Senior SIEM Engineer (Cybersecurity Analyst)
Location : Johannesburg, ZA
Date : 17 Oct 2025
Reference : Job Classification
Job Family
Information Technology
IT Risk
Manage Self : Technical
FAIS Affected
Job Purpose
We are seeking a highly skilled and experiencedSenior SIEM Engineerto lead and enhance our Security Information and Event Management (SIEM) capabilities. The ideal candidate will have deep expertise inElastic and / or Splunk, strongLinux and scripting skills, and a solid understanding ofWindows systems, firewalls, IPS, and EDR technologies. Experience in thefinancial sector, particularlybanking, is highly desirable.
Job Responsibilities
- Design, implement, and maintain SIEM solutions (Elastic / Splunk) across enterprise environments.
- Develop and optimize detection rules, dashboards, and alerts for threat monitoring.
- Integrate diverse log sources including Windows, Linux, firewalls, IPS, and EDRs.
- Collaborate with incident response and threat intelligence teams to improve detection and response capabilities.
- Conduct regular health checks, performance tuning, and upgrades of SIEM in frastructure.
- Support compliance and audit requirements through log retention and reporting.
- Mentor junior engineers and contribute to capability development within the department.
- Write and maintain technical documentationfor SIEM configurations, processes, and playbooks.
- Apply an automation-first mindsetto streamline operations and reduce manual effort.
- Demonstrate strong attention to deta il
Essential Qualifications - NQF Level
DiplomaAdvanced Diplomas / National 1st DegreesPreferred Qualification
Certifications such as GCIA, GCIH, Splunk Certified Architect, Elastic Certified Engineer, or similar.Exposure to regulatory frameworks (e.g., SARB, POPIA, PCI-DSS)Preferred Certifications
Relevant Information Security Certification
Required Skills & Experience
5+ years in cybersecurity operations or engineering roles.Proven experience with Sentinel,Elastic Stack (ELK)and / orSplunk Enterprise Security.Proficient inLinux administrationand scripting (Bash, Python).Familiarity withWindows event logging,firewalls,IPS / IDS, andEDR platforms.Familiarity with different Cloud platforms.Experience inlog ingestion, parsing, and normalization.Understanding ofMITRE ATT&CK, threat detection frameworks, and incident response workflows is highly advantageous.Excellent problem-solving and communication skills.Experience with alert lifecycle management, data indexing, and case managementis highly advantageous.Technical / Professional Knowledge
Administrative procedures and systemsData analysisGovernance, Risk and ControlsPrinciples of project managementRelevant regulatory knowledgeRelevant software and systems knowledgeCluster Specific Operational KnowledgeSystem Development Life cycle(SDLC)TCP / IPInformation Security terms and definitionsInformation Security policies and proceduresCommunicationCustomer FocusInitiating ActionManaging WorkTechnical / Professional Knowledge and SkillsFor assistance please contact the Nedbank Recruiting Team at
#J-18808-Ljbffr