C

Technology Risk and Cybersecurity Manager

CIC Insurance Group Plc

Nairobi Full-time Banking, Finance & Insurance Engineering & Technology Senior Level
Salary: Open / Negotiable

Posted 2 hours ago

Deadline: Oct 28, 2026

About the Company

CIC Insurance Group Plc is a financial services company specializing in banking and insurance, established in 1968. It operates across various sectors, providing comprehensive insurance and financial solutions.

Job Description

Reporting to the Group Director – Risk and Compliance, the Technology Risk and Cybersecurity Manager is responsible for embedding robust cybersecurity and information risk disciplines within the broader Enterprise Risk Management (ERM) framework. This entails ensuring that all technology-related risks are effectively identified, thoroughly assessed, accurately quantified, and appropriately treated in alignment with the organization’s established risk appetite and governance structures. Furthermore, the role holds comprehensive oversight for all ICT risks across the Group’s entire technology estate. This includes supervising the ICT Risk Specialist and ensuring that all infrastructure, system, and change-related risks are seamlessly integrated into the Group’s enterprise risk register, alongside emerging cybersecurity threats.

Key Responsibilities

  1. Support the Director, Risk and Compliance in integrating cybersecurity and ICT risk within the enterprise risk management framework, ensuring technology risks are consistently captured, assessed against agreed risk appetite, and reported to governance forums.
  2. Provide direct line management and professional development for the ICT Risk Specialist, Cyber Risk Specialist, and Project and Innovation Risk Specialist, setting clear objectives, coordinating workplans, conducting performance reviews, and ensuring high-quality delivery.
  3. Implement the CIC Group Cybersecurity Strategy, preparing reports on the Group’s cybersecurity risk appetite, monitoring quantified thresholds, and delivering quarterly and annual cybersecurity risk reports to Management, regulators, and the Board of Directors.
  4. Lead the Group’s cybersecurity incident response capability, directing the technical and governance response to material incidents in accordance with the Cyber Incident Response Plan.
  5. Direct the Group’s red and blue teaming program, commissioning annual red team adversarial simulation exercises, overseeing blue team defensive monitoring and response, reviewing findings, and driving remediation to strengthen the Group’s overall security posture.
  6. Provide expert input into the security design of IT architectures, system implementations, and digital transformation initiatives, ensuring security-by-design and privacy-by-design principles are embedded from project initiation.
  7. Implement the Group’s Third-Party Risk Management Framework for ICT-related vendors, ensuring all such relationships are assessed, classified, and managed proportionally to their risk tier, and monitoring for supply chain cyber threats and third-party data breaches.
  8. Support digital forensic investigations, maintaining chain of custody, and producing reports suitable for management, board, and regulatory submission or legal proceedings.
  9. Participate in budgeting and resource allocation for the Risk and Compliance function.
  10. Manage internal, external audit, and regulatory engagements related to cybersecurity and information risk, coordinating audit responses and tracking remediation of findings.
  11. Maintain current knowledge of developments in cybersecurity legislation, regulatory guidance, threat intelligence, and industry best practice across all operating jurisdictions, disseminating relevant updates to stakeholders.
  12. Maintain and enforce cybersecurity risk policies and standards, reviewing them periodically to reflect changes in the threat landscape, regulatory environment, and organizational risk appetite, and ensuring compliance across all nine subsidiaries.

Requirements

  1. Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field.
  2. A Master’s degree in Information Security, Risk Management, or a related discipline is an added advantage.
  3. Mandatory: One or more of CISSP, CISM, CISA, or equivalent senior cybersecurity certification.
  4. Desirable: CGEIT, CRISC, CEH, cloud security certifications (AWS Security Specialty, Microsoft SC-100/AZ-500), ISO 27001 Lead Implementer/Auditor, or a risk management qualification (IRM, CRMA).
  5. Minimum of six (6) years of progressive cybersecurity or IT risk experience.
  6. At least three (3) years in a management or team lead role with direct reports across multiple security or risk disciplines.
  7. Prior experience in financial services, insurance, or a regulated industry is strongly preferred.
  8. Strong working knowledge of ISO 27001, NIST CSF, and enterprise risk frameworks (e.g., COSO ERM, ISO 31000), with practical experience applying these in a compliance-driven environment.

Important Safety Tips

  • Do not make any payment to any job request or recruiter.
  • Be cautious of fraudulent job adverts and scams.
  • If you suspect this listing is not genuine, please report it immediately.

How to Apply

Sign in to view application details

Sign In to Apply

No account? Register free

Job Details

Function
Engineering & Technology
Industry
Banking, Finance & Insurance
Type
Full-time
Location
Nairobi
Experience
Senior Level
Salary
Open
Posted
Aug 29, 2026
Views
7
Deadline
Oct 28, 2026

Share This Job

Related Jobs

C

Regional IT Lead

CIC Insurance Group Plc

Kenya Full-time
View Job
C

IT Security Manager

CIC Insurance Group Plc

Kenya Full-time
View Job
I

Associate, Cards Dispute Management

I&M Bank Kenya Limited

Nairobi Full-time
View Job
ATS CV Builder