Senior Information Security Officer
Digaf & Micro-Credit Provider SC Addis Ababa · Addis Ababa Posted 2h ago
About this role
Job Purpose
The Senior Information Security Officer is responsible for protecting the organization’s information systems, data, networks, and digital assets from cyber threats and security risks. The position leads the implementation, monitoring, and continuous improvement of information security controls, policies, procedures, and incident response mechanisms.
Key Responsibilities
Develop, implement, and maintain information security policies, standards, procedures, and guidelines.
Monitor IT systems, networks, applications, and endpoints for security threats and vulnerabilities.
Conduct regular security assessments, vulnerability assessments, and risk analyses.
Identify, investigate, and respond to information security incidents and cyber threats.
Manage and monitor access controls, user privileges, authentication, and authorization mechanisms.
Ensure appropriate protection of confidential and sensitive organizational and customer information.
Conduct periodic review of user access rights and recommend corrective actions.
Support implementation and monitoring of endpoint protection, firewalls, antivirus/EDR, encryption, backup, and other security controls.
Conduct security awareness and cybersecurity training for employees.
Coordinate vulnerability remediation and follow up on identified security weaknesses.
Maintain and test Information Security Incident Response and Business Continuity procedures.
Support internal and external IT security audits and ensure timely closure of audit findings.
Monitor compliance with applicable laws, regulatory requirements, organizational policies, and information security standards.
Maintain security logs, incident records, risk registers, and security reports.
Work closely with IT, Risk, Compliance, Internal Audit, and other departments on security-related matters.
Investigate suspected unauthorized access, data leakage, malware, phishing, and other security incidents.
Provide regular information security reports and recommendations to management.
Stay updated on emerging cybersecurity threats, technologies, and best practices.
Job Requirements
Required Qualifications & Experience
Bachelor’s Degree in Information Technology, Computer Science, Information Systems, or a related field.
3–5 years of relevant experience in information security, cybersecurity, IT audit, network security, or a related field.
Strong knowledge of information security principles, risk management, and cybersecurity practices.
Practical knowledge of network, endpoint, application, and data security.
Experience with security monitoring and incident response.
Knowledge of vulnerability assessment and security testing tools.
Good understanding of access management, authentication, encryption, backup, and disaster recovery.
Knowledge of information security frameworks such as ISO 27001, NIST, or CIS Controls is an advantage.
Relevant certifications such as CISSP, CISM, Security+, CEH, ISO 27001 or equivalent are an advantage.
Cybersecurity and risk management
Incident investigation and response
Analytical and problem-solving skills
Security monitoring
Attention to detail
Confidentiality and integrity
Communication and reporting
Risk awareness
Teamwork and collaboration
How To Apply
- Interested candidates should send their resumes along with a cover letter to our HR department at hr.admin@digafcredit.com no later than 10 workdays. Please specify the position you are applying for in the subject line of your email.
Never miss a role
New jobs land on Telegram first
Every opening we aggregate is posted to @ethio_tech_jobs within minutes — join the channel and be the first to apply.