Senior SIEM Engineer
5 days ago
*Job Classification*
Job req
Closing date - 24 October 2025
Job Family
Information Technology
Career Stream
IT Risk
Leadership Pipeline
Manage Self: Technical
FAIS Affected
Job Purpose
We are seeking a highly skilled and experienced Senior SIEM Engineer to lead and enhance our Security Information and Event Management (SIEM) capabilities. The ideal candidate will have deep expertise in Elastic and/or Splunk, strong Linux and scripting skills, and a solid understanding of Windows systems, firewalls, IPS, and EDR technologies. Experience in the financial sector, particularly banking, is highly desirable.
*Job Responsibilities*
- Design, implement, and maintain SIEM solutions (Elastic/Splunk) across enterprise environments.
- Develop and optimize detection rules, dashboards, and alerts for threat monitoring.
- Integrate diverse log sources including Windows, Linux, firewalls, IPS, and EDRs.
- Automate tasks using scripting languages (Bash, Python).
- Collaborate with incident response and threat intelligence teams to improve detection and response capabilities.
- Conduct regular health checks, performance tuning, and upgrades of SIEM in frastructure.
- Support compliance and audit requirements through log retention and reporting.
- Mentor junior engineers and contribute to capability development within the department.
Write and maintain technical documentation for SIEM configurations, processes, and playbooks.
Apply an automation-first mindset to streamline operations and reduce manual effort.
- Demonstrate strong attention to detail in rule creation, log analysis, and incident handling.
Essential Qualifications - NQF Level
- Diploma
- Advanced Diplomas/National 1st Degrees
Preferred Qualification
- Certifications such as GCIA, GCIH, Splunk Certified Architect, Elastic Certified Engineer, or similar.
- Exposure to regulatory frameworks (e.g., SARB, POPIA, PCI-DSS)
Preferred Certifications
Relevant Information Security Certification
Required Skills & Experience
- 5+ years in cybersecurity operations or engineering roles.
- Proven experience with Sentinel, Elastic Stack (ELK) and/or Splunk Enterprise Security.
- Proficient in Linux administration and scripting (Bash, Python).
- Familiarity with Windows event logging, firewalls, IPS/IDS, and EDR platforms.
- Familiarity with different Cloud platforms.
- Experience in log ingestion, parsing, and normalization.
- Understanding of MITRE ATT&CK, threat detection frameworks, and incident response workflows is highly advantageous.
- Excellent problem-solving and communication skills.
- Experience with alert lifecycle management, data indexing, and case management is highly advantageous.
*Technical / Professional Knowledge*
- Administrative procedures and systems
- Data analysis
- Governance, Risk and Controls
- Principles of project management
- Relevant regulatory knowledge
- Relevant software and systems knowledge
- Cluster Specific Operational Knowledge
- System Development Life cycle(SDLC)
- TCP/IP
- Information Security terms and definitions
- Relevant Operating System
- Information Security policies and procedures
- Vendor Management Principles
Behavioural Competencies
- Applied Learning
- Communication
- Collaborating
- Customer Focus
- Initiating Action
- Managing Work
- Technical/Professional Knowledge and Skills
Please contact the Nedbank Recruiting Team
-
ArcSight Admin- SIEM
1 day ago
Johannesburg, Gauteng, South Africa Wipro Full time R65 000 - R180 375 per yearRole:SIEM ArcSight SME/Admin (Onsite, Johannesburg)Experience:6+ years in SIEM ArcSight content development & platform engineeringHands-on SOC experience in developing & fine-tuning SIEM custom contentRequired Skills:ArcSight certificationStrong SOC engineering skillsSecurity certifications (CEH, SANS, OSCP, CISSP)Knowledge of compliance (PCI, SOX, GDPR)Key...
