Senior SIEM Engineer

5 days ago


Johannesburg, Gauteng, South Africa Nedbank Full time R1 200 000 - R2 400 000 per year

*Job Classification*
Job req

Closing date - 24 October 2025

Job Family
Information Technology

Career Stream
IT Risk

Leadership Pipeline
Manage Self: Technical

FAIS Affected
Job Purpose
We are seeking a highly skilled and experienced Senior SIEM Engineer to lead and enhance our Security Information and Event Management (SIEM) capabilities. The ideal candidate will have deep expertise in Elastic and/or Splunk, strong Linux and scripting skills, and a solid understanding of Windows systems, firewalls, IPS, and EDR technologies. Experience in the financial sector, particularly banking, is highly desirable.

*Job Responsibilities*

  • Design, implement, and maintain SIEM solutions (Elastic/Splunk) across enterprise environments.
  • Develop and optimize detection rules, dashboards, and alerts for threat monitoring.
  • Integrate diverse log sources including Windows, Linux, firewalls, IPS, and EDRs.
  • Automate tasks using scripting languages (Bash, Python).
  • Collaborate with incident response and threat intelligence teams to improve detection and response capabilities.
  • Conduct regular health checks, performance tuning, and upgrades of SIEM in frastructure.
  • Support compliance and audit requirements through log retention and reporting.
  • Mentor junior engineers and contribute to capability development within the department.
  • Write and maintain technical documentation for SIEM configurations, processes, and playbooks.

  • Apply an automation-first mindset to streamline operations and reduce manual effort.

  • Demonstrate strong attention to detail in rule creation, log analysis, and incident handling.

Essential Qualifications - NQF Level

  • Diploma
  • Advanced Diplomas/National 1st Degrees

Preferred Qualification

  • Certifications such as GCIA, GCIH, Splunk Certified Architect, Elastic Certified Engineer, or similar.
  • Exposure to regulatory frameworks (e.g., SARB, POPIA, PCI-DSS)

Preferred Certifications
Relevant Information Security Certification

Required Skills & Experience

  • 5+ years in cybersecurity operations or engineering roles.
  • Proven experience with Sentinel, Elastic Stack (ELK) and/or Splunk Enterprise Security.
  • Proficient in Linux administration and scripting (Bash, Python).
  • Familiarity with Windows event logging, firewalls, IPS/IDS, and EDR platforms.
  • Familiarity with different Cloud platforms.
  • Experience in log ingestion, parsing, and normalization.
  • Understanding of MITRE ATT&CK, threat detection frameworks, and incident response workflows is highly advantageous.
  • Excellent problem-solving and communication skills.
  • Experience with alert lifecycle management, data indexing, and case management is highly advantageous.

*Technical / Professional Knowledge*

  • Administrative procedures and systems
  • Data analysis
  • Governance, Risk and Controls
  • Principles of project management
  • Relevant regulatory knowledge
  • Relevant software and systems knowledge
  • Cluster Specific Operational Knowledge
  • System Development Life cycle(SDLC)
  • TCP/IP
  • Information Security terms and definitions
  • Relevant Operating System
  • Information Security policies and procedures
  • Vendor Management Principles

Behavioural Competencies

  • Applied Learning
  • Communication
  • Collaborating
  • Customer Focus
  • Initiating Action
  • Managing Work
  • Technical/Professional Knowledge and Skills

Please contact the Nedbank Recruiting Team



  • Johannesburg, Gauteng, South Africa Wipro Full time R65 000 - R180 375 per year

    Role:SIEM ArcSight SME/Admin (Onsite, Johannesburg)Experience:6+ years in SIEM ArcSight content development & platform engineeringHands-on SOC experience in developing & fine-tuning SIEM custom contentRequired Skills:ArcSight certificationStrong SOC engineering skillsSecurity certifications (CEH, SANS, OSCP, CISSP)Knowledge of compliance (PCI, SOX, GDPR)Key...


