Corporate9 days left

Analyst - Cyber Threat Intelligence

Roodepoort, GautengPermanentSecurityCloses 9 August 2026

About this role

Mission 

To strengthen MTN Group's cyber defence capability through the collection, analysis, production and dissemination of actionable cyber threat intelligence, proactive threat hunting, and intelligence-led support to incident and vulnerability management. The role contributes to the protection of MTN's digital assets by identifying emerging threats, enhancing detection capabilities, and leveraging AI-driven automation to improve threat intelligence reporting and hunting effectiveness across the MTN operating environment.

Context

MTN's Ambition 2030 strategy is focused on leading digital solutions for Africa's progress by accelerating platform growth, advancing digital and financial inclusion, enabling sustainable connectivity, and building a resilient, future-fit organisation. As MTN continues its evolution into a digital platform business, Information Security plays a critical role in safeguarding customer trust, protecting digital services, enabling innovation, and ensuring operational resilience across MTN's diverse markets.

 

The Group Information Security function must therefore ensure the successful delivery of its mandate in the context of:

  • Supporting MTN's Ambition 2030 vision to be the leading platform business and digital solutions provider for Africa.

  • Accelerating digital transformation, cloud adoption, AI enablement, fintech expansion, digital services, and platform ecosystems across the Group.

  • Protecting MTN's rapidly expanding digital assets, customer data, financial platforms, and critical technology infrastructure.

  • Managing the geographic complexity of MTN's footprint across Africa and the Middle East, encompassing varying regulatory, political and cyber risk environments.

  • Maintaining stakeholder confidence by meeting the expectations of customers, shareholders, regulators, partners, and communities.

  • Enabling sustainable growth through secure digital innovation and the adoption of emerging technologies, including Artificial Intelligence.

  • Achieving operational excellence through standardised security processes, automation, intelligence-led decision-making, and continuous improvement.

  • Addressing an increasingly sophisticated and rapidly evolving cyber threat landscape targeting telecommunications operators, financial services, digital platforms, and critical infrastructure.

  • Ensuring business continuity, cyber resilience, and operational stability across a highly interconnected technology ecosystem.

  • Delivering integrated cyber defence capabilities across network, cloud, IT, digital, financial services, and enterprise environments.

  • Strengthening proactive threat intelligence, threat hunting, detection, response, and cyber risk management capabilities.

  • Supporting regulatory compliance and data protection requirements across multiple jurisdictions.

  • Enhancing MTN's reputation as a trusted, secure, and responsible digital operator.

  • Leveraging automation, machine learning, and AI-driven security capabilities to improve cyber defence effectiveness and operational efficiency.

  • Embedding a culture of security awareness, accountability, and resilience across MTN Group and its Operating Companies.

 

In this environment, the Information Security function is required to provide timely, actionable, and business-relevant intelligence that enables MTN to anticipate emerging threats, proactively manage cyber risks, and support the achievement of Ambition 2030 objectives.

 

Values

We at MTN are a purpose and value-led organization. At MTN, we believe that understanding our people’s needs and aspirations is key to creating experiences that delight you at work, everyday. We are committed to fostering an environment where every member of our Y’ello Family is heard, understood and empowered to live an inspired life. 

Our values keep us grounded and moving in the right direction. Most importantly, they keep us honest. It is not something we claim to be. It is in our DNA.

As an organisation, we consider it our mission to create an exciting and rewarding place to work, where our people can be themselves, thrive in positivity and ignite their full potential. A workplace that boosts creativity and innovation, improves productivity, and ultimately drives meaningful results. A workplace that is built on relationships and achieving a purpose that is bigger than us. 

Our commitments go beyond an organisational promise. It is in our leadership and managerial ethos to meaningfully partner with our employees, customers and stakeholders with a vision to realise our shared goals.