-
Senior Network Security Engineer
5 days ago
Johannesburg, Gauteng, South Africa ExecutivePlacements - The JOB Portal Full time R600 000 - R1 200 000 per yearSenior Network Security EngineerRecruiter:Data CentrixJob Ref:JHB006916/MSDate posted:Tuesday, October 14, 2025Location:Johannesburg, South AfricaSUMMARY:On behalf of our client—a leading organization in the automotive industry—we are seeking aSenior Network Security Engineerto play a pivotal role in safeguarding and optimizing their enterprise IT...
-
Junior Security Engineer
3 days ago
Johannesburg, Gauteng, South Africa Hire Resolve Full time R250 000 - R500 000 per yearAn established and award-winning holistic technology services company with a national presence is seeking a Junior Security Engineer to join their dynamic Operations team in Johannesburg, Gauteng. The Junior Security Engineer will be responsible for monitoring, detecting, and troubleshooting security events across internal systems and customer environments....
-
Associate Director Advisory Group: Water
5 days ago
Johannesburg, Gauteng, South Africa Gig Engineer Full time R2 000 000 - R2 500 000 per yearLocation:Woodmead, Johannesburg, Gauteng, South AfricaEmployment Type:PermanentOverviewThe Associate Director (AD) plays a critical role within the Water Advisory Group (AG) management team, driving performance, growth, and a positive culture. This position provides strategic, operational, client, and people leadership, supporting the delivery of the AG's...
-
Level 3 IT Engineer
1 week ago
Johannesburg, Gauteng, South Africa WESTECH Full time R900 000 - R1 200 000 per yearCompany DescriptionWestech is a professional IT Support and Services company dedicated to providing IT Stability and Security to companies across South Africa. Serving a wide range of industries such as engineering, mining, aviation, consulting, and media, Westech aims to enhance efficiency, productivity, and profitability. The company is recognized as the...
-
Senior Engineer
3 days ago
Johannesburg, Gauteng, South Africa Hire Resolve Full time R2 000 000 - R2 500 000 per yearHire Resolves client who is a multi-award-winning Integrated Infrastructure Sector, is looking for a Senior Engineer: Wastewater and Water Treatment to join their team, the company provides the roots for communities using innovative and sustainable engineering design, urban planning, and advisory services. Here you will find an environment conducive to...
-
Senior Network Engineer
3 days ago
Johannesburg, Gauteng, South Africa Boardroom Appointments Full time R120 000 - R240 000 per yearSenior Network EngineerJob purpose:As a Senior Network Engineer, you will be responsible for all aspects of network architecture and design. You'll also assist in the installation and maintenance of our LAN/WAN infrastructure as well as act as a troubleshooter when needed. You must have experience with Cisco devices, specifically the routers and switches...
-
Senior Contractor Engineer
1 day ago
Johannesburg, Gauteng, South Africa Hatch Full time R800 000 - R1 400 000 per yearRequisition ID: 96230 Job Category: Procurement Location: Johannesburg, Gauteng, South Africa Join a company that is passionately committed to the pursuit of a better world through positive change. With more than 65 years of business and technical expertise in mining, energy, and infrastructure, our 10,000 colleagues in 150 countries tirelessly...
-
Senior Chemical Engineer
3 days ago
Johannesburg, Gauteng, South Africa Boardroom Appointments Full time R1 200 000 - R2 400 000 per yearWe are seeking a highly experienced Senior Chemical Engineer with Mechanical Engineering experience to join our company in a senior management role. The ideal candidate will have extensive experience operating a distillation column and working in the fuel industry would be an added advantage. The successful candidate will report directly to the Chief...
-
Cyber Security Engineer
3 days ago
Johannesburg, Gauteng, South Africa Boardroom Appointments Full time R1 000 000 - R3 000 000 per yearMinimum Requirements:Information Security related Certification (CISSP / CISM / GCIA).Appropriate professional accreditation GCIH / Ethical Hacking (CEH)Offensive Security Certified Professional (OSCP) is preferred, GPEN, advantageous.Experience:Prior industry experience in a corporate environment (preference Financial Institution) in an IT Security...