1.Application Security Manager at BPR: (Deadline 13
August 2026)
Job Purpose
The Application Security Manager is responsible for leading
the Bank’s application security function, and a team of Application security
lead, Analyst and engineers ensuring that all business applications,
particularly Mission Critical Applications (MCAs) are secure, compliant, and
aligned with regulatory and industry standards. The role provides oversight
across application security assessments, Secure-Software Development Lifecycle
(Secure-SDLC), or Dev-SecOps Identity Lifecyle management, access governance,
and secure project delivery, while driving continuous improvement in security
posture of the Bank and its customer information. Secondly the Role will give
oversight support and guidance to the team of Cybersecurity lead and
Cybersecurity Analyst and engineers.
Main Responsibilities
- Monitor
and analyze security alerts from SIEM, EDR, NDR, SOAR, and other tools to
identify suspicious activities and threats.
- Lead
and manage the Application Security team, ensuring effective delivery of
security objectives and initiatives.
- Oversee
and conduct periodic user access recertification across all bank
applications, with focus on MCAs, to enforce least privilege and access
governance.
- Direct
and conduct the execution of Vulnerability Assessments and Penetration
Testing (VAPT) for all applications.
- Provide
security assurance for technology projects, ensuring compliance with
security requirements prior to CAB approval.
- Define
and enforce application security standards, policies, and secure SDLC
practices.
- Identify,
assess, and mitigate application-level risks and vulnerabilities.
- Provide
ongoing security assurance and reporting on the Bank’s application
landscape.
- Secure
Integration Management: Oversee and ensure secure integration of internal
systems such as microservices, API and other third-party services by
enforcing security controls, conducting risk assessments, and minimizing
potential attack vectors across all interfaces
- Advise
stakeholders on regulatory and industry frameworks (e.g., OWASP Top 10, NIST,
ISO 27001/ISMS, PCI DSS and GDPR).
Daily Responsibilities:
- Making
regular reports to line manager to issue identified or raised by internal
audit, risk and regulatory pertaining to application security unit to line
supervisors with clear strategic plan to address them
- Coordinated
and Conduct user access reviews and recertification activities
- Leading
the discovery of vulnerabilities and risks in application, software
systems and databases and cloud infrastructure with ongoing vulnerability
scans, penetration testing and identifying OWASP top 10 threats targeting
both bank internal applications and internet facing environments such as
digital channels and others on regular basis through intel monitoring and
ensuring software applications are updated.
- Review
and track application security findings, remediation status, and risk
exposure
- Follow
up and enforce the correction of Identified risks via RCSA (Risk Control
Self-Assessment)
Educational qualifications and work experience:
- Bachelor's
level degree BSc. Information Technology / Computer Science /
Telecommunications / Engineering (Electrical, Electronic) or related field
- Master’s
Degree in MBA/MSc
- Professional
Qualifications Certified Security certification such as: OSWE (Offensive
Security Web Expert), OSCP (Offensive Security Certified Professional
CISM, ISMS lead Implementeror Lead Audit, GIAC Certifications, CEH
- 3
years of minimum experience Information Security Management, Governance,
Risk Management and Compliance, Security Architecture and Engineering,
Security Program Management and Operations, Communication and Network
Security, Identity and Access Management, Software Development, Security
Assessment and Testing,Information Security Incident Management, IT or
Information SecuritySoftware Development, Security Assessment and Testing.
CLICK
HERE TO READ MORE AND APPLY
2.Security Monitoring and Response Analysts at BPR:
(Deadline 13 August 2026)
Security Monitoring and Response Analysts (1)
Job Purpose
The Security Monitoring and Response Analyst is responsible
for the continuous monitoring, detection, analysis, and response to
cybersecurity events and incidents within the Bank’s Security Operations Center
(SOC). The role supports the Senior Manager Information Security by ensuring
effective execution of security monitoring and incident response activities,
while working under the operational guidance of the Unit Manager to maintain
the security posture of the Bank. The analyst plays a critical role in safeguarding
the Bank’s systems, networks, applications, and data by identifying potential
threats, investigating suspicious activities, and responding promptly to
security incidents in line with internal policies, regulatory requirements, and
industry best practices.
Main Responsibilities
- Monitor
and analyze security alerts from SIEM, EDR, NDR, SOAR, and other tools to
identify suspicious activities and threats.
- Perform
initial triage and classification of alerts based on severity, impact, and
potential risk to the Bank.
- Investigate
security incidents through log analysis, network traffic inspection, and
endpoint activ
- ity
review.
- Execute
incident response actions (containment, eradication, and recovery) in line
with SOC procedures and SOC Lead guidance.
- Escalate
complex or high-risk incidents promptly to the Senior Manager Information
Security and relevant stakeholders.
- Support
threat intelligence usage and contribute to threat hunting by identifying
unusual patterns and indicators of compromise.
- Assist
in tuning SIEM rules, alert thresholds, and correlation logic to improve
detection accuracy and reduce false positives.
- Ensure
SOC tools are functioning effectively, including supporting log source
integration and reporting technical issues.
- Adhere
to SOC processes, playbooks, and regulatory requirements (ISO 27001, NCSA,
BNR), while identifying improvement opportunities.
