Technology Risk and Cybersecurity Manager
CIC Insurance Group Plc
Posted 2 hours ago
Deadline: Oct 28, 2026About the Company
CIC Insurance Group Plc is a financial services company specializing in banking and insurance, established in 1968. It operates across various sectors, providing comprehensive insurance and financial solutions.
Job Description
Reporting to the Group Director – Risk and Compliance, the Technology Risk and Cybersecurity Manager is responsible for embedding robust cybersecurity and information risk disciplines within the broader Enterprise Risk Management (ERM) framework. This entails ensuring that all technology-related risks are effectively identified, thoroughly assessed, accurately quantified, and appropriately treated in alignment with the organization’s established risk appetite and governance structures. Furthermore, the role holds comprehensive oversight for all ICT risks across the Group’s entire technology estate. This includes supervising the ICT Risk Specialist and ensuring that all infrastructure, system, and change-related risks are seamlessly integrated into the Group’s enterprise risk register, alongside emerging cybersecurity threats.
Key Responsibilities
- Support the Director, Risk and Compliance in integrating cybersecurity and ICT risk within the enterprise risk management framework, ensuring technology risks are consistently captured, assessed against agreed risk appetite, and reported to governance forums.
- Provide direct line management and professional development for the ICT Risk Specialist, Cyber Risk Specialist, and Project and Innovation Risk Specialist, setting clear objectives, coordinating workplans, conducting performance reviews, and ensuring high-quality delivery.
- Implement the CIC Group Cybersecurity Strategy, preparing reports on the Group’s cybersecurity risk appetite, monitoring quantified thresholds, and delivering quarterly and annual cybersecurity risk reports to Management, regulators, and the Board of Directors.
- Lead the Group’s cybersecurity incident response capability, directing the technical and governance response to material incidents in accordance with the Cyber Incident Response Plan.
- Direct the Group’s red and blue teaming program, commissioning annual red team adversarial simulation exercises, overseeing blue team defensive monitoring and response, reviewing findings, and driving remediation to strengthen the Group’s overall security posture.
- Provide expert input into the security design of IT architectures, system implementations, and digital transformation initiatives, ensuring security-by-design and privacy-by-design principles are embedded from project initiation.
- Implement the Group’s Third-Party Risk Management Framework for ICT-related vendors, ensuring all such relationships are assessed, classified, and managed proportionally to their risk tier, and monitoring for supply chain cyber threats and third-party data breaches.
- Support digital forensic investigations, maintaining chain of custody, and producing reports suitable for management, board, and regulatory submission or legal proceedings.
- Participate in budgeting and resource allocation for the Risk and Compliance function.
- Manage internal, external audit, and regulatory engagements related to cybersecurity and information risk, coordinating audit responses and tracking remediation of findings.
- Maintain current knowledge of developments in cybersecurity legislation, regulatory guidance, threat intelligence, and industry best practice across all operating jurisdictions, disseminating relevant updates to stakeholders.
- Maintain and enforce cybersecurity risk policies and standards, reviewing them periodically to reflect changes in the threat landscape, regulatory environment, and organizational risk appetite, and ensuring compliance across all nine subsidiaries.
Requirements
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field.
- A Master’s degree in Information Security, Risk Management, or a related discipline is an added advantage.
- Mandatory: One or more of CISSP, CISM, CISA, or equivalent senior cybersecurity certification.
- Desirable: CGEIT, CRISC, CEH, cloud security certifications (AWS Security Specialty, Microsoft SC-100/AZ-500), ISO 27001 Lead Implementer/Auditor, or a risk management qualification (IRM, CRMA).
- Minimum of six (6) years of progressive cybersecurity or IT risk experience.
- At least three (3) years in a management or team lead role with direct reports across multiple security or risk disciplines.
- Prior experience in financial services, insurance, or a regulated industry is strongly preferred.
- Strong working knowledge of ISO 27001, NIST CSF, and enterprise risk frameworks (e.g., COSO ERM, ISO 31000), with practical experience applying these in a compliance-driven environment.
Important Safety Tips
- Do not make any payment to any job request or recruiter.
- Be cautious of fraudulent job adverts and scams.
- If you suspect this listing is not genuine, please report it immediately.
How to Apply
Job Details
- Function
- Engineering & Technology
- Industry
- Banking, Finance & Insurance
- Type
- Full-time
- Location
- Nairobi
- Experience
- Senior Level
- Salary
- Open
- Posted
- Aug 29, 2026
- Views
- 7
- Deadline
- Oct 28, 2026