Engineering Job At USIU
Recruit Finds
Nairobi, Kenya
Job summary
Senior Engineer – Security Operation Center at United States International University - USIU Africa
About this role
Join Our Whatsapp Channel - CLICK HERE
Senior Security Operations Centre (SOC) Analyst
1. Position Overview
USIU-Africa is seeking a highly skilled and experienced Senior Security Operations Centre (SOC) Analyst to strengthen the institution's cybersecurity capabilities and protect its digital infrastructure.
The successful candidate will be responsible for monitoring the university's technology environment, identifying suspicious activity, investigating cybersecurity incidents, coordinating responses to threats, and supporting continuous improvements to information security controls.
This is a technically demanding position requiring strong knowledge of modern cybersecurity tools, security monitoring practices, incident response, vulnerability management, and information security governance.
The Senior SOC Analyst will work closely with the IT Division and other university departments to ensure that critical information systems remain secure, reliable, and available.
2. Job Purpose
The primary purpose of this position is to help protect the confidentiality, integrity, and availability of the university's information assets and technology services.
The Senior SOC Analyst will provide proactive security monitoring and analysis across the institution's digital environment. The role involves detecting potential threats at an early stage, investigating security events, coordinating appropriate responses, and recommending measures that reduce the likelihood and impact of future incidents.
The position will also contribute to the continuous improvement of the university's cybersecurity architecture by identifying vulnerabilities, analyzing emerging threats, strengthening security controls, and supporting compliance with recognized information security frameworks.
3. Key Areas of Responsibility
The role covers several important cybersecurity functions, including:
Security monitoring and threat detection.
Cybersecurity incident investigation and response.
Security tools administration and optimization.
Log monitoring and analysis.
Vulnerability and risk assessment.
Threat intelligence.
Cybersecurity asset and documentation management.
Information security governance and compliance.
General IT controls.
Collaboration with internal technical and business teams.
4. Security Monitoring and Threat Detection
The Senior SOC Analyst will be responsible for maintaining continuous visibility across the university's IT environment.
Key responsibilities include:
Participating in a 24-hour, seven-day rotational SOC shift arrangement.
Monitoring security alerts generated by cybersecurity platforms.
Reviewing and prioritizing alerts according to their severity and potential impact.
Responding to security events within established service-level requirements.
Identifying suspicious activities and indicators of compromise.
Conducting continuous surveillance of critical systems and networks.
Escalating serious incidents through established procedures.
Distinguishing genuine security threats from false positives.
Correlating information from multiple security monitoring sources.
Taking appropriate action to contain or mitigate identified threats.
The analyst will be expected to exercise sound judgment when determining which events require immediate investigation and escalation.
5. Cybersecurity Incident Response
The position will play a central role in investigating and responding to cybersecurity incidents.
Responsibilities include:
Investigating suspected security breaches.
Determining the origin and nature of security incidents.
Establishing the scope and potential impact of an incident.
Collecting and analyzing relevant technical evidence.
Supporting containment and eradication activities.
Coordinating incident remediation with relevant technical teams.
Developing and improving incident response procedures.
Documenting incidents and actions taken.
Recommending measures to prevent recurrence.
Participating in post-incident reviews.
The Senior SOC Analyst should be able to remain calm and methodical when responding to high-impact cybersecurity events.
6. Vulnerability and Risk Management
Proactive risk identification is an important component of the position.
The successful candidate will assist with:
Vulnerability assessment activities.
Identification of weaknesses within IT systems.
Risk analysis and prioritization.
Assessment of potential security exposures.
Recommendations for mitigating identified vulnerabilities.
Tracking remediation activities.
Working with technical teams to address security weaknesses.
Reviewing security controls to determine their effectiveness.
The objective is to identify and address vulnerabilities before they can be exploited by malicious actors7. Security Tools and Technology Management
The Senior SOC Analyst will work extensively with enterprise cybersecurity technologies and monitoring platforms.
Relevant technologies include:
Security Information and Event Management (SIEM)
Monitor SIEM alerts.
