Back to jobs
Job in Kenya

Information Security and Systems Lead, (Associate) Director

IDinsight Kenya Full Time Posted 2026-09-15
CountyNairobi CountyCityNot specifiedContractFull TimePosted2026-09-15Close dateNot specifiedExperience8 yearsSourceMyJobMag Kenya
information securityenterprise systemsassociate directorsystems leadershipsecurity governanceNairobifull timesenior roleinternational developmentrisk managementsecurityinternship
Use AI for this job

AI summary

IDinsight is hiring a senior Information Security and Systems Lead in Nairobi to own enterprise systems strategy and the information security program for a global, remote-first development organization. The role involves leading a small team, managing implementation partners, advising executives, and overseeing security governance, risk, and systems adoption across multiple countries.

  • Senior leadership role owning both enterprise systems and information security strategy.
  • Reports to and advises the executive team on technical and security decisions.
  • Leads a small internal team plus fractional resources and external partners.
  • Based in Nairobi with a global, multi-country scope.
  • Full-time position requiring around 8 years of experience.

AI job guide

Use this guide to check salary signals, requirements, documents, application steps and safety before you apply.

AI salary guide

Not enough public data

Not enough public salary data is available for this exact role. Before applying, prepare to ask about gross pay, benefits, contract length, probation period, transport and any allowances.

Can you qualify for this role?

  • Required8+ years of relevant experienceThe job post includes a minimum experience signal.
  • RequiredEducation or certification mentioned in the postThe captured text mentions education, a diploma, certificate, or licence.
  • PreferredPractical evidence in security, internship, entregadorThe tags and summary point to skills connected with this role.
  • RequiredAvailability to work in Not specifiedThe vacancy is associated with this location.
  • UnclearComfort with the Full Time contract termsConfirm hours, duration, probation and benefits at the original source.

Documents to prepare

  • Likely requiredUpdated CV
  • Role specificCover letter or short employer message
  • OptionalProfessional references
  • Role specificAcademic or professional certificates
  • VerifyID or passport only after verifying the employer

Application tips for this job

  • Place your strongest Information Security and Systems Lead, (Associate) Director evidence in the first half of your CV.
  • In your cover letter or employer message, connect your experience to IDinsight and the role in Not specified.
  • Add concrete examples related to security, internship, entregador, ideally with measurable outcomes or clear responsibilities.
  • Follow the instructions from MyJobMag Kenya; avoid sending documents to unofficial contacts or copied links.
  • Confirm the deadline, interview location and employer contact before sharing personal documents.
  • Prepare a polite question about pay, benefits and contract terms for later interview stages.

Source and safety check

  • MyJobMag Kenya
  • Original source link available
  • Application method is clear
  • Deadline not specified
  • No major risk signal was detected in the captured text.

Never pay for interviews, shortlisting, medical checks, uniforms, or job placement. Confirm every application at the original source before sharing personal documents. Report suspicious listing.

Interview preparation

  • What experience makes you a strong fit for this Information Security and Systems Lead, (Associate) Director role in security, internship?
  • How have you handled responsibilities similar to those in this job post?
  • Are you available to work in Not specified under the listed contract or schedule?
  • Prepare examples with clear responsibilities, tools used and measurable outcomes.
  • Review the source and research IDinsight before the interview.

Ask what the first priorities will be in the role and how success will be measured.

Use AI to apply better

After confirming the original source, use Career Assistant to check role fit, tailor your CV and prepare a cover letter or employer message.

Original source description

Never pay for any notarisation, certificate or assessment as part of any recruitment process. When in doubt,

contact us

IDinsight is an international development organization that helps policymakers and managers make socially impactful decisions using rigorous evidence. We carefully tailor a wide range of analytical and quantitative tools to enable our clients to design better policies, rigorously test those ideas, and take informed action at scale to improve lives. Our servi...

Information Security and Systems Lead, (Associate) Director

Job Type

Full Time

Qualification

BA/BSc/HND

Experience

8 years

Location

Nairobi

Job Field

Data, Business Analysis and AI

,

ICT / Computer

About the Information Security and Systems Lead Role

The Information Security and Systems team is the engine driving our uniquely dynamic, high-achieving, multicultural, multi-continental team at the cutting edge of how evidence is used to improve global development programs. This team's mandate is to build and maintain systems that enable IDinsight teams across 7+ countries to achieve social impact. We are looking for an Information Security and Enterprise Systems Leader to own that mandate end-to-end. You will lead a small, capable team of security and systems specialists, fractional resources, and external implementation partners. You will report to and advise the executive team. This role could be a fit if you have high-quality

running both security and enterprise systems initiatives at a global organisation and you’re comfortable being the most senior technical voice in the room without being the only person who understands the decision.

