Skip to main content

Get Matched To Jobs You Qualify For, Automatically!

C

IT Security Manager at CIC Insurance

CIC Insurance
August 30, 2026
Full-time
On-site
About the Role

Reporting to the Group Head of IT, the Information Security Manager is responsible for protecting the organization's information assets, technology infrastructure, applications, and digital services from cyber and information security threats. The role provides strategic direction and hands-on leadership in the implementation, monitoring, and continuous improvement of information security controls, while ensuring compliance with applicable regulatory requirements, policies, and recognized security frameworks such as ISO/IEC 27001 and NIST. The Information Security Manager will work closely with IT, Risk, Internal Audit, business teams, project teams, and external partners to embed security-by-design principles across technology initiatives, proactively manage cyber risks, and strengthen the organization's overall cyber resilience.

Key Responsibilities


Manage, maintain, and continuously improve the organization's information security infrastructure and controls, including firewalls, IDS/IPS, endpoint protection/EDR, PAM, NAC, patch and vulnerability management, security monitoring and logging, and cloud security controls across AWS and Microsoft Azure.
Lead the organization's technology security assessment programme, including vulnerability assessments, penetration testing, security reviews, configuration assessments, and risk assessments.
Develop, review, implement, and enforce information security policies, standards, procedures, and guidelines.
Ensure security policies remain aligned with business requirements, regulatory obligations, and industry standards.
Develop and deliver a comprehensive information security and cybersecurity awareness programme.
Conduct regular security awareness campaigns covering phishing, social engineering, password security, data protection, remote working, acceptable use, and emerging cyber threats.
Partner with project teams, IT managers, architects, developers, and business stakeholders to embed security-by-design principles throughout the technology lifecycle.
Provide security architecture guidance and recommendations for new systems, applications, integrations, infrastructure, and cloud initiatives.
Monitor the evolving cyber threat landscape and assess its potential impact on the organization.
Lead and coordinate the cybersecurity incident response lifecycle, including detection and identification, investigation and analysis, containment, eradication, recovery, and post-incident review.
Provide cybersecurity oversight for business continuity and disaster recovery programmes.
Establish and monitor security patching and vulnerability remediation requirements across technology platforms.
Establish and maintain effective relationships with cybersecurity and technology security vendors.
Prepare regular information security reports and dashboards for the Group Head of IT and other relevant management forums.


Who We're Looking For

Essential Knowledge/Skills and Experience Required:


Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field.
Relevant Professional Qualification such as CISA, CISM, CISP, CEH or similar.
Additional certifications in AWS, Azure, and GCP are a plus
Minimum of seven (7) years of hands-on IT security experience.
At least two (2) years of team leadership.
Experience in financial services industry.
Proven experience in conducting penetration tests vulnerability assessments and leading closure of findings through collaborating with various stakeholders Internal & External IT Auditors, Risk and Compliance department etc.
Strong knowledge of security frameworks and standards e.g., ISO 27001, NIST.
Skilled in IT risk management, Cyber threat mitigation, and hands-on problem-solving with strong analytical abilities.
Proven leadership and communication skills in cross functional teams.
Strategic, adaptable, and budget-conscious decision-maker, aligning security initiatives with business objectives and managing vendor relations effectively.

Get Matched To Jobs You Qualify For, Automatically!