 

Live Y’ello

  • Lead with Care

  • Can-do with Integrity

  • Collaborate with Agility

  • Serve with Respect

  • Act with Inclusion

Requirements

Qualifications A computer-related degree or diploma (Computer Science, Information Technology, Cybersecurity or a related field).   Preferred SANS GIAC Cyber Threat Intelligence (GCTI/FOR578) Microsoft SC-200 CompTIA CySA+ MITRE ATT&CK Defender Certifications Other Threat Intelligence or Threat Hunting Certifications Security exposure (CEH, eJPT, PNPT, PenTest+)   Experience Minimum 2–3 years' experience in a dedicated threat intelligence role. Sound understanding of cyber defense fundamentals, including incident management, vulnerability management and threat intelligence, and the value these bring to an organization. Demonstrated understanding of how threat intelligence reporting works and the ability to perform basic threat hunting. Some software development / scripting background, with the proven ability to build — or quickly learn to build — AI agents for automation. Practical understanding of Buffer overflows, Open ports, Offensive testing concepts   Technical Skills & Tools Endpoint: Microsoft Defender for Endpoint (MDE) SIEM: Microsoft Sentinel EDR / XDR: SentinelOne Working knowledge of threat intelligence frameworks such as MITRE ATT&CK, the Diamond Model, the Cyber Kill Chain and STIX/TAXII.   Preferred / Advantageous SANS GIAC Cyber Threat Intelligence (GCTI / FOR578), or an equivalent threat intelligence or threat hunting certification. Additional security certifications relevant to threat hunting and detection (e.g. Microsoft SC-200, CompTIA CySA+, MITRE ATT&CK Defender). A working understanding of modern AI principles — including large language models (LLMs), agentic AI and the Model Context Protocol (MCP) / MCP servers — and how they can be applied to automate threat hunting and threat intelligence reporting. Hands-on experience building AI agents or automation pipelines for threat intelligence and threat hunting. Experience within the telecommunications, ICT or other large, complex enterprise environments.   Competencies: Strong analytical thinking and attention to detail. Excellent written and verbal communication, with the ability to simplify and tailor technical content for diverse audiences. A risk-based mindset and sound judgement. Self-driven, curious and a fast learner who keeps pace with emerging threats and technologies, including AI. Collaborative team player able to work across departments and operating companies.

Duties

Key Performance Areas Threat Intelligence Collection, Analysis and Production Collect and analyse cyber threat intelligence relevant to MTN and the telecommunications sector. Monitor threat actors, campaigns, techniques, tactics and procedures (TTPs). Identify and assess indicators of compromise (IOCs). Contextualise threat intelligence to MTN's environment and risk profile. Produce actionable intelligence products that support informed decision-making. Demonstrate the business value and operational impact of threat intelligence.   Threat Hunting and Detection Engineering Conduct proactive threat hunting across MTN's digital estate. Develop and optimise hunting queries and detection logic. Analyse telemetry from security platforms. Identify visibility and detection gaps. Recommend and implement enhancements to monitoring coverage. Continuously improve threat detection effectiveness.   Intelligence Reporting and Stakeholder Engagement Produce intelligence reports for technical and business audiences. Communicate emerging threats and risks to relevant stakeholders. Translate complex technical findings into business-relevant insights. Disseminate intelligence products across MTN Group and OpCos. Tailor intelligence outputs according to stakeholder requirements.   AI-Driven Security Automation Support MTN's AI journey by implementing agentic AI capabilities. Develop and maintain AI-enabled threat hunting and reporting solutions. Automate repetitive threat intelligence activities. Enhance efficiency through scripting and workflow automation. Identify opportunities for AI adoption within Cyber Defence operations.   Incident and Vulnerability Management Support Provide intelligence support during cyber security incidents. Support vulnerability prioritisation through threat intelligence analysis. Assess exploitability and business impact of vulnerabilities. Enable risk-based remediation prioritisation. Collaborate with incident response and vulnerability management teams.   Cyber Risk Assessment and Advisory Evaluate cyber threats from a business risk perspective. Communicate cyber risks to relevant stakeholders. Provide recommendations to support risk-based decision making. Contribute to MTN's overall security posture and governance.