We at MTN are a purpose and value-led organization. At MTN, we believe that understanding our people’s needs and aspirations is key to creating experiences that delight you at work, everyday. We are committed to fostering an environment where every member of our Y’ello Family is heard, understood and empowered to live an inspired life.
Our values keep us grounded and moving in the right direction. Most importantly, they keep us honest. It is not something we claim to be. It is in our DNA.
As an organisation, we consider it our mission to create an exciting and rewarding place to work, where our people can be themselves, thrive in positivity and ignite their full potential. A workplace that boosts creativity and innovation, improves productivity, and ultimately drives meaningful results. A workplace that is built on relationships and achieving a purpose that is bigger than us.
Our commitments go beyond an organisational promise. It is in our leadership and managerial ethos to meaningfully partner with our employees, customers and stakeholders with a vision to realise our shared goals.
Live Y’ello
- Lead with Care
- Can-do with Integrity
- Collaborate with Agility
- Serve with Respect
- Act with Inclusion
Mission/ Core purpose of the Job
Responsible for managing incident management processes in accordance with industry best practices. The role provides support for operational security response activities, major incident coordination, escalation management, stakeholder communications, root cause analysis, SLA performance monitoring, and continuous service improvement.
The role also acts as the SOC technical lead for strategic security technology initiatives, including RFI/RFP technical requirements, Statements of Work, vendor technical evaluation, solution-fit validation, integration requirements, future-state operating models, implementation considerations and governance recommendation packs. This role is responsible for ensuring the technical requirements are clear, measurable, future-fit and aligned to MTN’s SOC, architecture, security and operational needs.
Key Performance Areas: Core, essential responsibilities / outputs of the position (KPA's)
The Manager: Incident Management will be accountable to achieve the following objectives:
Executing the incident management process tasks in adherence with group and local OpCo requirements.
Coordinate and manage the incident management process activities across the group and with external vendors as per agreed SLAs.
Escalate risks and issues to the senior management within the technology function
Support incident management reporting (KPIs and customer SLAs)
Assist the incident management process owners within OpCos in:
Driving service management best-practice and process standardisation
Implementing consistent end-to-end application of the incident management process across the business
Identifying and planning for incident management process improvement projects
driving cross-account process standardisation
Drive implementation of standard execution of the incident management process
Responsible for the complete process adherence and handling of incidents according to SLAs
Responsible for acting as an escalation point to expedite incident resolution
Strategic SOC Contribution
Support implementation of the strategic roadmap of the Group SOC, ensuring alignment with business objectives and emerging threat trends.
Drive visibility enhancement initiatives, including onboarding of critical assets, improving telemetry coverage, and reducing detection blind spots.
Collaborate with SOC Engineering, Threat Intelligence, and Detection teams to enhance detection rules, response playbooks, and automation.
Assist in identifying operational improvements and process efficiencies that reduce MTTD, MTTR, and enhance SOC efficiency and maturity.
Provide operational input to SOC enhancement initiatives to improve correlation, enrichment, and response automation.
Technical Lead for RFI/RFP, SOW and Vendor Evaluation
Participate in vendor demonstrations and proof-of-concept activities.
Support the development of technical requirements as requested by architecture and procurement teams.
Assist with vendor performance reviews and ongoing operational service assessments.
Provide operational and technical input into security technology evaluations for RFI/RFP activities, working with Procurement, GSSC, solution architecture, security architecture and relevant business stakeholders.
Develop or contribute to Statements of Work, technical questionnaires, technical evaluation criteria, vendor assessment frameworks, shortlisting rationale and recommendation packs.
Ensure RFI/RFP requirements describe MTN’s current environment, target state, integration expectations, scale, data sources, telemetry needs, OpCo context, regulatory constraints, operating model and implementation assumptions.
Validate vendor claims through evidence review, demonstrations, reference checks, proof-of-compliance, site visits where required, technical due diligence and fit-for-purpose analysis.
Ensure evaluation outcomes are objective, evidence-based, documented and aligned to the approved scoring process.
