Security Operations Centre Analyst

FirstRand Bank Limited

Randburg

On-site

ZAR 700,000 - 1,100,000

Full time

5 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

FirstRand Bank Limited seeks a Senior SOC Analyst to lead end-to-end incident response and digital forensics across Windows, Linux, and macOS environments. You will own escalations, perform threat hunts, and mentor junior staff in a high-stakes security operations context.

The role requires expertise in PCAP analysis, SIEM/EDR tools (Microsoft Sentinel, Splunk, MDE), and scripting with PowerShell and Python. Advanced knowledge of ATT&CK, logs, timelines, and reporting is essential.

Qualifications

  • Expert-level log and artifact analysis across Windows/Linux/macOS and web/network layers.
  • Hands-on PCAP analysis, Network IDS, NetFlow/IPFIX, and TLS/DNS telemetry.
  • Strong SIEM/EDR skills: Microsoft Sentinel, Splunk, Microsoft Defender for Endpoint.
  • Scripting for data parsing and automation (PowerShell, Python).
  • IR methodologies: evidence preservation, timeline construction, ATT&CK mapping, defensible reporting.

Responsibilities

  • Incident Response & Forensics: rapid triage and scoping for P1/P2 incidents; define hypotheses and investigative plan.
  • Evidence acquisition: volatile and non-volatile with chain-of-custody.
  • Web server log analysis and detection of LFI/RFI, RCE, SSRF, auth abuse, webshell indicators.
  • Endpoint artifacts (Windows) and Linux logs: ensure integrity and lineage.
  • Network: PCAP, Zeek logs, NetFlow/IPFIX; identify C2, beaconing, DNS tunneling, data exfiltration.
  • Firewall/Proxy/WAF/IDS: correlate rule hits and reconstruct attacker paths.
  • Malware triage: static/dynamic analysis; derive IOCs/IOAs and containment steps.
  • Timeline & correlation: multi-source timelines and ATT&CK mapping.
  • Reporting: technical reports and executive summaries; remediation guidance.
  • SOC L3: threat hunting, hypothesis-driven hunts;Detection engineering with SIEM/EDR teams.
  • Purple teaming: validate detections with red teams; telemetry assurance and SOPs.

Skills

Log Analysis
Windows
Linux
macOS
PCAP Analysis
SIEM/EDR
PowerShell
Python
ATT&CK Mapping
Threat Hunting
IR Methodologies
Networking Fundamentals
Digital Forensics

Tools

Microsoft Sentinel
Splunk
MD Defender for Endpoint
Magnet AX Cyber
FTK
SleuthKit
Autopsy
Redline
Wireshark
Zeek

Job description

Job Description

Hello Future Security Operations Centre Analyst III Welcome to FNB, the home of the #changeables. We design for the shapeshifters and deliver products and services that make us incredibly proud of people that make it happen. As part of our talent team, you will be surrounded by unique talents, diverse minds, and an adaptable environment that lives up to the promise of staying curious. Now’s the time to imagine your potential in a team where experts come together and ignite effective change.

Overview of the role

Lead end-to-end incident response and digital forensics with deep expertise in log and artifact analysis across host, network, and application layers. Function as SOC L3 between incidents owning escalations, threat hunts, detection engineering, and mentoring

Required Skills and Experience

Expert-level log and artifact analysis across Windows/Linux/macOS and web/network layers. Hands-on proficiency with PCAP analysis, Network IDS (Zeek etc.), NetFlow/IPFIX, and TLS/DNS telemetry. Strong SIEM/EDR skills: Microsoft Sentinel, Splunk, Microsoft Defender for Endpoint. Scripting for data parsing and automation (PowerShell, Python). IR methodologies: evidence preservation, timeline construction, ATT&CK mapping, defensible reporting. Networking fundamentals: TCP/IP, HTTP, proxies/WAF behavior, SSL/TLS. Digital Forensics Evidence Analysis: Experience with analyzing digital forensics evidence using tools such as Magnet Axiom Cyber, FTK, SleuthKit and Autopsy, or Redline. Offensive Security Assessment Experience: Understand attacks and how to execute these attacks to identify vulnerabilities and gaps within the organization

Preferred qualification

Certification in Cyber security / Splunk certificate / certified ethical hacker Offensive Security Certified Professional preferred

