SOC Lead job at Apeiro
22 Days Ago
Linkedid Twitter Share on facebook
SOC Lead
2026-07-22T11:37:08+00:00
Apeiro
https://cdn.greatkenyanjobs.com/jsjobsdata/data/employer/comp_10590/logo/Apeiro.jpeg
FULL_TIME
Orbit Place, 4th Floor, Westlands
Nairobi
Nairobi
00100
Kenya
Healthcare
Computer & IT, Management, Business Operations
KES
MONTH
2026-08-05T17:00:00+00:00
8

About the role

The SOC Lead is responsible for leading the day-to-day operations of the Security Operations Centre (SOC), ensuring continuous monitoring, detection, investigation, and response to cybersecurity threats across the organization's infrastructure, cloud platforms, networks, and applications. This role provides technical leadership to SOC analysts while driving operational excellence, incident response maturity, security automation, and continuous service improvement.

What you'll do

  • Lead and manage 24/7 Security Operations Centre (SOC) activities and operational performance.
  • Supervise and mentor L1 and L2 SOC Analysts, providing technical guidance and performance management.
  • Ensure timely triage, investigation, escalation, and resolution of security alerts within defined SLAs.
  • Monitor and manage enterprise security technologies including SIEM, EDR, Identity Security, Cloud Security, and Network Security solutions.
  • Lead the investigation, containment, and remediation of cybersecurity incidents including phishing, malware, ransomware, insider threats, and unauthorized access incidents.
  • Develop and enhance threat detection capabilities through continuous improvement of detection rules and correlation logic.
  • Manage and optimize security platforms including SIEM, SOAR, EDR, Email Security, Identity Protection, and Vulnerability Management solutions.
  • Develop and maintain SOAR playbooks and security automation workflows to improve incident response efficiency.
  • Ensure SOC operations comply with organizational security policies, standards, and industry best practices.
  • Prepare and present daily, weekly, and monthly SOC operational reports and security metrics.
  • Collaborate with Network Engineering, Cloud Engineering, Infrastructure, DevOps, and Service Desk teams to support secure operations.
  • Coach, mentor, and develop SOC Analysts through technical training, knowledge sharing, and performance reviews.

What we're looking for

  • Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Technology, or a related discipline.
  • Minimum of 5 years' experience in Security Operations, Cybersecurity, or Information Security roles.
  • Minimum of 2 years' experience leading, mentoring, or supervising SOC analysts or security teams.
  • Hands-on experience with enterprise SIEM platforms including Microsoft Sentinel, Splunk, IBM QRadar, or Elastic SIEM.
  • Experience with Endpoint Detection and Response (EDR) solutions such as Microsoft Defender, CrowdStrike, or SentinelOne.
  • Strong knowledge of network security concepts including TCP/IP, Firewalls, VPNs, IDS/IPS, DNS, and Web Security.
  • Proven experience investigating cybersecurity incidents including phishing, malware, insider threats, privilege abuse, and endpoint compromise.
  • Working knowledge of cybersecurity frameworks including MITRE ATT&CK, Cyber Kill Chain, and NIST Incident Response Framework.
  • Experience with SOAR platforms and security automation workflows.
  • Strong analytical, documentation, reporting, and problem-solving skills.
  • Excellent leadership, communication, stakeholder management, and team collaboration skills.

