Jobs Career Advice Post Job
X

Send this job to a friend

X

Did you notice an error or suspect this job is scam? Tell us.

  • Posted: Aug 29, 2026
    Deadline: Sep 4, 2026
    • @gmail.com
    • @yahoo.com
    • @outlook.com
  • Never pay for any notarisation, certificate or assessment as part of any recruitment process. When in doubt, contact us

    CIC Insurance Group Limited, commonly referred to as CIC Group, is an insurance and investment group that operates mainly in Kenya, Uganda, South Sudan and Malawi

     

    IT Security Manager

    About the Role

    Reporting to the Group Head of IT, the Information Security Manager is responsible for protecting the organization’s information assets, technology infrastructure, applications, and digital services from cyber and information security threats. The role provides strategic direction and hands-on leadership in the implementation, monitoring, and continuous improvement of information security controls, while ensuring compliance with applicable regulatory requirements, policies, and recognized security frameworks such as ISO/IEC 27001 and NIST. The Information Security Manager will work closely with IT, Risk, Internal Audit, business teams, project teams, and external partners to embed security-by-design principles across technology initiatives, proactively manage cyber risks, and strengthen the organization’s overall cyber resilience.

    Key Responsibilities

    • Manage, maintain, and continuously improve the organization’s information security infrastructure and controls, including firewalls, IDS/IPS, endpoint protection/EDR, PAM, NAC, patch and vulnerability management, security monitoring and logging, and cloud security controls across AWS and Microsoft Azure.
    • Lead the organization’s technology security assessment programme, including vulnerability assessments, penetration testing, security reviews, configuration assessments, and risk assessments.
    • Develop, review, implement, and enforce information security policies, standards, procedures, and guidelines.
    • Ensure security policies remain aligned with business requirements, regulatory obligations, and industry standards.
    • Develop and deliver a comprehensive information security and cybersecurity awareness programme.
    • Conduct regular security awareness campaigns covering phishing, social engineering, password security, data protection, remote working, acceptable use, and emerging cyber threats.
    • Partner with project teams, IT managers, architects, developers, and business stakeholders to embed security-by-design principles throughout the technology lifecycle.
    • Provide security architecture guidance and recommendations for new systems, applications, integrations, infrastructure, and cloud initiatives.
    • Monitor the evolving cyber threat landscape and assess its potential impact on the organization.
    • Lead and coordinate the cybersecurity incident response lifecycle, including detection and identification, investigation and analysis, containment, eradication, recovery, and post-incident review.
    • Provide cybersecurity oversight for business continuity and disaster recovery programmes.
    • Establish and monitor security patching and vulnerability remediation requirements across technology platforms.
    • Establish and maintain effective relationships with cybersecurity and technology security vendors.
    • Prepare regular information security reports and dashboards for the Group Head of IT and other relevant management forums.

    Who We’re Looking For

    Essential Knowledge/Skills and Experience Required:

    • Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field.
    • Relevant Professional Qualification such as CISA, CISM, CISP, CEH or similar.
    • Additional certifications in AWS, Azure, and GCP are a plus
    • Minimum of seven (7) years of hands-on IT security experience.
    • At least two (2) years of team leadership.
    • Experience in financial services industry.
    • Proven experience in conducting penetration tests vulnerability assessments and leading closure of findings through collaborating with various stakeholders Internal & External IT Auditors, Risk and Compliance department etc.
    • Strong knowledge of security frameworks and standards e.g., ISO 27001, NIST.
    • Skilled in IT risk management, Cyber threat mitigation, and hands-on problem-solving with strong analytical abilities.
    • Proven leadership and communication skills in cross functional teams.
    •  Strategic, adaptable, and budget-conscious decision-maker, aligning security initiatives with business objectives and managing vendor relations effectively.

    Check how your CV aligns with this job

    Method of Application

    Interested and qualified? Go to CIC Insurance on careers.cicinsurancegroup.com to apply

    Build your CV for free. Download in different templates.

  • Get new ICT / Computer jobs like this on Telegram.Subscribe on Telegram
  • Send your application

    Back To Home

Career Advice

View All Career Advice
 

Subscribe to Job Alert

 

Join our happy subscribers

 
 
Send your application through

GmailGmail YahoomailYahoomail