EC

Security Operation Center Supervisor (SOC Level 2)

Full-time Ghana, GH
Posted 1 week, 4 days ago 133 views 0 applications

Job Description

We need to output clean semantic HTML with

,

,
  • . No CSS, no divs, no br. Must preserve original content word-for-word, but we can restructure using tags. We need to extract sections: GENERAL JOB INFORMATION, JOB PURPOSE, KEY RESPONSIBILITIES, Key Performance Indicators (with subcategories Business and Financial performance, Customer experience, People, Process, Control and Operation, Ecobank Must win Battles), Education & Experience. We need to keep content exactly as is, but we can wrap paragraphs in

    , headings in

    , lists in
    • . The original includes many special characters like , , etc. We must preserve them. We need to remove any HTML tags from input (like

       

      etc) and produce our own. We must not add or remove content. So we need to output the same textual content, just with tags. We must not add extra spaces or change wording. Must preserve original content word-for-word. Thus we need to parse the input text, strip out original HTML tags, then apply our own tags. Let's extract the plain text content from the given input. The input includes:

       

      GENERAL JOB INFORMATION


      Job Title:                                   Security Operation Center Supervisor (SOC Level 2)
      Organization/Department:    Cybersecurity Department
      Head of Unit/Department:    Security Operation Center Unit 
      Salary Grade/ Band:                3A
      Reports To:                                Security Operation Center Unit Head
        

      JOB PURPOSE

      The Security Supervisor serves as the second line of defense, responsible for conducting in-depth investigations, responding to security incidents, and ensuring the effective management and mitigation of threats. The role focuses on proactive measures to strengthen Ecobank's overall security posture. 
      He/she focuses in enhancing Ecobank's security operations by addressing escalated threats, performing advanced analyses, and ensuring prompt and effective incident responses. Additionally, the position drives continuous improvements in security processes to protect Ecobank's systems and data.  

      This is a 24/7 shift-based role, operating on a rotation of three shifts, each lasting 8 hours within a 24-hour period.

       

      KEY RESPONSIBILITIES

      Incident Triage and Analysis
          Analyse and respond to incidents escalated by security analysts, ensuring accurate identification of threats and their root causes.
          Perform deeper analysis to determine the root cause, scope, and impact of security threats or event.
      Advanced Threat Detection
          Use SIEM tools, EDR platforms, and threat intelligence to identify complex and persistent threats such as malware, phishing campaigns, or insider attacks.
          Correlate data from various sources to detect patterns and anomalies that indicate malicious activity.
          Monitor threat intelligence feeds to detect and respond to emerging risks.
      Incident Response Coordination
          Lead the coordination of incident response efforts, ensuring timely containment, eradication, and recovery.
          Collaborate with other teams (e.g., IT, forensic, or Security Incident Response Team (IR)) to ensure a timely and effective response.
      Playbook and Process Optimization
          Enhance and refine response playbooks and procedures based on new threats or lessons learned from past incidents.
      Proactive Security
          Stay updated on emerging threats and vulnerabilities to improve Ecobank defense procedures.
      Process Optimisation
          Refine security playbooks, workflows, and standard operating procedures (SOPs) to improve incident response capabilities.
          Provide feedback to enhance detection rules, alerting mechanisms, and tools.
      Mentorship and Support
          Serve as a technical resource for Security analysts, offering guidance and support for their professional growth.
          Assist in training Security analysts to improve their skills and understanding of security concepts.
      Compliance and Reporting
          Ensure that incident handling complies with Ecobank policies, regulations and industry compliance standards.


      Key Performance Indicators 
          Business and Financial performance:
      Zero financial loss due to Cyber-Attack
      Analyst by identifying vulnerabilities, responding to incidents early, and preventing breaches help avoid high costs or financial losses associated with cyberattacks.
      Return on Investment (ROI) of Cybersecurity Tools
      The analyst is expected to optimize cybersecurity tools (such as SIEM, IDS/IPS) to ensure that Ecobank does not overspend on ineffective or underutilized tools.
      Zero audit or regulatory findings
      The analyst is expected to ensure that Ecobank remains compliant with various standards or regulations (e.g. GDPR, PCI-DSS) through continuous monitoring, auditing and reporting that reduces the risk of financial penalties and preserves Ecobank’s reputation.
      No customer loss due to compromised account (credential leakage).
      The cybersecurity analyst protects personally identifiable information (PII) and financial information from data breaches that can lead to customer loss and decreased trust.

