JOB TITLE INFORMATION SYSTEMS SECURITY MANAGER
NATURE OF JOB FULL TIME
INDUSTRY MANUFACTURING
SALARY KSHS.70,000-100,000
JOB LOCATION MLOLONGO
DUTIES AND RESPONSIBILITIES
Information Security Governance
· Develop and maintain the Information Security Strategy.
· Develop and review ICT security policies, standards and procedures.
· Maintain the Information Security Management Framework.
· Review security maturity and recommend improvements.
· Ensure security governance aligns with business objectives.
· Maintain ICT security documentation.
Cybersecurity
· Lead the enterprise cybersecurity programme.
· Coordinate vulnerability assessments and penetration testing.
· Monitor emerging cyber threats and recommend mitigation.
· Coordinate security incident response.
· Review malware, phishing and ransomware protection.
· Prepare monthly cybersecurity reports.
Firewall & Network Security
· Administer enterprise firewalls and security appliances.
· Approve firewall rule requests and conduct periodic rule reviews.
· Manage VPN security and remote access controls.
· Manage IDS/IPS policies.
· Monitor firewall logs and perimeter security events.
· Review network segmentation and internet security controls.
Endpoint Security
· Manage Endpoint Detection & Response (EDR).
· Ensure endpoint encryption and antivirus compliance.
· Develop endpoint hardening standards.
· Review endpoint vulnerabilities and coordinate remediation.
· Monitor endpoint compliance dashboards.
Identity & Access Management
· Manage identity governance and role-based access control.
· Approve privileged access requests.
· Conduct quarterly user access reviews.
· Enforce password and Multi-Factor Authentication policies.
· Ensure timely onboarding and offboarding of user accounts.
Risk, Audit & Compliance
· Maintain the ICT Risk Register.
· Conduct ICT security risk assessments.
· Coordinate ICT audits and implement corrective actions.
· Support regulatory and compliance reviews.
· Track audit findings to closure.
Business Continuity
· Support Business Continuity and Disaster Recovery planning.
· Coordinate Disaster Recovery security testing.
· Review backup security and ransomware readiness.
· Security Awareness
· Develop annual security awareness programmes.
· Conduct user security training.
· Coordinate phishing simulations and awareness campaigns.
Vendor Security
· Assess third-party security controls.
· Review cloud and hosted service security.
· Ensure vendor access is controlled and monitored.
Management
· Prepare departmental budgets and work plans.
· Provide security advice to management.
· Supervise security staff where applicable.
· Participate in ICT management meetings.
KEY REQUIREMENT SKILLS AND QUALIFICATION
· Degree in Computer Science, Information Technology, Information Systems or related field
· Minimum 5 years relevant ICT experience & 2 years in information security, infrastructure or ICT governance
· Strong understanding of information security governance and cybersecurity
· Knowledge of firewalls, VPNs, IDS/IPS, endpoint security and identity management
· Knowledge of ICT risk management and compliance
· Strong analytical and problem-solving skills
HOW TO APPLY
· If you meet the above qualifications, skills and experience share CV on recruitment@britesmanagement.com
· Interviews will be carried out on a rolling basis until the position is filled.
· Only the shortlisted candidates will be contacted.