Distinguish clearly between technical evaluation and procurement/commercial decision-making: Procurement owns process governance, sourcing rules, commercial evaluation and contracting; the role owns SOC technical content, requirements and technical recommendation.
Solution Architecture, Integration & Implementation Oversight
Support implementation of approved security solutions.
Provide operational requirements and incident-response considerations during solution deployment.
Assist with testing and operational readiness activities.
AI, LLM, Automation
Support adoption of approved automation and AI-enabled capabilities within security operations.
Identify operational opportunities for automation.
Escalate AI-related risks to Security Architecture and Governance teams
Governance, Business Cases & Decision Forums
Provide operational reporting and technical input for governance submissions.
Support preparation of status updates and incident management performance reports.
Prepare and present technical recommendations, , decision papers and progress updates to governance and decision-making forums.
Ensure submissions clearly describe purpose, decision required, value, risks, financial implications, stakeholders consulted, architecture alignment, security implications, implementation plan and residual risks.
Translate technical findings into executive-ready risk, business and operational language, including clear recommendations, options, trade-offs and decision rationale for Senior Manager review
Ensure solution decisions are aligned to MTN Group strategy, architecture standards, information security requirements, OpCo needs and regulatory constraints.
Key Deliverables
Manage major incidents end-to-end
Ensure SLA adherence
Improve visibility, telemetry and detection capabilities
Ensure safe and governed AI adoption
Lead technical aspects of RFI/RFP processes
Develop SOWs and technical requirements
Role Dependencies
Active support from the Group CTIO, GM: Enterprise Services and SM: Service Delivery
Deep understanding of the MTN business strategy
Understanding of the OpCo technology, business and regulatory context
Timely decision making and reporting
Alignment of OpCo and Group strategy initiatives
Job Requirements (Education, Experience and Competencies)
Education:
- Bachelor’s degree in computer science, Information Technology, Software Engineering or related field
- One or more relevant industry certifications (as per below)
Certifications:
- CISSP, CISM or equivalent security certification advantageous
- Microsoft Security certifications (SC-200, AZ-500).
- Cloud security certifications (CCSP, AWS or Azure security specialty).
Experience:
- 5-6 years' experience in information security, cybersecurity operations or a related technology environment.
- Experience in the following areas: Security Monitoring, Incident Response, Security Operations, or Security Tool Administration.
- Experience supporting the implementation and operation of security automation solutions within enterprise environments
- Experience operating in large, complex enterprise environments; telecommunications experience is an advantage.
- Experience participating in RFI/RFP, vendor evaluation, technical scoring, SOW development, proof-of-concept, proof-of-compliance, solution selection or technical due diligence activities.
- Proven track record of business improvement and strategy development
Technical competencies
- Strong knowledge of SIEM and SOAR and EDR/XDR tooling (e.g. Microsoft Defender).
- Proficiency in scripting and automation (Python, PowerShell, KQL) and integration via REST APIs.
- Practical knowledge of cloud security across Azure, AWS and/or GCP.
- Familiarity with AI/ML and LLM security concepts, agentic AI, and secure AI adoption.
- Working knowledge of security frameworks: MITRE ATT&CK, MITRE ATLAS, NIST CSF, OWASP, Zero Trust and CIS.
- Sound understanding of networking, operating systems and enterprise infrastructure.
Behavioural competencies
- Analytical, structured problem-solver with strong attention to detail.
- Self-driven and able to work independently and lead initiatives end-to-end.
- Strong collaboration and stakeholder engagement skills across technical and business teams.
- Excellent written and verbal communication.
- Comfortable with ambiguity and a rapidly evolving technology landscape.
- Committed to continuous learning, innovation and knowledge sharing.
Competencies:
- Strategy Implementers, Decisive Problem Solver, Best Practice Value Creator
- Culture and Change Champion, Guiding People Manager, Relationship Builder
- Results Achiever, Operationally Astute
Other:
- Regional and international travel

