Specialist; Cybersecurity
CRDB Bank Plc
Dar es Salaam, Tanzania
Full-Time
5th October 2023
Line Manager- Manager: Cyber Security
Unit- Cybersecurity
Location- HQ
Job Summary
Responsible for the protection of system boundaries, keeping computer systems and network devices hardened against attacks and securing highly sensitive data. This includes designing and managing computer security architecture and developing cyber security designs as per the established security requirements.
Key Responsibilities:
- Design, implement and enforce IT Security Policies to ensure alignment with related corporate policies.
- Provide expert advice on the ICT security risks facing information assets.
- Responsible for the technical IT security strategy, proposing and implementing solutions and processes to continuously reduce the risks and effects of hacking and cybercrime.
- Responsible for forensic investigation of IT security incidents/breaches, providing regular reporting using the appropriate assurance framework.
- Coordinate regular security testing with high-quality reporting. Responsible for the subsequent hardening of IT systems based on the results of regular tests.
- Implement technical solutions and new security tools to help mitigate security vulnerabilities and automate repeatable tasks.
- Administrate and monitor using specific IT Network Security applications including [but not limited to] the company-wide antivirus, email encryption, Data Loss prevention, file screening, server audit, and host protection systems. This requires continuous re-assessment of suitability for purpose and making or recommending any required changes.
- Run various assessment tools to obtain insight into security posture and create various reports for management and stakeholders.
- Provide remediation consultation to global teams to support enterprise risk reduction efforts
- Monitoring of all IT assets on configuration integrity in order to proactive manage the bank’s environment.
- Engineer, implement and monitor security measures for the protection of computer systems, networks and information assets.
- Identify and define system security requirements standards of the bank.
- Responsible for regular security testing with high-quality reporting. Responsible for the subsequent hardening of IT systems based on the results of regular tests.
- Hardening of all IT assets before being promoted to production environment. The formal checklist will be used for installation/changes of any configuration in the bank’s environment for a new/existing setup.
- Enhance and maintain current hardening standards for all information assets including but not limited to servers, workstations, databases, audiovisuals and network devices.
- Support penetration testing activities and exercises.
- Recommend through assessment-based findings, outcomes, and propositions for further system security hardening enhancement.
- Responsible for information security awareness and training program that informs and motivates workers on cyber-security matters as per the SAT program.
- Monitor internal and external policy compliance and cybersecurity framework is being complied with by both vendors and employees.
- Implement new technology on the network security and ensure security hardening and effectiveness of the control. Implement and Ensure compliance with the Cybersecurity framework within the organization.
- Participate in the incident response program, ensuring that the program is tested throughout the organization and that every staff knows his or her duties during such an incident.
- Prepare and report all security incidents to the ICT Management or as directed by the line manager.
- Real-time monitoring of network user activities.
Experience, Knowledge and Skills Requirements
- Bachelor’s Degree in Computer Systems, Software Engineering, Information Systems/ Computer Science or related discipline from a recognized university.
- Minimum of 3 years of experience in Cybersecurity or ICT Security experience in the banking environment.
- At least 1 ICT Security professional certifications, CISA, CISSP, CEH, CISM, etc.
- Expert knowledge of current IT cyber security issues
- Management of a complex IT Infrastructure within a large enterprise-level organization.
- Contingency and Disaster Recovery Planning.
- Up-to-date knowledge of technical applications
- Ability to think ahead and anticipate problems, issues, and solutions.
- Experience providing IT-focused Enterprise Architecture and strategy.
- Windows Operating systems and Active Directory Management.
Deadline 5th October 2023