Job Details
Job Type:
Full Time
Workplace Type:
On-site
Qualification:
Diploma
Job Experience:
Mandatory
Job Location:
Nairobi County, Kenya
Closing Date:
Undisclosed
Salary:
Estimated: KES 45,000 - KES 300,000 / month
Other Pay:
Benefits
Role Overview
This role is embedded in the Group Risk and Compliance function and exists to make sure technology risk carries the same weight as financial, operational, and regulatory risk in the organisation’s enterprise risk agenda. You will spend your time bridging two worlds: translating complex technical threats, system vulnerabilities, and control weaknesses into risk language that executives, regulators, and board members can understand and act on, while also giving your team clear direction on how to identify, assess, and monitor ICT and cyber risks across the group’s technology estate. The broader purpose is to embed security and privacy thinking into projects, vendors, and infrastructure from the start, rather than treating it as an afterthought, so that every subsidiary consistently operates within the group’s agreed risk appetite.
Key Responsibilities
- Work alongside the Group Director – Risk and Compliance to integrate cybersecurity and ICT risk into the enterprise risk management framework, making sure technology risks appear in the organisational risk register, are measured against the agreed risk appetite, and are presented to governance forums in terms the business can understand.
- Manage and develop a team of risk specialists covering ICT, cyber, project, and innovation risk; set objectives, coordinate their workplans, conduct performance reviews, and ensure consistent quality of delivery across all four disciplines.
- Drive the implementation of the group’s cybersecurity strategy, including monitoring quantified risk appetite thresholds and preparing quarterly and annual risk reports for management, regulators, and the board.
- Lead the group’s response to material cyber incidents, coordinating both the technical containment and the governance, communication, and escalation actions required under the cyber incident response plan.
- Oversee the group’s red and blue teaming programme by commissioning annual adversarial simulation exercises, directing defensive monitoring activities, reviewing findings, and tracking remediation efforts to improve the overall security posture.
- Provide security and privacy guidance during the design of IT architectures, system implementations, and digital transformation initiatives, ensuring security-by-design and privacy-by-design are applied from project initiation through to delivery.
- Operate the third-party risk management framework for ICT vendors by assessing, classifying, and monitoring suppliers according to their risk tier, including watching for supply chain threats and third-party data breaches and ensuring escalations happen on time.
- Support digital forensic investigations, maintain proper chain of custody, and produce written findings suitable for management, board, regulatory submission, or legal proceedings.
Requirements & Qualifications
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a closely related field. A Master’s degree in Information Security, Risk Management, or a similar discipline is an added advantage.
- Mandatory certification: at least one of CISSP, CISM, CISA, or an equivalent senior-level cybersecurity certification.
- Desirable certifications: CGEIT, CRISC, CEH, cloud security credentials (such as AWS Security Specialty or Microsoft SC-100/AZ-500), ISO 27001 Lead Implementer or Lead Auditor, or a recognised risk management qualification such as IRM or CRMA.
- A minimum of eight years of progressive experience in cybersecurity or IT risk, with at least four years in a management or team leadership role supervising staff across multiple security or risk disciplines.
- Strong practical knowledge of ISO 27001, the NIST Cybersecurity Framework, and enterprise risk frameworks such as COSO ERM or ISO 31000, ideally applied in a compliance-driven environment.
- Prior experience in financial services, insurance, or another heavily regulated industry is strongly preferred.
700 open positions on Semasocial right now
· 9928 open positions in Nairobi County, Kenya
· 38 posted in the last 7 days
Contact Information