Job description
- Location:Sandton/Mumbai
- Employee Type:Permanent
- Department:Group Security
- Division:Central Services
Senior Information Security Operations Analyst (13618)
Description
The Senior Information Security Operations Analyst is responsible for protecting Investec's information assets through proactive monitoring, detection, investigation, and response to cyber threats across both on-premise and cloud environments. The role supports the development, implementation, and continuous improvement of security operations capabilities, ensuring effective management of security technologies, cloud security controls and operational resilience.
The successful candidate will work closely with technology, cloud, engineering, and business teams to identify, assess, and mitigate cyber risks while enabling secure business operations. The role requires a strong technical background in Information Security Operations, Cloud Security, Security Monitoring and Security Automation.
The position will contribute to the enhancement of security monitoring, security automation, security governance, and cyber defence capabilities in alignment with industry best practices and regulatory requirements.
Key Responsibilities
• Monitor, investigate, and respond to security alerts, incidents, and cyber threats across cloud and on-premise environments.
• Support and enhance Azure security controls across IaaS and PaaS services.
• Develop, tune, and maintain SIEM use cases, correlation searches, alerts, and dashboards, with Splunk preferred.
• Support cyber incident response, containment, eradication, recovery, and post-incident reviews.
• Manage and maintain security technologies.
• Collaborate with technology and engineering teams to embed security controls into the software development lifecycle.
• Contribute to security governance, compliance monitoring, and audit activities.
• Develop and maintain operational procedures, standards, playbooks, and technical documentation.
• Support continuous improvement initiatives that strengthen Investec's security posture and cyber resilience.
Qualifications, Experience and Skills
• Information Systems degree, Computer Science degree, Cyber Security degree, or equivalent technical qualification.
• Minimum 6 years' experience in Information Security Operations, including Cloud Security Operations.
• Strong Azure security experience covering IaaS and PaaS environments.
• Experience supporting security operations activities across cloud and on-premise platforms.
• Microsoft security certifications such as AZ-500, AZ-900, SC-900, DevSecOps Practitioner, or equivalent.
• Strong experience with Microsoft Entra ID (Azure AD), Conditional Access, Identity Protection, and Azure native security technologies.
• Experience with Azure DevOps, Terraform, GitHub, GitHub Actions, and Infrastructure as Code practices.
• Experience troubleshooting endpoints, operating systems, and infrastructure components.
• Experience with Privileged Access Management (PAM) platforms and security administration processes.
• Strong Blue Team experience.
• Strong UNIX/Linux security administration experience.
• Strong SIEM experience, preferably Splunk, including query writing and alert tuning.
• Experience with Security Orchestration, Automation and Response (SOAR) platforms, preferably Cortex XSOAR.
• Knowledge of financial services security risks, controls, and regulatory requirements.
• Good understanding of IT operational processes, ITIL practices, and project delivery methodologies.
• Strong understanding of ISO 27001, NIST Cybersecurity Framework, CIS Controls, and SANS best practices.
• Industry-recognised security certifications such as CISSP, CISM, GIAC, or equivalent desirable.
• Strong analytical, communication, stakeholder engagement, and problem-solving skills.
Investec Culture
At Investec we seek creative, talented people with passion, energy and stamina, who collaborate unselfishly.
We are committed to diversity and inclusion when recruiting internally and externally.



