ATT&CK, Cyber Kill Chain, and NIST Incident Response Framework.
- Experience with SOAR platforms and security automation workflows.
- Strong analytical, documentation, reporting, and problem-solving skills.
- Excellent leadership, communication, stakeholder management, and team collaboration skills.
Nice to have
- CompTIA Security+ certification.
- Microsoft SC-200 Security Operations Analyst certification.
- Certified Ethical Hacker (CEH) certification.
- GIAC Certified Incident Handler (GCIH) certification.
- Cisco CCNA Security certification.
- ITILĀ® 4 Foundation certification.
- Microsoft Azure Security Engineer Associate (AZ-500) certification.
- Experience working within healthcare, cloud, or other regulated environments.
- Familiarity with information security frameworks and standards including ISO 27001, CIS Controls, NIST Cybersecurity Framework (NIST CSF), and SOC 2.
Work Hours: 8
Experience in Months: 60
Level of Education: bachelor degree
Job application procedure
To apply, please visit: https://talent.oneinfinia.ai/careers/apeiro/jobs/soc-lead
All Jobs | QUICK ALERT SUBSCRIPTION