Hiring Kenya

Blogger

Related Jobs

Principal Officer; Cyber Security Governance, Risk & Controls

Nairobi, Kenya
Company Details
Industry: Information Technology and Services
Description: Safaricom is the leading provider of converged communication solutions in Kenya. In addition to providing a broad range of first-class products and services for Telephony, Broadband Internet and Financial services, Safaricom seeks to uplift the welfare of Kenyans through value-added services and support for community projects. With over 29 Million subscribers and an estimated market share of 67%, the Company has the widest modern mobile network coverage in Kenya and prides in its experienced shareholders, attractive tariffs, a nationwide network of effective dealers, high caliber staff and management enabling it to maintain its position as the region’s mobile market leader.
Job Description

Reporting to the Senior Manager – Cyber Security Governance, Risk and Control, the successful candidate will be responsible for ensuring that the organization’s cyber security risks are under explicit management control and as well coordinate strategic integration of cyber security programs within Safaricom. He or she will be part of the team that drives compliance to internal and global cyber security related policies and standards, Vodafone Cyber Health & Adaptive Risk Method (Baseline controls) and applicable Kenyan laws and regulations

Responsibilities

Key Responsibilities:

  • Lead in continual review and update of security policies, standards, and guidelines in response to the ever-changing cyber threats in coordination with Enterprise Risk Management team.
  • Drive compliance to internal and global cyber security related policies and standards, Vodafone Cyber Health & Adaptive Risk Method (Baseline controls) Program, and applicable Kenyan laws and regulations.
  • Lead in coordination of stakeholders to deliver on targets or agreed business outcomes. 
  • Lead in coordination of periodic independent assurance of critical products and services and environment team’s readiness for external audits.
  • Coordinating implementation of recommendations from independent assessments.
  • Lead Cyber security risk assessments to determine cyber risk profile and define treatment plans.
  • Recommend cyber security services improvement plans.
  • Coordinate projects handover process within the cyber security functions.
  • Continually review, implementation and improvements of the user access governance process.
  • Coordinate periodic cyber security knowledge transfer, awareness sessions and phishing simulations to staff in line with strategy.
  • Participate actively in cyber security events and trade shows, reporting and presentations.
  • Communications, reporting and presentations skills.

Qualifications

  • Bachelor’s degree in computer science/ Telecomm /electrical Eng./ Information Technology (or equivalent) from a recognized university.
  • At least one professional Information Security Qualification: CISM/CISA/CISSP/CEH/CRISC.
  • At least 4+ years proven experience in Information Security Governance and Compliance Frameworks; Cyber Security related Standards (CIS, ISO 27001, PCI-DSS, etc.).
  • Proven experience with GDPR, Kenyan Data Protection laws, CBK guidelines on Cyber Security amongst others.
  • At least 3+ years of hands-on experience in managing Cyber Security technologies and operations.
  • Experience in the use of security tools.
  • Project management skills, and proven task execution (getting things done)
  • Good communication skills and team player
  • Superior Report writing skills
  • Analytical Thinking
Education: Degree, Diploma
Employment Type: Full Time

⚠️Report job

⚠️Safety Tips: Never pay anyone for job application, test or interview. A genuine employer will never ask you for the payment in anycase.

Disclaimer & TOS: Semasocial is an exclusive platform that ought to help jobseekers. We restrict any endorsement that demand for money and strictly advice against sharing personal or bank related information. If you notice deception or fraudulent, send us an email at [email protected]. For further details, please contact us »