P. Get in touch

Security Operations Engineer · Accra, Ghana

Making threats
visible.

I am Prosper, a security operations engineer who builds SIEM platforms, writes detections and leads incident investigations for organisations where a breach is felt far beyond the building: a national legislature, aviation infrastructure, a national health insurer and major banks.

01 / About

A SOC is only as good as what it can see.

I am a Level 3 cybersecurity analyst at CyberHawk Limited, a managed security service provider in Accra. My work runs from designing SIEM architectures and onboarding log sources, through writing and tuning detections, to leading investigations and training the analysts who will run a new SOC.

I care most about the failures that raise no alarm: a log source that quietly stops sending, a parser that drops fields, a rule nobody has tested in a year. So I build ways to prove coverage, not just assume it. I am currently preparing for GIAC GCTI and the CISSP.

02 / Expertise

Where I add the most value.

01

SIEM Engineering

Architecture, collector deployment and large-scale log onboarding in IBM QRadar and Graylog, integrated with EDR, NAC, PAM and firewall analytics.

02

Detection Engineering

Correlation rules mapped to MITRE ATT&CK, tuned to cut false positives, plus dashboards that expose gaps in coverage.

03

Incident Response

Triage, forensic analysis, containment, root cause analysis and post-incident review, followed through to the controls that prevent a repeat.

04

SOC Building

Standing up new SOC teams: workflows, escalation paths, analyst training, and clear reporting to leadership.

03 / Focus areas

SIEM EngineeringThreat DetectionIncident ResponseThreat IntelligenceEndpoint SecurityNetwork Access ControlPrivileged AccessZero Trust

Tools I use: IBM QRadar (AQL, Pulse), Graylog, FortiAnalyzer, SentinelOne, ESET Protect, Fortinet firewalls, FortiNAC, Secret Server (Delinea), Active Directory, PineApp, Veriti, GoPhish, Cerebro and Jira. Growing my Linux security skills through hands-on lab work.

04 / Selected work

Projects I have led.

Aviation

Enterprise SIEM build for an international airport operator

Designed the high-level and low-level monitoring architecture and onboarded the estate into IBM QRadar, integrating EDR, network access control, privileged access management and firewall analytics into one view. Fixed endpoint protection misconfigurations that were flooding the SOC with false positives.

150+ log sources · 50+ network devices

Finance

SSL VPN breach investigation at a national bank

Led the investigation from forensic analysis through containment and post-incident review, then delivered phishing simulation and awareness training to close the human side of the attack path.

Detection

Health and coverage dashboards for every client

A suite of custom QRadar Pulse dashboards covering log source health, offense operations, authentication, reconnaissance and rogue devices, data exfiltration, and parsing quality, so coverage gaps surface before an incident exposes them.

6 dashboard types · all managed clients

Government

Threat monitoring for a national legislature

Deployed log collectors, onboarded the network into centralised monitoring, and deliver monthly threat and posture briefings to leadership.

Finance

Assessment and Zero Trust advisory for a banking network

Found a flat network during an enterprise assessment and recommended segmentation, plus a Zero Trust model for the smaller banks connected to it, whose weaker controls posed systemic risk.

SOC build

New SOC teams for a national health insurer and a bank

Led onboarding and operational training for newly built internal SOC teams, covering workflows, triage, escalation and tooling.

05 / Experience

Six years in security operations.

Feb 2024 to now

Level 3 Cybersecurity Analyst / Solutions Specialist

CyberHawk Limited (MSSP), Accra

Oct 2022 to Nov 2023

Cybersecurity National Service Personnel

CyberHawk Limited (MSSP), Accra. Offered a permanent senior analyst role on completion.

Jan 2019 to Oct 2021

Cybersecurity Consultant

B&P Cyber Intelligence Consult, Accra. SIEM and IDS deployments, incident response, awareness training.

2018 to 2022

BSc Information Technology

University of Ghana, Accra

06 / Writing

Notes from the SOC.

07 / Credentials

08 / Contact

Let us talk detection.

I am open to remote roles in security operations, detection engineering and SIEM engineering, and to conversations with other defenders. Email is the best way to reach me.

LinkedIn ↗