Chief Manager – Information Security

Terms of Service: Five (5) years contract renewable up to attainment of mandatory retirement age, subject to satisfactory performance and adherence to the Authority’s Code of Conduct.

Remuneration:     As per KRA salary structure

 

Job Summary

The jobholder shall be responsible for management of Cybersecurity Operations, managing Information Security risks, implementation of security tools and infrastructure, formulating and enforcing policies, addressing technical vulnerabilities and ensuring compliance with security best practices and maintaining an effective Information Security Management System (ISMS).

Duties & Responsibilities

  • Develop and implement comprehensive Information Security strategies that deliver secure and reliable technology solutions, ensuring the protection of the Authority’s digital assets.
  • Coordinate the design and implementation of information security infrastructure to strengthen the Authority’s cyber resilience and safeguard critical assets
  • Ensure that the Authority’s infrastructure and assets are continuously monitored through a dedicated Security Operations Center (SOC) to detect, identify, and respond to cyber-attacks and information security incidents promptly.
  • Oversee timely security testing, including vulnerability assessments and penetration tests, to ensure that automated systems comply with security policies, meet established standards, and address identified risks.
  • Implement and maintain the Information Security Management System (ISMS) in alignment with the ISO/IEC 27001 standard to ensure continual improvement, compliance, and effective risk management
  • Oversee implementation of corporate initiatives in the region/division: Ensure conformity to ISO standards and data security requirements, and manage Audit, Integrity, Quality Management Systems (QMS), Risk Management programmes and staff performance.

Person specifications

For appointment to this job, the candidate must have:

  • A Bachelor’s degree in any of the following disciplines: - Computer Science, Information Communication Technology, Electrical / Electronic Engineering, Telecommunications, Cybersecurity & Digital Forensics or relevant and equivalent qualification from a recognized Institution;
  • A Master’s Degree in any of the following disciplines: - Computer Science, Information Communication Technology, Cybersecurity & Digital Forensics or relevant or equivalent qualification from a recognized Institution will be an added advantage.
  • Certification in lead auditor or implementer of ISO/IEC 27001, Risk Management or equivalent will be an added advantage.
  • Membership to a relevant professional body will be an added advantage
  • Minimum of seven (7) years in relevant work experience, three (3) years of which should be at middle managerial role.
  • Leadership Course lasting not less than four (4) weeks from a recognized institution will be an added advantage.
  • Any of the following professional certifications: Certified Ethical Hacker (CEH), Certified Information Systems Security Professional (CISSP), EC-Council Certified Incident Handler (ECIH), Certified Forensics Hacker Investigator (CFHI).

 

Key Competencies

  • Visionary leadership, strategic thinking, strong organizational, planning, analytical and interpersonal skills.
  • Adaptability and strong Project management skills
  • Strong decision-making, problem-solving and creative thinking skills
  • Strong persuasion, negotiation and communication skills–both oral and written.
  • Professionalism, Ethical Judgment and Integrity

 

Job Application Guidelines

Registration:

  • Go to https://erecruitment.kra.go.ke/login and then click on the ‘Register’ button to start the application process.
  • After registration, you will receive an email enabling you to confirm your email address and complete your registration.

Log on:

  • After registration go to https://erecruitment.kra.go.ke/login
  • Key in your username and password then click on ‘Log in’ to access your account.
  • After successful log in, the system will open the ‘Applicant Cockpit’.

Candidate Profile (To create or update applicant detail):

  • On the ‘Applicant Cockpit’ page, go to the tab ‘Candidate Profile’.
  • Click on ‘My Profile’ to create and update your profile.
  • Follow the instructions to complete your profile.
  • The process will end by clicking the tab “Overview and Release”.
  • Ensure you click the check box on the page to complete the profile.

Application process:

  • To view the open job postings, click on the tab ‘Employment Opportunities’ on the ‘Applicant Cockpit’ page.
  • Under the heading ‘Job Search’ click the ‘Start’ button to view all available vacancies.
  • Click on the Job posting to display the details of the position.
  • To apply for the position, click ‘Apply’ button at the top of the page.
  • Follow the instructions to complete and submit your application.
  • Kindly note that all mandatory fields must be completed.
  • To complete the process of application, click the ‘Send Application Now’ button after reviewing and accepting the ‘Data Privacy Statement’.

In case of any challenges, please send your email query to isupporthr@kra.go.ke

 

If you experience any delay in receiving an email notification at the end of the e-recruitment registration process, please refresh your email. In case of any challenge, please send your query to isupporthr@kra.go.ke

Kenya Revenue Authority does not charge any fee at any stage of the recruitment process (application, shortlisting, interviewing, and/or offer)

Apply Now
💬
Chief Manager – Information Security