Manager – IT Security job at HF Group
Website :
6 Days Ago
Linkedid Twitter Share on facebook
Manager – IT Security
2026-07-29T16:25:09+00:00
HF Group
https://cdn.greatkenyanjobs.com/jsjobsdata/data/employer/comp_8010/logo/hf.png
FULL_TIME
Nairobi
Nairobi
00100
Kenya
Professional Services
Management, Computer & IT, Business Operations
KES
MONTH
2026-08-15T17:00:00+00:00
8

About the Role

The Manager – IT Security supports the Head of ICT Security / CISO in strengthening the Group’s information security posture by coordinating IT security governance, cyber risk management, SOC operations oversight, security assurance, audit remediation, regulatory compliance and proactive cyber resilience across the Group. The role ensures that security policies, standards, controls, monitoring processes and assurance activities are embedded into technology operations, digital channels, projects, third-party engagements, and business processes. The role holder provides security support to the substantive Data Protection Officer by ensuring that technical and organisational security controls for personal data are defined, implemented, tested, monitored, and evidenced. This role supports privacy governance through technology control implementation, security assurance, access control, monitoring, incident coordination, third-party reviews, and remediation tracking.

Key Accountabilities

  • Data Protection and Privacy Security Support - Support the substantive Data Protection Officer by providing information security input into privacy governance, DPIAs, data classification, access controls, encryption, logging and monitoring, data loss prevention, third-party risk reviews, breach investigation, audit evidence and remediation tracking.
  • IT Security Governance and Strategy Execution - Support the CISO in implementing the Group information security strategy, governance framework, policies, standards, procedures, operating model and control assurance programme.
  • Regulatory Compliance and Security Reporting - Coordinate compliance reviews, evidence packs, management attestations, regulatory responses, control self-assessments and reporting to ICT, Risk, Compliance, Audit and management governance forums.
  • Cyber Risk, Audit and Remediation Management - Coordinate identification, assessment, monitoring, reporting and remediation of ICT and cyber risks across the Group, including audit and regulatory findings to closure.
  • SOC Operations Oversight and Incident Coordination - Provide management oversight of security monitoring, incident triage, escalation, response coordination, threat intelligence, SOC use cases, alert handling, incident reporting and post-incident remediation.
  • ICT Resilience, Disaster Recovery and Cyber Recovery Support - Coordinate security input into ICT business continuity, disaster recovery, cyber recovery planning, backup assurance, recovery testing and remediation of resilience gaps.
  • Identity and Access Governance - Maintain access governance covering privileged access, periodic user access reviews, role-based access control, joiner-mover-leaver controls, access certification, segregation of duties, exceptions, remediation tracking and evidence management.
  • Security Assurance for Projects, Platforms and Third Parties - Provide security assurance over systems, infrastructure, digital channels, cloud services, APIs, integrations, third parties and technology changes.

