Senior SOC Analyst - Incident Response & Forensics

RMB

Randburg

On-site

ZAR 600,000 - 900,000

Full time

5 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

FirstRand (RMB) is seeking a highly skilled Security Operations Centre Analyst III to lead incident response and digital forensics across host, network, and application layers. You will act as the SOC L3 bridge for escalations, threat hunts, and mentoring a talented team while advancing detection engineering and telemetry coverage.

Key duties include triage, evidence acquisition, and multi-source timelines with ATT&CK mapping.

Qualifications

  • Expert-level log and artifact analysis across Windows/Linux/macOS and web/network layers.
  • Proficient PCAP analysis, Network IDS, NetFlow/IPFIX, TLS/DNS telemetry.
  • Strong SIEM/EDR skills: MS Sentinel, Splunk, Defender for Endpoint.
  • Scripting for data parsing: PowerShell, Python.
  • IR methodologies: evidence preservation, timelines, ATT&CK mapping.
  • Networking basics: TCP/IP, HTTP, proxies/WAF, SSL/TLS.
  • Experience with digital forensics tools: Magnet AXIOM Cyber, FTK, SleuthKit, Autopsy, Redline.
  • Knowledge of offensive security concepts and vulnerability identification.

Responsibilities

  • Lead end-to-end incident response and forensics across host, network, and app layers.
  • Function as SOC L3: own escalations, threat hunts, detection engineering, mentoring.
  • Develop and tune SIEM/EDR detections with engineering teams.
  • Perform purple teaming to validate detections and response playbooks.
  • Maintain IR runbooks, chain-of-custody templates, and evidence vault workflows.
  • Provide technical reports and executive summaries with remediation guidance.

Skills

Log analysis
Artifact analysis
Windows
Linux
macOS
PCAP analysis
Network IDS
TLS/DNS telemetry
SIEM
EDR
Scripting
PowerShell
Python
ATT&CK mapping
Forensics
Threat hunting
Detection engineering
Sigma rules

Education

Certification in Cyber security
Splunk certificate
OSCP / Offensive Security Certified Professional

Tools

Magnet AXIOM Cyber
FTK
SleuthKit
Autopsy
Redline
Zeek
Suricata
Wireshark
tshark
NetFlow/IPFIX
JA3/JA3S
Microsoft Sentinel
Splunk
Microsoft Defender for Endpoint

Job description

FirstRand (RMB) is seeking a highly skilled Security Operations Centre Analyst III to lead incident response and digital forensics across host, network, and application layers. You will act as the SOC L3 bridge for escalations, threat hunts, and mentoring a talented team while advancing detection engineering and telemetry coverage.

Key duties include triage, evidence acquisition, and multi-source timelines with ATT&CK mapping.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior SOC Analyst - Incident Response & Forensics
Senior SOC Analyst - Incident Response & Forensics

Wesbank • Randburg

On-site
ZAR 900,000 - 1,200,000
Networking opportunities
Challenging work
Opportunities to innovate
Senior SOC Analyst: Incident Response & Forensics Leader
Senior SOC Analyst: Incident Response & Forensics Leader

FirstRand Limited • Randburg

On-site
ZAR 800,000 - 1,200,000
SOC Analyst III: Lead Incident Response & Forensics
SOC Analyst III: Lead Incident Response & Forensics

firstrand • Randburg

On-site
ZAR 600,000 - 900,000
null
Senior SOC Analyst: Incident Response & Digital Forensics
Senior SOC Analyst: Incident Response & Digital Forensics

FirstRand Bank Limited • Randburg

On-site
ZAR 700,000 - 1,100,000
Senior SOC Analyst — Incident Response & Forensics
Senior SOC Analyst — Incident Response & Forensics

FNB South Africa • Randburg

On-site
ZAR 600,000 - 900,000
Senior SOC Analyst - Incident Response & Forensics
Senior SOC Analyst - Incident Response & Forensics

Fnbnamibia • Randburg

On-site
ZAR 900,000 - 1,300,000
Senior SOC Analyst: Lead Incident Response & Hunting
Senior SOC Analyst: Lead Incident Response & Hunting

Afrocentric IP • South Africa

On-site
ZAR 700,000 - 900,000
Security Operations Centre Analyst
Security Operations Centre Analyst

firstrand • Randburg

On-site
ZAR 600,000 - 900,000
null
Senior Security Operations Center (SOC) Analyst
Senior Security Operations Center (SOC) Analyst

Placements24 • Randburg

On-site
ZAR 800,000 - 1,200,000
Competitive salary
Medical, dental, and vision insurance
Training and certifications
+2
Senior SOC Analyst – Threat Hunting & Incident Response
Senior SOC Analyst – Threat Hunting & Incident Response

Redherd.Io • Johannesburg

Hybrid
ZAR 900,000 - 1,200,000
Medical aid
Gap cover
Provident fund
+4