Technology Department,Rwanda.Security & Monitoring Response Analyst
KCB Group
Job Description
Other key purposes include:
- Perform real-time monitoring and analysis of security alerts and events.
- Conduct incident triage, investigation, and escalation.
- Support incident response activities to minimize business impact.
- Contribute to improving detection rules, use cases, and SOC processes.
- Ensure protection of confidentiality, integrity, and availability (CIA) of Bank information assets.
Support compliance with Rwanda data protection laws, NCSA, BNR, and other regulatory frameworks
KEY RESPONSIBILITIES:
- Monitor and analyze security alerts from SIEM, EDR, NDR, SOAR, and other tools to identify suspicious activities and threats.
- Perform initial triage and classification of alerts based on severity, impact, and potential risk to the Bank.
- Investigate security incidents through log analysis, network traffic inspection, and endpoint activity review.
- Execute incident response actions (containment, eradication, and recovery) in line with SOC procedures and SOC Lead guidance.
- Escalate complex or high-risk incidents promptly to the SOC Lead and relevant stakeholders.
- Support threat intelligence usage and contribute to threat hunting by identifying unusual patterns and indicators of compromise.
- Assist in tuning SIEM rules, alert thresholds, and correlation logic to improve detection accuracy and reduce false positives.
- Ensure SOC tools are functioning effectively, including supporting log source integration and reporting technical issues.
- Adhere to SOC processes, playbooks, and regulatory requirements (ISO 27001, NCSA, BNR), while identifying improvement opportunities.
- Document all incidents, investigations, and response actions, and provide timely updates and reporting on incident status.
DAILY RESPONSIBILITIES:
- Monitor SOC dashboards and respond to security alerts in real time.
- Perform triage and analysis of alerts to determine validity and severity.
- Investigate suspicious activities using logs, SIEM queries, and forensic tools.
- Escalate incidents as per defined escalation procedures.
- Track and update incident tickets to ensure timely resolution and proper documentation.
- Collaborate with SOC Lead and team members during incident handling.
- Review threat intelligence feeds and apply relevant insights.
- Ensure compliance with defined SLAs (e.g., response time, resolution time).
MINIMUM POSITION QUALIFICATION REQUIREMENTS
Academic & Professional
Education
Particulars |
Detail |
Specific Field or Qualification |
Education |
Bachelor’s Degree |
B.Sc. Information Technology / Computer Science / Telecommunications / Engineering or related field |
Education |
Professional Qualifications |
Certified Ethical Hacker, GIAC Certified Incident Handler (GCIH), GIAC Certified Forensic Analyst (GCFA), CompTIA CySA+ (Cybersecurity Analyst) CISSP: Certified Information Systems Security Professional • CISA: Certified Information Systems Auditor • CISM: Certified Information Systems Manager • CCISO: Certified Chief Information Security Officer, Certified SOC Manager (CSM) - EC-Council, or Similar |
Education |
Master’s Degree |
MBA / MSC |
Experience
Total Minimum No of Years’ Experience Required |
3 |
How well do you match?
Get an instant AI match score for this role — free, takes 3 minutes.
Tailor your CV for this role
The concierge rewrites your whole CV and writes a matching cover letter for this job — opens right here, nothing to paste.
Tailor My CV to This Job ✍️Free cover letter for this job
Upload your CV and get a tailored cover letter in seconds — free, no account needed.
Generate a Cover Letter 📝