View all 1003 Jobs
Job vacancy ICT Security Officer
View all 1003 Jobs
ICT Security Officer Job
IT Jobs In Kenya.
To oversee information security, cybersecurity and IT risk management programs based on industry-accepted information security and risk management framework.
Key responsibilities and accountabilities
- Monitor access to all bank systems and maintains access control profiles on computer network and systems. Track documentation of access authorizations to all resources.
- Develop and/or maintain appropriate Segregation of Duties within and across all banking applications.
- Develop and manage the Information Security risk management strategy, framework, guideline and approach for the bank’s systems and infrastructure landscape.
- Research and investigate measures that address data security risks and potential losses for reporting purposes.
- Install, modify, enhance, and maintain data system security software.
- Work on determining acceptable risk levels for the bank and ensuring the IT environments are adequately protected from potential risks and threats.
- Participate in development and implementation of the appropriate and effective controls to mitigate identified threats and risks.
- Follow-up on detected security issues and implement solutions to reduce security risks
- Assist in the research, development, communication, maintaining and working with the operational units on the enforcement of IT security architecture, policies, procedures, solutions, and standards.
- Oversee incident response planning as well as the investigation of security breaches, and assist with disciplinary and legal matters associated with such breaches as necessary
- Support improved data security awareness and education including on-call availability.
- Develop strategies and action plans to drive control maturity improvement in areas where controls do not adequately mitigate risks.
- Responsible for staying abreast of the latest industry security practices and technologies
- Meet with bank shareholders to analyze, document, and define requirements associated with new development or maintenance and enhancements to existing security roles and permissions. Review completed roles/permissions with users to ensure requirements are fully met.
- Deliver services that meet regulatory specifications. Work with internal and external auditors to document and confirm that all security administrative duties are properly performed as well as demonstrate overall compliance.
- Manage the 3rd party’s Information Security risk assessments process to ensure risk transparency and business acceptance, contractual obligations, due diligence assessments and enable risk-based decision making to support the Bank’s Third-party Risk Program.
- Plan and conduct Incident Response Plan tabletop exercises on a periodic basis with subsequent remediation planning, tracking and completion roadmap in place.
- Develop, update, and ensure completion of IS training and awareness initiatives throughout the Bank on a periodic basis. In addition, ensure respective reporting tracking metrics in place.
- Evaluate and recommend security products, services, and/or procedures to enhance productivity and effectiveness.
- Manage specified Information Security related projects from inception to completion.
- Provide guidance, evaluation, and advocacy on audit responses.
- Coordinate and track all information technology and security related audits. Liaise with Internal Audit, maintaining excellent relationships and provide transparency.
- To perform any other duty as assigned in line with the organization goals and objectives
Minimum Qualifications and experience
- Bachelor’s degree in Computer Science, Information Technology, or related discipline
- Minimum 4 years in Information Technology with 3 years of Information and Cybersecurity relevant experience
- Information security certifications preferred: CISSP, CISM, CISA or Equivalent (Note – If not certified, willing to obtain the CISO approved IS/Cyber certification(s) in the first year of employment)
- Strong knowledge of Information Security concepts including, but not limited to, Audit Reviews, Risk Assessment, Awareness & Training, Identity Access & Management, Data Protection, Secure SDLC, Incident Management, Vulnerability Assessment, Third Party IS Assessment, Secure Configurations, Patch Management, etc.
- Thorough understanding of fundamental security related frameworks and network concepts
- Hands-on troubleshooting, analysis, and technical expertise to resolve incidents and service requests; previous experience in troubleshooting day-to-day operational processes such as security monitoring, data correlation, security operations will be an added advantage
- Ability to communicate effectively at different levels of the organization, and with various technical and business audiences.
- Excellent problem-solving abilities and analytical skills. Ability to see the big picture with high attention to critical details.
- Results oriented, can achieve desired outcomes independently and at appropriate priority levels
- Highly motivated and energetic with ability to multi-task effectively
- Ability to complete projects and perform daily tasks with minimal supervision
- Ability to set and meet deadlines
- Strong interpersonal skills
How To Apply
Interested candidates who meet the criteria above are encouraged to send their application letters and detailed CVs (You must indicate the position title on the subject line) to: [email protected]
Closing date for application is on or before 24th March 2022.Only shortlisted candidates will be contacted.
NB: CMFB does not charge any fees for the recruitment processN.B: 1.Dont Miss Out On Your Next Job. Let's Have Your CV. Upload Your CV Here . NB: 2. Advance & Grow In Your Career? . Check Out Best short Courses For You.
Apply for this Job
More Job Vacancies
See all jobs