# Cybersecurity & Threat Intelligence Specialist

Canonical URL: https://primejobalerts.com/jobs/cybersecurity-threat-intelligence-specialist

Company: Zambia National Commercial Bank Plc

Category: Information & Communication Technology

Location: Zambia, Lusaka

Work type: Full-time

Work arrangement: On-site

Published: 2026-08-01

Expires: 2026-09-15

## Job Description

### Position Overview

Zanaco Bank Plc is inviting applications from suitably qualified and experienced individuals for the following job aimed at contributing to the Bank’s strategic vision, in the Information Technology Division under the IT Security at Head Office – Support Functions:

### Role Description

This role is responsible for safeguarding the Bank’s digital assets, information, and systems from various cyber threats and attacks. The safeguards include, but not limited to Data Loss prevention, Vulnerability Assessments and Penetration Testing (VAPT), Network Security, Endpoint Security, Mobile Device Management, Email Security, Database Security, Cyber threat intelligence, Security in projects implementation. The role focuses on ensuring that adequate Security Controls, Cyber Risk Management and Compliance is applied and monitored across the enterprise in all IT related projects, systems, automated processes, and people involved in running automated process. The role enforces all security policies, procedures, and control objectives to mitigate risks to the Bank.

Reporting to the Cybersecurity & Threat Intelligence Senior Specialist, the Cybersecurity Specialist executes his/ her roles and responsibilities in close collaboration with the IT Function to ensure that controls are implemented and effectively monitored ensuring no conflict of interest exists.

### Requirements

Cyber Security

• Security Architecture Design: Collaborate with the IT function to design and implement secure bank network and system architectures. This includes selecting appropriate security technologies and integrating them into the Bank’s infrastructure.

• Vulnerability Assessment and Penetration Testing: Regularly assess the bank’s IT infrastructure for vulnerabilities and ensure prompt remediations are carried out by the relevant IT Function teams.

• Working with business and support functions to ensure correct implementation of IT control requirements on various processes.

• Implementation and management of the Bank’s Public Key Infrastructure (PKI).

• Collaboration with Fraud Risk function to conduct digital forensic investigations.

• Spearhead the implementation and monitoring of advanced security controls ensuring no conflict of interest in management of implemented controls to ensure availability, integrity, and confidentiality of data.

• Offer continuous assurance in the deployment and maintenance of native IT Security controls such as intrusion detection/ prevention systems, firewalls to ensure availability, integrity, and confidentiality of data.

• Oversight, planning and execution of any required independent cybersecurity assessments and audits.

• Ensure compliance activities and reports associated with regulatory requirements are maintained.

• Involvement in arranging staff training in security awareness skills.

• Research, evaluate, and recommend new security technologies, processes, and methodologies.

• Participate in the implementation of an IT cyber-security strategy and proactively identify cyber-security threats.

• Applying information security foundations to complex network architectures

• Cyber Threat Intelligence: Monitor cyber threat intelligence sources to understand emerging threats and adapt security measures accordingly.

• Threat modelling: Identify and enumerate potential threats, such as structural vulnerabilities or the absence of appropriate safeguards, to recommend and communicate prioritized countermeasures for implementation by appropriate teams.

2. Security Operations Centre

Threat Detection: Monitor the bank’s network, systems, and applications to identify and analyse potential security threats and vulnerabilities.

• Cyber Incident Management: Lead the cyber incident management efforts in the event of a security breach or cyberattack by investigating the incident, assessing the extent of the damage, taking steps to mitigate the impact, documenting all relevant details, including the incident’s cause, impact, and steps taken for remediation.

• Work closely with third party managed security services providers (MSSPs) to ensure bank is protected on a 24/7 basis.

3. Risk Management

• Conduct Information Security Risk and Controls Self Assessments

• Maintain up to date Information Security Risk Registers

• Responsible for maintaining an up-to-date understanding of emerging trends in information security risks.

• Support for timely reporting of all IT risk events ensuring that root cause analysis is conducted.

• Responsible for monitoring control effectiveness where there are material risks of process control failure.