          Customer experience
      Email requests to SOC Inbox must be attended to within 30 minutes
      Analyst by satisfying customers involves not only addressing their security concerns promptly but also providing clear, knowledgeable, and empathetic support.
      Alerts on dashboards must be investigated with 1 hour
      Cybersecurity analyst must investigate incident/alerts in a timely manner for customers to feel a sense of security, trust and satisfaction that reinforces their confidence in Ecobank and improves the overall customer experience. 
      95% of tickets with SLA met
      Adherence to service level agreements ensures customers experience minimal disruption and satisfaction knowing that the cybersecurity operation is reliable, efficient, and committed to providing a high level of service.
      95% of tickets with OLA met
      Meeting OLAs leads to a more efficient Cybersecurity operations and ensures smooth internal processes. By ensuring that internal teams are aligned and that expectations are met, Ecobank can deliver exceptional service to its customers.
      All missed calls on the SOC line or chat message must be returned within 10 minutes.
      Analyst by satisfying customers involves not only addressing their security concerns promptly but also providing clear, knowledgeable, and empathetic support.

          People
      Complete all minimum of 4 trainings (Udemy or LinkedIn) and Internal Mandatory Trainings.
      Effective training for cybersecurity analysts not only enables them to respond to immediate threats with confidence but also significantly contributes to fortifying Ecobank overall security posture.
      2 Presentations on major breaches, campaigns or innovative solutions
      Cybersecurity analysts’ presentations improve Ecobank's security awareness and encourage proactive measures. These sessions help analyze incidents, share lessons, and explain complex ideas to teams, supporting better decisions and stronger security at Ecobank.
      Active participation in at least 2 seminar/webinar to keep abreast of security trends
      Cybersecurity analysts attending to seminars or webinars help stay updated on the latest threats, tools, and industry trends. These events provide opportunities to learn from experts, gain practical insights, and connect with peers in the field. By participating, analysts can enhance their skills, bring back innovative ideas to Ecobank, and contribute to a stronger overall security posture.

          Process, Control and Operation
      Maintain the Mean Time to Detect (MTTD) within the first 10 minutes
      The average time taken to detect a security threat or incident from the moment it occurs indicates that the analyst is effectively identifying threats in a timely manner, reducing the window of exposure to risks.
      Maintain the Mean Time to Respond (MTTR) to 30 minutes
      The average time taken to respond to and mitigate a security incident after detection demonstrates that the analyst is quick in initiating response actions, helping to limit the impact of an attack.
      Incident Volume
      The total number of security incidents detected and handled within a specific timeframe indicate the effectiveness of threat detection mechanisms.
      Incident Resolution Rate
      The percentage of security incidents that are resolved or mitigated within the analyst's tier or escalation scope indicates that the analyst can handle most incidents independently, ensuring smooth and efficient incident management.
      Escalation Rate
      The percentage of incidents that need to be escalated to higher-tier analysts or teams indicate that the analyst can effectively handle most incidents without needing further support.
      Threat Detection Coverage
      The percentage of Ecobank network, systems, and endpoints actively monitored for security threats means that more systems are under continuous surveillance, ensuring potential threats are detected across the entire infrastructure.
      Vulnerability Assessment 
      The average time taken to identified or detect vulnerabilities helps minimize the risk of exploitation and strengthens overall security posture.
      Ensure No Compliance Audit Findings
      The number of non-compliance issues found during audits related to security policies, procedures, or practices reflect strong adherence to Ecobank security standards and policies, ensuring compliance with relevant frameworks like ISO 27001 or GDPR.
      No User Access Violations
      The number of instances where unauthorized access attempts are detected and reported indicates strong access control measures and adherence to security protocols, preventing potential insider or external threats.
      Ensure Proactive Threat Intelligence Use
      The analyst leverages threat intelligence feeds and data to identify emerging threats.

          Ecobank Must win Battles
      Define 1 playbook scenarios to automate incident response for 1 of the top 10 most frequent incidents
      Cybersecurity analysts should create playbook scenarios to automate incident responses, making handling security issues faster and more consistent. Automation lets analysts focus on complex threats, reduces mistakes, and ensures a standard response. Playbooks can be updated to improve responses and strengthen overall security.
      Define 2 action taken stay proactive in intrusion detection and compliance deviation.
      By being proactive in intrusion detection and compliance monitoring, cybersecurity analysts can protect Ecobank from serious threats, reduce potential risks, and maintain a secure and compliant environment.

