Jobs Career Advice Post Job
X

Send this job to a friend

X

Did you notice an error or suspect this job is scam? Tell us.

  • Posted: Aug 29, 2026
    Deadline: Sep 4, 2026
    • @gmail.com
    • @yahoo.com
    • @outlook.com
  • Never pay for any notarisation, certificate or assessment as part of any recruitment process. When in doubt, contact us

    CIC Insurance Group Limited, commonly referred to as CIC Group, is an insurance and investment group that operates mainly in Kenya, Uganda, South Sudan and Malawi

     

    Regional IT Lead

    About the Role

    The Regional IT Lead coordinates and manages ICT business systems across the Uganda, Malawi, and South Sudan regions, supporting the Life Assurance, General Insurance, Medical, and Asset Management lines of business. This role exists to ensure the effective, secure, and standardized delivery of core ICT systems and services across the regions, in support of the organization’s corporate strategy and regional business objectives, while acting as the primary link between in-country IT operations and the central ICT function led by the Head of ICT.

    Key Responsibilities

    • Ensure the effective functioning of core Business Application systems and services supporting Life, General Insurance, Medical, and Asset Management lines across Uganda, Malawi, and South Sudan, targeting at least 99.99% system availability regionwide.
    • Conduct regular maintenance and implement necessary measures across all regional systems and platforms.
    • Review core business application systems in each region to support product innovation, recommend integration opportunities, and enforce robust system controls with comprehensive audit trails.
    • Serve as the central point of coordination between the Head of ICT and in-country IT teams/staff in Uganda, Malawi, and South Sudan.
    • Monitor regional systems performance, risks, and issues, and provide regular consolidated reports to the Head of ICT.
    • Ensure alignment of regional ICT practices, policies, and system configurations with group’s ICT standards.
    • Ensure closure of all audit issues related to ICT in the regions.
    • Design and implement user training programs on ICT applications across all regions to promote optimal software utilization.
    • Work closely with the head of technology reliability to ensure timely resolution of IT incidents and service requests across the regions, escalating complex issues to specialist teams and fast-tracking resolution as needed.
    • Manage relationships with ICT service providers across the regions and ensure compliance with established service level agreements (SLAs).
    • Carry out performance appraisals, coaching, and mentoring of regional IT staff.

    Who We’re Looking For

    Essential Knowledge/Skills and Experience Required:

    • Bachelor’s degree in Computer Science, Information Technology, or a related field of study.
    • Certification in Oracle, ITIL, Project Management, or COBIT.
    • Minimum of seven (7) years of hands-on Application Systems management experience.
    • Strong knowledge of core insurance business application systems (Life, General, and Asset Management).
    • Experience managing or supporting ICT systems across multiple countries/regions.
    • Communication and presentation skills.
    • Analytical and problem-solving skills.
    • Interpersonal skills and ability to work across diverse regional teams and cultures.
    • Integrity, Agility, performance orientation, and co-operation.

    go to method of application »

    IT Security Manager

    About the Role

    Reporting to the Group Head of IT, the Information Security Manager is responsible for protecting the organization’s information assets, technology infrastructure, applications, and digital services from cyber and information security threats. The role provides strategic direction and hands-on leadership in the implementation, monitoring, and continuous improvement of information security controls, while ensuring compliance with applicable regulatory requirements, policies, and recognized security frameworks such as ISO/IEC 27001 and NIST. The Information Security Manager will work closely with IT, Risk, Internal Audit, business teams, project teams, and external partners to embed security-by-design principles across technology initiatives, proactively manage cyber risks, and strengthen the organization’s overall cyber resilience.

    Key Responsibilities

    • Manage, maintain, and continuously improve the organization’s information security infrastructure and controls, including firewalls, IDS/IPS, endpoint protection/EDR, PAM, NAC, patch and vulnerability management, security monitoring and logging, and cloud security controls across AWS and Microsoft Azure.
    • Lead the organization’s technology security assessment programme, including vulnerability assessments, penetration testing, security reviews, configuration assessments, and risk assessments.
    • Develop, review, implement, and enforce information security policies, standards, procedures, and guidelines.
    • Ensure security policies remain aligned with business requirements, regulatory obligations, and industry standards.
    • Develop and deliver a comprehensive information security and cybersecurity awareness programme.
    • Conduct regular security awareness campaigns covering phishing, social engineering, password security, data protection, remote working, acceptable use, and emerging cyber threats.
    • Partner with project teams, IT managers, architects, developers, and business stakeholders to embed security-by-design principles throughout the technology lifecycle.
    • Provide security architecture guidance and recommendations for new systems, applications, integrations, infrastructure, and cloud initiatives.
    • Monitor the evolving cyber threat landscape and assess its potential impact on the organization.
    • Lead and coordinate the cybersecurity incident response lifecycle, including detection and identification, investigation and analysis, containment, eradication, recovery, and post-incident review.
    • Provide cybersecurity oversight for business continuity and disaster recovery programmes.
    • Establish and monitor security patching and vulnerability remediation requirements across technology platforms.
    • Establish and maintain effective relationships with cybersecurity and technology security vendors.
    • Prepare regular information security reports and dashboards for the Group Head of IT and other relevant management forums.