Nice to have

  • CompTIA Security+ certification.
  • Microsoft SC-200 Security Operations Analyst certification.
  • Certified Ethical Hacker (CEH) certification.
  • GIAC Certified Incident Handler (GCIH) certification.
  • Cisco CCNA Security certification.
  • ITILĀ® 4 Foundation certification.
  • Microsoft Azure Security Engineer Associate (AZ-500) certification.
  • Experience working within healthcare, cloud, or other regulated environments.
  • Familiarity with information security frameworks and standards including ISO 27001, CIS Controls, NIST Cybersecurity Framework (NIST CSF), and SOC 2.
  • Lead and manage 24/7 Security Operations Centre (SOC) activities and operational performance.
  • Supervise and mentor L1 and L2 SOC Analysts, providing technical guidance and performance management.
  • Ensure timely triage, investigation, escalation, and resolution of security alerts within defined SLAs.
  • Monitor and manage enterprise security technologies including SIEM, EDR, Identity Security, Cloud Security, and Network Security solutions.
  • Lead the investigation, containment, and remediation of cybersecurity incidents including phishing, malware, ransomware, insider threats, and unauthorized access incidents.
  • Develop and enhance threat detection capabilities through continuous improvement of detection rules and correlation logic.
  • Manage and optimize security platforms including SIEM, SOAR, EDR, Email Security, Identity Protection, and Vulnerability Management solutions.
  • Develop and maintain SOAR playbooks and security automation workflows to improve incident response efficiency.
  • Ensure SOC operations comply with organizational security policies, standards, and industry best practices.
  • Prepare and present daily, weekly, and monthly SOC operational reports and security metrics.
  • Collaborate with Network Engineering, Cloud Engineering, Infrastructure, DevOps, and Service Desk teams to support secure operations.
  • Coach, mentor, and develop SOC Analysts through technical training, knowledge sharing, and performance reviews.
  • SIEM
  • EDR
  • SOAR
  • Incident Response
  • Threat Hunting
  • Network Security
  • TCP/IP
  • Firewalls
  • VPN
  • IDS/IPS
  • DNS
  • Web Security
  • MITRE ATT&CK
  • Cyber Kill Chain
  • NIST Incident Response Framework
  • Vulnerability Management
  • Microsoft Sentinel
  • Splunk
  • IBM QRadar
  • Elastic SIEM
  • Microsoft Defender
  • CrowdStrike
  • SentinelOne
  • Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Technology, or a related discipline.
  • Minimum of 5 years' experience in Security Operations, Cybersecurity, or Information Security roles.
  • Minimum of 2 years' experience leading, mentoring, or supervising SOC analysts or security teams.
  • Hands-on experience with enterprise SIEM platforms including Microsoft Sentinel, Splunk, IBM QRadar, or Elastic SIEM.
  • Experience with Endpoint Detection and Response (EDR) solutions such as Microsoft Defender, CrowdStrike, or SentinelOne.
  • Strong knowledge of network security concepts including TCP/IP, Firewalls, VPNs, IDS/IPS, DNS, and Web Security.
  • Proven experience investigating cybersecurity incidents including phishing, malware, insider threats, privilege abuse, and endpoint compromise.
  • Working knowledge of cybersecurity frameworks including MITRE ATT&CK, Cyber Kill Chain, and NIST Incident Response Framework.
  • Experience with SOAR platforms and security automation workflows.
  • Strong analytical, documentation, reporting, and problem-solving skills.
  • Excellent leadership, communication, stakeholder management, and team collaboration skills.
bachelor degree
60
JOB-6a60ab6421ef3

Vacancy title:
SOC Lead

[Type: FULL_TIME, Industry: Healthcare, Category: Computer & IT, Management, Business Operations]

Jobs at:
Apeiro

Deadline of this Job:
Wednesday, August 5 2026

Duty Station:
Orbit Place, 4th Floor, Westlands | Nairobi | Nairobi

Summary
Date Posted: Wednesday, July 22 2026, Base Salary: Not Disclosed

Similar Jobs in Kenya
Learn more about Apeiro
Apeiro jobs in Kenya

JOB DETAILS:

About the role

The SOC Lead is responsible for leading the day-to-day operations of the Security Operations Centre (SOC), ensuring continuous monitoring, detection, investigation, and response to cybersecurity threats across the organization's infrastructure, cloud platforms, networks, and applications. This role provides technical leadership to SOC analysts while driving operational excellence, incident response maturity, security automation, and continuous service improvement.

