Specialist, Incident Response

4 days ago


Johannesburg, South Africa Standard Bank of South Africa Limited Full time

Overview Location: ZA, GP, Johannesburg, Simmonds Street As a Specialist Incident Response Analyst, you will play a central role in detecting, investigating, and responding to cyber incidents in a non-tiered SOC environment. You will own incidents end-to-end from triage through containment and recovery while applying an adversarial mindset to anticipate attacker behaviour. Alongside technical response, you will contribute to policy improvement, coaching, and industry engagement, ensuring the bank’s response capability matures continuously. This role includes after-hours standby as part of an on-call rotation. Qualifications A degree Information Technology is required. IT Risk/security certification such as CISM, CISSP or CISA, GCIA, GCIH, OSCP is required. AWS/Azure Cloud Certifications. Experience Required: 5-7 years experience in IT Security, preferably in a Financial Institution, with noted experience in developing threat models, threat analysis, cyber and incident management, offensive security, high level static and dynamic malware analysis. 5-7 years experience in strong IT understanding, gaining insight into digital and platform operating models and cyber security trends and solutions. Strong experience in incident management, threat modelling, malware analysis, and offensive security techniques. Broad IT systems knowledge and awareness of digital platform operating models. Key Responsibilities Detect & Investigate: Analyse alerts from SIEM, EDR, and threat intelligence sources; distinguish true vs false positives. Contain & Remediate: Lead active incidents through containment, eradication, and recovery actions. Threat Hunting: Proactively search for adversary activity using attacker TTPs and threat intel. Malware & Phishing Triage: Perform static/dynamic malware analysis and investigate phishing campaigns. Offensive Security Awareness: Apply penetration testing/red team knowledge to strengthen detection and response. Forensic Support: Collect and analyse logs, endpoint, and network artifacts for root cause analysis. On-Call Duties: Provide after-hours escalation support on a rotational basis. Documentation & Reporting: Produce incident reports, lessons learned, and contribute to playbook improvements. #J-18808-Ljbffr



  • Johannesburg, Gauteng, South Africa Standard Bank Full time

    Job OverviewBusiness Segment: Group FunctionsLocation: ZA, undefined, Johannesburg, Simmonds StreetJob Type: Full-timeJob Ref ID: A-0003Date Posted: 11/14/2025Job DescriptionAs a Specialist Incident Response Analyst, you will play a central role in detecting, investigating, and responding to cyber incidents in a non-tiered SOC environment. You will own...


  • Johannesburg, South Africa Standard Bank of South Africa Limited Full time

    A leading financial institution in South Africa is seeking a Specialist Incident Response Analyst to detect, investigate, and respond to cyber incidents in a dynamic environment. You will lead incidents from triage to recovery, contribute to policy improvements, and engage in threat hunting. The ideal candidate has 5-7 years of experience in IT security,...


  • Johannesburg, South Africa SavageOne Pty Ltd Full time

    A cybersecurity firm in South Africa is seeking a Cybersecurity Specialist responsible for defending systems and data against cyber threats. This role involves conducting vulnerability assessments, implementing security policies, and monitoring for incidents. The ideal candidate has knowledge of security tools, compliance standards, and scripting skills....


  • Johannesburg, South Africa FirstRand Full time

    Job Description Hello Future IT Incident and Problem Specialist Welcome to FNB, the home of the #changeables. We design for the shapeshifters and deliver products and services that make us incredibly proud of people that make it happen. As part of our talent team, you will be surrounded by unique talents, diverse minds, and an adaptable environment that...


  • Johannesburg, South Africa FusionTek Full time

    FusionTek is a Managed Security Service Provider (MSSP) with offices in multiple US locations and team members globally. We’re a tight-knit team of friendly, intelligent people focused on IT infrastructure management for small- to mid-sized businesses since 2007. We’re also rapidly growing and are looking for top-tier candidates who share our four core...


  • Johannesburg, South Africa Fusiontek Full time

    A Managed Security Service Provider in Johannesburg seeks an experienced Incident Response Technical Lead to manage incident response projects. Responsibilities include overseeing incident response efforts and maintaining communication with clients and vendors. Ideal candidates will have strong communication skills and previous technical leadership...


  • Johannesburg, South Africa FirstRand Full time

    Job Description To manage and resolve IT incidents and problems efficiently, ensuring mínimal disruption to business operations. The role involves identifying root causes, implementing preventative measures, and improving overall IT service delivery, with a strong focus on adherence to ITIL processes and collaboration across business...

  • Azure Forensics

    5 days ago


    Johannesburg, South Africa KPMG South Africa Full time

    A leading consulting firm in Johannesburg is seeking a Manager in Cyber Forensic and Response to manage secure and efficient forensic infrastructure on Azure. The ideal candidate should have 4–8 years of experience in IT/security operations and at least 3 years managing Azure environments. Relevant Azure certifications and a degree in IT or related fields...


  • Johannesburg, South Africa FusionTek Full time

    A Managed Security Service Provider in Johannesburg is seeking an Incident Response Technical Lead to deliver high-touch technical management for incident response projects. The role involves managing incident response efforts, communicating with clients and vendors, and serving as a subject-matter expert. Ideal candidates should have strong communication...


  • Johannesburg, South Africa TransUnion Full time

    TransUnion's Job Applicant Privacy Notice **What We'll Bring**: Our quest to modernizing the way we do technology is not slowing down anytime soon. We continue to make big strides in our agile atmosphere to bring the latest in products and solutions within the cloud infrastructure. Our cloud teams have the potential to shape the future by solving...