Cyber Risk Specialist job at CIC Insurance
New
Today
Linkedid Twitter Share on facebook
Cyber Risk Specialist
2026-04-22T07:10:05+00:00
CIC Insurance
https://cdn.greatkenyanjobs.com/jsjobsdata/data/employer/comp_7945/logo/CIC-Insurance.jpg
FULL_TIME
Nairobi
Nairobi
00100
Kenya
Insurance
Computer & IT, Science & Engineering, Business Operations
KES
MONTH
2026-04-28T17:00:00+00:00
8

About the Role

Reporting to the Technology Risk and Cybersecurity Manager, the role holder will be responsible for the identification, assessment, monitoring, and reporting of cybersecurity risks across CIC Insurance Group’s technology estate. The role supports the Technology Risk and Cybersecurity Manager in executing the ICT and cybersecurity risk programme. The role holder brings specialist cyber risk expertise that complements the broader ICT risk function focusing specifically on cybersecurity threat assessment, vulnerability management, security monitoring, and third-party cyber risk and is expected to operate with a high degree of technical competence, independence, and initiative across CIC Group.

Key Responsibilities

  • Conduct cyber risk assessments across the Group’s IT infrastructure, systems, applications, and data assets, documenting threats, vulnerabilities, likelihood, impact ratings, and recommended treatment actions in the Group’s cyber risk register.
  • Maintain and update the cyber risk register, ensuring all identified risks are classified, prioritised, assigned to risk owners, and tracked through to treatment or acceptance in line with the Group’s risk appetite framework.
  • Work closely with the ICT Risk Specialist to ensure that cybersecurity risks within the broader IT risk landscape are consistently identified, cross-referenced, and reported avoiding duplication while maintaining complete coverage of the technology risk environment.
  • Support the Project and innovation Risk Lead by providing specialist cyber risk input into project and innovation risk assessments, ensuring that cybersecurity threats and control requirements are identified and incorporated into project plans, Risk register, and change requests from initiation through to delivery.
  • Lead vulnerability screening across the Group’s technology environment, develop curative strategies for identified vulnerabilities, and track remediation progress.
  • Conduct real-time security monitoring, investigate and respond to security alerts from firewalls, intrusion detection systems, anti-malware software, and other monitoring tools, and escalate material incidents in accordance with the Cyber Incident Response Plan.
  • Support the Technology Risk and Cybersecurity Manager in leading the response to cybersecurity incidents, including triage, containment, evidence documentation, and preparation of incident reports suitable for internal governance or IRA submission.
  • Conduct cyber risk assessments for third-party vendors and technology partners, reviewing security questionnaires, certifications, penetration test reports, and incident history maintaining the third-party cyber risk register and escalating material findings to the Cybersecurity Manager.
  • Support annual penetration testing exercises and red / blue teaming activities, reviewing findings with technical teams and tracking remediation actions to closure.
  • Prepare cyber risk reports, dashboards, and management information for the Technology Risk and Cybersecurity Manager, including quarterly emerging ICT risk research reports and risk presentations for governance committees.
  • Support the delivery of cybersecurity awareness activities, contribute to staff training materials, and share threat intelligence and security alerts with relevant stakeholders across the Group.

General Responsibilities;

  • Participate in departmental planning, budgeting, and various governance meetings and committees as required.
  • Stay current with developments in the cybersecurity field, share emerging threat intelligence with the Cybersecurity Manager and relevant teams, and recommend new security technologies where appropriate.
  • Support internal and external audit engagements on cybersecurity matters, providing evidence, analysis, and technical input as required.

Who We’re Looking For

Essential Knowledge/Skills and Experience Required:

  • Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field.
  • Relevant certifications such as CISA, CISM, CISP, CEH or similar.
  • Additional certifications are a plus, including cloud security certifications (AWS, Azure, GCP).
  • Minimum of four (4) years of hands-on IT security experience
  • Experience in financial services and insurance is preferred
  • Proven experience in conducting penetration tests vulnerability assessments and leading closure of findings through collaborating with various stakeholders (Internal & External IT Auditors, IT Risk, External Pentesters etc)
  • Strong knowledge of security frameworks and standards (e.g., ISO 27001, NIST).
  • Experience working across multiple African jurisdictions is an advantage.

