Senior SOC Analyst: Incident Response & Digital Forensics

FirstRand Bank Limited

Randburg

On-site

ZAR 700,000 - 1,100,000

Full time

7 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

FirstRand Bank Limited seeks a Senior SOC Analyst to lead end-to-end incident response and digital forensics across Windows, Linux, and macOS environments. You will own escalations, perform threat hunts, and mentor junior staff in a high-stakes security operations context.

The role requires expertise in PCAP analysis, SIEM/EDR tools (Microsoft Sentinel, Splunk, MDE), and scripting with PowerShell and Python. Advanced knowledge of ATT&CK, logs, timelines, and reporting is essential.

Qualifications

  • Expert-level log and artifact analysis across Windows/Linux/macOS and web/network layers.
  • Hands-on PCAP analysis, Network IDS, NetFlow/IPFIX, and TLS/DNS telemetry.
  • Strong SIEM/EDR skills: Microsoft Sentinel, Splunk, Microsoft Defender for Endpoint.
  • Scripting for data parsing and automation (PowerShell, Python).
  • IR methodologies: evidence preservation, timeline construction, ATT&CK mapping, defensible reporting.

Responsibilities

  • Incident Response & Forensics: rapid triage and scoping for P1/P2 incidents; define hypotheses and investigative plan.
  • Evidence acquisition: volatile and non-volatile with chain-of-custody.
  • Web server log analysis and detection of LFI/RFI, RCE, SSRF, auth abuse, webshell indicators.
  • Endpoint artifacts (Windows) and Linux logs: ensure integrity and lineage.
  • Network: PCAP, Zeek logs, NetFlow/IPFIX; identify C2, beaconing, DNS tunneling, data exfiltration.
  • Firewall/Proxy/WAF/IDS: correlate rule hits and reconstruct attacker paths.
  • Malware triage: static/dynamic analysis; derive IOCs/IOAs and containment steps.
  • Timeline & correlation: multi-source timelines and ATT&CK mapping.
  • Reporting: technical reports and executive summaries; remediation guidance.
  • SOC L3: threat hunting, hypothesis-driven hunts;Detection engineering with SIEM/EDR teams.
  • Purple teaming: validate detections with red teams; telemetry assurance and SOPs.

Skills

Log Analysis
Windows
Linux
macOS
PCAP Analysis
SIEM/EDR
PowerShell
Python
ATT&CK Mapping
Threat Hunting
IR Methodologies
Networking Fundamentals
Digital Forensics

Tools

Microsoft Sentinel
Splunk
MD Defender for Endpoint
Magnet AX Cyber
FTK
SleuthKit
Autopsy
Redline
Wireshark
Zeek

Job description

FirstRand Bank Limited seeks a Senior SOC Analyst to lead end-to-end incident response and digital forensics across Windows, Linux, and macOS environments. You will own escalations, perform threat hunts, and mentor junior staff in a high-stakes security operations context.

The role requires expertise in PCAP analysis, SIEM/EDR tools (Microsoft Sentinel, Splunk, MDE), and scripting with PowerShell and Python. Advanced knowledge of ATT&CK, logs, timelines, and reporting is essential.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior SOC Analyst: Incident Response & Forensics Leader
Senior SOC Analyst: Incident Response & Forensics Leader

FirstRand Limited • Randburg

On-site
ZAR 800,000 - 1,200,000
Senior SOC Analyst - Incident Response & Forensics
Senior SOC Analyst - Incident Response & Forensics

Wesbank • Randburg

On-site
ZAR 900,000 - 1,200,000
Networking opportunities
Challenging work
Opportunities to innovate
SOC Analyst III: Lead Incident Response & Forensics
SOC Analyst III: Lead Incident Response & Forensics

firstrand • Randburg

On-site
ZAR 600,000 - 900,000
null
Senior SOC Analyst - Incident Response & Forensics
Senior SOC Analyst - Incident Response & Forensics

RMB • Randburg

On-site
ZAR 600,000 - 900,000
Senior SOC Analyst — Incident Response & Forensics
Senior SOC Analyst — Incident Response & Forensics

FNB South Africa • Randburg

On-site
ZAR 600,000 - 900,000
Senior SOC Analyst - Incident Response & Forensics
Senior SOC Analyst - Incident Response & Forensics

Fnbnamibia • Randburg

On-site
ZAR 900,000 - 1,300,000
Senior SOC Analyst: Lead Incident Response & Hunting
Senior SOC Analyst: Lead Incident Response & Hunting

Afrocentric IP • South Africa

On-site
ZAR 700,000 - 900,000
Senior Security Operations Center (SOC) Analyst
Senior Security Operations Center (SOC) Analyst

Placements24 • Randburg

On-site
ZAR 800,000 - 1,200,000
Competitive salary
Medical, dental, and vision insurance
Training and certifications
+2
Security Operations Centre Analyst
Security Operations Centre Analyst

firstrand • Randburg

On-site
ZAR 600,000 - 900,000
null
Senior Digital Forensics & Incident Response Specialist
Senior Digital Forensics & Incident Response Specialist

Standard Bank of South Africa Limited • Johannesburg

On-site
ZAR 900,000 - 1,300,000