CIC Group Hiring IT Security Manager – Nairobi

by Adonai

IT SECURITY MANAGER

  • Full Time
  • Nairobi
  • Posted 2 weeks ago
  • Closes: January 28, 2025

PURPOSE:

Reporting to the Group Head of IT the IT Security Manager protects information systems and maintains compliance through strategic planning and hands-on implementation of security controls while addressing emerging cyber threats. The role involves collaborating with cross-functional teams to embed security-by-design principles in new initiatives and ensuring compliance with security frameworks such as ISO 27001 and NIST.

PRIMARY RESPONSIBILITIES:

  • Manage and maintain IT security infrastructure including firewalls, IDS/IPS, endpoint protection, PAM, NAC, Patch management and cloud security controls across platforms (AWS, Azure), ensuring regular testing, patching, and updates.
  • Lead and conduct technology security assessment programs including vulnerability scanning, penetration testing, risk assessments, collaborating with IT audit and risk teams for timely closure of findings from both internal and external evaluations.
  • Develop and enforce security policies and procedures, including remote work protocols, while managing internal/external audit responses and maintaining policy compliance dashboards.
  • Design and deliver comprehensive security awareness programs, including incident response training and ongoing security awareness on security threats and best practice.
  • Partner with project teams and IT managers to embed security-by-design principles in new initiatives, providing security architecture guidance and risk assessments for all major projects.
  • Monitor and analyze security trends, implementing proactive measures to protect against emerging threats while maintaining up-to-date security measures across all systems.
  • Manage the incident response lifecycle, including detection, investigation, containment, eradication, and recovery processes, ensuring proper documentation and learning from each incident.
  • Oversee business continuity and disaster recovery processes, including bi-annual DR testing and implementation of comprehensive incident response procedures to effectively address security breaches.
  • Ensure regular patching and hardening of systems to maintain system integrity and resilience, and generate status reports on infrastructure health for executive review.
  • Establish and maintain relationships with security vendors ensuring effective service delivery and value for security investments.
Key Skills, Knowledge, Experience and Behavioural Competencies
Academic and Professional RequirementsParticularsDetailSpecific Field or Qualification EducationBachelor’s Degree·         Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field. Professional Qualification·         Relevant certifications such as CISA, CISM, CISP, CEH or similar.·         Additional certifications are a plus, including cloud security certifications (AWS, Azure, GCP).Experience Required:  DescriptionRequired years of experienceRelevant experienceMinimum of 7Leadership ExperienceMinimum of 2Skills and Competencies:Total Experience: Minimum of five (7) years of hands-on IT security experience.Leadership Experience: At least two (2) years of team leadership or project experience.Industry Experience: Experience in financial services and insurance is preferred.Vulnerability Management: Proven experience in conducting penetration tests vulnerability assessments and leading closure of findings through collaborating with various stakeholders (Internal & External IT Auditors, IT Risk, External Pentesters etc)Frameworks & Standards: Strong knowledge of security frameworks and standards (e.g., ISO 27001, NIST).Skilled in IT risk management, cyber threat mitigation, and hands-on problem-solving with strong analytical abilities.Proven leadership and communication skills in cross functional teams and conveying complex security concepts to diverse audiences. Strategic, adaptable, and budget-conscious decision-maker, aligning security initiatives with business objectives and managing vendor relations effectively.
CIC Insurance Values
CIC insurance Group is committed to providing excellent service, spur further growth and employees are required to align their behaviour to the following core values as critical to driving their performance;·         Integrity- Be fair and transparent·         Dynamism- Be passionate and innovative·         Performance- Be efficient and results driven·         Co-operation- Live the Co-operative spirit

If you have the aforementioned professional and academic qualifications and you are ready to execute the above mandate, strictly apply through: https://careers.cicinsurancegroup.com/ clearly indicating the position being applied for.

The application should reach us by close of business on 28th January, 2025. Please note only short-listed candidates will be contacted. If you do not hear from us by 28th February, 2025 consider your application unsuccessful.

N/B: This job advert is open to both internal and external candidates.

Apply

You may also like

We DO NOT support recruitment agents/entities that demand money or any other favors from applicants to expedite hiring process. We shall not be liable to any money, favors and valuables lost during the process. Incase you see it on this site, report it to us via our Facebook page Pata Kazi so as to take the necessary action. Report the matter to the police asap.

 

More from Us: OYK-CVs | Internshub

 

© 2025 All Rights Reserved. Web Design by Clinet Online

Adblock Detected

Please support us by disabling your AdBlocker extension from your browsers for our website.