Role Overview
This is a dual-mandate leadership role: you hold both the enterprise systems portfolio and the information security programme for a remote-first, globally distributed organisation that operates across more than seven countries. Day to day you set the multi-year roadmap for the organisation's core platforms, guide a compact team of specialists and external partners through delivery, and act as the senior technical advisor the executive team turns to when a decision carries security, privacy, or systems consequences. The work matters because field and regional colleagues can only deliver on the organisation's social impact mission if the underlying systems and controls are trustworthy, adopted, and reliably available wherever the work happens.
Key Responsibilities
- Set the enterprise systems direction. Own the multi-year strategy and prioritised roadmap for a distributed organisation's core platforms, and translate organisational goals into the sequence of investments and initiatives that follow from it.
- Run major systems delivery end to end. Lead requirements definition, platform evaluation, selection, and rollout for systems such as CRM and ERP; make the architecture, integration, and master data modelling decisions that keep the estate coherent rather than fragmented.
- Own vendor and budget accountability. Select, contract, and manage implementation and support partners — including scope, commercial terms, and delivery performance — and lead annual budgeting and financial planning for organisational systems, making the trade-offs a nonprofit funding model requires.
- Drive adoption and operational reliability. Champion change management across regions and functions so that systems investments actually shift behaviour, reduce shadow IT and duplicated tooling, and keep systems and support functions dependable across time zones.
- Define and govern the security programme. Own the information security strategy in line with recognised frameworks, lead implementation of security and privacy controls as regulation, client obligations, and risk demand, coordinate the Information Security Steering Committee, and contribute to enterprise risk management.
- Lead risk, assurance, and response. Run periodic risk assessments and ongoing mitigation tracking, own incident response planning and coordination when incidents occur, and commission penetration tests, vulnerability assessments, and audits while owning the resulting remediation. Support Legal, Compliance, and Operations when digital evidence bears on policy violations.
- Own data protection, AI governance, and policy. Maintain compliance with GDPR and the national data protection regimes in the countries where the organisation operates — data mapping, retention, subject rights, and impact assessments — define how AI may be used on project and organisational data, serve as the senior contact for funder, client, and government due diligence, and keep the security and data protection policy set practical enough that colleagues consult it.
- Lead the team and partner with leadership. Manage, develop, and grow full-time technology staff and fractional resources, including hiring and performance management, build depth so critical knowledge never rests with one person, and work with functional and regional leaders on requirements, prioritisation, and the systems implications of organisational strategy.
Requirements & Qualifications
- 8+ years in technology roles, including at least 5 years of Information Security or Enterprise IT leadership experience with people management responsibility.
- Demonstrated ownership of an information security programme at organisational scale — strategy, control framework, governance forum, and incident response — rather than security operations alone.
- Proven track record leading the selection and implementation of major enterprise systems such as ERP or CRM, including implementation partner management and budget ownership.
- Hands-on depth across enterprise security controls — endpoint protection, network security, vulnerability management — sufficient to make architecture decisions and credibly evaluate your team's work.
- Strong command of identity and access management in enterprise environments, including SSO, MFA, LDAP, and federation protocols such as SAML.
- Experience with control configuration and security architecture in common cloud environments.
- Working knowledge of GDPR and of national data protection regimes in Africa or Asia, plus familiarity with security frameworks such as NIST CSF, NIST SP 800-171, or ISO/IEC 27001.
- Experience administering enterprise systems for a globally distributed workforce, including workspace collaboration and human capital management platforms.
- Experience with enterprise systems architecture and data modelling.
- Information security leadership certification preferred — CISM, CISSP, CISA, or equivalent.
- Excellent collaboration, interpersonal, communication, and facilitation skills, with the ability to present to and influence audiences of varying technical fluency, including senior leadership.
- Strong internal and external stakeholder management, including with funders, government partners, and vendors.
- Experience managing change in a fast-moving, remote-first environment.
- Detail- and execution-oriented: able to move a task from high-level strategic idea to rapid execution with substantial autonomy and conscientiousness.
- Demonstrated self-starter and leader, comfortable with ambiguity, dynamic environments, and shifting work streams.
- Able to handle sensitive information, data, and issues with mature and discreet professionalism, and to work effectively with international, cross-cultural, and diverse teams across time zones.
What We Offer / Why Join
- Direct influence at the top: you report to and advise the executive team, and you are the senior technical voice shaping how the organisation governs its systems, security, and data.
- A small, capable team of security and systems specialists, supported by fractional expertise and external implementation partners — real scope with room to build the function your way.
- Work that connects technology to social impact, supporting colleagues who use evidence to improve global development programmes.
- A multicultural, multi-continental and remote-first environment, with the autonomy and conscientiousness-driven culture that distribution requires.
- Genuine ownership of strategy, budget, and vendor relationships, with the chance to build depth and redundancy into the team so knowledge and capability endure.
867 open positions on Semasocial right now
· 11674 open positions in Nairobi County, Kenya
· 25 posted in the last 7 days
Contact Information