Subscribe to Job Alert
Join our happy subscribers
Never pay for any notarisation, certificate or assessment as part of any recruitment process. When in doubt, contact us
At Sidian Bank, we recognize the significant accountability and inherent risks that an entrepreneur takes to make his ideas and dreams a reality. It is for this reason that our mission is to empower entrepreneurs to create wealth through provision of transformational financial solutions that meet entrepreneurs needs and facilitate growth through convenience and choice.
Branch: Kilimani Branch – Head Office
Department: ERM
Reports to: Head ERM
Chief Information Security Officer & Data Privacy Officer
JOB PURPOSE
To oversee the protection of bank and customer data, as well as the protection of infrastructure and assets from malicious actors. Serves as the process owner of all assurance activities related to the availability, integrity, and confidentiality of customer, business partner, employee, and business information in compliance with the bank’s information security policies.
KEY RESPONSIBILITIES
MAIN ACTIVITIES
Strategy
Draw out and implement a 5-year strategy plan towards the organization’s certification on ISMS – ISO27001
Draw out a yearly Budgetary proposal towards mitigating Technology Risk in the organization
Keep up to date with the latest security and technology developments
Research/evaluate emerging security threats and ways to manage them
Audit and Compliance
Leading auditing and security compliance initiatives.
Ensure that an annual Central Bank of Kenya (CBK) Cyber Security Compliance Report is provided
Drive the testing and evaluation of security products
Policies Standards and Procedure
Data Protection/Privacy
Develop a Strategy for Data Privacy Compliance and walk through its implementation.
Data Protection Awareness Champion.
Conducting Data Mapping and Data Protection Impact Assessment.
Information Security Awareness Training.
Develop an Information Security Awareness program, prepared curriculum for different set of users and executed the program
Risk Management
Maintain an information security risk register for the business
Ensuring security on all platform infrastructure and external integrations
Security Operation Center SOC
Business Continuity and Disaster Recovery
Update and implement a business continuity plan for the business.
Conduct Business Impact Assessment and define RPO and RTOs for the business.
Executed a tabletop and actual disaster recovery plan tests for people, systems, processes.
Conducted drills and work on areas of improvement.
Identity and Access Management
Incident Reporting
Cyber security
DECISION-MAKING AUTHORITY
ACADEMIC BACKGROUND
WORK EXPERIENCE
SKILLS & COMPETENCIES
PROFESSIONAL CERTIFICATION
Check how your CV aligns with this job
Build your CV for free. Download in different templates.
Join our happy subscribers