IT Security Manager job at CIC Insurance
New
Today
Linkedid Twitter Share on facebook
IT Security Manager
2026-08-29T10:41:25+00:00
CIC Insurance
https://cdn.greatkenyanjobs.com/jsjobsdata/data/employer/comp_7945/logo/CIC-Insurance.jpg
FULL_TIME
Nairobi
Nairobi
00100
Kenya
Insurance
Computer & IT,Management,Business Operations
KES
MONTH
2026-09-04T17:00:00+00:00
8

About the Role

Reporting to the Group Head of IT, the Information Security Manager is responsible for protecting the organization’s information assets, technology infrastructure, applications, and digital services from cyber and information security threats. The role provides strategic direction and hands-on leadership in the implementation, monitoring, and continuous improvement of information security controls, while ensuring compliance with applicable regulatory requirements, policies, and recognized security frameworks such as ISO/IEC 27001 and NIST. The Information Security Manager will work closely with IT, Risk, Internal Audit, business teams, project teams, and external partners to embed security-by-design principles across technology initiatives, proactively manage cyber risks, and strengthen the organization’s overall cyber resilience.

Key Responsibilities

  • Manage, maintain, and continuously improve the organization’s information security infrastructure and controls, including firewalls, IDS/IPS, endpoint protection/EDR, PAM, NAC, patch and vulnerability management, security monitoring and logging, and cloud security controls across AWS and Microsoft Azure.
  • Lead the organization’s technology security assessment programme, including vulnerability assessments, penetration testing, security reviews, configuration assessments, and risk assessments.
  • Develop, review, implement, and enforce information security policies, standards, procedures, and guidelines.
  • Ensure security policies remain aligned with business requirements, regulatory obligations, and industry standards.
  • Develop and deliver a comprehensive information security and cybersecurity awareness programme.
  • Conduct regular security awareness campaigns covering phishing, social engineering, password security, data protection, remote working, acceptable use, and emerging cyber threats.
  • Partner with project teams, IT managers, architects, developers, and business stakeholders to embed security-by-design principles throughout the technology lifecycle.
  • Provide security architecture guidance and recommendations for new systems, applications, integrations, infrastructure, and cloud initiatives.
  • Monitor the evolving cyber threat landscape and assess its potential impact on the organization.
  • Lead and coordinate the cybersecurity incident response lifecycle, including detection and identification, investigation and analysis, containment, eradication, recovery, and post-incident review.
  • Provide cybersecurity oversight for business continuity and disaster recovery programmes.
  • Establish and monitor security patching and vulnerability remediation requirements across technology platforms.
  • Establish and maintain effective relationships with cybersecurity and technology security vendors.
  • Prepare regular information security reports and dashboards for the Group Head of IT and other relevant management forums.

Who We’re Looking For

Essential Knowledge/Skills and Experience Required:

  • Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field.
  • Relevant Professional Qualification such as CISA, CISM, CISP, CEH or similar.
  • Additional certifications in AWS, Azure, and GCP are a plus
  • Minimum of seven (7) years of hands-on IT security experience.
  • At least two (2) years of team leadership.
  • Experience in financial services industry.
  • Proven experience in conducting penetration tests vulnerability assessments and leading closure of findings through collaborating with various stakeholders Internal & External IT Auditors, Risk and Compliance department etc.
  • Strong knowledge of security frameworks and standards e.g., ISO 27001, NIST.
  • Skilled in IT risk management, Cyber threat mitigation, and hands-on problem-solving with strong analytical abilities.
  • Proven leadership and communication skills in cross functional teams.
  • Strategic, adaptable, and budget-conscious decision-maker, aligning security initiatives with business objectives and managing vendor relations effectively.
  • Manage, maintain, and continuously improve the organization’s information security infrastructure and controls, including firewalls, IDS/IPS, endpoint protection/EDR, PAM, NAC, patch and vulnerability management, security monitoring and logging, and cloud security controls across AWS and Microsoft Azure.
  • Lead the organization’s technology security assessment programme, including vulnerability assessments, penetration testing, security reviews, configuration assessments, and risk assessments.
  • Develop, review, implement, and enforce information security policies, standards, procedures, and guidelines.
  • Ensure security policies remain aligned with business requirements, regulatory obligations, and industry standards.
  • Develop and deliver a comprehensive information security and cybersecurity awareness programme.
  • Conduct regular security awareness campaigns covering phishing, social engineering, password security, data protection, remote working, acceptable use, and emerging cyber threats.
  • Partner with project teams, IT managers, architects, developers, and business stakeholders to embed security-by-design principles throughout the technology lifecycle.
  • Provide security architecture guidance and recommendations for new systems, applications, integrations, infrastructure, and cloud initiatives.
  • Monitor the evolving cyber threat landscape and assess its potential impact on the organization.
  • Lead and coordinate the cybersecurity incident response lifecycle, including detection and identification, investigation and analysis, containment, eradication, recovery, and post-incident review.
  • Provide cybersecurity oversight for business continuity and disaster recovery programmes.
  • Establish and monitor security patching and vulnerability remediation requirements across technology platforms.
  • Establish and maintain effective relationships with cybersecurity and technology security vendors.
  • Prepare regular information security reports and dashboards for the Group Head of IT and other relevant management forums.
  • Strong knowledge of security frameworks and standards e.g., ISO 27001, NIST.
  • Skilled in IT risk management, Cyber threat mitigation, and hands-on problem-solving with strong analytical abilities.
  • Proven leadership and communication skills in cross functional teams.
  • Strategic, adaptable, and budget-conscious decision-maker, aligning security initiatives with business objectives and managing vendor relations effectively.
  • Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field.
  • Relevant Professional Qualification such as CISA, CISM, CISP, CEH or similar.
  • Additional certifications in AWS, Azure, and GCP are a plus
bachelor degree
84
JOB-6a92b75584356

