Security Operations Centre Analyst

FNB South Africa

Randburg

On-site

ZAR 600,000 - 900,000

Full time

5 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

FNB South Africa seeks an experienced SOC Operations Analyst III to lead end-to-end incident response and digital forensics across host, network, and application layers. You will act as the SOC L3 bridge for escalations, threat hunts, and detection engineering, mentoring teammates along the way.

Candidates should demonstrate expert log/artifact analysis, PCAP and NetFlow proficiency, and strong scripting skills in PowerShell and Python.

Qualifications

  • Expert-level analysis of logs and artifacts across Windows/Linux/macOS and web/network layers.
  • Hands-on PCAP analysis, IDS, NetFlow/IPFIX, and TLS/DNS telemetry.
  • Strong SIEM/EDR skills with Splunk, Sentinel and Defender for Endpoint.
  • Scripting for data parsing in PowerShell and Python.
  • IR methodologies including evidence preservation and chain-of-custody.

Responsibilities

  • Rapid triage and scoping for P1/P2 incidents with investigative plans.
  • Evidence acquisition and maintaining chain-of-custody for volatile and non-volatile data.
  • Web server and endpoint log analysis; detect web app and host indicators across platforms.
  • Network analysis using PCAP, Zeek, and NetFlow to identify C2 and exfiltration.
  • TIMELINE construction, ATT&CK mapping, and multi-source correlation.
  • Prepare technical reports and provide remediation guidance.

Skills

Log analysis
Artifact analysis
Windows/Linux/macOS
PCAP analysis
SIEM/EDR
PowerShell
Python
Network forensics
Incident response
Threat hunting

Tools

Zeek
Suricata
Wireshark/Tshark
NetFlow/IPFIX
Magnet AXIOM
FTK
SleuthKit/Autopsy
Splunk
Microsoft Defender for Endpoint

Job description

Job Description

Hello Future Security Operations Centre Analyst III

Welcome to FNB, the home of the #changeables. We design for the shapeshifters and deliver products and services that make us incredibly proud of people that make it happen.

As part of our talent team, you will be surrounded by unique talents, diverse minds, and an adaptable environment that lives up to the promise of staying curious. Now’s the time to imagine your potential in a team where experts come together and ignite effective change.

Overview Of The Role

Lead end-to-end incident response and digital forensics with deep expertise in log and artifact analysis across host, network, and application layers. Function as SOC L3 between incidents owning escalations, threat hunts, detection engineering, and mentoring

