KEYSTONE CYBER

Home Disciplines SOC analysts

SECURITY OPERATIONS

SOC analyst recruitment

Security operations is the highest-volume hiring in cyber and the easiest to get wrong. We screen SOC analysts on what they have actually investigated, not on which acronyms appear in their CV.

What we place

L1 ANALYST
Alert triage against playbooks, initial enrichment, escalation. Often the first security job someone holds.
L2 ANALYST
Investigation and containment. Pivots through logs and endpoint telemetry, decides what actually happened, owns the incident to closure.
L3 / SENIOR
Threat hunting, detection engineering, incident response leadership, and the cases with no playbook.
DETECTION ENGINEER
Writes, tests and tunes detection content. Increasingly a separate discipline from analysis, and considerably scarcer.
SHIFT LEAD
Runs the floor on a rotation — the bridge between analyst and manager, and a role employers routinely under-scope.
SOC MANAGER
Owns capability, metrics, staffing and the relationship with the rest of the business.

How we screen SOC analysts

A SOC analyst CV is unusually easy to inflate. Alert volumes, tool lists and incident counts all look impressive on paper and tell you almost nothing. We ask candidates to walk us through a real investigation they ran — what the alert was, what they checked first, what turned out to be true, and what they would do differently. The answer separates people who investigate from people who close tickets.

We also test the two things that break SOC placements. First, shift reality: whether someone genuinely accepts the rotation on offer, asked properly and early. Second, escalation judgement: whether they know what they do not know, which is the difference between a useful L1 and a liability.

The market, honestly

L1 and L2 supply is reasonable in both our markets — Cape Town in particular has depth, largely because of the offshore delivery centres running security operations for overseas parents. L3, detection engineering and incident response leadership are genuinely scarce, and employers hiring at that level are competing with remote offers from stronger currencies.

If a brief asks for five years of detection engineering, three specific SIEM platforms and a mid-level salary, we will say so at the briefing rather than search for six weeks and blame the market.

Where we recruit SOC analysts

Cape Town and Johannesburg across South Africa, and London and the wider United Kingdom.

Common questions

What is the difference between L1, L2 and L3 SOC analysts?

L1 triages alerts against a playbook and escalates. L2 investigates — pivoting through logs, deciding what actually happened, containing where authorised. L3 hunts proactively, writes and tunes detections, and handles the incidents nobody has a playbook for. Job titles blur these constantly, which is why we ask about the work rather than the title.

Do you place shift-based and 24/7 SOC roles?

Yes. Shift work is a specific screening problem: plenty of candidates will accept a rotation on paper and resent it within three months. We ask directly about night shifts, weekends and rotation patterns before shortlisting.

Which certifications matter for SOC hiring?

They are a signal, not a substitute. Security+ and the Blue Team Level 1 certification indicate genuine early commitment; GCIA, GCIH and vendor certifications on your specific SIEM carry more weight at L2 and above. We assess the work someone has actually done first.

Can you find analysts with experience on our specific SIEM?

Usually. Splunk, Microsoft Sentinel, Elastic, QRadar and CrowdStrike are the platforms we see most. Where the exact match does not exist in the market, we will tell you which adjacent experience transfers well rather than pretend.

How quickly can you shortlist SOC analysts?

L1 and L2 roles are the fastest work we do — days rather than weeks, because our network is deepest here. L3, detection engineering and SOC leadership take longer.

Related disciplines

Talk to us about your search

A short conversation is usually enough to tell you whether we can help.