Vacancy title:
IT Security Manager

[Type: FULL_TIME, Industry: Insurance, Category: Computer & IT,Management,Business Operations]

Jobs at:
CIC Insurance

Deadline of this Job:
Friday, September 4 2026

Duty Station:
Nairobi | Nairobi

Summary
Date Posted: Saturday, August 29 2026, Base Salary: Not Disclosed

Similar Jobs in Kenya
Learn more about CIC Insurance
CIC Insurance jobs in Kenya

JOB DETAILS:

About the Role

Reporting to the Group Head of IT, the Information Security Manager is responsible for protecting the organization’s information assets, technology infrastructure, applications, and digital services from cyber and information security threats. The role provides strategic direction and hands-on leadership in the implementation, monitoring, and continuous improvement of information security controls, while ensuring compliance with applicable regulatory requirements, policies, and recognized security frameworks such as ISO/IEC 27001 and NIST. The Information Security Manager will work closely with IT, Risk, Internal Audit, business teams, project teams, and external partners to embed security-by-design principles across technology initiatives, proactively manage cyber risks, and strengthen the organization’s overall cyber resilience.

Key Responsibilities

  • Manage, maintain, and continuously improve the organization’s information security infrastructure and controls, including firewalls, IDS/IPS, endpoint protection/EDR, PAM, NAC, patch and vulnerability management, security monitoring and logging, and cloud security controls across AWS and Microsoft Azure.
  • Lead the organization’s technology security assessment programme, including vulnerability assessments, penetration testing, security reviews, configuration assessments, and risk assessments.
  • Develop, review, implement, and enforce information security policies, standards, procedures, and guidelines.
  • Ensure security policies remain aligned with business requirements, regulatory obligations, and industry standards.
  • Develop and deliver a comprehensive information security and cybersecurity awareness programme.
  • Conduct regular security awareness campaigns covering phishing, social engineering, password security, data protection, remote working, acceptable use, and emerging cyber threats.
  • Partner with project teams, IT managers, architects, developers, and business stakeholders to embed security-by-design principles throughout the technology lifecycle.
  • Provide security architecture guidance and recommendations for new systems, applications, integrations, infrastructure, and cloud initiatives.
  • Monitor the evolving cyber threat landscape and assess its potential impact on the organization.
  • Lead and coordinate the cybersecurity incident response lifecycle, including detection and identification, investigation and analysis, containment, eradication, recovery, and post-incident review.
  • Provide cybersecurity oversight for business continuity and disaster recovery programmes.
  • Establish and monitor security patching and vulnerability remediation requirements across technology platforms.
  • Establish and maintain effective relationships with cybersecurity and technology security vendors.
  • Prepare regular information security reports and dashboards for the Group Head of IT and other relevant management forums.

Who We’re Looking For

Essential Knowledge/Skills and Experience Required:

  • Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field.
  • Relevant Professional Qualification such as CISA, CISM, CISP, CEH or similar.
  • Additional certifications in AWS, Azure, and GCP are a plus
  • Minimum of seven (7) years of hands-on IT security experience.
  • At least two (2) years of team leadership.
  • Experience in financial services industry.
  • Proven experience in conducting penetration tests vulnerability assessments and leading closure of findings through collaborating with various stakeholders Internal & External IT Auditors, Risk and Compliance department etc.
  • Strong knowledge of security frameworks and standards e.g., ISO 27001, NIST.
  • Skilled in IT risk management, Cyber threat mitigation, and hands-on problem-solving with strong analytical abilities.
  • Proven leadership and communication skills in cross functional teams.
  • Strategic, adaptable, and budget-conscious decision-maker, aligning security initiatives with business objectives and managing vendor relations effectively.

Work Hours: 8

Experience in Months: 84

Level of Education: bachelor degree

Job application procedure

Never pay for any notarisation, certificate or assessment as part of any recruitment process. When in doubt, contact us

Click Here to Apply Now

All Jobs | QUICK ALERT SUBSCRIPTION

Job Info
Job Category: Computer/ IT jobs in Kenya
Job Type: Full-time
Deadline of this Job: Friday, September 4 2026
Duty Station: Nairobi | Nairobi
Posted: 29-08-2026
No of Jobs: 1
Start Publishing: 29-08-2026
Stop Publishing (Put date of 2030): 10-10-2076
Apply Now
Notification Board

Join a Focused Community on job search to uncover both advertised and non-advertised jobs that you may not be aware of. A jobs WhatsApp Group Community can ensure that you know the opportunities happening around you and a jobs Facebook Group Community provides an opportunity to discuss with employers who need to fill urgent position. Click the links to join. You can view previously sent Email Alerts here incase you missed them and Subscribe so that you never miss out.

Caution: Never Pay Money in a Recruitment Process.

Some smart scams can trick you into paying for Psychometric Tests.