Back to jobs
Job in Kenya

Technology Risk and Cybersecurity Manager

CIC Insurance Kenya Type not specified Posted 2026-08-29
CountyNairobi CountyCityNot specifiedContractType not specifiedPosted2026-08-29Close dateNot specifiedExperienceNot specifiedSourceMyJobMag Kenya
cybersecurity managertechnology riskinformation securityrisk managementinsuranceNairobisenior managementCISSPCISMenterprise risksecurityinternship
Use AI for this job

AI summary

CIC Insurance is hiring a Technology Risk and Cybersecurity Manager to embed cybersecurity and ICT risk disciplines into the group's enterprise risk management framework. The role leads incident response, red/blue teaming, third-party risk management, and security-by-design across the group's technology estate while supervising a team of risk specialists.

  • Senior management role reporting to Group Director – Risk and Compliance
  • Leads cybersecurity incident response and red/blue teaming programme
  • Manages ICT Risk, Cyber Risk, and Project/Innovation Risk specialists
  • Requires CISSP, CISM, CISA, or equivalent senior cybersecurity certification
  • Bachelor's degree required; Master's in Information Security or Risk Management is an added advantage

AI job guide

Use this guide to check salary signals, requirements, documents, application steps and safety before you apply.

AI salary guide

Not enough public data

Not enough public salary data is available for this exact role. Before applying, prepare to ask about gross pay, benefits, contract length, probation period, transport and any allowances.

Can you qualify for this role?

  • UnclearRelated work experienceThe text mentions experience, but the exact level should be confirmed at source.
  • RequiredEducation or certification mentioned in the postThe captured text mentions education, a diploma, certificate, or licence.
  • PreferredPractical evidence in security, internship, entregadorThe tags and summary point to skills connected with this role.
  • RequiredAvailability to work in Not specifiedThe vacancy is associated with this location.

Documents to prepare

  • Likely requiredUpdated CV
  • Role specificCover letter or short employer message
  • OptionalProfessional references
  • Role specificAcademic or professional certificates
  • VerifyID or passport only after verifying the employer

Application tips for this job

  • Place your strongest Technology Risk and Cybersecurity Manager evidence in the first half of your CV.
  • In your cover letter or employer message, connect your experience to CIC Insurance and the role in Not specified.
  • Add concrete examples related to security, internship, entregador, ideally with measurable outcomes or clear responsibilities.
  • Follow the instructions from MyJobMag Kenya; avoid sending documents to unofficial contacts or copied links.
  • Confirm the deadline, interview location and employer contact before sharing personal documents.
  • Prepare a polite question about pay, benefits and contract terms for later interview stages.

Source and safety check

  • MyJobMag Kenya
  • Original source link available
  • Application method is clear
  • Deadline not specified
  • No major risk signal was detected in the captured text.

Never pay for interviews, shortlisting, medical checks, uniforms, or job placement. Confirm every application at the original source before sharing personal documents. Report suspicious listing.

Interview preparation

  • What experience makes you a strong fit for this Technology Risk and Cybersecurity Manager role in security, internship?
  • How have you handled responsibilities similar to those in this job post?
  • Are you available to work in Not specified under the listed contract or schedule?
  • Prepare examples with clear responsibilities, tools used and measurable outcomes.
  • Review the source and research CIC Insurance before the interview.

Ask what the first priorities will be in the role and how success will be measured.

Use AI to apply better

After confirming the original source, use Career Assistant to check role fit, tailor your CV and prepare a cover letter or employer message.

Original source description

Reporting to the Group Director – Risk and Compliance, the role holder will be responsible for embedding cybersecurity and information risk disciplines into the organization’s broader ERM framework ensuring technology-related risks are identified, assessed, quantified, and treated in a manner consistent with the organization’s risk appetite and governance structures. In addition to cybersecurity risk, the role carries oversight responsibility for the full spectrum of ICT risk across the Group’s technology estate, supervising the ICT Risk Specialist and ensuring that infrastructure, system, and change-related risks are integrated into the Group’s enterprise risk register alongside cybersecurity threats.