Key Competencies:

  • Strong technical knowledge of cybersecurity risk management principles.
  • Ability to conduct and document structured cyber risk assessments, maintain risk registers, and produce clear risk reports and dashboards for non-technical management audiences.
  • Strong analytical, report-writing, and presentation skills.
  • High personal integrity, discretion, and reliability in handling sensitive security information.
  • Exceptional personal integrity, absolute reliability, and the highest standards of professional conduct.
  • Intellectual authority and technical confidence.
  • Stakeholder management and communication skills.
  • Established strategic planning and organizational skills.
  • Deep awareness of both the internal and external threat environment, including sector-specific attack patterns and adversary motivation.
  • Conduct cyber risk assessments across the Group’s IT infrastructure, systems, applications, and data assets, documenting threats, vulnerabilities, likelihood, impact ratings, and recommended treatment actions in the Group’s cyber risk register.
  • Maintain and update the cyber risk register, ensuring all identified risks are classified, prioritised, assigned to risk owners, and tracked through to treatment or acceptance in line with the Group’s risk appetite framework.
  • Work closely with the ICT Risk Specialist to ensure that cybersecurity risks within the broader IT risk landscape are consistently identified, cross-referenced, and reported avoiding duplication while maintaining complete coverage of the technology risk environment.
  • Support the Project and innovation Risk Lead by providing specialist cyber risk input into project and innovation risk assessments, ensuring that cybersecurity threats and control requirements are identified and incorporated into project plans, Risk register, and change requests from initiation through to delivery.
  • Lead vulnerability screening across the Group’s technology environment, develop curative strategies for identified vulnerabilities, and track remediation progress.
  • Conduct real-time security monitoring, investigate and respond to security alerts from firewalls, intrusion detection systems, anti-malware software, and other monitoring tools, and escalate material incidents in accordance with the Cyber Incident Response Plan.
  • Support the Technology Risk and Cybersecurity Manager in leading the response to cybersecurity incidents, including triage, containment, evidence documentation, and preparation of incident reports suitable for internal governance or IRA submission.
  • Conduct cyber risk assessments for third-party vendors and technology partners, reviewing security questionnaires, certifications, penetration test reports, and incident history maintaining the third-party cyber risk register and escalating material findings to the Cybersecurity Manager.
  • Support annual penetration testing exercises and red / blue teaming activities, reviewing findings with technical teams and tracking remediation actions to closure.
  • Prepare cyber risk reports, dashboards, and management information for the Technology Risk and Cybersecurity Manager, including quarterly emerging ICT risk research reports and risk presentations for governance committees.
  • Support the delivery of cybersecurity awareness activities, contribute to staff training materials, and share threat intelligence and security alerts with relevant stakeholders across the Group.
  • Participate in departmental planning, budgeting, and various governance meetings and committees as required.
  • Stay current with developments in the cybersecurity field, share emerging threat intelligence with the Cybersecurity Manager and relevant teams, and recommend new security technologies where appropriate.
  • Support internal and external audit engagements on cybersecurity matters, providing evidence, analysis, and technical input as required.
  • Strong technical knowledge of cybersecurity risk management principles.
  • Ability to conduct and document structured cyber risk assessments, maintain risk registers, and produce clear risk reports and dashboards for non-technical management audiences.
  • Strong analytical, report-writing, and presentation skills.
  • High personal integrity, discretion, and reliability in handling sensitive security information.
  • Exceptional personal integrity, absolute reliability, and the highest standards of professional conduct.
  • Intellectual authority and technical confidence.
  • Stakeholder management and communication skills.
  • Established strategic planning and organizational skills.
  • Deep awareness of both the internal and external threat environment, including sector-specific attack patterns and adversary motivation.
  • Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field.
  • Relevant certifications such as CISA, CISM, CISP, CEH or similar.
  • Additional certifications are a plus, including cloud security certifications (AWS, Azure, GCP).
  • Proven experience in conducting penetration tests vulnerability assessments and leading closure of findings through collaborating with various stakeholders (Internal & External IT Auditors, IT Risk, External Pentesters etc)
  • Strong knowledge of security frameworks and standards (e.g., ISO 27001, NIST).
bachelor degree
12
JOB-69e8744dcd8bc

Vacancy title:
Cyber Risk Specialist

[Type: FULL_TIME, Industry: Insurance, Category: Computer & IT, Science & Engineering, Business Operations]

Jobs at:
CIC Insurance

Deadline of this Job:
Tuesday, April 28 2026

Duty Station:
Nairobi | Nairobi

Summary
Date Posted: Wednesday, April 22 2026, Base Salary: Not Disclosed

Similar Jobs in Kenya
Learn more about CIC Insurance
CIC Insurance jobs in Kenya

JOB DETAILS:

About the Role

Reporting to the Technology Risk and Cybersecurity Manager, the role holder will be responsible for the identification, assessment, monitoring, and reporting of cybersecurity risks across CIC Insurance Group’s technology estate. The role supports the Technology Risk and Cybersecurity Manager in executing the ICT and cybersecurity risk programme. The role holder brings specialist cyber risk expertise that complements the broader ICT risk function focusing specifically on cybersecurity threat assessment, vulnerability management, security monitoring, and third-party cyber risk and is expected to operate with a high degree of technical competence, independence, and initiative across CIC Group.

