SOC Analyst III: Lead Incident Response & Forensics

firstrand

Randburg

On-site

ZAR 600,000 - 900,000

Full time

5 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

null

Job summary

FirstRand is seeking a Senior SOC Operations Centre Analyst III in Randburg to lead end-to-end incident response and digital forensics. You will analyze logs and artifacts across host, network, and application layers, act as the L3 bridge for escalations, threat hunts, and detection engineering, while mentoring junior analysts.

The role demands expertise in Windows/Linux/macOS, PCAP, Zeek, Suricata, Wireshark, and SIEM/EDR suites, with scripting in PowerShell and Python to automate data parsing

Qualifications

  • Expert-level log and artifact analysis across Windows/Linux/macOS and web/network layers.
  • Hands-on proficiency with PCAP analysis, Network IDS (Zeek etc.), NetFlow/IPFIX, and TLS/DNS telemetry.
  • Strong SIEM/EDR skills: Microsoft Sentinel, Splunk, Microsoft Defender for Endpoint.
  • Scripting for data parsing and automation (PowerShell, Python).
  • IR methodologies: evidence preservation, timeline construction, ATT&CK mapping, defensible reporting.
  • Networking fundamentals: TCP/IP, HTTP, proxies/WAF behavior, SSL/TLS.
  • Digital Forensics Evidence Analysis: Magnet Axiom Cyber, FTK, SleuthKit or Redline.
  • Offensive Security Assessment Experience: understand attacks to identify vulnerabilities and gaps.
  • Preferred qualification: Cyber security certification / Splunk certificate / OSCP preferred

Responsibilities

  • Incident Response & Forensics: rapid triage and scoping for P1/P2 incidents; define hypotheses and investigative plan.
  • Evidence acquisition: volatile and non-volatile data with chain-of-custody.
  • Web server log analysis: identify LFI/RFI, RCE, SSRF, auth abuse, webshell indicators.
  • Endpoint artifacts (Windows): Prefetch, Amcache, SRUM, registry keys, LNK, browser artifacts.
  • Endpoint artifacts (Linux): auth.log, syslog, journald, bash history, cron, SSH logs.
  • Network: PCAP, Zeek logs, NetFlow/IPFIX; identify C2, beaconing, DNS tunneling, data exfiltration.
  • Firewall/Proxy/WAF/IDS: correlate rule hits; reconstruct attacker pathing and egress controls.
  • Malware/binary triage: static/dynamic; derive IOCs/IOAs and containment steps.
  • Timeline & correlation: build multi-source timelines; ATT&CK mapping.
  • Reporting: technical reports and executive summaries; remediation guidance and validation testing.

Skills

Log & artifact analysis
PCAP analysis
SIEM/EDR
Scripting (PowerShell, Python)
IR methodologies
Networking fundamentals
Digital forensics tools
Offensive security concepts

Tools

Zeek
Suricata
Wireshark
Microsoft Sentinel
Splunk
MD Defender for Endpoint

Job description

FirstRand is seeking a Senior SOC Operations Centre Analyst III in Randburg to lead end-to-end incident response and digital forensics. You will analyze logs and artifacts across host, network, and application layers, act as the L3 bridge for escalations, threat hunts, and detection engineering, while mentoring junior analysts.

The role demands expertise in Windows/Linux/macOS, PCAP, Zeek, Suricata, Wireshark, and SIEM/EDR suites, with scripting in PowerShell and Python to automate data parsing

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior SOC Analyst: Incident Response & Forensics Leader
Senior SOC Analyst: Incident Response & Forensics Leader

FirstRand Limited • Randburg

On-site
ZAR 800,000 - 1,200,000
Senior SOC Analyst - Incident Response & Forensics
Senior SOC Analyst - Incident Response & Forensics

RMB • Randburg

On-site
ZAR 600,000 - 900,000
Senior SOC Analyst: Incident Response & Digital Forensics
Senior SOC Analyst: Incident Response & Digital Forensics

FirstRand Bank Limited • Randburg

On-site
ZAR 700,000 - 1,100,000
Senior SOC Analyst - Incident Response & Forensics
Senior SOC Analyst - Incident Response & Forensics

Wesbank • Randburg

On-site
ZAR 900,000 - 1,200,000
Networking opportunities
Challenging work
Opportunities to innovate
Senior SOC Analyst — Incident Response & Forensics
Senior SOC Analyst — Incident Response & Forensics

FNB South Africa • Randburg

On-site
ZAR 600,000 - 900,000
Senior SOC Analyst - Incident Response & Forensics
Senior SOC Analyst - Incident Response & Forensics

Fnbnamibia • Randburg

On-site
ZAR 900,000 - 1,300,000
Onsite Senior SOC Analyst: Incident Response & Forensics
Onsite Senior SOC Analyst: Incident Response & Forensics

Forensic Focus Limited • Randburg

On-site
ZAR 600,000 - 900,000
Security Operations Centre Analyst
Security Operations Centre Analyst

Forensic Focus Limited • Randburg

On-site
ZAR 600,000 - 900,000
Senior Security Operations Center (SOC) Analyst
Senior Security Operations Center (SOC) Analyst

Placements24 • Randburg

On-site
ZAR 800,000 - 1,200,000
Competitive salary
Medical, dental, and vision insurance
Training and certifications
+2
Senior SOC Analyst: Lead Incident Response & Hunting
Senior SOC Analyst: Lead Incident Response & Hunting

Afrocentric IP • South Africa

On-site
ZAR 700,000 - 900,000