4. Audit and Compliance Management

• Supports the coordination of internal and external information security assessments by internal and external partners.

• Supports the tracking and closure of internal and external assessment issues.

• Make recommendations for action plans addressing management commitments.

1. Cyber Security

• Security Architecture Design: Collaborate with the IT function to design and implement secure bank network and system architectures. This includes selecting appropriate security technologies and integrating them into the Bank’s infrastructure.

• Vulnerability Assessment and Penetration Testing: Regularly assess the bank’s IT infrastructure for vulnerabilities and ensure prompt remediations are carried out by the relevant IT Function teams.

• Working with business and support functions to ensure correct implementation of IT control requirements on various processes.

• Implementation and management of the Bank’s Public Key Infrastructure (PKI).

• Collaboration with Fraud Risk function to conduct digital forensic investigations.

• Spearhead the implementation and monitoring of advanced security controls ensuring no conflict of interest in management of implemented controls to ensure availability, integrity, and confidentiality of data.

• Offer continuous assurance in the deployment and maintenance of native IT Security controls such as intrusion detection/ prevention systems, firewalls to ensure availability, integrity, and confidentiality of data.

• Oversight, planning and execution of any required independent cybersecurity assessments and audits.

• Ensure compliance activities and reports associated with regulatory requirements are maintained.

• Involvement in arranging staff training in security awareness skills.

• Research, evaluate, and recommend new security technologies, processes, and methodologies.

• Participate in the implementation of an IT cyber-security strategy and proactively identify cyber-security threats.

• Applying information security foundations to complex network architectures

• Cyber Threat Intelligence: Monitor cyber threat intelligence sources to understand emerging threats and adapt security measures accordingly.

• Threat modelling: Identify and enumerate potential threats, such as structural vulnerabilities or the absence of appropriate safeguards, to recommend and communicate prioritized countermeasures for implementation by appropriate teams.

2. Security Operations Centre

Threat Detection: Monitor the bank’s network, systems, and applications to identify and analyse potential security threats and vulnerabilities.

• Cyber Incident Management: Lead the cyber incident management efforts in the event of a security breach or cyberattack by investigating the incident, assessing the extent of the damage, taking steps to mitigate the impact, documenting all relevant details, including the incident’s cause, impact, and steps taken for remediation.

• Work closely with third party managed security services providers (MSSPs) to ensure bank is protected on a 24/7 basis.

3. Risk Management

• Conduct Information Security Risk and Controls Self Assessments

• Maintain up to date Information Security Risk Registers

• Responsible for maintaining an up-to-date understanding of emerging trends in information security risks.

• Support for timely reporting of all IT risk events ensuring that root cause analysis is conducted.

• Responsible for monitoring control effectiveness where there are material risks of process control failure.

4. Audit and Compliance Management

• Supports the coordination of internal and external information security assessments by internal and external partners.

• Supports the tracking and closure of internal and external assessment issues.

• Make recommendations for action plans addressing management commitments.

Key Outputs

Success Measures

Inputs and Behaviors

Measurement Method

Privileged Access Management (PAM)

Successful Implementation and management of PAM solution to ensure secure and controlled access to the bank’s information assets.

Undertake relevant research and prepare the technical requirements to operationalize the department’s strategic initiatives.

Cybersecurity scorecard

Mature Cybersecurity Environment

Secure IT Infrastructure resulting in reduced cybersecurity incidents and related losses.

Undertake relevant research and prepare the technical requirements to ensure security controls are effectively implemented, managed, and continuously monitored.

Cybersecurity Maturity Assessment Report

Vulnerability Management

Reduced risk of exploitation of Information systems

Continuous and consistent vulnerability assessments and penetration testing and tracking of remediation activities.

Vulnerability assessment reports

Compliance with International Industry specific and other adopted Information Security Standards and Regulations

Successful implementation, maintenance, and continuous improvement of technical controls making up SWIFT SC,

PCI DSS and ISO/IEC 27001, Information Security

Management Systems.

