×
Register Here to Apply for Jobs or Post Jobs. X

Security Operations Centre Analyst

Job in Randburg, Johannesburg, 2000, South Africa
Listing for: RMB
Full Time position
Listed on 2026-09-12
Job specializations:
  • IT/Tech
    Cybersecurity, Network Security, Systems Engineer
Job Description & How to Apply Below

Job Description

Hello Future Security Operations Centre Analyst III Welcome to FNB, the home of the #changeables. We design for the shapeshifters and deliver products and services that make us incredibly proud of people that make it happen. As part of our talent team, you will be surrounded by unique talents, diverse minds, and an adaptable environment that lives up to the promise of staying curious.

Now’s the time to imagine your potential in a team where experts come together and ignite effective change.

Overview of the role

Lead end-to-end incident response and digital forensics with deep expertise in log and artifact analysis across host, network, and application layers. Function as SOC L3 between incidents owning escalations, threat hunts, detection engineering, and mentoring

Required Skills and Experience

Expert-level log and artifact analysis across Windows/Linux/macOS and web/network layers. Hands-on proficiency with PCAP analysis, Network IDS (Zeek etc.), Net Flow/IPFIX, and TLS/DNS telemetry. Strong SIEM/EDR skills:
Microsoft Sentinel, Splunk, Microsoft Defender for Endpoint. Scripting for data parsing and automation (Power Shell, Python). IR methodologies: evidence preservation, timeline construction, ATT&CK mapping, defensible reporting. Networking fundamentals: TCP/IP, HTTP, proxies/WAF behavior, SSL/TLS. Digital Forensics Evidence Analysis:

Experience with analyzing digital forensics evidence using tools such as Magnet Axiom Cyber, FTK, Sleuth Kit and Autopsy, or Redline. Offensive Security Assessment

Experience:

Understand attacks and how to execute these attacks to identify vulnerabilities and gaps within the organization

Preferred qualification

Certification in Cyber security / Splunk certificate / certified ethical hacker Offensive Security Certified Professional preferred

Primary Responsibilities
  • Incident Response & Forensics Rapid triage and scoping for P1/P2 incidents; define hypotheses and investigative plan
  • Evidence acquisition: volatile (RAM, network) and non-volatile (disk, artifacts) with chain-of custody
  • Web server log analysis: IIS (W3C, u_ex*, HTTPERR), Apache/Nginx (access/error); detect LFI/RFI, RCE, SSRF, auth abuse, webshell indicators
  • Endpoint artifacts (Windows):
    Prefetch, Shimcache/App Compat Cache , Amcache, SRUM, User Assist, Jump Lists, LNK, browser artifacts, registry keys, $MFT/USN basics
  • Endpoint artifacts (Linux): auth.log, syslog, journald, bash history, cron, SSH logs; process/file lineage
  • Network: PCAP (Wireshark/tshark), Zeek logs, Net Flow/IPFIX; identify C2, beaconing (JA3/JA3S), DNS tunneling, data exfiltration, lateral movement
  • Firewall/Proxy/WAF/IDS:
    Correlate rule hits, proxies, WAF logs, IPS alerts; reconstruct attacker pathing and egress controls
  • Malware/binary triage: static/dynamic (strings, headers, sandbox); derive IOCs/IOAs and containment steps
  • Timeline & correlation:
    Build and maintain multi-source timelines (Timeline Tacker) to reconstruct intrusion and dwell time; ATT&CK technique mapping
  • Reporting:
    Technical reports and executive summaries; remediation guidance and validation testing
  • SOC L3 Functions Threat hunting:
    Hypothesis-driven hunts across SIEM/EDR/network; codify repeatable playbooks
  • Detection engineering:
    Create/tune SIEM rules with Detection Engineering Team (e.g., Splunk), EDR analytics (MDE), Sigma Rule queries / conversions, to reduce false positives
  • Purple teaming:
    Collaborate with red teams to validate detections and test response playbooks
  • Telemetry assurance:
    Review logging coverage, retention, integrity; recommend improvements
  • Process maturity: maintain IR runbooks, forensic SOPs, chain-of-custody templates, evidence vault workflows
Technology Stack
  • SIEM:
    Microsoft Sentinel, Splunk
  • EDR/XDR:
    Microsoft Defender Suite (MDI, MDE,…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary