I
Information Security Analyst at IDinsight
IDinsight
September 15, 2026
Full-time
On-site
About the Information Security Analyst Role
The Information Security and Systems team is the engine driving our uniquely dynamic, high-achieving, multicultural, multi-continental team at the cutting edge of how evidence is used to improve global development programs. This team's mandate is to build and maintain systems that enable IDinsight teams to achieve social impact. This role will be a great fit for someone who is genuinely hands-on with security tooling, who can write clearly enough that a policy actually changes behaviour, and who would rather reduce risk at the design stage than document it after the fact.
Responsibilities
As an Information Security Analyst, your core day-to-day work may include:
Security tooling administration — Owning day-to-day administration of our security stack, including SASE, CASB, EDR, SIEM, and MDM. Tuning policies and detections, maintaining coverage across a distributed fleet, investigating alerts, and keeping the tooling useful rather than merely deployed.
Security Education, Training and Awareness — Designing and running SETA across the organisation: onboarding security training, phishing simulations, targeted sessions for higher-risk teams, and awareness material that colleagues in six offices actually read.
Incident response — Triaging and investigating security events, coordinating containment and recovery, maintaining and exercising the incident response plan, and writing up what happened and what changes as a result.
Risk assessment — Conducting information and data security risk assessments on projects, systems, vendors, and data flows. Translating findings into recommendations that project teams can act on within their timelines.
Partner due diligence — Responding to security and data protection due diligence requests from funders, government partners, and clients, and maintaining the evidence library so each response is faster than the last.
Policy and guidance — Developing and maintaining information security policies, standards, and practical guidelines, and keeping them aligned with recognised frameworks and with our regulatory obligations.
Data protection compliance — Supporting compliance with GDPR and the national data protection regimes in the countries where we operate: data mapping, retention, subject rights requests, and the assessments that new processing activities require.
Governance, risk, and compliance — Contributing to the control framework, maintaining the risk register, and supporting internal and external assurance activity.
AI governance — Contributing to how IDinsight governs AI use on project and organisational data: tool assessment, acceptable use guidance, and the controls that make responsible use the default.
Professional Growth and Internal Contributions
Beyond your core responsibilities, you will contribute to the Information Security and Systems team and your own professional development through:
Systems Support: You will occasionally provide Systems Support via our internal help desk. This gives you direct insight into the technical challenges IDinsighters face and lets you deliver high-impact solutions.
Continuous Learning: IDinsight utilises a diverse ecosystem of tools. While we don't expect day-one mastery of every system, we look for a commitment to building deep technical expertise over time. We support security certification and continuing professional education.
Qualifications
We're looking for an entrepreneurial, "get stuff done" teammate with 3 - 5 years of relevant experience. Desired qualifications include:
3 - 5 years of professional experience in information security, IT security operations, or a closely related role;
Hands-on administration experience with at least three of SASE, CASB, EDR, SIEM, and MDM, and the ability to get productive on the rest;
Demonstrated experience in incident response, including investigation and post-incident reporting;
Experience conducting information or data security risk assessments and communicating findings to non-technical audiences;
Experience developing information security policies, standards, or guidelines that were adopted and used;
Working knowledge of GDPR and of at least one national data protection law in the regions where we operate, such as Kenya's Data Protection Act, Zambia's Data Protection Act, or India's DPDP Act;
Familiarity with recognised information security standards and frameworks, such as NIST SP 800-171, NIST CSF, or ISO/IEC 27001;
A security certification is valued — Security+ or SSCP at this level, with CISM or CISSP as a credible next step we will support you toward;
Demonstrated interest in IT governance, risk, and compliance, and in AI governance;
A bachelor's degree in Computer Science or other quantitative disciplines;
Strong communicator in multiple forms (written communications, public speaking, teamwork, and upward management), with a track record of explaining risk to people who have competing priorities;
Detail- and execution-oriented, able to take a task from high-level strategic idea to rapid execution with a large amount of autonomy and conscientiousness;
Demonstrated track record as a self-starter and leader, including comfort with ambiguity and dynamic environments and work streams;
Strong desire for professional growth and development, with a track record of openness to give and receive feedback;
Strong problem-solving skills in handling system challenges;
People-focused and people-facing, with high levels of empathy and desire to listen to and share in teammates' victories, concerns, and needs;
Strong ability to maintain integrity and confidentiality in complex situations;
Ability to handle sensitive information, data, and issues with mature and discreet professionalism;
Ability to work with international, cross-cultural, and diverse teams across time zones.
The Information Security and Systems team is the engine driving our uniquely dynamic, high-achieving, multicultural, multi-continental team at the cutting edge of how evidence is used to improve global development programs. This team's mandate is to build and maintain systems that enable IDinsight teams to achieve social impact. This role will be a great fit for someone who is genuinely hands-on with security tooling, who can write clearly enough that a policy actually changes behaviour, and who would rather reduce risk at the design stage than document it after the fact.
Responsibilities
As an Information Security Analyst, your core day-to-day work may include:
Security tooling administration — Owning day-to-day administration of our security stack, including SASE, CASB, EDR, SIEM, and MDM. Tuning policies and detections, maintaining coverage across a distributed fleet, investigating alerts, and keeping the tooling useful rather than merely deployed.
Security Education, Training and Awareness — Designing and running SETA across the organisation: onboarding security training, phishing simulations, targeted sessions for higher-risk teams, and awareness material that colleagues in six offices actually read.
Incident response — Triaging and investigating security events, coordinating containment and recovery, maintaining and exercising the incident response plan, and writing up what happened and what changes as a result.
Risk assessment — Conducting information and data security risk assessments on projects, systems, vendors, and data flows. Translating findings into recommendations that project teams can act on within their timelines.
Partner due diligence — Responding to security and data protection due diligence requests from funders, government partners, and clients, and maintaining the evidence library so each response is faster than the last.
Policy and guidance — Developing and maintaining information security policies, standards, and practical guidelines, and keeping them aligned with recognised frameworks and with our regulatory obligations.
Data protection compliance — Supporting compliance with GDPR and the national data protection regimes in the countries where we operate: data mapping, retention, subject rights requests, and the assessments that new processing activities require.
Governance, risk, and compliance — Contributing to the control framework, maintaining the risk register, and supporting internal and external assurance activity.
AI governance — Contributing to how IDinsight governs AI use on project and organisational data: tool assessment, acceptable use guidance, and the controls that make responsible use the default.
Professional Growth and Internal Contributions
Beyond your core responsibilities, you will contribute to the Information Security and Systems team and your own professional development through:
Systems Support: You will occasionally provide Systems Support via our internal help desk. This gives you direct insight into the technical challenges IDinsighters face and lets you deliver high-impact solutions.
Continuous Learning: IDinsight utilises a diverse ecosystem of tools. While we don't expect day-one mastery of every system, we look for a commitment to building deep technical expertise over time. We support security certification and continuing professional education.
Qualifications
We're looking for an entrepreneurial, "get stuff done" teammate with 3 - 5 years of relevant experience. Desired qualifications include:
3 - 5 years of professional experience in information security, IT security operations, or a closely related role;
Hands-on administration experience with at least three of SASE, CASB, EDR, SIEM, and MDM, and the ability to get productive on the rest;
Demonstrated experience in incident response, including investigation and post-incident reporting;
Experience conducting information or data security risk assessments and communicating findings to non-technical audiences;
Experience developing information security policies, standards, or guidelines that were adopted and used;
Working knowledge of GDPR and of at least one national data protection law in the regions where we operate, such as Kenya's Data Protection Act, Zambia's Data Protection Act, or India's DPDP Act;
Familiarity with recognised information security standards and frameworks, such as NIST SP 800-171, NIST CSF, or ISO/IEC 27001;
A security certification is valued — Security+ or SSCP at this level, with CISM or CISSP as a credible next step we will support you toward;
Demonstrated interest in IT governance, risk, and compliance, and in AI governance;
A bachelor's degree in Computer Science or other quantitative disciplines;
Strong communicator in multiple forms (written communications, public speaking, teamwork, and upward management), with a track record of explaining risk to people who have competing priorities;
Detail- and execution-oriented, able to take a task from high-level strategic idea to rapid execution with a large amount of autonomy and conscientiousness;
Demonstrated track record as a self-starter and leader, including comfort with ambiguity and dynamic environments and work streams;
Strong desire for professional growth and development, with a track record of openness to give and receive feedback;
Strong problem-solving skills in handling system challenges;
People-focused and people-facing, with high levels of empathy and desire to listen to and share in teammates' victories, concerns, and needs;
Strong ability to maintain integrity and confidentiality in complex situations;
Ability to handle sensitive information, data, and issues with mature and discreet professionalism;
Ability to work with international, cross-cultural, and diverse teams across time zones.