Job Listings
🗺️ View on map
Information Systems Security Manager
📍 Nairobi 💼 On-site ⏰ Full Time 📋 Permanent Contract 🏷️ General Services, Cleaning and Security
Minimum Experience
1 year
Application Deadline
📅 31/12/2026
Interested in this job?
Create your profile in 30 seconds and we'll apply for you automatically
📣 Share this job
Link copied ✓
Job Description

JOB TITLE INFORMATION SYSTEMS SECURITY MANAGER

NATURE OF JOB FULL TIME

INDUSTRY MANUFACTURING

SALARY KSHS.70,000-100,000

JOB LOCATION MLOLONGO


DUTIES AND RESPONSIBILITIES

Information Security Governance

· Develop and maintain the Information Security Strategy.

· Develop and review ICT security policies, standards and procedures.

· Maintain the Information Security Management Framework.

· Review security maturity and recommend improvements.

· Ensure security governance aligns with business objectives.

· Maintain ICT security documentation.

Cybersecurity

· Lead the enterprise cybersecurity programme.

· Coordinate vulnerability assessments and penetration testing.

· Monitor emerging cyber threats and recommend mitigation.

· Coordinate security incident response.

· Review malware, phishing and ransomware protection.

· Prepare monthly cybersecurity reports.

Firewall & Network Security

· Administer enterprise firewalls and security appliances.

· Approve firewall rule requests and conduct periodic rule reviews.

· Manage VPN security and remote access controls.

· Manage IDS/IPS policies.

· Monitor firewall logs and perimeter security events.

· Review network segmentation and internet security controls.

Endpoint Security

· Manage Endpoint Detection & Response (EDR).

· Ensure endpoint encryption and antivirus compliance.

· Develop endpoint hardening standards.

· Review endpoint vulnerabilities and coordinate remediation.

· Monitor endpoint compliance dashboards.

Identity & Access Management

· Manage identity governance and role-based access control.

· Approve privileged access requests.

· Conduct quarterly user access reviews.

· Enforce password and Multi-Factor Authentication policies.

· Ensure timely onboarding and offboarding of user accounts.

Risk, Audit & Compliance

· Maintain the ICT Risk Register.

· Conduct ICT security risk assessments.

· Coordinate ICT audits and implement corrective actions.

· Support regulatory and compliance reviews.

· Track audit findings to closure.

Business Continuity

· Support Business Continuity and Disaster Recovery planning.

· Coordinate Disaster Recovery security testing.

· Review backup security and ransomware readiness.

· Security Awareness

· Develop annual security awareness programmes.

· Conduct user security training.

· Coordinate phishing simulations and awareness campaigns.

Vendor Security

· Assess third-party security controls.

· Review cloud and hosted service security.

· Ensure vendor access is controlled and monitored.

Management

· Prepare departmental budgets and work plans.

· Provide security advice to management.

· Supervise security staff where applicable.

· Participate in ICT management meetings.

KEY REQUIREMENT SKILLS AND QUALIFICATION

· Degree in Computer Science, Information Technology, Information Systems or related field

· Minimum 5 years relevant ICT experience & 2 years in information security, infrastructure or ICT governance

· Strong understanding of information security governance and cybersecurity

· Knowledge of firewalls, VPNs, IDS/IPS, endpoint security and identity management

· Knowledge of ICT risk management and compliance

· Strong analytical and problem-solving skills

HOW TO APPLY

· If you meet the above qualifications, skills and experience share CV on recruitment@britesmanagement.com

· Interviews will be carried out on a rolling basis until the position is filled.

· Only the shortlisted candidates will be contacted.

Location
📍 Approximate location
🗺️ View full map →
About the Company
Brites Management Services Limited publishes its vacancies in Kenya through Saplic. Profile created automatically.