Analyze events collected from multiple systems.
Develop or refine detection logic where required.
Correlate events to identify suspicious patterns.
Support optimization of SIEM monitoring capabilities.
Security Orchestration, Automation and Response (SOAR)
Support administration of SOAR platforms.
Assist with automated response workflows.
Improve incident-handling efficiency through appropriate automation.
Support integration between security technologies.
Endpoint Detection and Response (EDR)
Monitor endpoint security events.
Investigate suspicious endpoint activity.
Support threat containment.
Analyze endpoint indicators of compromise.
Intrusion Detection and Prevention
Monitor IDS/IPS alerts.
Investigate network-based security events.
Identify potentially malicious network traffic.
Support improvements to network security controls.
Enterprise Antivirus
Monitor antivirus alerts.
Investigate malware detections.
Support endpoint protection activities.
Escalate persistent or serious malware incidents.
8. Security Operations Administration
The role will also include administrative responsibilities associated with the university's cybersecurity environment.
These duties include:
Maintaining accurate cybersecurity asset registers.
Keeping security documentation current.
Supporting the integration of new log sources into monitoring systems.
Assisting with the configuration of cybersecurity platforms.
Maintaining relevant operational records.
Supporting security platform administration as assigned.
Ensuring monitoring systems have appropriate visibility across critical infrastructure.
Documenting changes made to security tools and configurations.
Accurate documentation is essential for effective cybersecurity operations, audits, incident investigations, and institutional continuity.
9. Log Analysis and Security Investigation
The Senior SOC Analyst will review logs from multiple sources to identify unusual activity and possible security breaches.
Responsibilities include:
Examining system and application logs.
Reviewing network activity.
Analyzing authentication events.
Identifying abnormal user behaviour.
Detecting policy violations.
Correlating events across different platforms.
Investigating indicators of compromise.
Taking appropriate corrective action.
Escalating suspicious activity where necessary.
The candidate must be comfortable working with large volumes of technical information and identifying meaningful patterns within complex datasets.
10. Threat Intelligence and Cybersecurity Research
Cybersecurity threats evolve continuously, requiring the university to maintain awareness of emerging attack techniques.
The successful candidate will:
Research new cybersecurity threats.
Monitor emerging attack methods.
Track relevant vulnerabilities.
Review threat intelligence sources.
Analyze changing patterns in cyberattacks.
Share relevant security information with technical teams.
Recommend proactive security measures.
Keep up to date with cybersecurity technologies and industry practices.
Contribute to improving the university's threat detection capabilities.
The position requires a continuous learning mindset because attackers regularly adopt new tools, techniques, and methods.11. Information Security Governance and Compliance
The Senior SOC Analyst will contribute to the university's broader information security governance framework.
Responsibilities include:
Supporting implementation of incident response policies and procedures.
Contributing to information security compliance initiatives.
Supporting implementation of recognized security standards.
Maintaining effective General IT Controls.
Supporting security audits and assessments.
Ensuring security practices are appropriately documented.
Contributing to risk management activities.
Supporting privacy and information protection initiatives.
Helping ensure security controls are implemented consistently.
Knowledge of the regulatory and privacy environment applicable to higher education institutions will be valuable.
12. Internal Collaboration
Cybersecurity requires cooperation across the entire organization.
The successful candidate will work closely with:
IT Division teams.
Network and infrastructure specialists.
Systems administrators.
Application teams.
University schools and faculties.
Administrative departments.
Management and other institutional stakeholders.
The analyst must be able to communicate security risks clearly to both technical and non-technical audiences and work collaboratively to resolve identified issues.
13. Academic Qualifications
Applicants should meet the following educational requirements:
Bachelor's degree in Information Security, Cybersecurity, Computer Science, Information Technology, or a related discipline from a recognized university.
A Master's degree in Information Security, Cybersecurity, IT, or a related field will be an added advantage.
14. Professional Certifications
Relevant industry certifications are expected.
Candidates should possess at least one appropriate professional certification such as:
CISSP – Certified Information Systems Security Professional.