Primary Responsibilities
  • Incident Response & Forensics Rapid triage and scoping for P1/P2 incidents; define hypotheses and investigative plan
  • Evidence acquisition: volatile (RAM, network) and non-volatile (disk, artifacts) with chain-of custody
  • Web server log analysis: IIS (W3C, u_ex*, HTTPERR), Apache/Nginx (access/error); detect LFI/RFI, RCE, SSRF, auth abuse, webshell indicators
  • Endpoint artifacts (Windows): Prefetch, Shimcache/AppCompatCache, Amcache, SRUM, UserAssist, Jump Lists, LNK, browser artifacts, registry keys, $MFT/USN basics
  • Endpoint artifacts (Linux): auth.log, syslog, journald, bash history, cron, SSH logs; process/file lineage
  • Network: PCAP (Wireshark/tshark), Zeek logs, NetFlow/IPFIX; identify C2, beaconing (JA3/JA3S), DNS tunneling, data exfiltration, lateral movement
  • Firewall/Proxy/WAF/IDS: Correlate rule hits, proxies, WAF logs, IPS alerts; reconstruct attacker pathing and egress controls
  • Malware/binary triage: static/dynamic (strings, headers, sandbox); derive IOCs/IOAs and containment steps
  • Timeline & correlation: Build and maintain multi-source timelines (Timeline Tacker) to reconstruct intrusion and dwell time; ATT&CK technique mapping
  • Reporting: Technical reports and executive summaries; remediation guidance and validation testing
  • SOC L3 Functions Threat hunting: Hypothesis-driven hunts across SIEM/EDR/network; codify repeatable playbooks
  • Detection engineering: Create/tune SIEM rules with Detection Engineering Team (e.g., Splunk), EDR analytics (MDE), Sigma Rule queries / conversions, to reduce false positives
  • Purple teaming: Collaborate with red teams to validate detections and test response playbooks
  • Telemetry assurance: Review logging coverage, retention, integrity; recommend improvements
  • Process maturity: maintain IR runbooks, forensic SOPs, chain-of-custody templates, evidence vault workflows
Technology Stack
  • SIEM: Microsoft Sentinel, Splunk
  • EDR/XDR: Microsoft Defender Suite (MDI, MDE, MDO, MDC)
  • OS: Windows, Linux, macOS
  • Network & Microsegmentation: Cisco Secure Workload (formerly Tetration)
  • Identity: Cisco Identity Services Engine (ISE), Microsoft Defender for Identity (MDI), Microsoft Purview
  • Network sensors/tools: Zeek, Suricata, Wireshark/tshark, NetFlow/IPFIX collectors
  • Web Application Firewalls: F5 BIG-IP Advanced WAF (formerly ASM); other major WAFs (Imperva, Akamai Kona, Cloudflare WAF, AWS/Azure WAF)
  • Firewalls/Proxies/IDS: Enterprise firewall/WAF/secure web gateway platforms that integrate with SIEM for centralized logging
You will have access to
  • Opportunities to network and collaborate
  • Challenging Work
  • Opportunities to innovate
Important Closing Date Note

Take note that applications will not be accepted on the below date and onwards, kindly submit applications ahead of the closing date indicated below. 14/09/26

Employment Equity and Diversity Statement

All appointments will be made in line with FirstRand Group’s Employment Equity plan.

The Bank supports the recruitment and advancement of individuals with disabilities. In order for us to fulfill this purpose, candidates can disclose their disability information on a voluntary basis. The Bank will keep this information confidential unless we are required by law to disclose this information to other parties.

About FirstRand

FirstRand provides a comprehensive range of financial services in South Africa and certain markets in broader Africa. The group also offers certain niche products and services in the UK and India. Listed on the Johannesburg Stock Exchange (JSE) and the Namibian Stock Exchange (NSX), FirstRand Limited is the largest financial institution by market capitalisation in Africa. The group follows a multi-branding approach. Its portfolio of financial services businesses includes FNB, RMB, WesBank, Ashburton Investments, Aldermore, MotoNovo and DirectAxis. Many are leaders in their respective segments and markets, offering transactional, lending, investment and insurance products and services The FirstRand Corporate Centre houses many of the critical functions required by a large and complex financial services group. The group’s track record of delivering superior returns to shareholders has been achieved through a combination of organic growth, acquisitions, innovation and the creation of completely new businesses The group’s purpose of delivering Shared Prosperity provides many opportunities for employees to innovate to address social and environmental challenges in our markets. All of our businesses have successful Volunteering programmes which also allow employees to adopt and support causes close to their hearts.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Operations Centre Analyst
Security Operations Centre Analyst

Fnbnamibia • Randburg

On-site
ZAR 900,000 - 1,300,000
Security Operations Centre Analyst
Security Operations Centre Analyst

FirstRand Limited • Randburg

On-site
ZAR 800,000 - 1,200,000
Threat Intelligence and Threat Hunting Manager
Threat Intelligence and Threat Hunting Manager

FirstRand Bank Limited • Randburg

On-site
ZAR 1,200,000 - 1,800,000
Developer
Developer

Wesbank • Johannesburg

On-site
ZAR 800,000 - 1,000,000
Developer
Developer

RMB Nigeria Limited • Johannesburg

On-site
ZAR 1,200,000 - 1,600,000
Developer
Developer

FirstRand Limited • Johannesburg

On-site
ZAR 900,000 - 1,200,000
Developer
Developer

Fnbnamibia • Johannesburg

On-site
ZAR 1,000,000 - 1,800,000
Product Specialist
Product Specialist

Fnbnamibia • Johannesburg

On-site
ZAR 900,000 - 1,300,000
Networking opportunities
Challenging, agile environment
End-to-end ownership opportunities
Private Wealth Advisor
Private Wealth Advisor

Fnbnamibia • Johannesburg

On-site
ZAR 900,000 - 1,300,000
Private Wealth Advisor
Private Wealth Advisor

FirstRand Limited • Johannesburg

On-site
ZAR 900,000 - 1,300,000