Jobs Career Advice Post Job
X

Send this job to a friend

X

Did you notice an error or suspect this job is scam? Tell us.

  • Posted: Sep 15, 2026
    Deadline: Not specified
    • @gmail.com
    • @yahoo.com
    • @outlook.com
  • Never pay for any notarisation, certificate or assessment as part of any recruitment process. When in doubt, contact us

    IDinsight is an international development organization that helps policymakers and managers make socially impactful decisions using rigorous evidence. We carefully tailor a wide range of analytical and quantitative tools to enable our clients to design better policies, rigorously test those ideas, and take informed action at scale to improve lives. Our servi...

     

    Information Security Analyst

    About the Information Security Analyst Role

    • The Information Security and Systems team is the engine driving our uniquely dynamic, high-achieving, multicultural, multi-continental team at the cutting edge of how evidence is used to improve global development programs. This team's mandate is to build and maintain systems that enable IDinsight teams to achieve social impact. This role will be a great fit for someone who is genuinely hands-on with security tooling, who can write clearly enough that a policy actually changes behaviour, and who would rather reduce risk at the design stage than document it after the fact.

    Responsibilities

    As an Information Security Analyst, your core day-to-day work may include:

    • Security tooling administration — Owning day-to-day administration of our security stack, including SASE, CASB, EDR, SIEM, and MDM. Tuning policies and detections, maintaining coverage across a distributed fleet, investigating alerts, and keeping the tooling useful rather than merely deployed.
    • Security Education, Training and Awareness — Designing and running SETA across the organisation: onboarding security training, phishing simulations, targeted sessions for higher-risk teams, and awareness material that colleagues in six offices actually read.
    • Incident response — Triaging and investigating security events, coordinating containment and recovery, maintaining and exercising the incident response plan, and writing up what happened and what changes as a result.
    • Risk assessment — Conducting information and data security risk assessments on projects, systems, vendors, and data flows. Translating findings into recommendations that project teams can act on within their timelines.
    • Partner due diligence — Responding to security and data protection due diligence requests from funders, government partners, and clients, and maintaining the evidence library so each response is faster than the last.
    • Policy and guidance — Developing and maintaining information security policies, standards, and practical guidelines, and keeping them aligned with recognised frameworks and with our regulatory obligations.
    • Data protection compliance — Supporting compliance with GDPR and the national data protection regimes in the countries where we operate: data mapping, retention, subject rights requests, and the assessments that new processing activities require.
    • Governance, risk, and compliance — Contributing to the control framework, maintaining the risk register, and supporting internal and external assurance activity.
    • AI governance — Contributing to how IDinsight governs AI use on project and organisational data: tool assessment, acceptable use guidance, and the controls that make responsible use the default.

    Professional Growth and Internal Contributions

    Beyond your core responsibilities, you will contribute to the Information Security and Systems team and your own professional development through:

    • Systems Support: You will occasionally provide Systems Support via our internal help desk. This gives you direct insight into the technical challenges IDinsighters face and lets you deliver high-impact solutions.
    • Continuous Learning: IDinsight utilises a diverse ecosystem of tools. While we don't expect day-one mastery of every system, we look for a commitment to building deep technical expertise over time. We support security certification and continuing professional education.

    Qualifications

    We're looking for an entrepreneurial, “get stuff done” teammate with 3–5 years of relevant experience. Desired qualifications include:

    • 3–5 years of professional experience in information security, IT security operations, or a closely related role;
    • Hands-on administration experience with at least three of SASE, CASB, EDR, SIEM, and MDM, and the ability to get productive on the rest;
    • Demonstrated experience in incident response, including investigation and post-incident reporting;
    • Experience conducting information or data security risk assessments and communicating findings to non-technical audiences;
    • Experience developing information security policies, standards, or guidelines that were adopted and used;
    • Working knowledge of GDPR and of at least one national data protection law in the regions where we operate, such as Kenya's Data Protection Act, Zambia's Data Protection Act, or India's DPDP Act;
    • Familiarity with recognised information security standards and frameworks, such as NIST SP 800-171, NIST CSF, or ISO/IEC 27001;
    • A security certification is valued — Security+ or SSCP at this level, with CISM or CISSP as a credible next step we will support you toward;
    • Demonstrated interest in IT governance, risk, and compliance, and in AI governance;
    • A bachelor's degree in Computer Science or other quantitative disciplines;
    • Strong communicator in multiple forms (written communications, public speaking, teamwork, and upward management), with a track record of explaining risk to people who have competing priorities;
    • Detail- and execution-oriented, able to take a task from high-level strategic idea to rapid execution with a large amount of autonomy and conscientiousness;
    • Demonstrated track record as a self-starter and leader, including comfort with ambiguity and dynamic environments and work streams;
    • Strong desire for professional growth and development, with a track record of openness to give and receive feedback;
    • Strong problem-solving skills in handling system challenges;
    • People-focused and people-facing, with high levels of empathy and desire to listen to and share in teammates' victories, concerns, and needs;
    • Strong ability to maintain integrity and confidentiality in complex situations;
    • Ability to handle sensitive information, data, and issues with mature and discreet professionalism;
    • Ability to work with international, cross-cultural, and diverse teams across time zones.

    go to method of application »

    Information Security and Systems Lead, (Associate) Director

    About the Information Security and Systems Lead Role

    • The Information Security and Systems team is the engine driving our uniquely dynamic, high-achieving, multicultural, multi-continental team at the cutting edge of how evidence is used to improve global development programs. This team's mandate is to build and maintain systems that enable IDinsight teams across 7+ countries to achieve social impact. We are looking for an Information Security and Enterprise Systems Leader to own that mandate end-to-end. You will lead a small, capable team of security and systems specialists, fractional resources, and external implementation partners. You will report to and advise the executive team. This role could be a fit if you have high-quality experience running both security and enterprise systems initiatives at a global organisation and you’re comfortable being the most senior technical voice in the room without being the only person who understands the decision.

