Security Monitoring and Response Analysts (1)
Job Purpose
The Security Monitoring and Response Analyst is responsible for the continuous monitoring, detection, analysis, and response to cybersecurity events and incidents within the Bank’s Security Operations Center (SOC).
The role supports the Senior Manager Information Security by ensuring effective execution of security monitoring and incident response activities, while working under the operational guidance of the Unit Manager to maintain the security posture of the Bank.
The analyst plays a critical role in safeguarding the Bank’s systems, networks, applications, and data by identifying potential threats, investigating suspicious activities, and responding promptly to security incidents in line with internal policies, regulatory requirements, and industry best practices.
Main Responsibilities
Monitor and analyze security alerts from SIEM, EDR, NDR, SOAR, and other tools to identify suspicious activities and threats.
Perform initial triage and classification of alerts based on severity, impact, and potential risk to the Bank.
Investigate security incidents through log analysis, network traffic inspection, and endpoint activity review.
Execute incident response actions (containment, eradication, and recovery) in line with SOC procedures and SOC Lead guidance.
Escalate complex or high-risk incidents promptly to the Senior Manager Information Security and relevant stakeholders.
Support threat intelligence usage and contribute to threat hunting by identifying unusual patterns and indicators of compromise.
Assist in tuning SIEM rules, alert thresholds, and correlation logic to improve detection accuracy and reduce false positives.
Ensure SOC tools are functioning effectively, including supporting log source integration and reporting technical issues.
Adhere to SOC processes, playbooks, and regulatory requirements (ISO 27001, NCSA, BNR), while identifying improvement opportunities.
Document all incidents, investigations, and response actions, and provide timely updates and reporting on incident status.
Daily Responsibilities:
Monitor and analyze security alerts from SIEM, EDR, NDR, SOAR, Monitor SOC dashboards and respond to security alerts in real time.
Perform triage and analysis of alerts to determine validity and severity.
Investigate suspicious activities using logs, SIEM queries, and forensic tools.
Escalate incidents as per defined escalation procedures.
Track and update incident tickets to ensure timely resolution and proper documentation.
Collaborate with line manager and team members during incident handling.
Review threat intelligence feeds and apply relevant insights.
Ensure compliance with defined SLAs (e.g., response time, resolution time).
Educational qualifications and work experience:
Bachelor's level degree I B.Sc. Information Technology / Computer
Science / Telecommunications Engineering or related field.
Master’s Degree in MBA / MSC
Professional Qualifications Certified Ethical Hacker, GIAC Certified Incident Handler (GCIH), GIAC Certified Forensic Analyst (GCFA), CompTIA CySA+ (Cybersecurity Analyst)
CISSP: Certified Information Systems Security Professional • CISA: Certified Information Systems Auditor • CISM: Certified Information Systems Manager • CCISO: Certified Chief Information Security Officer, Certified SOC Manager (CSM) - EC-Council, or Similar.
3 years of minimum experience Information Security Management, Governance, Risk Management and Compliance, Security Architecture and Engineering, Security Program Management and Operations, Communication and Network Security, Identity and Access Management, Software Development, Security Assessment and Testing,Information Security Incident Management, IT or Information Security Software Development, Security Assessment and Testing.