Technology Risk and Cybersecurity Manager

Company Details

Rating: No ratings yet log in to rate this company
Industry: Banking
Description: CIC Insurance Group Limited, commonly referred to as CIC Group, is an insurance and investment group that operates mainly in Kenya, Uganda, South Sudan and Malawi

Job Details

Job Type: Full Time
Workplace Type: On-site
Qualification: Diploma
Job Experience: Mandatory
Job Location: Nairobi County, Kenya
Closing Date: Undisclosed
Salary: Estimated: KES 45,000 - KES 300,000 / month
Other Pay: Benefits
Job Category: Telecommunications

Job Description

Role Overview

This role is embedded in the Group Risk and Compliance function and exists to make sure technology risk carries the same weight as financial, operational, and regulatory risk in the organisation’s enterprise risk agenda. You will spend your time bridging two worlds: translating complex technical threats, system vulnerabilities, and control weaknesses into risk language that executives, regulators, and board members can understand and act on, while also giving your team clear direction on how to identify, assess, and monitor ICT and cyber risks across the group’s technology estate. The broader purpose is to embed security and privacy thinking into projects, vendors, and infrastructure from the start, rather than treating it as an afterthought, so that every subsidiary consistently operates within the group’s agreed risk appetite.

Key Responsibilities

  • Work alongside the Group Director – Risk and Compliance to integrate cybersecurity and ICT risk into the enterprise risk management framework, making sure technology risks appear in the organisational risk register, are measured against the agreed risk appetite, and are presented to governance forums in terms the business can understand.
  • Manage and develop a team of risk specialists covering ICT, cyber, project, and innovation risk; set objectives, coordinate their workplans, conduct performance reviews, and ensure consistent quality of delivery across all four disciplines.
  • Drive the implementation of the group’s cybersecurity strategy, including monitoring quantified risk appetite thresholds and preparing quarterly and annual risk reports for management, regulators, and the board.
  • Lead the group’s response to material cyber incidents, coordinating both the technical containment and the governance, communication, and escalation actions required under the cyber incident response plan.
  • Oversee the group’s red and blue teaming programme by commissioning annual adversarial simulation exercises, directing defensive monitoring activities, reviewing findings, and tracking remediation efforts to improve the overall security posture.
  • Provide security and privacy guidance during the design of IT architectures, system implementations, and digital transformation initiatives, ensuring security-by-design and privacy-by-design are applied from project initiation through to delivery.
  • Operate the third-party risk management framework for ICT vendors by assessing, classifying, and monitoring suppliers according to their risk tier, including watching for supply chain threats and third-party data breaches and ensuring escalations happen on time.
  • Support digital forensic investigations, maintain proper chain of custody, and produce written findings suitable for management, board, regulatory submission, or legal proceedings.

Requirements & Qualifications

  • Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a closely related field. A Master’s degree in Information Security, Risk Management, or a similar discipline is an added advantage.
  • Mandatory certification: at least one of CISSP, CISM, CISA, or an equivalent senior-level cybersecurity certification.
  • Desirable certifications: CGEIT, CRISC, CEH, cloud security credentials (such as AWS Security Specialty or Microsoft SC-100/AZ-500), ISO 27001 Lead Implementer or Lead Auditor, or a recognised risk management qualification such as IRM or CRMA.
  • A minimum of eight years of progressive experience in cybersecurity or IT risk, with at least four years in a management or team leadership role supervising staff across multiple security or risk disciplines.
  • Strong practical knowledge of ISO 27001, the NIST Cybersecurity Framework, and enterprise risk frameworks such as COSO ERM or ISO 31000, ideally applied in a compliance-driven environment.
  • Prior experience in financial services, insurance, or another heavily regulated industry is strongly preferred.
700 open positions on Semasocial right now · 9928 open positions in Nairobi County, Kenya · 38 posted in the last 7 days
Contact Information
CV Job Description Matcher See how well your CV matches this job and get tips to improve your chances AI Tool

This tool helps you see how closely your CV matches a job description. It also gives you simple suggestions on what to improve so you have a better chance of getting shortlisted.

Similar Jobs

CIC Insurance Nairobi County, Kenya
View Job Aug 30, 2026
CIC Insurance Nairobi County, Kenya
View Job Aug 30, 2026
View Job Aug 29, 2026
View Job Aug 29, 2026
Beware of Fraudsters!
Never pay anyone for job applications, interview tests, or job interviews. A genuine employer will never ask you for payment under any circumstances.
Disclaimer & TOS: We do not guarantee the authenticity of every single job posting and are not responsible for any fraudulent activity or misrepresentation by third parties. We are not involved in any stage of the interview or recruitment process and do not charge any fees from job seekers. For further details, please read the rest of the Terms of Service.