# Manager – IT Security Job HFCB, Nairobi, Kenya

Canonical URL: https://primejobalerts.com/jobs/manager-it-security-job-hfcb-nairobi-kenya

Company: HFCB, Nairobi, Kenya

Category: Accounting

Location: Kenya

Work type: Full-time

Work arrangement: On-site

Published: 2026-07-29

Expires: 2026-09-13

## Job Description

About the Role

The Manager – IT Security supports the Head of ICT Security / CISO in strengthening the Group’s information security posture by coordinating IT security governance, cyber risk management, SOC operations oversight, security assurance, audit remediation, regulatory compliance and proactive cyber resilience across the Group. The role ensures that security policies, standards, controls, monitoring processes and assurance activities are embedded into technology operations, digital channels, projects, third-party engagements, and business processes. The role holder provides security support to the substantive Data Protection Officer by ensuring that technical and organisational security controls for personal data are defined, implemented, tested, monitored, and evidenced. This role supports privacy governance through technology control implementation, security assurance, access control, monitoring, incident coordination, third-party reviews, and remediation tracking.

### Key Responsibilities

- Data Protection and Privacy Security Support – Support the substantive Data Protection Officer by providing information security input into privacy governance, DPIAs, data classification, access controls, encryption, logging and monitoring, data loss prevention, third-party risk reviews, breach investigation, audit evidence and remediation tracking.

- IT Security Governance and Strategy Execution – Support the CISO in implementing the Group information security strategy, governance framework, policies, standards, procedures, operating model and control assurance programme.

- Regulatory Compliance and Security Reporting – Coordinate compliance reviews, evidence packs, management attestations, regulatory responses, control self-assessments and reporting to ICT, Risk, Compliance, Audit and management governance forums.

- Cyber Risk, Audit and Remediation Management – Coordinate identification, assessment, monitoring, reporting and remediation of ICT and cyber risks across the Group, including audit and regulatory findings to closure.

- SOC Operations Oversight and Incident Coordination – Provide management oversight of security monitoring, incident triage, escalation, response coordination, threat intelligence, SOC use cases, alert handling, incident reporting and post-incident remediation.

- ICT Resilience, Disaster Recovery and Cyber Recovery Support – Coordinate security input into ICT business continuity, disaster recovery, cyber recovery planning, backup assurance, recovery testing and remediation of resilience gaps.

- Identity and Access Governance – Maintain access governance covering privileged access, periodic user access reviews, role-based access control, joiner-mover-leaver controls, access certification, segregation of duties, exceptions, remediation tracking and evidence management.

- Security Assurance for Projects, Platforms and Third Parties – Provide security assurance over systems, infrastructure, digital channels, cloud services, APIs, integrations, third parties and technology changes.

Qualifications

- Bachelor’s degree in information security, Computer Science, Information Systems, Information Technology, Cybersecurity, Risk Management, or related fields.

- Relevant certifications such as CISM, CISSP, CRISC, CISA, ISO 27001 Lead Implementer/Lead Auditor, CompTIA Security+, CBCP or equivalent will be an added advantage.

- At least 5 years’ experience in information security, IT governance, cyber risk, security operations, security assurance, or technology risk management.

- Understanding of implementation of technical security controls, identity and access management and designing security solutions in a dynamic environment

- At least 2 years in a supervisory or managerial role within a highly regulated or digitized environment.

- Demonstrable experience in security governance, SOC oversight, audit remediation, regulatory compliance, access governance, third-party assurance, project security assurance, incident coordination, cyber resilience and executive reporting.

- Understanding of IT Audit processes, technical security testing (Red Team, Blue Team, Penetration Testing) and Cyber Incident Response including data protection guidelines.

Competencies

- IT security governance and strategy execution

- SOC operations oversight and incident coordination

- Understanding of securing cloud infrastructure, SOA (Service Oriented Architecture) and AI based technologies

- Cyber risk assessment, remediation tracking and reporting

- Security assurance for projects, platforms, APIs, cloud services and third parties

- Vulnerability assessments, red and blue team testing and Cyber Incident response.

- Identity and access governance

- Data protection security controls supporting the substantive DPO

- ICT resilience, disaster recovery, cyber recovery and backup assurance

- ISO 27001, COBIT, PCI DSS, CBK guidance and applicable regulatory requirements

- Strategic thinking and Innovation oriented

- Leadership and stakeholder management

- Problem solving and structured follow-up

- Communication skills

- Integrity, confidentiality and ethical practice

### How to Apply

Click here to apply

## Apply

Use the canonical Prime Job Alerts page for full application instructions and source verification.
