Senior Manager – Information Security Governance, Data Protection and Compliance job at HF Group
New
Today
Linkedid Twitter Share on facebook
Senior Manager – Information Security Governance, Data Protection and Compliance
2025-12-30T15:06:36+00:00
HF Group
https://cdn.greatkenyanjobs.com/jsjobsdata/data/employer/comp_8010/logo/hf.png
FULL_TIME
 
Nairobi
Nairobi
00100
Kenya
Professional Services
Management, Computer & IT, Business Operations
KES
 
MONTH
2026-01-07T17:00:00+00:00
 
 
8

Housing Finance Company of Kenya was incorporated as the premier mortgage Finance Institution in Kenya licensed under the Banking Act with the CDC and the GoK owning 60% and 40% respectively.

Housing Finance started operations with the main objective of implementing the government’s policy of promoting thrift and home ownership by lending ...

  • Facilitate data privacy through transparent data protection policies, procedures and systems.
  • Act as point of contact with any supervisory authorities and internal teams on data processing-related issues
  • Identify and evaluate the organization’s data processing activities
  • Provide guidance in conducting Data Protection Impact Assessments (DPIAs)
  • Inform and advise the organization (data controller/data processor) and employees involved in data processing of their obligations to comply with Data Protection Act and other applicable regulations.
  • Monitor Compliance with the Data Protection Act, as well as internal polices related to various data protection activities, including awareness, training, and internal audits
  • Co-operate with the Data Commissioner and any other authority on matters relating to data protection.
  • Provide guidance to ICT and drive technology best practices (COBIT, ISO 27001, PCI DSS), while enshrining these with the ICT policies and practices.
  • Keep up-to-date with regulatory guidelines (e.g. CBK prudential guidelines etc.) affecting information technology and information security, and continuously update the organization’s policies, standards and procedures
  • Manage risk management tools and practices within ICT; including Risk Control Self Assessments (RCSA) and ICT risk registers, across the organization.
  • Manage and act as the key liaison for all Internal and External ICT and IS audit and risk assessment engagements across the organization.
  • Track and report on ICT audit and risk findings, including managing ICT management forums for discussion and reporting of these findings.
  • Manage the Information Security Awareness program across the organization and with external stakeholders, including awareness trainings, tools and reporting.
  • Risk champion for the ICT department
  • Manage the ICT Business Continuity Program across the organization.
  • Manage the ICT Business Impact Analysis process and outputs.
  • In liaison with the other ICT stakeholders, maintain up-to-date disaster recovery plans and ensure recovery procedures are effective for restoration of key ICT systems and therefore resumption of critical business processes
  • Manage Disaster Recovery and backup testing schedules, reporting and remedial actions.
  • Regular monitoring and reporting on any significant gaps on ICT business continuity practices, including data replication and backups.
  • Maintain a robust program for system user access management.
  • Participate and contribute towards developing and supporting progressive ICT practices (e.g. agile, DevOps)
  • Provide ICT security assurance to business projects to ensure that any new products, services, channels and other ICT changes introduced meet the security compliance threshold.
  • Knowledge to develop and manage Information Security strategy and policy frameworks.
  • Technical skills to effectively perform IS security management activities/tasks in a manner that consistently achieves established quality standards or benchmarks.
  • Knowledge of the Kenya Data Protection Act (2019) and related laws as well as applicable CBK Prudential Guidelines on data protection and privacy.
  • Knowledge to develop and manage Business Continuity and Disaster Recovery plans and processes.
  • Knowledge and effective application of all relevant banking policies, processes, procedures and guidelines to consistently achieve required compliance standards or benchmarks.
  • Knowledge and application of modern IS security management practices and best practice compliance standards in financial services industry, to proactively define and implement security quality improvements in line with technological and product changes.
  • Performance management to optimise personal and team productivity.
  • Interpersonal skills to effectively communicate with and manage expectations of all team members and other stakeholders who impact performance.
  • Self-empowerment to enable the development of open communication, teamwork and trust that are needed to support true performance and a customer-service-oriented culture.
  • Demonstrable integrity and ethical practices.
  • Bachelor’s Degree in, Information Systems, Computer Science, Information Security or related field required
  • At least 7 years’ experience in IT, Information Security or IT Governance, with 2 years in a managerial role within a highly digitized organization.
  • 3+ years’ experience conducting IT compliance assessments or IT governance and assurance/compliance assessments in an organization
  • Relevant certifications in information security knowledge areas, such as Information Systems Audit, Information Security Management and Business Continuity/Disaster Recovery.
  • Knowledge of information security best practice & compliance standards.
  • Knowledge and experience in audit management and reporting
  • Knowledge of relevant CBK Prudential Guidelines and laws applicable to data protection and privacy.
  • Prior experience working within a financial service organization will be an added advantage
bachelor degree
12
JOB-6953ea7c4cd11

Vacancy title:
Senior Manager – Information Security Governance, Data Protection and Compliance

[Type: FULL_TIME, Industry: Professional Services, Category: Management, Computer & IT, Business Operations]

Jobs at:
HF Group

Deadline of this Job:
Wednesday, January 7 2026

Duty Station:
Nairobi | Nairobi

Summary
Date Posted: Tuesday, December 30 2025, Base Salary: Not Disclosed

Similar Jobs in Kenya
Learn more about HF Group
HF Group jobs in Kenya

JOB DETAILS:

Housing Finance Company of Kenya was incorporated as the premier mortgage Finance Institution in Kenya licensed under the Banking Act with the CDC and the GoK owning 60% and 40% respectively.

Housing Finance started operations with the main objective of implementing the government’s policy of promoting thrift and home ownership by lending ...

 

Work Hours: 8

Experience in Months: 12

Level of Education: bachelor degree

Job application procedure

Application Link:

Click Here to Apply Now

 

All Jobs | QUICK ALERT SUBSCRIPTION

Job Info
Job Category: Administrative jobs in Kenya
Job Type: Full-time
Deadline of this Job: Wednesday, January 7 2026
Duty Station: Nairobi | Nairobi
Posted: 30-12-2025
No of Jobs: 1
Start Publishing: 30-12-2025
Stop Publishing (Put date of 2030): 10-10-2076
Apply Now
Notification Board

Join a Focused Community on job search to uncover both advertised and non-advertised jobs that you may not be aware of. A jobs WhatsApp Group Community can ensure that you know the opportunities happening around you and a jobs Facebook Group Community provides an opportunity to discuss with employers who need to fill urgent position. Click the links to join. You can view previously sent Email Alerts here incase you missed them and Subscribe so that you never miss out.

Caution: Never Pay Money in a Recruitment Process.

Some smart scams can trick you into paying for Psychometric Tests.