IT Security Manager
AI summary
CIC Insurance is hiring an IT Security Manager to lead information security strategy, manage cyber risks, and ensure compliance with ISO 27001 and NIST frameworks. The role involves overseeing security infrastructure, incident response, penetration testing, and security awareness programmes across AWS and Azure environments. Candidates need a relevant degree, professional certification, and at least seven years of IT security experience in financial services.
- Strategic leadership role reporting to the Group Head of IT
- Hands-on management of firewalls, EDR, PAM, NAC, and cloud security across AWS and Azure
- Lead penetration testing, vulnerability assessments, and security reviews
- Requires CISA, CISM, CISP, CEH or similar professional certification
- Minimum seven years IT security experience with two years team leadership
- Financial services industry experience required
AI job guide
Use this guide to check salary signals, requirements, documents, application steps and safety before you apply.
AI salary guide
Not enough public dataNot enough public salary data is available for this exact role. Before applying, prepare to ask about gross pay, benefits, contract length, probation period, transport and any allowances.
Can you qualify for this role?
- Required7+ years of relevant experienceThe job post includes a minimum experience signal.
- RequiredEducation or certification mentioned in the postThe captured text mentions education, a diploma, certificate, or licence.
- PreferredPractical evidence in security, internship, segurancaThe tags and summary point to skills connected with this role.
- RequiredAvailability to work in Not specifiedThe vacancy is associated with this location.
Documents to prepare
- Likely requiredUpdated CV
- Role specificCover letter or short employer message
- OptionalProfessional references
- Role specificAcademic or professional certificates
- VerifyID or passport only after verifying the employer
Application tips for this job
- Place your strongest IT Security Manager evidence in the first half of your CV.
- In your cover letter or employer message, connect your experience to CIC Insurance and the role in Not specified.
- Add concrete examples related to security, internship, seguranca, ideally with measurable outcomes or clear responsibilities.
- Follow the instructions from MyJobMag Kenya; avoid sending documents to unofficial contacts or copied links.
- Confirm the deadline, interview location and employer contact before sharing personal documents.
- Prepare a polite question about pay, benefits and contract terms for later interview stages.
Source and safety check
- MyJobMag Kenya
- Original source link available
- Application method is clear
- Deadline not specified
- No major risk signal was detected in the captured text.
Never pay for interviews, shortlisting, medical checks, uniforms, or job placement. Confirm every application at the original source before sharing personal documents. Report suspicious listing.
Interview preparation
- What experience makes you a strong fit for this IT Security Manager role in security, internship?
- How have you handled responsibilities similar to those in this job post?
- Are you available to work in Not specified under the listed contract or schedule?
- Prepare examples with clear responsibilities, tools used and measurable outcomes.
- Review the source and research CIC Insurance before the interview.
Ask what the first priorities will be in the role and how success will be measured.
Similar jobs to consider
Use AI to apply better
After confirming the original source, use Career Assistant to check role fit, tailor your CV and prepare a cover letter or employer message.
Original source description
Reporting to the Group Head of IT, the Information Security Manager is responsible for protecting the organization’s information assets, technology infrastructure, applications, and digital services from cyber and information security threats. The role provides strategic direction and hands-on leadership in the implementation, monitoring, and continuous improvement of information security controls, while ensuring compliance with applicable regulatory requirements, policies, and recognized security frameworks such as ISO/IEC 27001 and NIST. The Information Security Manager will work closely with IT, Risk, Internal Audit, business teams, project teams, and external partners to embed security-by-design principles across technology initiatives, proactively manage cyber risks, and strengthen the organization’s overall cyber resilience.
Key
Responsibilities
Manage, maintain, and continuously improve the organization’s information security infrastructure and controls, including firewalls, IDS/IPS, endpoint protection/EDR, PAM, NAC, patch and vulnerability management, security monitoring and logging, and cloud security controls across AWS and Microsoft Azure.
Lead the organization’s technology security assessment programme, including vulnerability assessments, penetration testing, security reviews, configuration assessments, and risk assessments.
Develop, review, implement, and enforce information security policies, standards, procedures, and guidelines.
Ensure security policies remain aligned with business requirements, regulatory obligations, and industry standards.
Develop and deliver a comprehensive information security and cybersecurity awareness programme.
Conduct regular security awareness campaigns covering phishing, social engineering, password security, data protection, remote working, acceptable use, and emerging cyber threats.
Partner with project teams, IT managers, architects, developers, and business stakeholders to embed security-by-design principles throughout the technology lifecycle.
Provide security architecture guidance and recommendations for new systems, applications, integrations, infrastructure, and cloud initiatives.
Monitor the evolving cyber threat landscape and assess its potential impact on the organization.
Lead and coordinate the cybersecurity incident response lifecycle, including detection and identification, investigation and analysis, containment, eradication, recovery, and post-incident review.
Provide cybersecurity oversight for business continuity and disaster recovery programmes.
Establish and monitor security patching and vulnerability remediation
Requirements
- across technology platforms.
- Establish and maintain effective relationships with cybersecurity and technology security vendors.
- Prepare regular information security reports and dashboards for the Group Head of IT and other relevant management forums.
- Who We’re Looking For
- Essential Knowledge/Skills and
Experience
- Required:
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field.
- Relevant Professional Qualification such as CISA, CISM, CISP, CEH or similar.
- Additional certifications in AWS, Azure, and GCP are a plus
- Minimum of seven (7) years of hands-on IT security experience.
- At least two (2) years of team leadership.
- in financial services industry.
- Proven
- in conducting penetration tests vulnerability assessments and leading closure of findings through collaborating with various stakeholders Internal & External IT Auditors, Risk and Compliance department etc.
- Strong knowledge of security frameworks and standards e.g., ISO 27001, NIST.
- Skilled in IT risk management, Cyber threat mitigation, and hands-on problem-solving with strong analytical abilities.
- Proven leadership and communication skills in cross functional teams.
- Strategic, adaptable, and budget-conscious decision-maker, aligning security initiatives with business objectives and managing vendor relations effectively.
- Check how your CV aligns with this job
- Method of Application
- Interested and qualified? Go to
- CIC Insurance on careers.cicinsurancegroup.com
- to apply
- Build your CV for free.
- Download in different templates.
