Information Security & Compliance Manager
Information Security & Compliance Manager
22
Nanyuki, Laikipia, Kenya
Job Views:
Created Date: 2026-08-03
End Date:
Salary: 2000
Industry: Professional Training and Coaching
Openings: 1
Primary Responsibilities :
nual SOC 2 audits with external auditors.
Maintain security controls aligned with Trust Services Criteria.
Develop and maintain information security policies, procedures, and compliance documentation.
Risk Management & Incident Response
Lead security incident response activities, including investigation, containment, root cause analysis, and corrective actions.
Develop and maintain incident response plans and conduct tabletop exercises.
Manage vendor risk assessments and third-party security reviews.
Oversee business continuity and disaster recovery planning and testing.
Client Security & Compliance Support
Participate in customer security reviews and technical discussions.
Respond to client security questionnaires and due diligence requests.
Present the organization's security posture during sales and client meetings.
Support enterprise customers with security and compliance-related requirements.
Security Awareness & Governance
Develop and deliver security awareness and phishing simulation programs.
Support secure onboarding and offboarding processes.
Act as the organization's security subject matter expert.
Maintain security documentation, trust center content, and compliance reports.
Leadership & Collaboration
Manage and mentor compliance team members.
Collaborate with IT, Operations, HR, Legal, and business stakeholders.
Drive continuous improvement in security operations and compliance programs.
Recommend security enhancements and technology improvements.
Experience Requirements:
Qualification
Bachelor's degree in Information Technology, Computer Science, Cybersecurity, or a related field.
Master's degree or equivalent certifications will be an advantage.
Required Experience
5+ years of experience in Information Security, IT Security, or Compliance.
Minimum 2 years leading security or compliance initiatives.
Hands-on experience with Microsoft 365 security administration.
Experience managing SOC 2 Type II compliance programs.
Client-facing experience conducting security reviews and responding to security questionnaires.
Required Skills
Microsoft 365 Security
Microsoft Entra ID (Azure AD)
Microsoft Defender Suite
Microsoft Purview
Microsoft Intune
Conditional Access
Privileged Identity Management (PIM)
Data Loss Prevention (DLP)
AI Platform Security
SOC 2 Type II Compliance
Risk Assessment
Vendor Risk Management
Security Incident Response
Business Continuity & Disaster Recovery
Security Awareness Programs
Security Audits
Policy Development
Technical Documentation
Preferred Certifications
CISSP
CISM
CISA
CRISC
CCSP
Microsoft Security Certifications (SC-100, SC-200, SC-300, SC-400, MS-500)
Preferred Knowledge
ISO 27001
NIST Cybersecurity Framework
HIPAA
GDPR
PCI DSS
Remote Workforce Security
AI Security Governance
Personal Attributes
Strong analytical and problem-solving skills.
Excellent leadership and stakeholder management abilities.
Strong written and verbal communication skills.
Customer-focused with executive presentation skills.
Detail-oriented with high ethical standards.
Ability to manage multiple priorities in a dynamic environment.
Languages
English (Mandatory)
Key Performance Indicators (KPIs)
SOC 2 Audit Readiness & Compliance
Microsoft 365 Security Posture Improvement
Security Incident Response Time
Security Awareness Program Effectiveness
Vendor Risk Assessment Completion
Compliance Audit Success Rate
Client Security Questionnaire Response Time
Business Continuity & Disaster Recovery Readiness
Risk Reduction Initiatives Completed
Security Policy Compliance
