Integrity360
Principal Security & Detection Engineer
Johannesburg
Get past the screening software and onto a recruiter's desk
hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.
- Keywords matched to this posting
- Fit score before you apply
- Cover letter included
Matched against 2.4M live jobs from 200,000+ employers in 200+ countries.
Tailor my resume for this job →Apply from your AI assistant
Connect hirly to Claude and ask it to apply to this job. hirly tailors your resume, fills the employer’s form and asks before sending. ChatGPT: manual setup today.
Some employer sites stop an application at a CAPTCHA or sign-in and hand it back with a link. Applying needs a paid plan. Works with any assistant that supports MCP.
hirly's read of this role
- Seniority
- Lead / management
- Country
- ZA
- Work mode
- On-site / unstated
- First seen by hirly
- 2 Sept 2026
Derived automatically from the posting. Upload your resume above to see how the role scores against it.
the posting
Principal Security & Detection Engineer
Title: Principal Security & Detection Engineer
Job type: Full-Time Permanent
Working arrangement: 3 days a week onsite/hybrid. No
Salary: Negotiable / DOE
About Us
Integrity360 is a leading independent cybersecurity and PCI specialist operating across Europe, Africa, the Caribbean, and North America. The company has office locations in Ireland, the UK, Bulgaria, Italy, Sweden, Spain, Lithuania, Ukraine, Africa, the Caribbean, and Canada, supported by seven Security Operations Centres (SOCs) located in Dublin, Sofia, Madrid, Stockholm, Rome, Johannesburg and Cape Town.
With over 780 employees, including more than 585 dedicated cybersecurity professionals, Integrity360 delivers a full suite of professional, support, and managed security services. These span the complete cyber risk lifecycle, from identification and prevention to detection, response, and recovery. Integrity360 supports over 3000 mid-market and enterprise organisations across sectors including financial services, insurance, government, healthcare, retail, telecommunications, and utilities.
At Integrity360, people come first. We invest heavily in learning, development and progression, fostering a dynamic culture where innovation, collaboration and continuous growth are at the heart of what we do. If you're ready to take your cyber security career to the next level, we’d love to hear from you.
Job Role / Responsibilities
As a Principal Security & Detection Engineer , you will provide senior technical leadership across our Security Operations capability, with a particular focus on detection engineering, security research, SOC automation, threat hunting, and the continued development of our fraud monitoring platform .
This is a highly technical role for an individual who is comfortable operating with a high degree of autonomy and taking ownership of complex technical problems from concept through to implementation.
You will operate as a senior member of the technical leadership team, helping define the direction of our detection and research capabilities while continuing to work hands-on across security engineering, software development, research and automation.
The ideal candidate is equally comfortable investigating how a new attack technique works, reproducing an exploit in a controlled environment, writing software to automate a security process, developing a new detection, and turning that work into a repeatable capability for the wider SOC.
This is not a traditional SOC monitoring or incident-response role . The focus is on building and improving the technology, methodologies and intelligence that enable the SOC to operate more effectively.
Key Responsibilities
Detection Engineering & Threat Hunting
Develop and maintain security detections across the technology stack.
Execute hypothesis-driven threat hunts and translate attacker TTPs into practical detections.
Map capabilities to MITRE ATT&CK and identify coverage gaps.
Fraud Monitoring Platform Development
Lead the development of the fraud and abuse monitoring platform.
Design analytics, detection logic, and integrations to identify abuse patterns within business applications.
Security Automation & SOAR
Design and develop automation to improve SOC efficiency.
Build automated enrichment, investigation, and response workflows (SOAR playbooks).
Security Research & Development
Conduct independent research into emerging threats, vulnerabilities, and attack techniques.
Reproduce exploits in a controlled environment to validate findings.
Technical Leadership & Autonomy
Provide technical leadership and establish standards for engineering activities.
Conduct quality reviews and act as a senior technical decision-maker.
Operate with a high degree of autonomy, owning projects from concept to implementation.
Technical En vironment
The successful candidate should be comfortable working across a broad security and software engineering environment, including:
SIEM
EDR/XDR technologies
SOAR and security automation
Threat hunting
Vulnerability research and exploitation
Network security and networking technologies
Python
SQL
APIs and system integrations
Required Experience & Skills
Minimum 3 years of professional experience in cybersecurity, software development, or a combination of both with a strong security focus.
Demonstrated experience developing software, automation or security tooling.
Strong Python development capability.
Strong understanding of security monitoring and detection engineering.
Experience working with SIEM, security analytics and large-scale security telemetry.
Experience designing and developing integrations between security platforms and other systems.
Strong understanding of networking and network security principles.
Ability to translate security research into practical detections, automation or engineering solutions.
Strong analytical and problem-solving ability.
Excellent technical documentation skills.
Ability to work independently with minimal supervision.
Demonstrated initiative and a willingness to research unfamiliar technologies and problems.
Ability to manage multiple technical projects and prioritise work effectively.
Certifications/Qualifications
A relevant degree, diploma or equivalent formal qualification is preferred.
However, demonstrated professional experience and technical capability will be considered equally important. Candidates who can demonstrate strong practical cybersecurity or software-development experience without a traditional academic background will be considered.
Industry certifications are not a primary requirement for this position. Demonstrated technical ability, initiative, engineering capability and practical experience are more important.
#LI-JL1
Similar jobs
- Detection Engineer Manager, Cyber SecurityCapitalone · 4 LocationsFirst seen 3d ago
- Windows Detection Engineering ManagerSentinellabs · Tel Aviv-Yafo, Tel Aviv District, IsraelFirst seen 3d ago
- Staff Detection EngineerAsana · WarsawFirst seen 3d ago
- Detection Engineering LeadDropzone AI · Remote - USFirst seen 4d agoremote
- Detection Engineering & Automation LeadJustMarkets · Remote, EuropeFirst seen 4d agoremote
Browse similar roles
Want this one?
Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.
Tailor my resume for this job