Analyst - Cyber Threat Intelligence

Description

Mission  To strengthen MTN Group's cyber defence capability through the collection, analysis, production and dissemination of actionable cyber threat intelligence, proactive threat hunting, and intelligence-led support to incident and vulnerability management. The role contributes to the protection of MTN's digital assets by identifying emerging threats, enhancing detection capabilities, and leveraging AI-driven automation to improve threat intelligence reporting and hunting effectiveness across the MTN operating environment.

Context

MTN's Ambition 2030 strategy is focused on leading digital solutions for Africa's progress by accelerating platform growth, advancing digital and financial inclusion, enabling sustainable connectivity, and building a resilient, future-fit organisation. As MTN continues its evolution into a digital platform business, Information Security plays a critical role in safeguarding customer trust, protecting digital services, enabling innovation, and ensuring operational resilience across MTN's diverse markets.

The Group Information Security function must therefore ensure the successful delivery of its mandate in the context of:

  • Supporting MTN's Ambition 2030 vision to be the leading platform business and digital solutions provider for Africa.

  • Accelerating digital transformation, cloud adoption, AI enablement, fintech expansion, digital services, and platform ecosystems across the Group.

  • Protecting MTN's rapidly expanding digital assets, customer data, financial platforms, and critical technology infrastructure.

  • Managing the geographic complexity of MTN's footprint across Africa and the Middle East, encompassing varying regulatory, political and cyber risk environments.

  • Maintaining stakeholder confidence by meeting the expectations of customers, shareholders, regulators, partners, and communities.

  • Enabling sustainable growth through secure digital innovation and the adoption of emerging technologies, including Artificial Intelligence.

  • Achieving operational excellence through standardised security processes, automation, intelligence-led decision-making, and continuous improvement.

  • Addressing an increasingly sophisticated and rapidly evolving cyber threat landscape targeting telecommunications operators, financial services, digital platforms, and critical infrastructure.

  • Ensuring business continuity, cyber resilience, and operational stability across a highly interconnected technology ecosystem.

  • Delivering integrated cyber defence capabilities across network, cloud, IT, digital, financial services, and enterprise environments.

  • Strengthening proactive threat intelligence, threat hunting, detection, response, and cyber risk management capabilities.

  • Supporting regulatory compliance and data protection requirements across multiple jurisdictions.

  • Enhancing MTN's reputation as a trusted, secure, and responsible digital operator.

  • Leveraging automation, machine learning, and AI-driven security capabilities to improve cyber defence effectiveness and operational efficiency.

  • Embedding a culture of security awareness, accountability, and resilience across MTN Group and its Operating Companies.

In this environment, the Information Security function is required to provide timely, actionable, and business-relevant intelligence that enables MTN to anticipate emerging threats, proactively manage cyber risks, and support the achievement of Ambition 2030 objectives.

Values

We at MTN are a purpose and value-led organization. At MTN, we believe that understanding our people’s needs and aspirations is key to creating experiences that delight you at work, everyday. We are committed to fostering an environment where every member of our Y’ello Family is heard, understood and empowered to live an inspired life.

Our values keep us grounded and moving in the right direction. Most importantly, they keep us honest. It is not something we claim to be. It is in our DNA.

As an organisation, we consider it our mission to create an exciting and rewarding place to work, where our people can be themselves, thrive in positivity and ignite their full potential. A workplace that boosts creativity and innovation, improves productivity, and ultimately drives meaningful results. A workplace that is built on relationships and achieving a purpose that is bigger than us.

Our commitments go beyond an organisational promise. It is in our leadership and managerial ethos to meaningfully partner with our employees, customers and stakeholders with a vision to realise our shared goals.

Live Y’ello

  • Lead with Care

  • Can-do with Integrity

  • Collaborate with Agility

  • Serve with Respect

  • Act with Inclusion

Responsibilities

Key Performance Areas

Threat Intelligence Collection, Analysis and Production

  • Collect and analyse cyber threat intelligence relevant to MTN and the telecommunications sector.

  • Monitor threat actors, campaigns, techniques, tactics and procedures (TTPs).

  • Identify and assess indicators of compromise (IOCs).

  • Contextualise threat intelligence to MTN's environment and risk profile.

  • Produce actionable intelligence products that support informed decision-making.

  • Demonstrate the business value and operational impact of threat intelligence.

Threat Hunting and Detection Engineering
  • Conduct proactive threat hunting across MTN's digital estate.

  • Develop and optimise hunting queries and detection logic.

  • Analyse telemetry from security platforms.

  • Identify visibility and detection gaps.

  • Recommend and implement enhancements to monitoring coverage.

  • Continuously improve threat detection effectiveness.

Intelligence Reporting and Stakeholder Engagement
  • Produce intelligence reports for technical and business audiences.

  • Communicate emerging threats and risks to relevant stakeholders.

  • Translate complex technical findings into business-relevant insights.

  • Disseminate intelligence products across MTN Group and OpCos.

  • Tailor intelligence outputs according to stakeholder requirements.

AI-Driven Security Automation
  • Support MTN's AI journey by implementing agentic AI capabilities.

  • Develop and maintain AI-enabled threat hunting and reporting solutions.

  • Automate repetitive threat intelligence activities.

  • Enhance efficiency through scripting and workflow automation.

  • Identify opportunities for AI adoption within Cyber Defence operations.

Incident and Vulnerability Management Support
  • Provide intelligence support during cyber security incidents.