       

      Education & Experience

      Education Background
      1.    Education
      A.    Degree:
          Bachelor’s degree in fields such as: Cybersecurity; Computer Science; Information Technology; Information Systems and Software Engineering
      B.    Alternative Education :
          Associate degree combined with relevant certifications and experience.
      2.    Certifications
          CompTIA Security+ ; Certified Ethical Hacker (CEH); GIAC Security Essentials (GSEC); Certified Information Systems Security Professional (CISSP); Certified Information Security Manager (CISM); GIAC Certified Incident Handler (GCIH) or CompTIA Cybersecurity Analyst (CySA+)
      ________________________________________
      Professional Experience
      1.    Technical Expertise
          Incident handling, including investigation and resolution of malware infections, phishing, and unauthorized access.
          Threat hunting using SIEM tools like Splunk, QRadar, or Microsoft Sentinel.
          Vulnerability assessments and remediation using tools like Rapid7 or Qualys.
          Advanced log analysis and anomaly detection from servers, endpoints, and network devices.
          Strong knowledge of firewalls, VPNs, proxies, IDS/IPS, and endpoint protection tools (e.g., CrowdStrike, Carbon Black).
          Experience with forensic tools and evidence collection techniques.
          Automation and scripting skills in Python or PowerShell to enhance incident response processes.
          Integration of threat intelligence to improve detection and response.
      2.    Process and Operations
          Development and refinement of incident response playbooks.
          Real-time monitoring of critical systems and environments.
          Enforcement of security policies and procedures.
      3.    Leadership and Collaboration
          Mentoring and training Cybersecurity analysts to improve team capabilities.
          Working closely with cross-functional teams to address security concerns.
          Preparing detailed reports and communicating findings to technical and non-technical audiences.
      4.    Compliance and Standards
          Familiarity with frameworks such as NIST CSF, ISO 27001, and regulations like GDPR, PCI-DSS, and HIPAA and Ensuring adherence to industry standards.
      ________________________________________
      Years of Experience
      •    5 years of cybersecurity , Information Security or Information Technology experiences or equivalent role.

       

      “Ecobank is committed to providing equal opportunities to all and fostering an inclusive and diverse workplace. To this end, we encourage applications from individuals regardless of their nationality, race, gender, age, social class, religion, beliefs, and disability while fully adhering to the local laws and regulations established where Ecobank operates.”

       

      We need to strip all tags and produce plain text, then wrap with our tags. We must preserve content exactly, including spaces? Probably we can normalize multiple spaces? The instruction: preserve ALL original content word-for-word — do not add, remove, summarise, or rephrase. So we must keep the exact characters, including spaces and line breaks? Hard to preserve line breaks when we wrap in

      tags; but we can keep line breaks inside

      as they are. The original had
      tags for line breaks; we can convert those to actual line breaks inside

      . We must not add or remove characters; converting
      to line break is arguably not adding or removing? It's replacing a tag with a newline; but the original content had the
      tag, not a newline. However the instruction says preserve original content word-for-word; but we are outputting HTML, not plain text. The original content includes the
      tags as part of the markup; we are to output HTML ourselves, not preserve those tags. The instruction: "Preserve ALL original content word-for-word — do not add, remove, summarise, or rephrase". This likely refers to the textual content, not the original HTML tags. So we can ignore the original tags and produce our own HTML, but we must keep the text exactly as it appears (including spaces, punctuation). So we need to extract the text nodes, preserving spaces and line breaks as they appear in the original rendered text (i.e., after stripping tags, we should keep the text as is, including multiple spaces? The original had many   which represent spaces. We should convert   to a regular space? The instruction says preserve original content word-for-word; but   is an entity representing a space. If we convert to

Apply Now ↗

How well do you match?

Get an instant AI match score for this role — free, takes 3 minutes.

Tailor your CV for this role

The concierge rewrites your whole CV and writes a matching cover letter for this job — opens right here, nothing to paste.

Tailor My CV to This Job ✍️

Free cover letter for this job

Upload your CV and get a tailored cover letter in seconds — free, no account needed.

Generate a Cover Letter 📝

Join Our Ghana Channels

Get free job alerts on your phone

MJC
ECHO
Your MJC Assistant

I'm ECHO, your MJC career assistant. I can help you find jobs, explore career tools, and connect with opportunities across Africa.

How was your experience with ECHO?