CEH – Certified Ethical Hacker.
CHFI – Computer Hacking Forensic Investigator.
Additional certifications that would strengthen an applicant's profile include:
CISM – Certified Information Security Manager.
LPT – Licensed Penetration Tester.
OSCP – Offensive Security Certified Professional.
Membership in a recognized professional cybersecurity or information technology body will also be advantageous.
15. Required Professional Experience
Applicants should have:
At least four years of full-time experience working in information security.
A minimum of two years of direct experience in a Security Operations Centre environment.
Practical experience with enterprise cybersecurity monitoring and incident response.
Experience working with security technologies and information security processes.
Experience in a university or higher education environment will be an added advantage.
16. Technical Knowledge and Competencies
The successful candidate should have advanced practical knowledge of cybersecurity technologies, including:
SIEM platforms.
SOAR technologies.
EDR solutions.
Enterprise antivirus systems.
IDS/IPS technologies.
Network security controls.
Firewalls.
Web proxy technologies.
Windows operating systems.
Linux environments.
Cloud-based infrastructure.
On-premise IT environments.
Security information systems.
Database technologies.
The candidate should also understand how different security technologies interact within an enterprise environment.
17. Security Frameworks and Standards
Knowledge of established cybersecurity and risk management frameworks is highly desirable.
Applicants should be familiar with one or more of the following:
NIST SP 800 series
ISO/IEC 27001
NIST Cybersecurity Framework (CSF)
Understanding information security and privacy principles, particularly those relevant to educational institutions, will be an important advantage.
18. Essential Soft Skills
Technical knowledge must be supported by strong professional and interpersonal capabilities.
The ideal candidate should demonstrate:
Excellent analytical skills.
Strong investigative and problem-solving ability.
Excellent written communication.
Strong verbal communication.
Attention to detail.
Ability to work independently.
Ability to collaborate effectively within a team.
Strong organizational skills.
Effective time management.
Ability to manage competing priorities.
Professional integrity.
High ethical standards.
Commitment to continuous learning.
Ability to communicate complex technical matters clearly.
19. Key Personal Attributes
The successful candidate should be:
Analytical: Able to interpret complex technical information and identify meaningful security patterns.
Proactive: Capable of identifying potential threats before they become major incidents.
Detail-oriented: Able to detect subtle indicators of compromise.
Reliable: Consistently follows security procedures and escalation requirements.
Collaborative: Works effectively with technical teams and other university departments.
Adaptable: Able to respond to rapidly changing cybersecurity threats.
Integrity-driven: Handles sensitive information responsibly and maintains strict confidentiality.
Self-motivated: Can work independently while knowing when escalation is necessary.
Organized: Capable of managing several security investigations and priorities simultaneously.
20. Performance Expectations
Success in this role will be demonstrated through the ability to:
Detect and respond to cybersecurity threats promptly.
Reduce the impact of security incidents.
Maintain effective monitoring across critical systems.
Improve the performance of security monitoring tools.
Support timely vulnerability remediation.
Maintain accurate cybersecurity documentation and asset inventories.
Strengthen incident response capabilities.
Contribute to compliance with applicable security frameworks.
Provide clear and actionable security analysis.
Maintain a strong security posture across the university's digital environment.
The Senior SOC Analyst will therefore serve as an important part of USIU-Africa's cybersecurity defence capability, helping protect institutional systems, data, users, and digital services against an increasingly complex threat landscape.
Application Procedure
Interested candidates should submit their applications by Friday, 8 August 2026. Each application should include the following:
A detailed cover letter.
An up-to-date curriculum vitae (CV).
Certified copies of relevant academic certificates and academic transcripts.
The names, postal addresses, telephone numbers, and email addresses of three (3) referees.
Two of the referees should be the applicant’s current and previous employers.
Details of the applicant’s current salary and benefits package.
The applicant’s current telephone and email contact information.
Completed applications should be addressed to:
Director, Human Resource
United States International University–Africa
P.O. Box 14634–00800
Nairobi, Kenya
Email: jobs-ict@usiu.ac.ke