Qualifications

  • Bachelor's degree in information security, Computer Science, Information Systems, Information Technology, Cybersecurity, Risk Management, or related fields.
  • Relevant certifications such as CISM, CISSP, CRISC, CISA, ISO 27001 Lead Implementer/Lead Auditor, CompTIA Security+, CBCP or equivalent will be an added advantage.
  • At least 5 years’ experience in information security, IT governance, cyber risk, security operations, security assurance, or technology risk management.
  • Understanding of implementation of technical security controls, identity and access management and designing security solutions in a dynamic environment
  • At least 2 years in a supervisory or managerial role within a highly regulated or digitized environment.
  • Demonstrable experience in security governance, SOC oversight, audit remediation, regulatory compliance, access governance, third-party assurance, project security assurance, incident coordination, cyber resilience and executive reporting.
  • Understanding of IT Audit processes, technical security testing (Red Team, Blue Team, Penetration Testing) and Cyber Incident Response including data protection guidelines.
  • Data Protection and Privacy Security Support - Support the substantive Data Protection Officer by providing information security input into privacy governance, DPIAs, data classification, access controls, encryption, logging and monitoring, data loss prevention, third-party risk reviews, breach investigation, audit evidence and remediation tracking.
  • IT Security Governance and Strategy Execution - Support the CISO in implementing the Group information security strategy, governance framework, policies, standards, procedures, operating model and control assurance programme.
  • Regulatory Compliance and Security Reporting - Coordinate compliance reviews, evidence packs, management attestations, regulatory responses, control self-assessments and reporting to ICT, Risk, Compliance, Audit and management governance forums.
  • Cyber Risk, Audit and Remediation Management - Coordinate identification, assessment, monitoring, reporting and remediation of ICT and cyber risks across the Group, including audit and regulatory findings to closure.
  • SOC Operations Oversight and Incident Coordination - Provide management oversight of security monitoring, incident triage, escalation, response coordination, threat intelligence, SOC use cases, alert handling, incident reporting and post-incident remediation.
  • ICT Resilience, Disaster Recovery and Cyber Recovery Support - Coordinate security input into ICT business continuity, disaster recovery, cyber recovery planning, backup assurance, recovery testing and remediation of resilience gaps.
  • Identity and Access Governance - Maintain access governance covering privileged access, periodic user access reviews, role-based access control, joiner-mover-leaver controls, access certification, segregation of duties, exceptions, remediation tracking and evidence management.
  • Security Assurance for Projects, Platforms and Third Parties - Provide security assurance over systems, infrastructure, digital channels, cloud services, APIs, integrations, third parties and technology changes.
  • Information security
  • IT governance
  • Cyber risk management
  • Security operations
  • Security assurance
  • Technology risk management
  • Technical security controls implementation
  • Identity and access management
  • Security solution design
  • Security governance
  • SOC oversight
  • Audit remediation
  • Regulatory compliance
  • Access governance
  • Third-party assurance
  • Project security assurance
  • Incident coordination
  • Cyber resilience
  • Executive reporting
  • IT Audit processes
  • Technical security testing (Red Team, Blue Team, Penetration Testing)
  • Cyber Incident Response
  • Data protection guidelines
  • Bachelor's degree in information security, Computer Science, Information Systems, Information Technology, Cybersecurity, Risk Management, or related fields.
  • Relevant certifications such as CISM, CISSP, CRISC, CISA, ISO 27001 Lead Implementer/Lead Auditor, CompTIA Security+, CBCP or equivalent will be an added advantage.
  • At least 5 years’ experience in information security, IT governance, cyber risk, security operations, security assurance, or technology risk management.
  • Understanding of implementation of technical security controls, identity and access management and designing security solutions in a dynamic environment
  • At least 2 years in a supervisory or managerial role within a highly regulated or digitized environment.
  • Demonstrable experience in security governance, SOC oversight, audit remediation, regulatory compliance, access governance, third-party assurance, project security assurance, incident coordination, cyber resilience and executive reporting.
  • Understanding of IT Audit processes, technical security testing (Red Team, Blue Team, Penetration Testing) and Cyber Incident Response including data protection guidelines.
bachelor degree
60
JOB-6a6a296563a53

Vacancy title:
Manager – IT Security

[Type: FULL_TIME, Industry: Professional Services, Category: Management, Computer & IT, Business Operations]

Jobs at:
HF Group

Deadline of this Job:
Saturday, August 15 2026

Duty Station:
Nairobi | Nairobi

Summary
Date Posted: Wednesday, July 29 2026, Base Salary: Not Disclosed

Similar Jobs in Kenya
Learn more about HF Group
HF Group jobs in Kenya

JOB DETAILS:

About the Role

The Manager – IT Security supports the Head of ICT Security / CISO in strengthening the Group’s information security posture by coordinating IT security governance, cyber risk management, SOC operations oversight, security assurance, audit remediation, regulatory compliance and proactive cyber resilience across the Group. The role ensures that security policies, standards, controls, monitoring processes and assurance activities are embedded into technology operations, digital channels, projects, third-party engagements, and business processes. The role holder provides security support to the substantive Data Protection Officer by ensuring that technical and organisational security controls for personal data are defined, implemented, tested, monitored, and evidenced. This role supports privacy governance through technology control implementation, security assurance, access control, monitoring, incident coordination, third-party reviews, and remediation tracking.