Enterprise Systems Leadership

Strategy and roadmap — Define and own the multi-year enterprise systems strategy for a remote-first, globally distributed organisation, and the priorities that follow from it.

Systems implementation — Lead identification, selection, and implementation of new enterprise systems such as CRMs, ERPs, etc. Own architecture and integration decisions and the master data model that holds them together.

Implementation partner management — Select, contract, and manage external implementation and support partners, including scope, commercial terms, and delivery accountability.

Budget ownership — Lead annual budgeting and financial planning for organisational systems, and make the trade-offs that a non-profit budget requires.

Change management — Champion adoption across regions and functions, so that systems investments produce behaviour change.

Operational effectiveness — Identify bottlenecks and inefficiencies across the estate, streamline usage to reduce shadow IT, and ensure systems and support functions operate reliably across time zones.

Leadership partnership — Work with functional and regional leadership on requirements, prioritisation, and the systems implications of organisational strategy.

Information Security Program Management

Security strategy — Define and own the information security strategy in alignment with organisational strategy and recognised frameworks, and monitor delivery against the roadmap.

Control framework — Lead implementation of security and privacy controls as regulation, client obligations, and risk require.

Governance — Coordinate the Information Security Steering Committee and contribute to Enterprise Risk Management.

Incident response — Own incident response planning, lead coordination during incidents, and drive the changes that follow.

External assurance — Commission and support penetration tests, vulnerability assessments, audits, and own remediation.

Risk management — Lead periodic risk assessment exercises and the ongoing identification, mitigation, and monitoring of information security risk.

Due diligence — Serve as senior point of contact for funder, client, and government partner security and data protection due diligence.

Investigations — Support Legal, Compliance, and Operations where digital evidence is relevant to policy violations.

Data Protection and AI Governance

Multi-jurisdiction compliance — Own compliance with GDPR and the national data protection regimes in the countries where we operate, including data mapping, retention, subject rights, and impact assessments.

AI governance — Define how IDinsight governs AI use on project and organisational data: tool assessment, acceptable use, and the controls that make responsible use the default.

Policy — Own the information security and data protection policy set, and keep it usable enough that colleagues consult it rather than route around it.

Team and Function Leadership

People management — Manage, develop, and grow full-time technology staff and fractional resources, including hiring and performance management.

Capability building — Build depth and redundancy in the team so that critical knowledge is not concentrated in one person.

Organisational contribution — Contribute to cross-functional leadership initiatives and to IDinsight's institutional practice on data ethics and responsible technology use.

Qualifications

We're looking for an entrepreneurial, “get stuff done” teammate with substantial leadership experience. Desired qualifications include:

8+ years of professional

in technology roles, including at least 5 years of Information Security or Enterprise IT leadership

(involving people management).

Demonstrated ownership of an information security programme at organisational scale — strategy, control framework, governance forum, and incident response, not solely operations;

leading the selection and implementation of major enterprise systems such as ERP, CRM, including partner management and budget ownership;

Hands-on depth across enterprise security controls — endpoint protection, network security, vulnerability management — sufficient to make architecture decisions and evaluate your team's work credibly;

Strong command of identity and access management in enterprise environments, including SSO, MFA, LDAP, and federation protocols such as SAML;

with control configuration and security architecture in common cloud environments;

Working knowledge of GDPR and of national data protection regimes in Africa or Asia, and of security frameworks such as NIST CSF, NIST SP 800-171, or ISO/IEC 27001;

administering enterprise systems for a globally distributed team, including workspace collaboration and human capital management platforms;

with enterprise systems architecture and data modelling;

Information security leadership certification

managing change in a fast-moving, remote-first environment.

Detail- and execution-oriented, able to take a task from high-level strategic idea to rapid execution with a large amount of autonomy and conscientiousness;

Demonstrated track record as a self-starter and leader, including comfort with ambiguity and dynamic environments and work streams;

Ability to handle sensitive information, data, and issues with mature and discreet professionalism;

Ability to work with international, cross-cultural, and diverse teams across time zones.

Check how your CV aligns with this job

Method of Application

Interested and qualified? Go to

IDinsight on idinsight.bamboohr.com

to apply

Build your CV for free.

Download in different templates.

Preferred Qualifications

  • — CISM, CISSP, CISA, or equivalent;
  • Excellent collaboration, interpersonal, communication, and facilitation skills, with the ability to present to and influence audiences of varying technical fluency, including senior leadership;
  • Strong internal and external stakeholder management skills, including with funders, government partners, and vendors;
Source and provenanceSource: MyJobMag Kenya. Last checked: 2026-09-27.Kazi Connect is a job discovery service, not the employer. Always confirm the vacancy at the original source.Summaries may be AI-assisted. Report inaccurate content.
Never pay to apply. Always confirm the original source and watch for payment requests, sensitive document requests, or unrealistic promises.