- Document
all incidents, investigations, and response actions, and provide timely
updates and reporting on incident status.
Daily Responsibilities:
- Monitor
and analyze security alerts from SIEM, EDR, NDR, SOAR, Monitor SOC
dashboards and respond to security alerts in real time.
- Perform
triage and analysis of alerts to determine validity and severity.
- Investigate
suspicious activities using logs, SIEM queries, and forensic tools.
- Escala
- te
incidents as per defined escalation procedures.
- Track
and update incident tickets to
- ensure
timely resolution and proper documentation.
- Collaborate
with line manager and team members during incident handling.
- Review
threat intelligence feeds and apply relevant insights.
- Ensure
compliance with defined SLAs (e.g., response time, resolution time).
Educational qualifications and work experience:
- Bachelor's
level degree I B.Sc. Information Technology / Computer Science /
Telecommunications Engineering or related field.
- Master’s
Degree in MBA / MSC
- Professional
Qualifications Certified Ethical Hacker, GIAC Certified Incident Handler
(GCIH), GIAC Certified Forensic Analyst (GCFA), CompTIA CySA+
(Cybersecurity Analyst) CISSP: Certified Information Systems Security
Professional • CISA: Certified Information Systems Auditor • CISM:
Certified Information Systems Manager • CCISO: Certified Chief Information
Security Officer, Certified SOC Manager (CSM) - EC-Council, or Similar.
- 3
years of minimum experience Information Security Management, Governance,
Risk Management and Compliance, Security Architecture and Engineering,
Security Program Management and Operations, Communication and Network
Security, Identity and Access Management, Software Development, Security
Assessment and Testing,Information Security Incident Management, IT or
Information Security Software Development, Security Assessment and
Testing.
CLICK HERE
TO READ MORE AND APPLY
3.IT Security Analyst at BPR: (Deadline 13 August 2026)
Job Purpose
The IT Security Analyst is responsible for supporting the
implementation and day-to-day execution of the Bank’s cybersecurity controls,
ensuring that technology infrastructure is secure, compliant, and aligned with
defined cybersecurity policies and minimum-security baselines. The role reports
to the Application Security Manager and plays a key role in security
assessments, vulnerability management, infrastructure protection, and
operational support of security systems. The IT Security Analyst contributes to
ensuring that all systems across the BPR bank including networks, servers,
cloud environments, endpoints, IoT, and enterprise platforms—are monitored,
assessed, and secured against cyber threats. The role also supports the
operational management of internal security solutions and ensures timely
remediation of identified vulnerabilities and audit findings.
Main Responsibilities
- Conduct
technical security assessments of infrastructure, systems, and platforms
against defined minimum security baseline standards and report findings.
- Support
validation and enforcement of minimum-security configurations across
infrastructure components before and after system deployment.
- Identify,
track, and follow up on remediation of vulnerabilities in collaboration
with IT and SOC/CiSOC teams, ensuring adherence to defined SLAs.
- Administer
and support internal cybersecurity tools and solutions including handling
operational tickets and routine changes addressed to information security
- Assist
in monitoring the security posture of networks, servers, endpoints, cloud,
and IoT devices, and escalate identified risks.
- Support
cybersecurity reviews for ICT projects and changes, ensuring
implementation of required security controls under guidance from the
Application Security Manager.
- Work
closely with IT teams to ensure systems are patched, hardened, and
compliant with defined security standards.
- Provide
support for internal and external audits by preparing evidence, tracking
findings, and ensuring timely remediation of assigned actions.
- Collaborate
with SOC/CiSOC in identifying, reporting, and supporting the response to
security incidents affecting infrastructure.
- Maintain
accurate documentation of security assessments, vulnerabilities, and remediation
status, and provide regular updates to the Application Security Manager.
Daily Responsibilities:
- Certifying
user accounts and access.
- Perform
security checks and assessments on systems to validate compliance with
baseline standards.
- Manage
and resolve operational tickets related to cybersecurity systems (e.g.,
firewall requests, endpoint issues, access controls).
- Track
and follow up on vulnerability remediation with IT teams.
- Support
enforcement of patching, hardening, and endpoint protection across the
infrastructure.
- Assist
in monitoring alerts and escalate potential security threats or incidents.
Educational qualifications and work experience:
- Bachelor’s
Degree in B.Sc. Information Technology / Computer Science /
Telecommunications /
- Engineering
or related field
- Master’s
Degree in MBA/MSc related field is an added advantage.
- Professional
Qualifications Certified Offsec Certification for Penetration testing like
PEN-200, or PEN-300, CCNA Security, CCPN Security, CEH: Certified Ethical
Hacker; CISA: Certified Information Systems Auditor; CISM: Certified
Information Security Manager; CISSP: Certified Information Systems
Security Professional, or any other related certification.
- 3
years Minimum experience in Security / System / Network / Database / Platform
Administration, Information security policies as well as applicable
government regulations, Security Baseline standards (Unix, Windows,
Databases),
- Encryption
and Certificate Management, Identity and Access Management, Software
Development, Security Assessment and Testing, Computer network penetration
testing and techniques, IT or Information Security.
CLICK HERE
TO READ MORE AND APPLY
Post a Comment