Skip to main content

Security operations analyst

Detect an incident, qualify it and respond to it by a written procedure.

Block code
CYBER-SOC
The format

Three months, two hours a day.

  • Certificate programme · 128 h
  • Two hours a day
  • 250,000 F — the same fee for all sixty
  • All in the same format, at the same fee.
The qualification

A CQP under MINEFOP accreditation.

  • Leads to the CQP — Certificat de Qualification Professionnelle, which the ministry used to call the AQP.
  • Awarded under MINEFOP accreditation.
  • The full programme for the same profession remains open to anyone aiming for the complete qualification.
Sessions

A new session opens every quarter.

Next intake: Monday 5 October, with enrolment open until 2 October. The following one starts on 4 January 2027.

  • First-quarter intake — enrolment closes on 2 October5 Oct.
  • Second-quarter intake — 20274 Jan.
Objectives

What you will be able to do.

  • Choose the sources to log and discard those that cost without adding anything

  • Centralise, timestamp, normalise and enrich events

  • Place an attack technique within the MITRE ATT&CK framework

  • Write, test and tune a detection rule

  • Triage an alert by severity, scope and urgency

  • Contain, eradicate and restore service while preserving evidence

  • Use an AI assistant for triage without delegating the decision to it

Programme

Four modules.

  1. Module 0132 h

    Logs, collection and monitoring

  2. Module 0232 h

    Detection: rules, signals and false positives

  3. Module 0332 h

    Qualifying and handling an incident

  4. Module 0432 h

    AI in detection: use and distrust

Who it is for

Who it is aimed at.

  • Learners who have mastered systems and networking fundamentals — in practice those who have completed Endpoint and network security technician or Network administrator. Ease with the command line is required.
Afterwards

Where it leads.

  • Level 1 security analyst, security operations centre operator, detection and response technician. Natural next step towards investigation (Digital forensics and crisis management).
Method

How it works.

  • Systematic alternation between short theory sessions and practical work, with most of the time spent on practice

  • Progression from simple to complex: each module builds on what was learnt in the previous one

  • Realistic role-plays drawn from Cameroonian business cases

  • Considered use of generative AI as a working tool, in line with the common core

  • Regular formative assessments and a final integrative project drawing on all four modules

Assessment

How you are assessed.

  • Formative assessment at the end of each module (graded role-play and practical exercises)

  • Practical work assessed against competency sheets

  • Final integrative project, presented and defended before the trainer

  • One graded assignment per module in the online course space

Tools

What you work with.

  • Wazuh or Elastic — collection, normalisation and detection

  • Sysmon and Windows logs, systemd and auditd logs on Linux

  • MITRE ATT&CK framework and Atomic Red Team for detection testing

  • An analysis sandbox and harmless samples

  • An AI assistant with controlled instructions for alert triage

Join the next session

Ready to get started?

Sessions open every quarter. Apply now or request the detailed brochure — our advisers will get back to you.