Security Operations Centre Analyst
FNB South Africa
Randburg, Gauteng
The Role
Operating as a SOC Level 3 analyst, this position leads end-to-end incident response and digital forensics investigations, covering evidence acquisition, multi-source timeline construction, malware triage, and detailed reporting. Between incidents, the analyst owns threat hunting, detection engineering, purple team collaboration, and escalation handling.
Skills & Experience
Candidates need expert-level artifact analysis across Windows, Linux, and macOS, strong PCAP and network forensics skills, and hands-on experience with Microsoft Sentinel, Splunk, and Microsoft Defender. Forensic tooling such as Magnet AXIOM, FTK, or Autopsy is required, alongside scripting in Python or PowerShell. OSCP or CEH certifications are preferred.
Who It Suits
This role suits an experienced DFIR professional with a SOC background who is comfortable leading complex investigations independently, mentoring junior analysts, and contributing to detection engineering. Those with both defensive and offensive security experience will thrive in this technically demanding, senior-level position.





