INFORMATION SYSTEMS SECURITY MANAGER
Nutné:CloudSecurityLeadPrincipalRemote
JOB TITLE INFORMATION SYSTEMS SECURITY MANAGER
NATURE OF JOB FULL TIME
INDUSTRY MANUFACTURING
SALARY KSHS.70,000-100,000
JOB LOCATION MLOLONGO
DUTIES AND RESPONSIBILITIES
Information Security Governance
- Develop and maintain the Information Security Strategy.
- Develop and review ICT security policies, standards and procedures.
- Maintain the Information Security Management Framework.
- Review security maturity and recommend improvements.
- Ensure security governance aligns with business objectives.
- Maintain ICT security documentation.
Cybersecurity
- Lead the enterprise cybersecurity programme.
- Coordinate vulnerability assessments and penetration testing.
- Monitor emerging cyber threats and recommend mitigation.
- Coordinate security incident response.
- Review malware, phishing and ransomware protection.
- Prepare monthly cybersecurity reports.
Firewall & Network Security
- Administer enterprise firewalls and security appliances.
- Approve firewall rule requests and conduct periodic rule reviews.
- Manage VPN security and remote access controls.
- Manage IDS/IPS policies.
- Monitor firewall logs and perimeter security events.
- Review network segmentation and internet security controls.
Endpoint Security
- Manage Endpoint Detection & Response (EDR).
- Ensure endpoint encryption and antivirus compliance.
- Develop endpoint hardening standards.
- Review endpoint vulnerabilities and coordinate remediation.
- Monitor endpoint compliance dashboards.
Identity & Access Management
- Manage identity governance and role-based access control.
- Approve privileged access requests.
- Conduct quarterly user access reviews.
- Enforce password and Multi-Factor Authentication policies.
- Ensure timely onboarding and offboarding of user accounts.
Risk, Audit & Compliance
- Maintain the ICT Risk Register.
- Conduct ICT security risk assessments.
- Coordinate ICT audits and implement corrective actions.
- Support regulatory and compliance reviews.
- Track audit findings to closure.
Business Continuity
- Support Business Continuity and Disaster Recovery planning.
- Coordinate Disaster Recovery security testing.
- Review backup security and ransomware readiness.
Security Awareness
- Develop annual security awareness programmes.
- Conduct user security training.
- Coordinate phishing simulations and awareness campaigns.
Vendor Security
- Assess third-party security controls.
- Review cloud and hosted service security.
- Ensure vendor access is controlled and monitored.
Management
- Prepare departmental budgets and work plans.
- Provide security advice to management.
- Supervise security staff where applicable.
- Participate in ICT management meetings.
KEY REQUIREMENT SKILLS AND QUALIFICATION
- Degree in Computer Science, Information Technology, Information Systems or related field
- Minimum 5 years relevant ICT experience & 2 years in information security, infrastructure or ICT governance
- Strong understanding of information security governance and cybersecurity
- Knowledge of firewalls, VPNs, IDS/IPS, endpoint security and identity management
- Knowledge of ICT risk management and compliance
- Strong analytical and problem-solving skills
HOW TO APPLY
- If you meet the above qualifications, skills and experience share CV on recruitment@britesmanagement.com
- Interviews will be carried out on a rolling basis until the position is filled.
- Only the shortlisted candidates will be contacted.
Kontaktní osoba
Uvedeno zaměstnavatelem v inzerátu — pro dotazy a tvou přihlášku.