Required Skills And Experience
  • Expert-level log and artifact analysis across Windows/Linux/macOS and web/network layers.
  • Hands-on proficiency with PCAP analysis, Network IDS (Zeek etc.), NetFlow/IPFIX, and TLS/DNS telemetry.
  • Strong SIEM/EDR skills: Microsoft Sentinel, Splunk, Microsoft Defender for Endpoint.
  • Scripting for data parsing and automation (PowerShell, Python).
  • IR methodologies: evidence preservation, timeline construction, ATT&CK mapping, defensible reporting.
  • Networking fundamentals: TCP/IP, HTTP, proxies/WAF behavior, SSL/TLS.
  • Digital Forensics Evidence Analysis: Experience with analyzing digital forensics evidence using tools such as Magnet Axiom Cyber, FTK, SleuthKit and Autopsy, or Redline.
  • Offensive Security Assessment Experience: Understand attacks and how to execute these attacks to identify vulnerabilities and gaps within the organization
  • Preferred qualification: Certification in Cyber security / Splunk certificate / certified ethical hacker Offensive Security Certified Professional preferred
Primary Responsibilities
  • Rapid triage and scoping for P1/P2 incidents; define hypotheses and investigative plan.
  • Evidence acquisition: volatile (RAM, network) and non-volatile (disk, artifacts) with chain-of custody.
  • Web server log analysis: IIS (W3C, u_ex*, HTTPERR), Apache/Nginx (access/error); detect LFI/RFI, RCE, SSRF, auth abuse, webshell indicators
  • Endpoint artifacts (Windows): Prefetch, Shimcache/AppCompatCache, Amcache, SRUM, UserAssist, Jump Lists, LNK, browser artifacts, registry keys, $MFT/USN basics.
  • Endpoint artifacts (Linux): auth.log, syslog, journald, bash history, cron, SSH logs; process/file lineage.
  • Network: PCAP (Wireshark/tshark), Zeek logs, NetFlow/IPFIX; identify C2, beaconing (JA3/JA3S), DNS tunneling, data exfiltration, lateral movement.
  • Firewall/Proxy/WAF/IDS: Correlate rule hits, proxies, WAF logs, IPS alerts; reconstruct attacker pathing and egress controls.
  • Malware/binary triage: static/dynamic (strings, headers, sandbox); derive IOCs/IOAs and containment steps.
  • Timeline & correlation: Build and maintain multi-source timelines (Timeline Tacker) to reconstruct intrusion and dwell time; ATT&CK technique mapping.
  • Reporting: Technical reports and executive summaries; remediation guidance and validation testing.
SOC L3 Functions
  • Threat hunting: Hypothesis-driven hunts across SIEM/EDR/network; codify repeatable playbooks.
  • Detection engineering: Create/tune SIEM rules with Detection Engineering Team (e.g., Splunk), EDR analytics (MDE), Sigma Rule queries / conversions, to reduce false positives.
  • Purple teaming: Collaborate with red teams to validate detections and test response playbooks.
  • Telemetry assurance: Review logging coverage, retention, integrity; recommend improvements.
  • Process maturity: maintain IR runbooks, forensic SOPs, chain-of-custody templates, evidence vault workflows.
Technology Stack
  • SIEM: Microsoft Sentinel, Splunk
  • EDR/XDR: Microsoft Defender Suite (MDI, MDE, MDO, MDC)
  • OS: Windows, Linux, macOS
  • Network & Microsegmentation: Cisco Secure Workload (formerly Tetration)
  • Identity: Cisco Identity Services Engine (ISE), Microsoft Defender for Identity (MDI), Microsoft Purview
  • Network sensors/tools: Zeek, Suricata, Wireshark/tshark, NetFlow/IPFIX collectors
  • Web Application Firewalls: F5 BIG-IP Advanced WAF (formerly ASM); other major WAFs (Imperva, Akamai Kona, Cloudflare WAF, AWS/Azure WAF)
  • Firewalls/Proxies/IDS: Enterprise firewall/WAF/secure web gateway platforms that integrate with SIEM for centralized logging.
You Will Have Access To
  • Opportunities to network and collaborate.
  • Challenging Work.
  • Opportunities to innovate.
Important Closing Date Note

Take note that applications will not be accepted on the below date and onwards, kindly submit applications ahead of the closing date indicated below.

14/09/26

Equal Opportunity & Diversity

All appointments will be made in line with FirstRand Group’s Employment Equity plan. The Bank supports the recruitment and advancement of individuals with disabilities. In order for us to fulfill this purpose, candidates can disclose their disability information on a voluntary basis. The Bank will keep this information confidential unless we are required by law to disclose this information to other parties.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Operations Centre Analyst
Security Operations Centre Analyst

firstrand • Randburg

On-site
ZAR 600,000 - 900,000
null
Security Operations Centre Analyst
Security Operations Centre Analyst

Fnbnamibia • Randburg

On-site
ZAR 900,000 - 1,300,000
Security Operations Centre Analyst
Security Operations Centre Analyst

FirstRand Bank Limited • Randburg

On-site
ZAR 700,000 - 1,100,000
Security Operations Centre Analyst
Security Operations Centre Analyst

FirstRand Limited • Randburg

On-site
ZAR 800,000 - 1,200,000
Security Operations Centre Analyst
Security Operations Centre Analyst

Wesbank • Randburg

On-site
ZAR 900,000 - 1,200,000
Networking opportunities
Challenging work
Opportunities to innovate
Security Operations Centre Analyst
Security Operations Centre Analyst

RMB • Randburg

On-site
ZAR 600,000 - 900,000
L3 SOC Analyst - Johannesburg
L3 SOC Analyst - Johannesburg

Integrity360 • Johannesburg

On-site
ZAR 600,000 - 900,000
SOC Analyst III: Lead Incident Response & Forensics
SOC Analyst III: Lead Incident Response & Forensics

firstrand • Randburg

On-site
ZAR 600,000 - 900,000
null
L2 SOC Analyst - Cape Town or Johannesburg
L2 SOC Analyst - Cape Town or Johannesburg

Integrity360 • Johannesburg

On-site
ZAR 420,000 - 620,000
Threat Intelligence and Threat Hunting Manager
Threat Intelligence and Threat Hunting Manager

RMB Nigeria Limited • Randburg

On-site
ZAR 700,000 - 1,000,000