Key Accountabilities

  • Data Protection and Privacy Security Support - Support the substantive Data Protection Officer by providing information security input into privacy governance, DPIAs, data classification, access controls, encryption, logging and monitoring, data loss prevention, third-party risk reviews, breach investigation, audit evidence and remediation tracking.
  • IT Security Governance and Strategy Execution - Support the CISO in implementing the Group information security strategy, governance framework, policies, standards, procedures, operating model and control assurance programme.
  • Regulatory Compliance and Security Reporting - Coordinate compliance reviews, evidence packs, management attestations, regulatory responses, control self-assessments and reporting to ICT, Risk, Compliance, Audit and management governance forums.
  • Cyber Risk, Audit and Remediation Management - Coordinate identification, assessment, monitoring, reporting and remediation of ICT and cyber risks across the Group, including audit and regulatory findings to closure.
  • SOC Operations Oversight and Incident Coordination - Provide management oversight of security monitoring, incident triage, escalation, response coordination, threat intelligence, SOC use cases, alert handling, incident reporting and post-incident remediation.
  • ICT Resilience, Disaster Recovery and Cyber Recovery Support - Coordinate security input into ICT business continuity, disaster recovery, cyber recovery planning, backup assurance, recovery testing and remediation of resilience gaps.
  • Identity and Access Governance - Maintain access governance covering privileged access, periodic user access reviews, role-based access control, joiner-mover-leaver controls, access certification, segregation of duties, exceptions, remediation tracking and evidence management.
  • Security Assurance for Projects, Platforms and Third Parties - Provide security assurance over systems, infrastructure, digital channels, cloud services, APIs, integrations, third parties and technology changes.

Qualifications

  • Bachelor's degree in information security, Computer Science, Information Systems, Information Technology, Cybersecurity, Risk Management, or related fields.
  • Relevant certifications such as CISM, CISSP, CRISC, CISA, ISO 27001 Lead Implementer/Lead Auditor, CompTIA Security+, CBCP or equivalent will be an added advantage.
  • At least 5 years’ experience in information security, IT governance, cyber risk, security operations, security assurance, or technology risk management.
  • Understanding of implementation of technical security controls, identity and access management and designing security solutions in a dynamic environment
  • At least 2 years in a supervisory or managerial role within a highly regulated or digitized environment.
  • Demonstrable experience in security governance, SOC oversight, audit remediation, regulatory compliance, access governance, third-party assurance, project security assurance, incident coordination, cyber resilience and executive reporting.
  • Understanding of IT Audit processes, technical security testing (Red Team, Blue Team, Penetration Testing) and Cyber Incident Response including data protection guidelines.

Work Hours: 8

Experience in Months: 60

Level of Education: bachelor degree

Job application procedure

Click Here to Apply Now

All Jobs | QUICK ALERT SUBSCRIPTION

Job Info
Job Category: Computer/ IT jobs in Kenya
Job Type: Full-time
Deadline of this Job: Saturday, August 15 2026
Duty Station: Nairobi | Nairobi
Posted: 29-07-2026
No of Jobs: 1
Start Publishing: 29-07-2026
Stop Publishing (Put date of 2030): 10-10-2076
Apply Now
Notification Board

Join a Focused Community on job search to uncover both advertised and non-advertised jobs that you may not be aware of. A jobs WhatsApp Group Community can ensure that you know the opportunities happening around you and a jobs Facebook Group Community provides an opportunity to discuss with employers who need to fill urgent position. Click the links to join. You can view previously sent Email Alerts here incase you missed them and Subscribe so that you never miss out.

Caution: Never Pay Money in a Recruitment Process.

Some smart scams can trick you into paying for Psychometric Tests.