Security Operation Center Supervisor (SOC Level 2)
- Hiring from
- Ghana
- Work type
- Hybrid
- Posted
- Sep 29, 2026
GENERAL JOB INFORMATION
Job Title: Security Operation Center Supervisor (SOC Level 2)
Organization/Department: Cybersecurity Department
Head of Unit/Department: Security Operation Center Unit
Salary Grade/ Band: 3A
Reports To: Security Operation Center Unit Head
JOB PURPOSE
The Security Supervisor serves as the second line of defense, responsible for conducting in-depth investigations, responding to security incidents, and ensuring the effective management and mitigation of threats. The role focuses on proactive measures to strengthen Ecobank's overall security posture.
He/she focuses in enhancing Ecobank's security operations by addressing escalated threats, performing advanced analyses, and ensuring prompt and effective incident responses. Additionally, the position drives continuous improvements in security processes to protect Ecobank's systems and data.
This is a 24/7 shift-based role, operating on a rotation of three shifts, each lasting 8 hours within a 24-hour period.
KEY RESPONSIBILITIES
Incident Triage and Analysis
Analyse and respond to incidents escalated by security analysts, ensuring accurate identification of threats and their root causes.
Perform deeper analysis to determine the root cause, scope, and impact of security threats or event.
Advanced Threat Detection
Use SIEM tools, EDR platforms, and threat intelligence to identify complex and persistent threats such as malware, phishing campaigns, or insider attacks.
Correlate data from various sources to detect patterns and anomalies that indicate malicious activity.
Monitor threat intelligence feeds to detect and respond to emerging risks.
Incident Response Coordination
Lead the coordination of incident response efforts, ensuring timely containment, eradication, and recovery.
Collaborate with other teams (e.g., IT, forensic, or Security Incident Response Team (IR)) to ensure a timely and effective response.
Playbook and Process Optimization
Enhance and refine response playbooks and procedures based on new threats or lessons learned from past incidents.
Proactive Security
Stay updated on emerging threats and vulnerabilities to improve Ecobank defense procedures.
Process Optimisation
Refine security playbooks, workflows, and standard operating procedures (SOPs) to improve incident response capabilities.
Provide feedback to enhance detection rules, alerting mechanisms, and tools.
Mentorship and Support
Serve as a technical resource for Security analysts, offering guidance and support for their professional growth.
Assist in training Security analysts to improve their skills and understanding of security concepts.
Compliance and Reporting
Ensure that incident handling complies with Ecobank policies, regulations and industry compliance standards.
Key Performance Indicators
Business and Financial performance:
Zero financial loss due to Cyber-Attack
Analyst by identifying vulnerabilities, responding to incidents early, and preventing breaches help avoid high costs or financial losses associated with cyberattacks.
Return on Investment (ROI) of Cybersecurity Tools
The analyst is expected to optimize cybersecurity tools (such as SIEM, IDS/IPS) to ensure that Ecobank does not overspend on ineffective or underutilized tools.
Zero audit or regulatory findings
The analyst is expected to ensure that Ecobank remains compliant with various standards or regulations (e.g. GDPR, PCI-DSS) through continuous monitoring, auditing and reporting that reduces the risk of financial penalties and preserves Ecobank’s reputation.
No customer loss due to compromised account (credential leakage).
The cybersecurity analyst protects personally identifiable information (PII) and financial information from data breaches that can lead to customer loss and decreased trust.
Customer experience
Email requests to SOC Inbox must be attended to within 30 minutes
Analyst by satisfying customers involves not only addressing their security concerns promptly but also providing clear, knowledgeable, and empathetic support.
Alerts on dashboards must be investigated with 1 hour
Cybersecurity analyst must investigate incident/alerts in a timely manner for customers to feel a sense of security, trust and satisfaction that reinforces their confidence in Ecobank and improves the overall customer experience.
95% of tickets with SLA met
Adherence to service level agreements ensures customers experience minimal disruption and satisfaction knowing that the cybersecurity operation is reliable, efficient, and committed to providing a high level of service.
95% of tickets with OLA met
Meeting OLAs leads to a more efficient Cybersecurity operations and ensures smooth internal processes. By ensuring that internal teams are aligned and that expectations are met, Ecobank can deliver exceptional service to its customers.
All missed calls on the SOC line or chat message must be returned within 10 minutes.
Analyst by satisfying customers involves not only addressing their security concerns promptly but also providing clear, knowledgeable, and empathetic support.
People
Complete all minimum of 4 trainings (Udemy or LinkedIn) and Internal Mandatory Trainings.
Effective training for cybersecurity analysts not only enables them to respond to immediate threats with confidence but also significantly contributes to fortifying Ecobank overall security posture.
2 Presentations on major breaches, campaigns or innovative solutions
Cybersecurity analysts’ presentations improve Ecobank's security awareness and encourage proactive measures. These sessions help analyze incidents, share lessons, and explain complex ideas to teams, supporting better decisions and stronger security at Ecobank.