  • Support vulnerability prioritisation through threat intelligence analysis.

  • Assess exploitability and business impact of vulnerabilities.

  • Enable risk-based remediation prioritisation.

  • Collaborate with incident response and vulnerability management teams.

Cyber Risk Assessment and Advisory
  • Evaluate cyber threats from a business risk perspective.

  • Communicate cyber risks to relevant stakeholders.

  • Provide recommendations to support risk-based decision making.

  • Contribute to MTN's overall security posture and governance.

Qualifications

Qualifications

  • A computer-related degree or diploma (Computer Science, Information Technology, Cybersecurity or a related field).

Preferred
  • SANS GIAC Cyber Threat Intelligence (GCTI/FOR578)

  • Microsoft SC-200

  • CompTIA CySA+

  • MITRE ATT&CK Defender Certifications

  • Other Threat Intelligence or Threat Hunting Certifications

  • Security exposure (CEH, eJPT, PNPT, PenTest+)

Experience
  • Minimum 2–3 years' experience in a dedicated threat intelligence role.

  • Sound understanding of cyber defense fundamentals, including incident management, vulnerability management and threat intelligence, and the value these bring to an organization.

  • Demonstrated understanding of how threat intelligence reporting works and the ability to perform basic threat hunting.

  • Some software development / scripting background, with the proven ability to build — or quickly learn to build — AI agents for automation.

  • Practical understanding of Buffer overflows, Open ports, Offensive testing concepts

Technical Skills & Tools
  • Endpoint: Microsoft Defender for Endpoint (MDE)

  • SIEM: Microsoft Sentinel

  • EDR / XDR: SentinelOne

  • Working knowledge of threat intelligence frameworks such as MITRE ATT&CK, the Diamond Model, the Cyber Kill Chain and STIX/TAXII.

Preferred / Advantageous
  • SANS GIAC Cyber Threat Intelligence (GCTI / FOR578), or an equivalent threat intelligence or threat hunting certification.

  • Additional security certifications relevant to threat hunting and detection (e.g. Microsoft SC-200, CompTIA CySA+, MITRE ATT&CK Defender).

  • A working understanding of modern AI principles — including large language models (LLMs), agentic AI and the Model Context Protocol (MCP) / MCP servers — and how they can be applied to automate threat hunting and threat intelligence reporting.

  • Hands-on experience building AI agents or automation pipelines for threat intelligence and threat hunting.

  • Experience within the telecommunications, ICT or other large, complex enterprise environments.

Competencies:
  • Strong analytical thinking and attention to detail.

  • Excellent written and verbal communication, with the ability to simplify and tailor technical content for diverse audiences.

  • A risk-based mindset and sound judgement.

  • Self-driven, curious and a fast learner who keeps pace with emerging threats and technologies, including AI.

  • Collaborative team player able to work across departments and operating companies.

Back to blog

Other Jobs To Apply

No other job posts for this day.

Common Interview Questions And Answers

1. HOW DO YOU PLAN YOUR DAY?

This is what this question poses: When do you focus and start working seriously? What are the hours you work optimally? Are you a night owl? A morning bird? Remote teams can be made up of people working on different shifts and around the world, so you won't necessarily be stuck in the 9-5 schedule if it's not for you...

2. HOW DO YOU USE THE DIFFERENT COMMUNICATION TOOLS IN DIFFERENT SITUATIONS?

When you're working on a remote team, there's no way to chat in the hallway between meetings or catch up on the latest project during an office carpool. Therefore, virtual communication will be absolutely essential to get your work done...

3. WHAT IS "WORKING REMOTE" REALLY FOR YOU?

Many people want to work remotely because of the flexibility it allows. You can work anywhere and at any time of the day...

4. WHAT DO YOU NEED IN YOUR PHYSICAL WORKSPACE TO SUCCEED IN YOUR WORK?

With this question, companies are looking to see what equipment they may need to provide you with and to verify how aware you are of what remote working could mean for you physically and logistically...

5. HOW DO YOU PROCESS INFORMATION?

Several years ago, I was working in a team to plan a big event. My supervisor made us all work as a team before the big day. One of our activities has been to find out how each of us processes information...

6. HOW DO YOU MANAGE THE CALENDAR AND THE PROGRAM? WHICH APPLICATIONS / SYSTEM DO YOU USE?

Or you may receive even more specific questions, such as: What's on your calendar? Do you plan blocks of time to do certain types of work? Do you have an open calendar that everyone can see?...

7. HOW DO YOU ORGANIZE FILES, LINKS, AND TABS ON YOUR COMPUTER?

Just like your schedule, how you track files and other information is very important. After all, everything is digital!...

8. HOW TO PRIORITIZE WORK?

The day I watched Marie Forleo's film separating the important from the urgent, my life changed. Not all remote jobs start fast, but most of them are...

9. HOW DO YOU PREPARE FOR A MEETING AND PREPARE A MEETING? WHAT DO YOU SEE HAPPENING DURING THE MEETING?

Just as communication is essential when working remotely, so is organization. Because you won't have those opportunities in the elevator or a casual conversation in the lunchroom, you should take advantage of the little time you have in a video or phone conference...

10. HOW DO YOU USE TECHNOLOGY ON A DAILY BASIS, IN YOUR WORK AND FOR YOUR PLEASURE?

This is a great question because it shows your comfort level with technology, which is very important for a remote worker because you will be working with technology over time...