    Who We’re Looking For

    Essential Knowledge/Skills and Experience Required:

    • Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field.
    • Relevant Professional Qualification such as CISA, CISM, CISP, CEH or similar.
    • Additional certifications in AWS, Azure, and GCP are a plus
    • Minimum of seven (7) years of hands-on IT security experience.
    • At least two (2) years of team leadership.
    • Experience in financial services industry.
    • Proven experience in conducting penetration tests vulnerability assessments and leading closure of findings through collaborating with various stakeholders Internal & External IT Auditors, Risk and Compliance department etc.
    • Strong knowledge of security frameworks and standards e.g., ISO 27001, NIST.
    • Skilled in IT risk management, Cyber threat mitigation, and hands-on problem-solving with strong analytical abilities.
    • Proven leadership and communication skills in cross functional teams.
    •  Strategic, adaptable, and budget-conscious decision-maker, aligning security initiatives with business objectives and managing vendor relations effectively.

    go to method of application »

    Technology Risk and Cybersecurity Manager

    About the Role

    Reporting to the Group Director – Risk and Compliance, the role holder will be responsible for embedding cybersecurity and information risk disciplines into the organization’s broader ERM framework ensuring technology-related risks are identified, assessed, quantified, and treated in a manner consistent with the organization’s risk appetite and governance structures.  In addition to cybersecurity risk, the role carries oversight responsibility for the full spectrum of ICT risk across the Group’s technology estate, supervising the ICT Risk Specialist and ensuring that infrastructure, system, and change-related risks are integrated into the Group’s enterprise risk register alongside cybersecurity threats.

    Key Responsibilities

    • Support the Director, Risk and Compliance in embedding cybersecurity and ICT risk within the enterprise risk management framework, ensuring that technology risks are consistently captured in the organizational risk register, assessed against agreed risk appetite, and reported to governance forums in clear business terms.
    • Provide direct line management and professional development for the ICT Risk Specialist, Cyber Risk Specialist, Project and Innovation Risk Specialist setting clear objectives, coordinating workplans, conducting performance reviews, and ensuring high-quality delivery across all four disciplines.
    • Implement the CIC Group Cybersecurity Strategy and preparing reports on the Group’s cybersecurity risk appetite, monitoring quantified thresholds and for quarterly and annual cybersecurity risk reports to Management, regulators and Board of Directors.
    • Lead the Group’s cybersecurity incident response capability directing the technical and governance response to material incidents in accordance with the Cyber Incident Response Plan.
    • Direct the Group’s red and blue teaming programme commissioning annual red team adversarial simulation exercises, overseeing blue team defensive monitoring and response capability, reviewing findings from both disciplines, and driving remediation to strengthen the Group’s overall security posture.
    • Provide expert input into the security design of IT architectures, system implementations, and digital transformation initiatives, ensuring security-by-design and privacy-by-design principles are embedded from project initiation.
    • Implement the Group’s Third-Party Risk Management Framework for ICT-related vendors ensuring all such relationships are assessed, classified, and managed proportionately to their risk tier, and monitoring for supply chain cyber threats and third-party data breaches in line with the Framework’s escalation timelines.
    • Supporting digital forensic investigations, maintaining chain of custody, and producing reports suitable for management, board and regulatory submission or legal proceedings.

    General Responsibilities;

    • Participate in budgeting and resource allocation for the Risk and Compliance function.
    • Manage internal, external audit and regulatory engagements related to cybersecurity and information risk, coordinating audit responses and tracking remediation of findings.
    • Maintain current knowledge of developments in cybersecurity legislation, regulatory guidance, threat intelligence, and industry best practice across all operating jurisdictions, disseminating relevant updates to stakeholders.
    • Maintain and enforce cybersecurity risk policies and standards, reviewing them periodically to reflect changes in the threat landscape, regulatory environment, and organizational risk appetite, and ensuring compliance across all nine subsidiaries.

    Who We’re Looking For

    Essential Knowledge/Skills and Experience Required:

    • Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field.
    • A Master’s degree in Information Security, Risk Management, or a related discipline is an added advantage.
    • Mandatory: One or more of CISSP, CISM, CISA, or equivalent senior cybersecurity certification.
    • Desirable: CGEIT, CRISC, CEH, cloud security certifications (AWS Security Specialty, Microsoft SC-100/AZ-500), ISO 27001 Lead Implementer/Auditor, or a risk management qualification (IRM, CRMA).
    • Total Experience: Minimum of eight (6) years of progressive cybersecurity or IT risk experience.
    • Leadership Experience: At least four (3) years in a management or team lead role with direct reports across multiple security or risk disciplines.
    • Industry Experience: Prior experience in financial services, insurance, or a regulated industry is strongly preferred.
    • Frameworks & Standards: Strong working knowledge of ISO 27001, NIST CSF, and enterprise risk frameworks (e.g. COSO ERM, ISO 31000), with practical experience applying these in a compliance-driven environment

    Method of Application

    Use the link(s) below to apply on company website.

     

    Build your CV for free. Download in different templates.

  • Get new ICT / Computer jobs like this on Telegram.Subscribe on Telegram
  • Send your application

    Back To Home

Career Advice

View All Career Advice
 

Subscribe to Job Alert

 

Join our happy subscribers

 
 
Send your application through

GmailGmail YahoomailYahoomail