IT Security Manager
CIC Insurance Group Plc
Posted 2 hours ago
Deadline: Oct 28, 2026About the Company
CIC Insurance Group Plc is a Kenyan insurance and financial services provider, established in 1968. It operates in the banking, financial services, and insurance sectors, offering a range of products and services.
Job Description
This role involves protecting the organization's information assets, technology infrastructure, applications, and digital services from cyber and information security threats. The manager provides strategic direction and hands-on leadership in implementing, monitoring, and continuously improving information security controls. They ensure compliance with applicable regulatory requirements, company policies, and recognized security frameworks like ISO/IEC 27001 and NIST. The role requires close collaboration with IT, Risk, Internal Audit, business teams, project teams, and external partners to integrate security-by-design principles into technology initiatives, proactively manage cyber risks, and enhance the organization’s overall cyber resilience.
Key Responsibilities
- Manage and continuously improve the organization's information security infrastructure and controls, including firewalls, IDS/IPS, endpoint protection/EDR, PAM, NAC, patch and vulnerability management, and cloud security controls across AWS and Microsoft Azure.
- Lead the technology security assessment program, covering vulnerability assessments, penetration testing, security reviews, configuration assessments, and risk assessments.
- Develop, review, implement, and enforce information security policies, standards, procedures, and guidelines, ensuring alignment with business requirements, regulatory obligations, and industry standards.
- Develop and deliver a comprehensive information security and cybersecurity awareness program, conducting regular campaigns on topics like phishing, social engineering, password security, data protection, remote working, acceptable use, and emerging cyber threats.
- Collaborate with project teams, IT managers, architects, developers, and business stakeholders to embed security-by-design principles throughout the technology lifecycle.
- Provide security architecture guidance and recommendations for new systems, applications, integrations, infrastructure, and cloud initiatives.
- Monitor the evolving cyber threat landscape and assess its potential impact on the organization.
- Lead and coordinate the cybersecurity incident response lifecycle, from detection and identification to investigation, analysis, containment, eradication, recovery, and post-incident review.
- Provide cybersecurity oversight for business continuity and disaster recovery programs.
- Establish and monitor security patching and vulnerability remediation requirements across technology platforms.
- Establish and maintain effective relationships with cybersecurity and technology security vendors.
- Prepare regular information security reports and dashboards for the Group Head of IT and other relevant management forums.
Requirements
- Hold a Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field.
- Possess relevant professional qualifications such as CISA, CISM, CISP, CEH, or similar. Additional certifications in AWS, Azure, and GCP are advantageous.
- Have a minimum of seven (7) years of hands-on IT security experience.
- Include at least two (2) years of experience in a team leadership role.
- Demonstrate experience within the financial services industry.
- Show proven experience in conducting penetration tests and vulnerability assessments, and leading the closure of findings through collaboration with internal and external IT auditors, risk, and compliance departments.
- Exhibit strong knowledge of security frameworks and standards, such as ISO 27001 and NIST.
- Be skilled in IT risk management, cyber threat mitigation, and hands-on problem-solving with strong analytical abilities.
- Possess proven leadership and communication skills for cross-functional teams.
- Be a strategic, adaptable, and budget-conscious decision-maker, capable of aligning security initiatives with business objectives and managing vendor relations effectively.
Important Safety Tips
- Do not make any payment to any job request or recruiter.
- Be cautious of fraudulent job adverts and scams.
- If you suspect this listing is not genuine, please report it immediately.
How to Apply
Job Details
- Function
- Engineering & Technology
- Industry
- Banking, Finance & Insurance
- Type
- Full-time
- Experience
- Senior Level
- Salary
- Open
- Posted
- Aug 29, 2026
- Views
- 7
- Deadline
- Oct 28, 2026