    Enterprise Systems Leadership

    • Strategy and roadmap — Define and own the multi-year enterprise systems strategy for a remote-first, globally distributed organisation, and the priorities that follow from it.
    • Systems implementation — Lead identification, selection, and implementation of new enterprise systems such as CRMs, ERPs, etc. Own architecture and integration decisions and the master data model that holds them together.
    • Implementation partner management — Select, contract, and manage external implementation and support partners, including scope, commercial terms, and delivery accountability.
    • Budget ownership — Lead annual budgeting and financial planning for organisational systems, and make the trade-offs that a non-profit budget requires.
    • Change management — Champion adoption across regions and functions, so that systems investments produce behaviour change.
    • Operational effectiveness — Identify bottlenecks and inefficiencies across the estate, streamline usage to reduce shadow IT, and ensure systems and support functions operate reliably across time zones.
    • Leadership partnership — Work with functional and regional leadership on requirements, prioritisation, and the systems implications of organisational strategy.

    Information Security Program Management

    • Security strategy — Define and own the information security strategy in alignment with organisational strategy and recognised frameworks, and monitor delivery against the roadmap.
    • Control framework — Lead implementation of security and privacy controls as regulation, client obligations, and risk require.
    • Governance — Coordinate the Information Security Steering Committee and contribute to Enterprise Risk Management.
    • Incident response — Own incident response planning, lead coordination during incidents, and drive the changes that follow.
    • External assurance — Commission and support penetration tests, vulnerability assessments, audits, and own remediation.
    • Risk management — Lead periodic risk assessment exercises and the ongoing identification, mitigation, and monitoring of information security risk.
    • Due diligence — Serve as senior point of contact for funder, client, and government partner security and data protection due diligence.
    • Investigations — Support Legal, Compliance, and Operations where digital evidence is relevant to policy violations.

    Data Protection and AI Governance

    • Multi-jurisdiction compliance — Own compliance with GDPR and the national data protection regimes in the countries where we operate, including data mapping, retention, subject rights, and impact assessments.
    • AI governance — Define how IDinsight governs AI use on project and organisational data: tool assessment, acceptable use, and the controls that make responsible use the default.
    • Policy — Own the information security and data protection policy set, and keep it usable enough that colleagues consult it rather than route around it.

    Team and Function Leadership

    • People management — Manage, develop, and grow full-time technology staff and fractional resources, including hiring and performance management.
    • Capability building — Build depth and redundancy in the team so that critical knowledge is not concentrated in one person.
    • Organisational contribution — Contribute to cross-functional leadership initiatives and to IDinsight's institutional practice on data ethics and responsible technology use.

    Qualifications

    We're looking for an entrepreneurial, “get stuff done” teammate with substantial leadership experience. Desired qualifications include:

    • 8+ years of professional experience in technology roles, including at least 5 years of Information Security or Enterprise IT leadership experience (involving people management).
    • Demonstrated ownership of an information security programme at organisational scale — strategy, control framework, governance forum, and incident response, not solely operations;
    • Experience leading the selection and implementation of major enterprise systems such as ERP, CRM, including partner management and budget ownership;
    • Hands-on depth across enterprise security controls — endpoint protection, network security, vulnerability management — sufficient to make architecture decisions and evaluate your team's work credibly;
    • Strong command of identity and access management in enterprise environments, including SSO, MFA, LDAP, and federation protocols such as SAML;
    • Experience with control configuration and security architecture in common cloud environments;
    • Working knowledge of GDPR and of national data protection regimes in Africa or Asia, and of security frameworks such as NIST CSF, NIST SP 800-171, or ISO/IEC 27001;
    • Experience administering enterprise systems for a globally distributed team, including workspace collaboration and human capital management platforms;
    • Experience with enterprise systems architecture and data modelling;
    • Information security leadership certification preferred — CISM, CISSP, CISA, or equivalent;
    • Excellent collaboration, interpersonal, communication, and facilitation skills, with the ability to present to and influence audiences of varying technical fluency, including senior leadership;
    • Strong internal and external stakeholder management skills, including with funders, government partners, and vendors;
    • Experience managing change in a fast-moving, remote-first environment.
    • Detail- and execution-oriented, able to take a task from high-level strategic idea to rapid execution with a large amount of autonomy and conscientiousness;
    • Demonstrated track record as a self-starter and leader, including comfort with ambiguity and dynamic environments and work streams;
    • Ability to handle sensitive information, data, and issues with mature and discreet professionalism;
    • Ability to work with international, cross-cultural, and diverse teams across time zones.

    Method of Application

    Build your CV for free. Download in different templates.

  • Get new Data, Business Analysis and AI jobs like this on Telegram.Subscribe on Telegram
  • Send your application

    Back To Home

Career Advice

View All Career Advice
 

Subscribe to Job Alert

 

Join our happy subscribers

 
 
Send your application through

GmailGmail YahoomailYahoomail