Collaborate with relevant stakeholders to ensure all technical controls needed to comply with the standards and regulations are effectively met and continuously improved.

SWIFT, PCI DSS and ISO/IEC 27001 Compliance

Certificates or Reports.

Compliance with local

Information Security Laws and

Regulations

• Compliance with the Bank of Zambia’s Information Security Regulations and

Guidelines

• Compliance with

Information Security laws, regulations, and guidelines of the Republic of Zambia

Collaborate with relevant stakeholders to ensure all technical controls needed to comply with the laws and regulations are effectively met and continuously improved.

Regulatory Examination/ Assessment Reports

Compliance Management

Prompt addressing of issues arising from assessments and audits from internal and external assurance partners.

Collaborate with relevant stakeholders to close off all issues arising from the assessments and audits.

Assessments/ Audit Reports

Risk Management

• Up to date Information Security Risk Register

Cyber Incident Reporting

Collaborate with relevant stakeholders to ensure Information Security risks are well captured and reported.

Risk and Controls SelfAssessment Report

ERM Dashboard

JOB DIMENSIONS SUMMARY

FINANCIAL DIMENSION

### Budget

Support the Cybersecurity & Threat Intelligence Senior Specialist in regulating the departmental budgets to maximize the return on investments.

MANAGEMENT DIMENSION

### Planning

This is a strategic role (aligning to the long-term ambitions of the bank) and drives the Information Security Strategy from planning to execution alongside other units in the division.

### Organizing

This role requires a very highly self-organizing skillset to be able to effectively present the broader picture of where the Information Security Unit is driving towards in relation to the Bank’s strategy execution. It heavily contributes towards providing visibility to the Board members on the performance of the division and its contribution to the overall profitability of the bank.

### Direct Subordinates

• None

### Indirect Subordinates

• None

COMMUNICATION/INFLUENCING

### Communication

This role requires interaction and communication at all levels (i.e., Internal & External). This involves stakeholder engagement at different levels within the bank and being able to communicate effectively thereof.

External: Vendors and Consultants

Internal: All internal Business Units

DECISION MAKING

### Autonomous Decisions

• Solutions to operational problems

• Business Impact

• Controls effectiveness and criticality Non-Autonomous Decisions:

• Strategic solutions

QUALIFICATIONS/EXPERIENCE

### Skills and Qualifications

### Required

• Bachelor’s degree (or equivalent) in Information Systems, Technology, or Security, Computer Science, or related field

• Master’s degree is added advantage.

• At least two (2) Information Security certifications such as GIAC, OSCP, CISSP, CRISC, CISM, CEH, ISO/IEC 27001 or equivalent.

• Three to five years of experience in cybersecurity at a midsize or large company in the Banking or similar environment.

### Professional

• Digital Forensic Knowledge

• Experience with cloud computing

• Should possess high skills in implementing and maintaining cybersecurity controls.

COMPLEXITY

• Information Security/ Cybersecurity

• Risk management

• IT Audit management

• Security in Strategic Projects

• Complex Decision-Making Processes

COMPETENCIES & PERSONAL ATTRIBUTES

• Excellent verbal and written communication skills.

• Self-starter and self-motivated

• Ability to work successfully in both individual and team settings.

• Leadership skills

• Clinical and attentive to detail

• Must aspire to a culture of Service Excellence

• Stakeholder Management

• Budget Management

Reference Documents

Information Security Policies, IT Policies, PMDS Policy, ISO/IEC 27001 Standard, PCI DSS Standard, BOZ Cyber and Information Risk Management Guidelines.

Operating environment

e.g., Physical Demands, Mental Requirements

High stress environment, 24-hour operations on call always.

### Prepared by

Acting Head Information Security

### Approved by

### Date

### Date

### Incumbent

Vacant

### Disclaimer

ONLY SHORTLISTED APPLICANTS WILL BE COMMUNICATED TO.

Zanaco provides equal opportunity in employment for all qualified persons and prohibits discrimination in employment (women are encouraged to apply).

## Apply

Use the canonical Prime Job Alerts page for full application instructions and source verification.
