SECURITY OPERATIONS ASSISTANT (1 POSITION)
Job Summary
Reporting to the Systems Security Officer, the job holder will be responsible for, among others, monitoring the Information Technology infrastructure, supporting the investigation of security breaches, incident response, and performing security impact analysis in the change process.
Key Responsibilities
- Proactively monitor and report the security posture of all information assets as per Security Operations Center (SOC) procedures by utilizing technical tools such as SIEM, Antimalware, Database Activity Monitoring Systems, Fraud Management Systems, etc.
- Work in 24/7 shifts performing real-time monitoring of security alerts generated by various security tools deployed by the SOC. Analyse and assess security alerts and escalate for further investigations and communication.
- Periodically review systems within the Sacco to ensure they are configured as per established security baseline standards. Report any non-compliance with information security policies.
- Participate in establishing mechanisms for information and cyber security incident response management, including monitoring, detecting, remediating, and fully investigating security breaches to establish and address root causes to minimize future occurrences, as well as performing impact analysis.
- Perform threat intelligence research, including the collection of global and internal threat intelligence, and implement actions based on analysis and recommendations.
- Offer support in cyber security awareness and training campaigns.
- Document and research security breaches and assess any damage caused.
- Keep abreast of emerging issues by attending educational workshops, seminars, conferences, and participating in professional societies.
- Partners: Assess external partners such as vendors’ and contractors’ procedures, processes, and security controls to ensure they adequately protect the organization’s business information and transactions.
- Collaboration: Work with user departments to ensure information technology threats are properly identified, analysed, communicated, investigated, and corrective actions taken.
Qualifications
Technical Skills
- Bachelor’s degree in Information Technology, Computer Science, or any other related field with relevant IT Security professional qualifications (CISA/CISM/CEH or other relevant security certifications).
- 3 years’ experience in Security/Network administration with strong technical knowledge of database, network, and operating systems security.
- Knowledge of various security methodologies, processes, and technical security solutions (SIEM, EDR, firewall, and intrusion detection systems).
- Knowledge of TCP/IP protocols, network analysis, network protocols, and network/security applications.
- Working knowledge and experience in penetration testing and vulnerability assessments.
- Knowledge of common cybersecurity threats and sources of cybersecurity information.
- Good understanding and knowledge of risk assessment, risk procedures, security assessment, vulnerability management, and penetration testing.
Non-Technical Skills
- Good communication skills
- Problem-solving skills
Qualified applicants should apply on or before 5:00 pm on 1 December 2025 using the link provided on the Society’s website.
Only shortlisted candidates will be contacted.
