Manager – Information Security job at Bank of Africa Kenya Limited
New
2 Days Ago
Linkedid Twitter Share on facebook
Manager – Information Security
2026-02-25T10:22:36+00:00
Bank of Africa Kenya Limited
https://cdn.greatkenyanjobs.com/jsjobsdata/data/employer/comp_8316/logo/download%20(2).jpg
FULL_TIME
Nairobi
Nairobi
00100
Kenya
Banking
Management, Computer & IT, Business Operations
KES
MONTH
2026-03-07T17:00:00+00:00
8

BANK OF AFRICA - KENYA LIMITED (BOA-KENYA) is a commercial bank providing banking services to corporate, SME and retail clientele.

Responsibilities and Accountabilities.

  • Develop and implement the Bank’s information security strategy, framework and policies, and liaise with the Head of Enterprise Risk to ensure full alignment with the Banks Enterprise Risk Management Framework and Governance, business goals and group requirements.
  • Drive and ensure the full implementation of all technology control systems and continuously monitor against business requirements, identified and reported incidences and good practices to ensure that they remain relevant and robust.
  • Design and put in place an appropriate information security architecture and coordinate reviews to assess data losses and breaches and prioritize solutions and actions to minimize and mitigate business threats and risks.
  • Develop and implement information security risk assessments and penetration testing schedules and procedures and ensure these are undertaken as required to identify and remediate vulnerabilities.
  • Lead in the implementation and continuous monitoring of systems, applications, platforms etc. to facilitate effective incident response management and ensure timely containment and recovery.
  • Contribute to the development and introduction of new products, services, channels and IT systems by reviewing their information system/ technology requirements and processes to provide assurance of compliance with all stipulated security compliance thresholds.
  • Review and approve key infrastructure change requests and ensure all requests meet and approvals are within the minimum risk and compliance thresholds.
  • Establish and implement an information security business continuity plan and processes and continuously run tests to ensure it is fit for purpose, identify gaps and follow up on agreed actions to avoid negative impacts on the Bank’s processes and operations and to ensure continuity in the event of a disruption.
  • Develop and implement security awareness sessions for both employees and customers to enhance the overall security culture.
  • Ensure that all regulations, group requirements and best governance practices are embedded in the Bank’s information system and cyber security practices to ensure compliance and adherence to ISO 27001, PCI DSS, CBK prudential guidelines, Data Protection Regulation regulations etc.
  • Liaise and collaborate with all risk, compliance and audit teams to ensure all necessary assessments and audits are carried out on time, relevant information is provided and proactively implement recommendations and agreed actions.
  • Manage the security risks associated with third-party information services/ technology vendors and partners by undertaking risk assessments, identifying potential risks and gaps, ensuring all SLAs are met and by providing relevant guidance, when required, on controls or mitigants to eliminate, minimize and or manage
  • Prepare and submit information security risk reports including monthly and quarterly group, management and Board reports.

Minimum Requirement; Work Experience, Academic and Professional Qualifications.

  • Bachelor’s degree in information systems, Computer Science, Information Security or any related field from a recognized and accredited institution.
  • At least eight (8) years’ experience in information security, risk management and governance with at least three (3) years conducting compliance assessments, implementing IT controls, cyber security management etc.
  • Certified in information security knowledge areas, such as an ISACA related certification e.g. CISM/ CISA, Certified Ethical Hacker, Licensed Penetration Tester amongst others and from a recognized and accredited institution.
  • In-depth knowledge of information security governance frameworks such as ISO 27001/2, PCIDSS, NIST, OWASP etc.
  • Knowledge of authentication, End Point Security, Internet Policy Enforcement, Firewalls, Web Content Filtering, Database Activity Monitoring (DAM), Public Key Infrastructure (PKI), Data Loss Prevention (DLP), Identity and Access Management (IAM).
  • Good knowledge of the local and regional regulatory and statutory information security and risk management, cyber security and data protection requirements and good/ best industry practices.
  • A good understanding of banking and or financial services operations, processes and practices.

Competencies and Attributes.

