PURPOSE:
Reporting to the Group Head of IT the IT Security Manager protects information systems and maintains compliance through strategic planning and hands-on implementation of security controls while addressing emerging cyber threats. The role involves collaborating with cross-functional teams to embed security-by-design principles in new initiatives and ensuring compliance with security frameworks such as ISO 27001 and NIST.
PRIMARY RESPONSIBILITIES:
- Manage and maintain IT security infrastructure including firewalls, IDS/IPS, endpoint protection, PAM, NAC, Patch management and cloud security controls across platforms (AWS, Azure), ensuring regular testing, patching, and updates.
- Lead and conduct technology security assessment programs including vulnerability scanning, penetration testing, risk assessments, collaborating with IT audit and risk teams for timely closure of findings from both internal and external evaluations.
- Develop and enforce security policies and procedures, including remote work protocols, while managing internal/external audit responses and maintaining policy compliance dashboards.
- Design and deliver comprehensive security awareness programs, including incident response training and ongoing security awareness on security threats and best practice.
- Partner with project teams and IT managers to embed security-by-design principles in new initiatives, providing security architecture guidance and risk assessments for all major projects.
- Monitor and analyze security trends, implementing proactive measures to protect against emerging threats while maintaining up-to-date security measures across all systems.
- Manage the incident response lifecycle, including detection, investigation, containment, eradication, and recovery processes, ensuring proper documentation and learning from each incident.
- Oversee business continuity and disaster recovery processes, including bi-annual DR testing and implementation of comprehensive incident response procedures to effectively address security breaches.
- Ensure regular patching and hardening of systems to maintain system integrity and resilience, and generate status reports on infrastructure health for executive review.
- Establish and maintain relationships with security vendors ensuring effective service delivery and value for security investments.
Key Skills, Knowledge, Experience and Behavioural Competencies | |||||||||||||||
Academic and Professional Requirements
Experience Required:
Skills and Competencies:
|
|||||||||||||||
CIC Insurance Values | |||||||||||||||
CIC insurance Group is committed to providing excellent service, spur further growth and employees are required to align their behaviour to the following core values as critical to driving their performance;
· Integrity- Be fair and transparent · Dynamism- Be passionate and innovative · Performance- Be efficient and results driven · Co-operation- Live the Co-operative spirit |
If you have the aforementioned professional and academic qualifications and you are ready to execute the above mandate, strictly apply through: https://careers.cicinsurancegroup.com/ clearly indicating the position being applied for.
The application should reach us by close of business on 28th January, 2025. Please note only short-listed candidates will be contacted. If you do not hear from us by 28th February, 2025 consider your application unsuccessful.
N/B: This job advert is open to both internal and external candidates.