What you'll do

  • Lead and manage 24/7 Security Operations Centre (SOC) activities and operational performance.
  • Supervise and mentor L1 and L2 SOC Analysts, providing technical guidance and performance management.
  • Ensure timely triage, investigation, escalation, and resolution of security alerts within defined SLAs.
  • Monitor and manage enterprise security technologies including SIEM, EDR, Identity Security, Cloud Security, and Network Security solutions.
  • Lead the investigation, containment, and remediation of cybersecurity incidents including phishing, malware, ransomware, insider threats, and unauthorized access incidents.
  • Develop and enhance threat detection capabilities through continuous improvement of detection rules and correlation logic.
  • Manage and optimize security platforms including SIEM, SOAR, EDR, Email Security, Identity Protection, and Vulnerability Management solutions.
  • Develop and maintain SOAR playbooks and security automation workflows to improve incident response efficiency.
  • Ensure SOC operations comply with organizational security policies, standards, and industry best practices.
  • Prepare and present daily, weekly, and monthly SOC operational reports and security metrics.
  • Collaborate with Network Engineering, Cloud Engineering, Infrastructure, DevOps, and Service Desk teams to support secure operations.
  • Coach, mentor, and develop SOC Analysts through technical training, knowledge sharing, and performance reviews.

What we're looking for

  • Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Technology, or a related discipline.
  • Minimum of 5 years' experience in Security Operations, Cybersecurity, or Information Security roles.
  • Minimum of 2 years' experience leading, mentoring, or supervising SOC analysts or security teams.
  • Hands-on experience with enterprise SIEM platforms including Microsoft Sentinel, Splunk, IBM QRadar, or Elastic SIEM.
  • Experience with Endpoint Detection and Response (EDR) solutions such as Microsoft Defender, CrowdStrike, or SentinelOne.
  • Strong knowledge of network security concepts including TCP/IP, Firewalls, VPNs, IDS/IPS, DNS, and Web Security.
  • Proven experience investigating cybersecurity incidents including phishing, malware, insider threats, privilege abuse, and endpoint compromise.
  • Working knowledge of cybersecurity frameworks including MITRE ATT&CK, Cyber Kill Chain, and NIST Incident Response Framework.
  • Experience with SOAR platforms and security automation workflows.
  • Strong analytical, documentation, reporting, and problem-solving skills.
  • Excellent leadership, communication, stakeholder management, and team collaboration skills.

Nice to have

  • CompTIA Security+ certification.
  • Microsoft SC-200 Security Operations Analyst certification.
  • Certified Ethical Hacker (CEH) certification.
  • GIAC Certified Incident Handler (GCIH) certification.
  • Cisco CCNA Security certification.
  • ITILĀ® 4 Foundation certification.
  • Microsoft Azure Security Engineer Associate (AZ-500) certification.
  • Experience working within healthcare, cloud, or other regulated environments.
  • Familiarity with information security frameworks and standards including ISO 27001, CIS Controls, NIST Cybersecurity Framework (NIST CSF), and SOC 2.

Work Hours: 8

Experience in Months: 60

Level of Education: bachelor degree

Job application procedure

To apply, please visit: https://talent.oneinfinia.ai/careers/apeiro/jobs/soc-lead

All Jobs | QUICK ALERT SUBSCRIPTION

Job Info
Job Category: Management jobs in Kenya
Job Type: Full-time
Deadline of this Job: Wednesday, August 5 2026
Duty Station: Orbit Place, 4th Floor, Westlands | Nairobi | Nairobi
Posted: 22-07-2026
No of Jobs: 1
Start Publishing: 22-07-2026
Stop Publishing (Put date of 2030): 10-10-2076
Apply Now
Notification Board

Join a Focused Community on job search to uncover both advertised and non-advertised jobs that you may not be aware of. A jobs WhatsApp Group Community can ensure that you know the opportunities happening around you and a jobs Facebook Group Community provides an opportunity to discuss with employers who need to fill urgent position. Click the links to join. You can view previously sent Email Alerts here incase you missed them and Subscribe so that you never miss out.

Caution: Never Pay Money in a Recruitment Process.

Some smart scams can trick you into paying for Psychometric Tests.