  • Johannesburg, Gauteng, South Africa ExecutivePlacements - The JOB Portal Full time R600 000 - R1 200 000 per year

    Senior Network Security EngineerRecruiter:Data CentrixJob Ref:JHB006916/MSDate posted:Tuesday, October 14, 2025Location:Johannesburg, South AfricaSUMMARY:On behalf of our client—a leading organization in the automotive industry—we are seeking aSenior Network Security Engineerto play a pivotal role in safeguarding and optimizing their enterprise IT...


  • Johannesburg, Gauteng, South Africa Hire Resolve Full time R250 000 - R500 000 per year

    An established and award-winning holistic technology services company with a national presence is seeking a Junior Security Engineer to join their dynamic Operations team in Johannesburg, Gauteng. The Junior Security Engineer will be responsible for monitoring, detecting, and troubleshooting security events across internal systems and customer environments....


  • Johannesburg, Gauteng, South Africa Gig Engineer Full time R2 000 000 - R2 500 000 per year

    Location:Woodmead, Johannesburg, Gauteng, South AfricaEmployment Type:PermanentOverviewThe Associate Director (AD) plays a critical role within the Water Advisory Group (AG) management team, driving performance, growth, and a positive culture. This position provides strategic, operational, client, and people leadership, supporting the delivery of the AG's...

  • Level 3 IT Engineer

    1 week ago


    Johannesburg, Gauteng, South Africa WESTECH Full time R900 000 - R1 200 000 per year

    Company DescriptionWestech is a professional IT Support and Services company dedicated to providing IT Stability and Security to companies across South Africa. Serving a wide range of industries such as engineering, mining, aviation, consulting, and media, Westech aims to enhance efficiency, productivity, and profitability. The company is recognized as the...

  • Senior Engineer

    3 days ago


    Johannesburg, Gauteng, South Africa Hire Resolve Full time R2 000 000 - R2 500 000 per year

    Hire Resolves client who is a multi-award-winning Integrated Infrastructure Sector, is looking for a Senior Engineer: Wastewater and Water Treatment to join their team, the company provides the roots for communities using innovative and sustainable engineering design, urban planning, and advisory services. Here you will find an environment conducive to...


  • Johannesburg, Gauteng, South Africa Boardroom Appointments Full time R120 000 - R240 000 per year

    Senior Network EngineerJob purpose:As a Senior Network Engineer, you will be responsible for all aspects of network architecture and design. You'll also assist in the installation and maintenance of our LAN/WAN infrastructure as well as act as a troubleshooter when needed. You must have experience with Cisco devices, specifically the routers and switches...


  • Johannesburg, Gauteng, South Africa Hatch Full time R800 000 - R1 400 000 per year

    Requisition ID: 96230 Job Category: Procurement Location: Johannesburg, Gauteng, South Africa  Join a company that is passionately committed to the pursuit of a better world through positive change. With more than 65 years of business and technical expertise in mining, energy, and infrastructure, our 10,000 colleagues in 150 countries tirelessly...


  • Johannesburg, Gauteng, South Africa Boardroom Appointments Full time R1 200 000 - R2 400 000 per year

    We are seeking a highly experienced Senior Chemical Engineer with Mechanical Engineering experience to join our company in a senior management role. The ideal candidate will have extensive experience operating a distillation column and working in the fuel industry would be an added advantage. The successful candidate will report directly to the Chief...


  • Johannesburg, Gauteng, South Africa Boardroom Appointments Full time R1 000 000 - R3 000 000 per year

    Minimum Requirements:Information Security related Certification (CISSP / CISM / GCIA).Appropriate professional accreditation GCIH / Ethical Hacking (CEH)Offensive Security Certified Professional (OSCP) is preferred, GPEN, advantageous.Experience:Prior industry experience in a corporate environment (preference Financial Institution) in an IT Security...