About Us
CIC Insurance Group is a leading insurance and financial services organisation with more than five decades of experience helping individuals, families, and organizations achieve financial security.
We have grown into a dynamic Group offering life, general, micro insurance, asset management, and investment solutions, with operations in Kenya, Uganda, South Sudan, and Malawi, and are listed on the Nairobi Securities Exchange.
Our tagline, “We Keep Our Word,” reflects our unwavering commitment to integrity, transparency, and delivering on our promises to our clients, partners, and communities.
CIC Group is passionate about innovation, digital transformation, and inclusive insurance solutions that meet the evolving needs of cooperatives, SMEs, corporates, and individuals. By joining us, you will be part of a team that is shaping the future of financial protection across Africa.
About the Role
Reporting to the Group Head of IT, the Information Security Manager is responsible for protecting the organization’s information assets, technology infrastructure, applications, and digital services from cyber and information security threats. The role provides strategic direction and hands-on leadership in the implementation, monitoring, and continuous improvement of information security controls, while ensuring compliance with applicable regulatory requirements, policies, and recognized security frameworks such as ISO/IEC 27001 and NIST. The Information Security Manager will work closely with IT, Risk, Internal Audit, business teams, project teams, and external partners to embed security-by-design principles across technology initiatives, proactively manage cyber risks, and strengthen the organization’s overall cyber resilience.
Key Responsibilities
- Manage, maintain, and continuously improve the organization’s information security infrastructure and controls, including firewalls, IDS/IPS, endpoint protection/EDR, PAM, NAC, patch and vulnerability management, security monitoring and logging, and cloud security controls across AWS and Microsoft Azure.
- Lead the organization’s technology security assessment programme, including vulnerability assessments, penetration testing, security reviews, configuration assessments, and risk assessments.
- Develop, review, implement, and enforce information security policies, standards, procedures, and guidelines.
- Ensure security policies remain aligned with business requirements, regulatory obligations, and industry standards.
- Develop and deliver a comprehensive information security and cybersecurity awareness programme.
- Conduct regular security awareness campaigns covering phishing, social engineering, password security, data protection, remote working, acceptable use, and emerging cyber threats.
- Partner with project teams, IT managers, architects, developers, and business stakeholders to embed security-by-design principles throughout the technology lifecycle.
- Provide security architecture guidance and recommendations for new systems, applications, integrations, infrastructure, and cloud initiatives.
- Monitor the evolving cyber threat landscape and assess its potential impact on the organization.
- Lead and coordinate the cybersecurity incident response lifecycle, including detection and identification, investigation and analysis, containment, eradication, recovery, and post-incident review.
- Provide cybersecurity oversight for business continuity and disaster recovery programmes.
- Establish and monitor security patching and vulnerability remediation requirements across technology platforms.
- Establish and maintain effective relationships with cybersecurity and technology security vendors.
- Prepare regular information security reports and dashboards for the Group Head of IT and other relevant management forums.
Who We’re Looking For
Essential Knowledge/Skills and Experience Required:
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field.
- Relevant Professional Qualification such as CISA, CISM, CISP, CEH or similar.
- Additional certifications in AWS, Azure, and GCP are a plus
- Minimum of seven (7) years of hands-on IT security experience.
- At least two (2) years of team leadership.
- Experience in financial services industry.
- Proven experience in conducting penetration tests vulnerability assessments and leading closure of findings through collaborating with various stakeholders Internal & External IT Auditors, Risk and Compliance department etc.
- Strong knowledge of security frameworks and standards e.g., ISO 27001, NIST.
- Skilled in IT risk management, Cyber threat mitigation, and hands-on problem-solving with strong analytical abilities.
- Proven leadership and communication skills in cross functional teams.
- Strategic, adaptable, and budget-conscious decision-maker, aligning security initiatives with business objectives and managing vendor relations effectively.
Why Join Us?
Joining CIC Insurance Group as an IT Security Manager offers the opportunity to play a strategic role in protecting the digital assets, systems, and information that underpin a leading regional financial services organization. You will lead initiatives that strengthen cybersecurity resilience, manage technology risks, and safeguard critical infrastructure while supporting the Group’s digital transformation agenda. Working closely with technology, business, risk, and compliance teams, you will influence security strategy, strengthen governance and controls, and build organizational readiness against evolving cyber threats. If you are a forward-thinking cybersecurity professional passionate about resilience, innovation, and protecting business value, CIC provides a platform to lead meaningful security transformation and make a lasting impact.
If you have the aforementioned professional and academic qualifications and you are ready to execute the above mandate, strictly apply through: https://careers.cicinsurancegroup.com/ clearly indicating the position being applied for.
The application should reach us by close of business on 4th September, 2026. Please note only short-listed candidates will be contacted. If you do not hear from us by 30th September, 2026 consider your application unsuccessful.
CIC Group is an equal opportunity employer and does not solicit or require any form of payment for employment opportunities.
N/B: This job advert is open to both internal and external candidates.