  • Driven by results and business outcomes.
  • A good understanding of business principles and industry and market trends.
  • Critical thinker – Objective analysis of information, consideration of multiple perspectives, etc.
  • Ability to analyze and define a problem, evaluate alternatives, find efficient solutions, and make optimal desirable choices/ decisions.
  • Goal oriented – Setting clear objectives and actively working to achieve them.
  • Strong planning, organization and self-management.
  • Continuous professional learning – Ability to continuously acquire knowledge and updates with current happening/ new industry developments.
  • Develop and implement the Bank’s information security strategy, framework and policies, and liaise with the Head of Enterprise Risk to ensure full alignment with the Banks Enterprise Risk Management Framework and Governance, business goals and group requirements.
  • Drive and ensure the full implementation of all technology control systems and continuously monitor against business requirements, identified and reported incidences and good practices to ensure that they remain relevant and robust.
  • Design and put in place an appropriate information security architecture and coordinate reviews to assess data losses and breaches and prioritize solutions and actions to minimize and mitigate business threats and risks.
  • Develop and implement information security risk assessments and penetration testing schedules and procedures and ensure these are undertaken as required to identify and remediate vulnerabilities.
  • Lead in the implementation and continuous monitoring of systems, applications, platforms etc. to facilitate effective incident response management and ensure timely containment and recovery.
  • Contribute to the development and introduction of new products, services, channels and IT systems by reviewing their information system/ technology requirements and processes to provide assurance of compliance with all stipulated security compliance thresholds.
  • Review and approve key infrastructure change requests and ensure all requests meet and approvals are within the minimum risk and compliance thresholds.
  • Establish and implement an information security business continuity plan and processes and continuously run tests to ensure it is fit for purpose, identify gaps and follow up on agreed actions to avoid negative impacts on the Bank’s processes and operations and to ensure continuity in the event of a disruption.
  • Develop and implement security awareness sessions for both employees and customers to enhance the overall security culture.
  • Ensure that all regulations, group requirements and best governance practices are embedded in the Bank’s information system and cyber security practices to ensure compliance and adherence to ISO 27001, PCI DSS, CBK prudential guidelines, Data Protection Regulation regulations etc.
  • Liaise and collaborate with all risk, compliance and audit teams to ensure all necessary assessments and audits are carried out on time, relevant information is provided and proactively implement recommendations and agreed actions.
  • Manage the security risks associated with third-party information services/ technology vendors and partners by undertaking risk assessments, identifying potential risks and gaps, ensuring all SLAs are met and by providing relevant guidance, when required, on controls or mitigants to eliminate, minimize and or manage
  • Prepare and submit information security risk reports including monthly and quarterly group, management and Board reports.
  • Knowledge of authentication, End Point Security, Internet Policy Enforcement, Firewalls, Web Content Filtering, Database Activity Monitoring (DAM), Public Key Infrastructure (PKI), Data Loss Prevention (DLP), Identity and Access Management (IAM).
  • Good knowledge of the local and regional regulatory and statutory information security and risk management, cyber security and data protection requirements and good/ best industry practices.
  • A good understanding of banking and or financial services operations, processes and practices.
  • Driven by results and business outcomes.
  • A good understanding of business principles and industry and market trends.
  • Critical thinker – Objective analysis of information, consideration of multiple perspectives, etc.
  • Ability to analyze and define a problem, evaluate alternatives, find efficient solutions, and make optimal desirable choices/ decisions.
  • Goal oriented – Setting clear objectives and actively working to achieve them.
  • Strong planning, organization and self-management.
  • Continuous professional learning – Ability to continuously acquire knowledge and updates with current happening/ new industry developments.
  • Bachelor’s degree in information systems, Computer Science, Information Security or any related field from a recognized and accredited institution.
  • Certified in information security knowledge areas, such as an ISACA related certification e.g. CISM/ CISA, Certified Ethical Hacker, Licensed Penetration Tester amongst others and from a recognized and accredited institution.
  • In-depth knowledge of information security governance frameworks such as ISO 27001/2, PCIDSS, NIST, OWASP etc.
bachelor degree
12
JOB-699ecd6c7b3b5

Vacancy title:
Manager – Information Security

[Type: FULL_TIME, Industry: Banking, Category: Management, Computer & IT, Business Operations]

Jobs at:
Bank of Africa Kenya Limited

Deadline of this Job:
Saturday, March 7 2026

Duty Station:
Nairobi | Nairobi

Summary
Date Posted: Wednesday, February 25 2026, Base Salary: Not Disclosed

Similar Jobs in Kenya
Learn more about Bank of Africa Kenya Limited
Bank of Africa Kenya Limited jobs in Kenya

JOB DETAILS:

BANK OF AFRICA - KENYA LIMITED (BOA-KENYA) is a commercial bank providing banking services to corporate, SME and retail clientele.

Responsibilities and Accountabilities.

