
Real job — pulled straight from Ecobank’s careers page · Verified October 8, 2026 · No reposts.
Job description
Ecobank is hiring a Group Officer Cyber Security — a full-time, based in Togo role. Apply directly on Ecobank's careers page below.
Group Officer Cyber Security
Location: Togo
Job Title: Group Officer Cyber Security
Reports to: Group Manager Technology Assurance & Cyber Security Auditor
JOB PURPOSE
The Group Officer Cyber Security supports the Group Manager Technology Assurance & Cyber Security Auditor in delivering independent assurance over the Group's cyber security posture across multiple jurisdictions. The role combines hands-on technical depth across cyber security operations, cloud security, infrastructure security, and application security with data-driven, AI-enabled assurance techniques.
The position is responsible for executing risk-based cyber audits, performing technical testing and analysis, building continuous monitoring routines, and contributing to the modernization of cyber assurance through analytics, automation, and emerging technologies. The role plays a key part in strengthening the bank's cyber resilience and governance through both traditional audit rigour and modern data-driven assurance approaches.
JOB CONTEXT
This position requires the candidate to exhibit integrity, technical curiosity, attention to detail, and a proactive mindset. The candidate should bring strong hands-on technical capability across cyber security disciplines, the ability to translate technical findings into clear assurance insights, and a willingness to apply data analytics and automation to enhance audit effectiveness.
The person will support the strengthening of the bank's governance, risk management, and controls environment through technical cyber audit work combined with modern data-driven assurance solutions.
KEY RESPONSIBILITIES
1. Cyber Security Audit Execution
• Execute risk-based cyber security audits covering networks, infrastructure, cloud platforms, business applications, and security controls.
• Perform technical reviews of cyber security operations and Security Operations Centre (SOC) processes, including detection engineering, incident response readiness, security monitoring effectiveness, and threat intelligence operations.
• Conduct cloud security audits across AWS, Azure, and Google Cloud Platform environments, including assurance over cloud workloads, configurations, IAM, encryption, and shared-responsibility boundaries.
• Perform infrastructure security reviews, including network architecture, endpoint controls, privileged access management, system hardening, and patch management.
• Conduct application security audits, including secure SDLC reviews, API security assessments, container and Kubernetes security, and DevSecOps practices.
• Carry out vulnerability assessments, review penetration testing outputs, and evaluate the adequacy and timeliness of remediation activities.
• Document audit procedures, evidence, findings, and recommendations in line with audit methodology and quality standards.
• Communicate technical findings clearly to auditees, the Group Manager, and senior stakeholders, ensuring issues are well-articulated and actionable.
2. Cyber Risk Management & Compliance
• Assess cyber security controls against applicable frameworks, standards, and regulations, including ISO 27001, NIST Cybersecurity Framework, CIS Controls, COBIT, PCI DSS, and SWIFT Customer Security Controls Framework (CSCF).
• Evaluate compliance with internal cyber security policies, standards, and procedures, identifying gaps and areas for improvement.
• Review the effectiveness of incident response, business continuity, and disaster recovery arrangements relating to cyber threats and critical technology assets.
• Assess third-party cyber risk, including the adequacy of vendor security assurance arrangements, concentration risks, and cloud-service-provider dependencies.
• Support cyber risk reporting and tracking of remediation activities, ensuring timely closure of audit findings.
• Stay current on emerging cyber threats, vulnerabilities, attack techniques, and the evolving threat landscape relevant to the banking and financial services sector.
3. Data-Driven, AI-Enabled Cyber Assurance
• Build and maintain data analytics routines and automated monitoring tests for cyber security controls, leveraging SQL, Python, Power BI, Power Automate, and Audit Command Language (ACL).
• Apply AI-enabled assurance techniques — including predictive analytics, anomaly detection, and AI-assisted auditing — to identify cyber risk indicators, control weaknesses, and emerging threats across the Group.
• Develop continuous auditing routines for cyber security controls across critical platforms, business applications, and digital channels.
• Analyse large volumes of security log data, SIEM/SOAR outputs, vulnerability scan data, and threat intelligence feeds to identify patterns, anomalies, and audit-worthy events.
• Contribute to the development of reusable analytics, scripts, dashboards, and automated tests that standardise and scale cyber audit procedures.
• Apply data science and machine learning techniques, where relevant, to support intelligent risk monitoring and proactive cyber assurance.
• Partner with the Continuous Data-Driven Assurance & Innovation pillar to embed data-driven approaches and analytics tooling across cyber audit activities.
4. Stakeholder Engagement & Investigation Support
• Engage with cyber security, IT, and business stakeholders to understand systems, controls, and emerging initiatives across the Group.
• Support ad-hoc investigations into suspected cyber incidents, fraud, misconduct, or irregularities through technical analysis, digital evidence review, and data-driven investigative techniques.
• Collaborate with the broader GIAMS team — including Technology Assurance, Continuous Data-Driven Assurance & Innovation, and Forensic & Investigation — on cross-cutting matters.