Key Responsibilities

  • Conduct cyber risk assessments across the Group’s IT infrastructure, systems, applications, and data assets, documenting threats, vulnerabilities, likelihood, impact ratings, and recommended treatment actions in the Group’s cyber risk register.
  • Maintain and update the cyber risk register, ensuring all identified risks are classified, prioritised, assigned to risk owners, and tracked through to treatment or acceptance in line with the Group’s risk appetite framework.
  • Work closely with the ICT Risk Specialist to ensure that cybersecurity risks within the broader IT risk landscape are consistently identified, cross-referenced, and reported avoiding duplication while maintaining complete coverage of the technology risk environment.
  • Support the Project and innovation Risk Lead by providing specialist cyber risk input into project and innovation risk assessments, ensuring that cybersecurity threats and control requirements are identified and incorporated into project plans, Risk register, and change requests from initiation through to delivery.
  • Lead vulnerability screening across the Group’s technology environment, develop curative strategies for identified vulnerabilities, and track remediation progress.
  • Conduct real-time security monitoring, investigate and respond to security alerts from firewalls, intrusion detection systems, anti-malware software, and other monitoring tools, and escalate material incidents in accordance with the Cyber Incident Response Plan.
  • Support the Technology Risk and Cybersecurity Manager in leading the response to cybersecurity incidents, including triage, containment, evidence documentation, and preparation of incident reports suitable for internal governance or IRA submission.
  • Conduct cyber risk assessments for third-party vendors and technology partners, reviewing security questionnaires, certifications, penetration test reports, and incident history maintaining the third-party cyber risk register and escalating material findings to the Cybersecurity Manager.
  • Support annual penetration testing exercises and red / blue teaming activities, reviewing findings with technical teams and tracking remediation actions to closure.
  • Prepare cyber risk reports, dashboards, and management information for the Technology Risk and Cybersecurity Manager, including quarterly emerging ICT risk research reports and risk presentations for governance committees.
  • Support the delivery of cybersecurity awareness activities, contribute to staff training materials, and share threat intelligence and security alerts with relevant stakeholders across the Group.

General Responsibilities;

  • Participate in departmental planning, budgeting, and various governance meetings and committees as required.
  • Stay current with developments in the cybersecurity field, share emerging threat intelligence with the Cybersecurity Manager and relevant teams, and recommend new security technologies where appropriate.
  • Support internal and external audit engagements on cybersecurity matters, providing evidence, analysis, and technical input as required.

Who We’re Looking For

Essential Knowledge/Skills and Experience Required:

  • Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field.
  • Relevant certifications such as CISA, CISM, CISP, CEH or similar.
  • Additional certifications are a plus, including cloud security certifications (AWS, Azure, GCP).
  • Minimum of four (4) years of hands-on IT security experience
  • Experience in financial services and insurance is preferred
  • Proven experience in conducting penetration tests vulnerability assessments and leading closure of findings through collaborating with various stakeholders (Internal & External IT Auditors, IT Risk, External Pentesters etc)
  • Strong knowledge of security frameworks and standards (e.g., ISO 27001, NIST).
  • Experience working across multiple African jurisdictions is an advantage.

Key Competencies:

  • Strong technical knowledge of cybersecurity risk management principles.
  • Ability to conduct and document structured cyber risk assessments, maintain risk registers, and produce clear risk reports and dashboards for non-technical management audiences.
  • Strong analytical, report-writing, and presentation skills.
  • High personal integrity, discretion, and reliability in handling sensitive security information.
  • Exceptional personal integrity, absolute reliability, and the highest standards of professional conduct.
  • Intellectual authority and technical confidence.
  • Stakeholder management and communication skills.
  • Established strategic planning and organizational skills.
  • Deep awareness of both the internal and external threat environment, including sector-specific attack patterns and adversary motivation.

Work Hours: 8

Experience in Months: 12

Level of Education: bachelor degree

Job application procedure

Application Link:

Never pay for any notarisation, certificate or assessment as part of any recruitment process. When in doubt, contact us

All Jobs | QUICK ALERT SUBSCRIPTION

Job Info
Job Category: Computer/ IT jobs in Kenya
Job Type: Full-time
Deadline of this Job: Tuesday, April 28 2026
Duty Station: Nairobi | Nairobi
Posted: 22-04-2026
No of Jobs: 1
Start Publishing: 22-04-2026
Stop Publishing (Put date of 2030): 10-10-2076
Apply Now
Notification Board

Join a Focused Community on job search to uncover both advertised and non-advertised jobs that you may not be aware of. A jobs WhatsApp Group Community can ensure that you know the opportunities happening around you and a jobs Facebook Group Community provides an opportunity to discuss with employers who need to fill urgent position. Click the links to join. You can view previously sent Email Alerts here incase you missed them and Subscribe so that you never miss out.

Caution: Never Pay Money in a Recruitment Process.

Some smart scams can trick you into paying for Psychometric Tests.