Active participation in at least 2 seminar/webinar to keep abreast of security trends
Cybersecurity analysts attending to seminars or webinars help stay updated on the latest threats, tools, and industry trends. These events provide opportunities to learn from experts, gain practical insights, and connect with peers in the field. By participating, analysts can enhance their skills, bring back innovative ideas to Ecobank, and contribute to a stronger overall security posture.
Process, Control and Operation
Maintain the Mean Time to Detect (MTTD) within the first 10 minutes
The average time taken to detect a security threat or incident from the moment it occurs indicates that the analyst is effectively identifying threats in a timely manner, reducing the window of exposure to risks.
Maintain the Mean Time to Respond (MTTR) to 30 minutes
The average time taken to respond to and mitigate a security incident after detection demonstrates that the analyst is quick in initiating response actions, helping to limit the impact of an attack.
Incident Volume
The total number of security incidents detected and handled within a specific timeframe indicate the effectiveness of threat detection mechanisms.
Incident Resolution Rate
The percentage of security incidents that are resolved or mitigated within the analyst's tier or escalation scope indicates that the analyst can handle most incidents independently, ensuring smooth and efficient incident management.
Escalation Rate
The percentage of incidents that need to be escalated to higher-tier analysts or teams indicate that the analyst can effectively handle most incidents without needing further support.
Threat Detection Coverage
The percentage of Ecobank network, systems, and endpoints actively monitored for security threats means that more systems are under continuous surveillance, ensuring potential threats are detected across the entire infrastructure.
Vulnerability Assessment
The average time taken to identified or detect vulnerabilities helps minimize the risk of exploitation and strengthens overall security posture.
Ensure No Compliance Audit Findings
The number of non-compliance issues found during audits related to security policies, procedures, or practices reflect strong adherence to Ecobank security standards and policies, ensuring compliance with relevant frameworks like ISO 27001 or GDPR.
No User Access Violations
The number of instances where unauthorized access attempts are detected and reported indicates strong access control measures and adherence to security protocols, preventing potential insider or external threats.
Ensure Proactive Threat Intelligence Use
The analyst leverages threat intelligence feeds and data to identify emerging threats.
Ecobank Must win Battles
Define 1 playbook scenarios to automate incident response for 1 of the top 10 most frequent incidents
Cybersecurity analysts should create playbook scenarios to automate incident responses, making handling security issues faster and more consistent. Automation lets analysts focus on complex threats, reduces mistakes, and ensures a standard response. Playbooks can be updated to improve responses and strengthen overall security.
Define 2 action taken stay proactive in intrusion detection and compliance deviation.
By being proactive in intrusion detection and compliance monitoring, cybersecurity analysts can protect Ecobank from serious threats, reduce potential risks, and maintain a secure and compliant environment.
Education & Experience
Education Background
1. Education
A. Degree:
Bachelor’s degree in fields such as: Cybersecurity; Computer Science; Information Technology; Information Systems and Software Engineering
B. Alternative Education :
Associate degree combined with relevant certifications and experience.
2. Certifications
CompTIA Security+ ; Certified Ethical Hacker (CEH); GIAC Security Essentials (GSEC); Certified Information Systems Security Professional (CISSP); Certified Information Security Manager (CISM); GIAC Certified Incident Handler (GCIH) or CompTIA Cybersecurity Analyst (CySA+)
________________________________________
Professional Experience
1. Technical Expertise
Incident handling, including investigation and resolution of malware infections, phishing, and unauthorized access.
Threat hunting using SIEM tools like Splunk, QRadar, or Microsoft Sentinel.
Vulnerability assessments and remediation using tools like Rapid7 or Qualys.
Advanced log analysis and anomaly detection from servers, endpoints, and network devices.
Strong knowledge of firewalls, VPNs, proxies, IDS/IPS, and endpoint protection tools (e.g., CrowdStrike, Carbon Black).
Experience with forensic tools and evidence collection techniques.
Automation and scripting skills in Python or PowerShell to enhance incident response processes.
Integration of threat intelligence to improve detection and response.
2. Process and Operations
Development and refinement of incident response playbooks.
Real-time monitoring of critical systems and environments.
Enforcement of security policies and procedures.
3. Leadership and Collaboration
Mentoring and training Cybersecurity analysts to improve team capabilities.
Working closely with cross-functional teams to address security concerns.
Preparing detailed reports and communicating findings to technical and non-technical audiences.
4. Compliance and Standards
Familiarity with frameworks such as NIST CSF, ISO 27001, and regulations like GDPR, PCI-DSS, and HIPAA and Ensuring adherence to industry standards.
________________________________________
Years of Experience
• 5 years of cybersecurity , Information Security or Information Technology experiences or equivalent role.
“Ecobank is committed to providing equal opportunities to all and fostering an inclusive and diverse workplace. To this end, we encourage applications from individuals regardless of their nationality, race, gender, age, social class, religion, beliefs, and disability while fully adhering to the local laws and regulations established where Ecobank operates.”