Date Posted:
2026-09-16 12:43:17
Employment Type
Full Time
Website
Location:
Lusaka
Salary:
Negotiable
Phone:
Description:
Job Purpose
The IT Security Officer will be responsible for developing, implementing, and overseeing the bank’s information security strategy, policies, and controls - with the supervision of the Head of IT & Security. The role ensures that the bank’s data, systems, applications, and infrastructure are safeguarded against internal and external threats while meeting local and regulatory requirements and international standards. Establish, maintain, and enforce the bank’s information security framework, aligned with international and local cybersecurity regulations.
Summary of Key Responsibilities:
- Preparation and continuous improvement of the Information Security Policy, standards and other supporting documentation in the field of information security;
- Monitoring compliance of security policies and procedures among employees, contractors and third parties.
- Performing information security risk analysis and ongoing analysis of threats, vulnerabilities and security controls related to the security of information;
- Work with the Head of IT & Security in defining the IT security strategy, as well as determining new or adjustment the current IT security measures, in accordance with the Bank's strategic security documents;
- Monitoring and assessing the database security activities, procedures and, systems
- Managing the process of Business Continuity Management (BCM) and follow-up the activities related to the BCM (such as disaster recovery, back-up procedures and system recovery from back-up);
- Ensure compliance with international standards and conduct regular gap analyses.
- Supporting database Security systems through data audits, scanning and, assessment tools
- Assist the Head of IT & Security in preparing and presenting security risk assessments and reports to senior management, regulators, and the Board Risk Committee.
- Design, implement, and enforce security policies and procedures to safeguard the bank’s infrastructure and data.
- Lead investigations of security breaches, develop strategies for handling incidents, and ensure lessons learned are integrated into policies and processes.
- Stay current with the latest security systems, standards, and products to ensure optimal protection.
- Regularly evaluate the effectiveness of security measures and update them against emerging threats and industry best practices.
- Conduct regular staff training on security awareness, best practices, and incident procedures.
- Collaborate with IT and business management to continuously improve security controls and culture.
- Identify vulnerabilities and ensure timely remediation through patch management and secure configurations.
- Work with IT and business units to integrate security into new product initiatives.
- Evaluate and approve technology vendors, outsourcing partners, and cloud solutions for compliance with security standards.
- Manage penetration tests, vulnerability assessments, and external audits.
Required Skills and Competencies
- Excellent communication and stakeholder-management skills, capable of engaging effectively with regulators, auditors, and the Board.
- Attention to detail
- Exceptional numerical & analytical skills
- Strong risk management skills.
- Team player
- Ethically sound
- Ability to influence across departments, build a culture of security, and lead change initiatives without direct authority
- Sober minded
- Incident management skills
- Excellent time management skills
Primary Areas of Accountability:
Qualifications and Experience
- Bachelor’s degree in information security, Computer Science, or related field. Master’s degree preferred.
- Professional certifications: CISSP or CISM required; CISA and ISO 27001 Lead Implementer preferred.
- Cloud security certifications (e.g., CCSP, AWS Security) are a plus.
- Must have a minimum of 5-7 years in information security, with at least 3 years in the regulated financial-services sector (Commercial Bank).
- Strong background in banking systems, digital channels, payment systems, and regulatory environments.
- Must be experienced with common core banking systems including their architecture, integrations, and data security requirements.
- Proven expertise in cybersecurity frameworks, Database & network security, cryptography, and identity & access management.
- Must have proven experience of conducting ICT security training and awareness plans for end users.
- Must be a member of relevant ICT Security professional body
QUALIFIED FEMALES & THE DIFFERENTLY ABLED PERSONS ARE ENCOURAGED TO APPLY FOR THIS POSITION
If you meet the hiring requirements for the position, please email your CV, Cover Letter and Qualifications clearly stating your salary expectations to: jobs@bemconsult.com & Cc bemconsult8@gmail.com
Note that, all communications will be kept in the strictest of confidence. If you do not receive communication within 21 working days of the closing date of the advert, please consider your application unsuccessful.
Note that if you are successful, verified qualifications from the Zambia Qualifications Authority (ZAQA) will be required before the job offer.
