The Data Protection and Information Security Analyst will support both internal operations and customer-facing engagements to ensure compliance with the Personal Data Protection Act (PDPA) 2022.
The role will also maintain information security controls aligned with ISO 27001 and protect the confidentiality, integrity, and availability of information assets.
The successful candidate will monitor, assess, and improve data protection and information security practices across the organization and its clients. The position also involves managing incidents and delivering training and awareness initiatives to strengthen the organization’s overall compliance and security posture.
Key responsibilities
Data protection and privacy compliance
- Support the implementation and maintenance of the organization’s data protection framework.
- Assist in developing and maintaining the Record of Processing Activities (ROPA).
- Conduct regular Data Protection Impact Assessments (DPIAs).
- Advise departments on measures to mitigate privacy risks.
- Review data processing agreements and contracts to ensure compliance with PDPA 2022 requirements.
- Assist in responding to Data Subject Access Requests (DSARs).
- Help manage privacy incidents and data breaches.
- Monitor data transfer activities to ensure compliance with cross-border data flow restrictions.
- Support the Data Protection Officer (DPO) in preparing periodic compliance and audit reports for management and regulators.
Information security management
- Implement, monitor, and continually improve information security controls under the Integrated Management System (IMS).
- Ensure that controls align with ISO 9001:2015 and ISO/IEC 27001:2022 standards.
- Conduct risk assessments and support the development of risk mitigation plans.
- Participate in vulnerability assessments.
- Coordinate with relevant teams to remediate identified vulnerabilities.
- Monitor system logs, alerts, and incidents to detect and respond to security threats.
- Support the development and maintenance of Information Security Management System (ISMS) documentation.
- Develop and maintain policies, procedures, and guidelines relating to data protection and information security.
Training and collaboration
- Coordinate internal and client-facing security awareness and training programmes.
- Conduct awareness sessions for employees, customers, and third parties on privacy and cybersecurity best practices.
- Collaborate with the IT, Legal, HR, and other departments to embed data protection and information security into daily operations.
Incident response and business continuity
- Participate in incident response activities, including investigation, containment, and reporting.
- Maintain the incident register.
- Assist in preparing incident reports for the DPO and management.
- Support business continuity and disaster recovery initiatives.
Requirements
Education
- Bachelor’s degree in Computer Science, Information Technology, Information Security, or a related field.
Knowledge and experience
- Minimum of two years’ experience in information security, data protection, or a related field.
- Foundational knowledge of data protection, information security, or quality management systems.
- Familiarity with Tanzania’s PDPA 2022, the GDPR, or similar privacy regulations.
- Good understanding of documentation and record-keeping within a structured management system.
Preferred certifications
Any of the following certifications would be an advantage but are not mandatory:
- ISO/IEC 27001 Foundation, Implementer, or Auditor certification
- ISO 9001 Internal Auditor certification
- CompTIA Security+
- Certified Ethical Hacker (CEH)
- An equivalent cybersecurity certification
- Data protection or privacy certification
- ISACA Certified Information Security Manager (CISM)
- Certified Information Systems Auditor (CISA)
How to Apply:
Job type Full-time Job, To submit your application, please follow the link provided below.
CLICK HERE TO APPLY