Urwego Finance CBC
Information & Cybersecurity Officer
Posted
1 month ago
Experience
2/3 Years
Deadline
Closed
Job Summary
The Information & Cybersecurity Officer is tasked with leading the organization's information security function. This role involves overseeing the development, implementation, and management of the company's cybersecurity strategy, policies, and procedures to protect against unauthorized access and malicious threats. Additionally, the officer guarantees regulatory compliance, monitors automatic system activities, and conducts staff training. The role reports administratively to the Chief Executive Officer (CEO) and functionally to the IT Board Committee.
Qualification
Candidates must hold a degree from an accredited institution alongside highly preferred professional industry certifications:
- Required Education: Bachelor’s degree in Computer Science, Information Technology, or a related field.
- Highly Desirable Certifications: Certified Ethical Hacker (CEH), Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), or Certified Information Systems Auditor (CISA).
Experience
- 2–3 years of full-time work experience in Information Security or a related field.
- Strong preference for experience gained within the banking, financial services, telecommunications, or related corporate sectors.
- Demonstrated background in technical IT roles (such as IT architecture, development, or operations) coupled with a dedicated focus on system controls.
- Advanced experience in IT Audit or IT Risk Management is considered a distinct added advantage.
Core Duties and Responsibilities
Strategy, Policy & Risk Management:
- Design and execute a robust cybersecurity strategy that aligns seamlessly with organizational goals and financial regulatory requirements.
- Create, implement, and maintain comprehensive security policies, standards, and guidelines that align with industry best practices.
- Establish threat modeling capabilities, maintain threat profiles, and assess internal and external risks threatening non-public institutional data.
- Recommend clear corrective actions to address program shortfalls and strictly enforce compliance across all departments.
- Perform regular risk assessments, vulnerability assessments, and security audits to identify operational weaknesses.
Incident Monitoring, Defense & Recovery:
- Conduct comprehensive penetration tests and regular internal security audits to detect system vulnerabilities.
- Regularly track and detect cybersecurity incidents, checking for abnormal or unauthorized access to the organization's information systems.
- Deploy preventive and detective infrastructure to protect financial data and networks from malicious acts.
- Respond to active cybersecurity incidents to mitigate negative effects, execute disaster recovery, and restore normal banking operations promptly.
- Create and maintain an incident response plan, coordinating closely with relevant stakeholders for containment and remediation.
Vendor Governance, Compliance & Training:
- Evaluate the security posture of third-party vendors and service providers, ensuring contracts contain relevant security clauses.
- Continuously track industry trends, emerging technologies, and new exploits to verify that organizational controls remain effective.
- Foster a strict culture of security awareness by creating and delivering regular training programs for employees on information security.
- Deliver comprehensive status reports to the CEO and the IT Board Committee regarding risks, incidents, and compliance metrics.
- Translate complex cybersecurity vulnerabilities and strategies clearly to non-technical business stakeholders.
Skills & Competencies
Required Technical & Interpersonal Skills:
- System Administration: Strong working knowledge of network and systems administration, including firewalls, intrusion detection systems, and vulnerability scanning tools.
- Regulatory Compliance: Deep familiarity with regulatory requirements related to financial services, cybersecurity, data protection, and digital privacy.
- Operational Autonomy: Ability to work independently, manage tight deadlines, and motivate team members to achieve technical goals.
- Aptitude: Strong analytical, problem-solving, and troubleshooting skills to detect and isolate intricate infrastructure vulnerabilities.
- Organizational Fit: Knowledge of the financial sector matched with an understanding of Christian organizational values.
- Core Characteristics: Displays Christ-centered character and a genuine passion to serve the underserved communities of Rwanda.
Skills Required:
- Computer / Software / It / Data
Quick Actions
Share Vacancy