Key

Responsibilities

Support the Director, Risk and Compliance in embedding cybersecurity and ICT risk within the enterprise risk management framework, ensuring that technology risks are consistently captured in the organizational risk register, assessed against agreed risk appetite, and reported to governance forums in clear business terms.

Provide direct line management and professional development for the ICT Risk Specialist, Cyber Risk Specialist, Project and Innovation Risk Specialist setting clear objectives, coordinating workplans, conducting performance reviews, and ensuring high-quality delivery across all four disciplines.

Implement the CIC Group Cybersecurity Strategy and preparing reports on the Group’s cybersecurity risk appetite, monitoring quantified thresholds and for quarterly and annual cybersecurity risk reports to Management, regulators and Board of Directors.

Lead the Group’s cybersecurity incident response capability directing the technical and governance response to material incidents in accordance with the Cyber Incident Response Plan.

Direct the Group’s red and blue teaming programme commissioning annual red team adversarial simulation exercises, overseeing blue team defensive monitoring and response capability, reviewing findings from both disciplines, and driving remediation to strengthen the Group’s overall security posture.

Provide expert input into the security design of IT architectures, system implementations, and digital transformation initiatives, ensuring security-by-design and privacy-by-design principles are embedded from project initiation.

Implement the Group’s Third-Party Risk Management Framework for ICT-related vendors ensuring all such relationships are assessed, classified, and managed proportionately to their risk tier, and monitoring for supply chain cyber threats and third-party data breaches in line with the Framework’s escalation timelines.

Supporting digital forensic investigations, maintaining chain of custody, and producing reports suitable for management, board and regulatory submission or legal proceedings.

General Responsibilities;

Participate in budgeting and resource allocation for the Risk and Compliance function.

Manage internal, external audit and regulatory engagements related to cybersecurity and information risk, coordinating audit responses and tracking remediation of findings.

Maintain current knowledge of developments in cybersecurity legislation, regulatory guidance, threat intelligence, and industry best practice across all operating jurisdictions, disseminating relevant updates to stakeholders.

Maintain and enforce cybersecurity risk policies and standards, reviewing them periodically to reflect changes in the threat landscape, regulatory environment, and organizational risk appetite, and ensuring compliance across all nine subsidiaries.

Who We’re Looking For

Essential Knowledge/Skills and

Experience

  • Required:
  • Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field.
  • A Master’s degree in Information Security, Risk Management, or a related discipline is an added advantage.
  • Mandatory: One or more of CISSP, CISM, CISA, or equivalent senior cybersecurity certification.
  • Desirable: CGEIT, CRISC, CEH, cloud security certifications (AWS Security Specialty, Microsoft SC-100/AZ-500), ISO 27001 Lead Implementer/Auditor, or a risk management qualification (IRM, CRMA).
  • Total
  • Minimum of eight (6) years of progressive cybersecurity or IT risk experience.
  • Leadership
  • At least four (3) years in a management or team lead role with direct reports across multiple security or risk disciplines.
  • Industry
  • Prior
  • in financial services, insurance, or a regulated industry is strongly preferred.
  • Frameworks & Standards: Strong working knowledge of ISO 27001, NIST CSF, and enterprise risk frameworks (e.g. COSO ERM, ISO 31000), with practical
  • applying these in a compliance-driven environment
  • Check how your CV aligns with this job
  • Method of Application
  • Interested and qualified? Go to
  • CIC Insurance on careers.cicinsurancegroup.com
  • to apply
  • Build your CV for free.
  • Download in different templates.
Source and provenanceSource: MyJobMag Kenya. Last checked: 2026-09-27.Kazi Connect is a job discovery service, not the employer. Always confirm the vacancy at the original source.Summaries may be AI-assisted. Report inaccurate content.
Never pay to apply. Always confirm the original source and watch for payment requests, sensitive document requests, or unrealistic promises.