Our client is a leading international insurance and risk-management group with a strong presence across Africa, the Middle East, and Europe. The company specializes in corporate health, life, and protection solutions, supporting multinational clients through regional offices and specialized teams. They are seeking a Senior Information Security Specialist to lead and enhance their cybersecurity posture, safeguard critical systems, and support the organization’s long-term security strategy.
Key Responsibilities
- Develop, support, and enhance security strategies, policies, programs, and projects to strengthen overall cyber resilience.
- Oversee compliance with all applicable cyber and information security laws, rules, and regulations.
- Collaborate with the compliance team to define and enforce policies and guidelines ensuring proper logging of user activity and access to sensitive data, supporting insider risk initiatives.
- Regularly review and evaluate security control operations, recommending upgrades to address emerging risks.
- Provide recommendations to management or external vendors regarding tools, technologies, services, and procedures to enhance security posture.
- Lead vendor evaluation and selection for penetration testing, security assessments, and other external security services.
- Work with internal and external stakeholders to identify and drive cyber risk reduction initiatives across IT infrastructure.
- Serve as a subject-matter expert during internal and external audits.
- Lead end-to-end security incident response, including investigation, containment, eradication, and post-incident analysis.
- Oversee and optimize security monitoring systems, ensuring effective alerting and timely event analysis.
- Manage the full vulnerability remediation lifecycle, coordinating patching and configuration changes with IT and development teams.
Qualifications
- Minimum 5 years of hands-on information security experience, including at least 2 years in a senior/lead role.
- Expert knowledge of network security technologies (firewalls, VPNs, IDS/IPS, NAC, secure network architecture).
- Strong experience with public cloud security, especially IAM, security group management, and cloud-native security tools.
- Deep understanding of operating system security, virtualization, and container security.
- Hands-on experience with SIEM, DLP, log analysis, and custom detection rule development.
- Preferred certifications: CISSP, CISM, CEH, CompTIA Security+, or equivalent.
Key Competencies
- Excellent written and verbal communication skills; ability to articulate complex concepts to all audiences.
- Fluency in French is mandatory; strong English proficiency required.
- Proven leadership in managing security projects and initiatives with minimal supervision.
- Strong analytical and problem-solving abilities for incident investigation and vulnerability resolution.
- Ability to work effectively with cross-functional teams (IT Ops, Development, Legal, etc.).
- High ethical standards and strict adherence to confidentiality.
- Flexibility to travel within the African continent as needed, including short-notice assignments.
Salary
- USD 2,000 – 3,000 + Transportation
Benefits
- 13th month salary
- USD 50/day Mobility Allowance for work travel
- Medical insurance + NSSF
- 15 days of annual leave
- Performance bonuses based on KPIs