• Support follow-up reviews and verification of remediation effectiveness for cyber audit findings.
• Contribute to the continuous improvement of the pillar's methodology, tools, and ways of working.
• Stay abreast of evolving cyber audit techniques, tools, and platforms; share learning and emerging practice across the team.
QUALIFICATION AND EXPERIENCE
Background/Experience
Experience:
• 5 to 8 years of experience in cyber security, IT security audit, or technology risk, with strong hands-on technical exposure.
• Demonstrable experience across cyber security operations, cloud security, infrastructure security, and application security.
• Experience executing risk-based cyber audits and security control reviews, preferably within the banking or financial services sector.
• Experience applying data analytics, automation, and modern audit techniques to cyber security assurance is an added advantage.
Knowledge and Skills:
Technical Expertise:
• Strong hands-on knowledge of cyber security operations, SOC processes, SIEM/SOAR platforms, security monitoring, detection engineering, and incident response.
• Working knowledge of cloud security across AWS, Azure, and Google Cloud Platform — including IAM, network controls, workload protection, encryption, and shared-responsibility models.
• Solid understanding of infrastructure security — network architecture, endpoint security, privileged access management, system hardening, and patch management.
• Familiarity with application security — secure SDLC, API security, OWASP Top 10, container and Kubernetes security, and DevSecOps practices.
• Understanding of cybersecurity frameworks, standards, and regulations (e.g., ISO 27001, NIST Cybersecurity Framework, CIS Controls, COBIT, PCI DSS, and SWIFT Customer Security Controls Framework (CSCF)).
• Hands-on experience with data analytics and automation tools, including SQL, Python, Power BI, Power Automate, and ACL.
• Working knowledge of AI/ML concepts and their application to cyber security and audit analytics.
• Familiarity with vulnerability assessment tools, penetration testing concepts, and threat intelligence platforms.
• Awareness of emerging technology risks, including AI/ML governance and security considerations, and identity-related controls.
Risk Management and Audit:
• Good understanding of Risk-Based Audit principles and the ability to comply with IIA (Institute of Internal Auditors) standards.
• Ability to apply risk and control concepts in the context of cyber security and technology.
• Working knowledge of IT governance, risk, and compliance best practices, and experience supporting the assessment of cyber security risks.
Analytical and Problem-Solving Skills:
• Strong analytical mindset with technical curiosity and the ability to dig into complex systems and datasets.
• Detail-oriented, with the ability to identify control weaknesses, anomalies, and indicators of compromise.
• Problem-solving orientation, with the ability to translate technical issues into clear audit narratives and actionable recommendations.
Communication and Interpersonal Skills:
• Good communication skills, both written and verbal, with the ability to explain complex technical and cyber security issues to non-technical stakeholders.
• Strong team player, able to work collaboratively with auditors, business stakeholders, and technical specialists across the Group.
• Demonstrates a positive, can-do attitude with a commitment to continuous learning and professional development.
Other Requirements:
• High degree of integrity, professionalism, and ethical standards, with a commitment to maintaining confidentiality and handling sensitive information with discretion.
• Demonstrates a strong understanding of the evolving cyber threat landscape and keeps up-to-date with emerging cyber security threats and best practices.
• Willingness to maintain technical depth through ongoing learning, hands-on practice, and relevant certifications.
Qualifications
• Bachelor's Degree in Computer Science, Engineering, Information Systems, Cyber Security, or a related field. A Master's degree is an added advantage.
• Professional certifications such as CISA, CISSP, CEH, OSCP, AWS/Azure/GCP Security certifications, or equivalent (one or more expected; additional certifications are an advantage).
PERSONAL ATTRIBUTES
• Ability to work effectively under pressure and meet deadlines.
• Strong technical curiosity and hands-on mindset.
• Culturally sensitive and able to work effectively in a diverse, pan-African environment.
• Good written and oral communication skills.
• Excellent time management and organizational skills.
• Good interpersonal skills.
• Strong analytical and result-oriented skills, with attention to detail and documentation discipline.
About Us
Get Group Officer Cyber Security jobs like this→
New roles from thousands of companies land hourly, straight from their careers pages. Get the freshest matches by email so you never miss one.
Email me new jobsSimilar jobs
Frequently asked questions
What skills are required for Group Officer Cyber Security at Ecobank?
The required skills for Group Officer Cyber Security at Ecobank include: Cybersecurity, ISO 27001, PCI DSS, SQL, Python, Power BI, Power Automate, AI, Machine Learning, AWS, Azure, GCP, IAM, SIEM, DevSecOps, Kubernetes, CISA, CISSP.
What is the seniority level for Group Officer Cyber Security at Ecobank?
Group Officer Cyber Security at Ecobank is a Mid Level / Senior level position.
How do I apply for Group Officer Cyber Security at Ecobank?
You can view the full description and apply for Group Officer Cyber Security at Ecobank on EchoJobs: https://echojobs.io/job/ecobank-group-officer-cyber-security-fstus.


