Never pay for any notarisation, certificate or assessment as part of any recruitment process. When in doubt, contact us
Housing Finance Company of Kenya was incorporated as the premier mortgage Finance Institution in Kenya licensed under the Banking Act with the CDC and the GoK owning 60% and 40% respectively.
Housing Finance started operations with the main objective of implementing the government’s policy of promoting thrift and home ownership by lending ...
Read more about this company
About the Role
The Manager – IT Security supports the Head of ICT Security / CISO in strengthening the Group’s information security posture by coordinating IT security governance, cyber risk management, SOC operations oversight, security assurance, audit remediation, regulatory compliance and proactive cyber resilience across the Group. The role ensures that security policies, standards, controls, monitoring processes and assurance activities are embedded into technology operations, digital channels, projects, third-party engagements, and business processes. The role holder provides security support to the substantive Data Protection Officer by ensuring that technical and organisational security controls for personal data are defined, implemented, tested, monitored, and evidenced. This role supports privacy governance through technology control implementation, security assurance, access control, monitoring, incident coordination, third-party reviews, and remediation tracking.
Key Accountabilities
- Data Protection and Privacy Security Support - Support the substantive Data Protection Officer by providing information security input into privacy governance, DPIAs, data classification, access controls, encryption, logging and monitoring, data loss prevention, third-party risk reviews, breach investigation, audit evidence and remediation tracking.
- IT Security Governance and Strategy Execution - Support the CISO in implementing the Group information security strategy, governance framework, policies, standards, procedures, operating model and control assurance programme.
- Regulatory Compliance and Security Reporting - Coordinate compliance reviews, evidence packs, management attestations, regulatory responses, control self-assessments and reporting to ICT, Risk, Compliance, Audit and management governance forums.
- Cyber Risk, Audit and Remediation Management - Coordinate identification, assessment, monitoring, reporting and remediation of ICT and cyber risks across the Group, including audit and regulatory findings to closure.
- SOC Operations Oversight and Incident Coordination - Provide management oversight of security monitoring, incident triage, escalation, response coordination, threat intelligence, SOC use cases, alert handling, incident reporting and post-incident remediation.
- ICT Resilience, Disaster Recovery and Cyber Recovery Support - Coordinate security input into ICT business continuity, disaster recovery, cyber recovery planning, backup assurance, recovery testing and remediation of resilience gaps.
- Identity and Access Governance - Maintain access governance covering privileged access, periodic user access reviews, role-based access control, joiner-mover-leaver controls, access certification, segregation of duties, exceptions, remediation tracking and evidence management.
- Security Assurance for Projects, Platforms and Third Parties - Provide security assurance over systems, infrastructure, digital channels, cloud services, APIs, integrations, third parties and technology changes.
Qualifications
- Bachelor's degree in information security, Computer Science, Information Systems, Information Technology, Cybersecurity, Risk Management, or related fields.
- Relevant certifications such as CISM, CISSP, CRISC, CISA, ISO 27001 Lead Implementer/Lead Auditor, CompTIA Security+, CBCP or equivalent will be an added advantage.
- At least 5 years’ experience in information security, IT governance, cyber risk, security operations, security assurance, or technology risk management.
- Understanding of implementation of technical security controls, identity and access management and designing security solutions in a dynamic environment
- At least 2 years in a supervisory or managerial role within a highly regulated or digitized environment.
- Demonstrable experience in security governance, SOC oversight, audit remediation, regulatory compliance, access governance, third-party assurance, project security assurance, incident coordination, cyber resilience and executive reporting.
- Understanding of IT Audit processes, technical security testing (Red Team, Blue Team, Penetration Testing) and Cyber Incident Response including data protection guidelines.