  • Develop and implement the Bank’s information security strategy, framework and policies, and liaise with the Head of Enterprise Risk to ensure full alignment with the Banks Enterprise Risk Management Framework and Governance, business goals and group requirements.
  • Drive and ensure the full implementation of all technology control systems and continuously monitor against business requirements, identified and reported incidences and good practices to ensure that they remain relevant and robust.
  • Design and put in place an appropriate information security architecture and coordinate reviews to assess data losses and breaches and prioritize solutions and actions to minimize and mitigate business threats and risks.
  • Develop and implement information security risk assessments and penetration testing schedules and procedures and ensure these are undertaken as required to identify and remediate vulnerabilities.
  • Lead in the implementation and continuous monitoring of systems, applications, platforms etc. to facilitate effective incident response management and ensure timely containment and recovery.
  • Contribute to the development and introduction of new products, services, channels and IT systems by reviewing their information system/ technology requirements and processes to provide assurance of compliance with all stipulated security compliance thresholds.
  • Review and approve key infrastructure change requests and ensure all requests meet and approvals are within the minimum risk and compliance thresholds.
  • Establish and implement an information security business continuity plan and processes and continuously run tests to ensure it is fit for purpose, identify gaps and follow up on agreed actions to avoid negative impacts on the Bank’s processes and operations and to ensure continuity in the event of a disruption.
  • Develop and implement security awareness sessions for both employees and customers to enhance the overall security culture.
  • Ensure that all regulations, group requirements and best governance practices are embedded in the Bank’s information system and cyber security practices to ensure compliance and adherence to ISO 27001, PCI DSS, CBK prudential guidelines, Data Protection Regulation regulations etc.
  • Liaise and collaborate with all risk, compliance and audit teams to ensure all necessary assessments and audits are carried out on time, relevant information is provided and proactively implement recommendations and agreed actions.
  • Manage the security risks associated with third-party information services/ technology vendors and partners by undertaking risk assessments, identifying potential risks and gaps, ensuring all SLAs are met and by providing relevant guidance, when required, on controls or mitigants to eliminate, minimize and or manage
  • Prepare and submit information security risk reports including monthly and quarterly group, management and Board reports.

Minimum Requirement; Work Experience, Academic and Professional Qualifications.

  • Bachelor’s degree in information systems, Computer Science, Information Security or any related field from a recognized and accredited institution.
  • At least eight (8) years’ experience in information security, risk management and governance with at least three (3) years conducting compliance assessments, implementing IT controls, cyber security management etc.
  • Certified in information security knowledge areas, such as an ISACA related certification e.g. CISM/ CISA, Certified Ethical Hacker, Licensed Penetration Tester amongst others and from a recognized and accredited institution.
  • In-depth knowledge of information security governance frameworks such as ISO 27001/2, PCIDSS, NIST, OWASP etc.
  • Knowledge of authentication, End Point Security, Internet Policy Enforcement, Firewalls, Web Content Filtering, Database Activity Monitoring (DAM), Public Key Infrastructure (PKI), Data Loss Prevention (DLP), Identity and Access Management (IAM).
  • Good knowledge of the local and regional regulatory and statutory information security and risk management, cyber security and data protection requirements and good/ best industry practices.
  • A good understanding of banking and or financial services operations, processes and practices.

Competencies and Attributes.

  • Driven by results and business outcomes.
  • A good understanding of business principles and industry and market trends.
  • Critical thinker – Objective analysis of information, consideration of multiple perspectives, etc.
  • Ability to analyze and define a problem, evaluate alternatives, find efficient solutions, and make optimal desirable choices/ decisions.
  • Goal oriented – Setting clear objectives and actively working to achieve them.
  • Strong planning, organization and self-management.
  • Continuous professional learning – Ability to continuously acquire knowledge and updates with current happening/ new industry developments.

Work Hours: 8

Experience in Months: 12

Level of Education: bachelor degree

Job application procedure

Never pay for any notarisation, certificate or assessment as part of any recruitment process. When in doubt, contact us

Click Here to Apply Now

All Jobs | QUICK ALERT SUBSCRIPTION

Job Info
Job Category: Management jobs in Kenya
Job Type: Full-time
Deadline of this Job: Saturday, March 7 2026
Duty Station: Nairobi | Nairobi
Posted: 25-02-2026
No of Jobs: 1
Start Publishing: 25-02-2026
Stop Publishing (Put date of 2030): 10-10-2076
Apply Now
Notification Board

Join a Focused Community on job search to uncover both advertised and non-advertised jobs that you may not be aware of. A jobs WhatsApp Group Community can ensure that you know the opportunities happening around you and a jobs Facebook Group Community provides an opportunity to discuss with employers who need to fill urgent position. Click the links to join. You can view previously sent Email Alerts here incase you missed them and Subscribe so that you never miss out.

Caution: Never Pay Money in a Recruitment Process.

Some smart scams can trick you into paying for Psychometric Tests.