Saturday, August 1, 2026

Cybersecurity & Threat Intelligence Specialist

Job overview

Cybersecurity & Threat Intelligence Specialist is available at Zambia National Commercial Bank Plc in Lusaka. Review the job description, requirements, closing date and application details below.

Beware of scammers: an employer will never ask for money from you.

Position Overview Zanaco Bank Plc is inviting applications from suitably qualified and experienced individuals for the following job aimed at contributing to the Bank’s strategic vision, in the Information Technology Division under the IT Security at Head Office – Support Functions: Role Description This role is responsible for safeguarding the Bank’s digital assets, information, and systems from various cyber threats and attacks. The safeguards include, but not limited to Data Loss prevention, Vulnerability Assessments and Penetration Testing (VAPT), Network Security, Endpoint Security, Mobile Device Management, Email Security, Database Security, Cyber threat intelligence, Security in projects implementation. The role focuses on ensuring that adequate Security Controls, Cyber Risk Management and Compliance is applied and monitored across the enterprise in all IT related projects, systems, automated processes, and people involved in running automated process. The role enforces all security policies, procedures, and control objectives to mitigate risks to the Bank. Reporting to the Cybersecurity & Threat Intelligence Senior Specialist, the Cybersecurity Specialist executes his/ her roles and responsibilities in close collaboration with the IT Function to ensure that controls are implemented and effectively monitored ensuring no conflict of interest exists. Requirements Cyber Security • Security Architecture Design: Collaborate with the IT function to design and implement secure bank network and system architectures. This includes selecting appropriate security technologies and integrating them into the Bank’s infrastructure. • Vulnerability Assessment and Penetration Testing: Regularly assess the bank’s IT infrastructure for vulnerabilities and ensure prompt remediations are carried out by the relevant IT Function teams. • Working with business and support functions to ensure correct implementation of IT control requirements on various processes. • Implementation and management of the Bank’s Public Key Infrastructure (PKI). • Collaboration with Fraud Risk function to conduct digital forensic investigations. • Spearhead the implementation and monitoring of advanced security controls ensuring no conflict of interest in management of implemented controls to ensure availability, integrity, and confidentiality of data. • Offer continuous assurance in the deployment and maintenance of native IT Security controls such as intrusion detection/ prevention systems, firewalls to ensure availability, integrity, and confidentiality of data. • Oversight, planning and execution of any required independent cybersecurity assessments and audits. • Ensure compliance activities and reports associated with regulatory requirements are maintained. • Involvement in arranging staff training in security awareness skills. • Research, evaluate, and recommend new security technologies, processes, and methodologies. • Participate in the implementation of an IT cyber-security strategy and proactively identify cyber-security threats. • Applying information security foundations to complex network architectures • Cyber Threat Intelligence: Monitor cyber threat intelligence sources to understand emerging threats and adapt security measures accordingly. • Threat modelling: Identify and enumerate potential threats, such as structural vulnerabilities or the absence of appropriate safeguards, to recommend and communicate prioritized countermeasures for implementation by appropriate teams. 2. Security Operations Centre Threat Detection: Monitor the bank’s network, systems, and applications to identify and analyse potential security threats and vulnerabilities. • Cyber Incident Management: Lead the cyber incident management efforts in the event of a security breach or cyberattack by investigating the incident, assessing the extent of the damage, taking steps to mitigate the impact, documenting all relevant details, including the incident’s cause, impact, and steps taken for remediation. • Work closely with third party managed security services providers (MSSPs) to ensure bank is protected on a 24/7 basis. 3. Risk Management • Conduct Information Security Risk and Controls Self Assessments • Maintain up to date Information Security Risk Registers • Responsible for maintaining an up-to-date understanding of emerging trends in information security risks. • Support for timely reporting of all IT risk events ensuring that root cause analysis is conducted. • Responsible for monitoring control effectiveness where there are material risks of process control failure. 4. Audit and Compliance Management • Supports the coordination of internal and external information security assessments by internal and external partners. • Supports the tracking and closure of internal and external assessment issues. • Make recommendations for action plans addressing management commitments. 1. Cyber Security • Security Architecture Design: Collaborate with the IT function to design and implement secure bank network and system architectures. This includes selecting appropriate security technologies and integrating them into the Bank’s infrastructure. • Vulnerability Assessment and Penetration Testing: Regularly assess the bank’s IT infrastructure for vulnerabilities and ensure prompt remediations are carried out by the relevant IT Function teams. • Working with business and support functions to ensure correct implementation of IT control requirements on various processes. • Implementation and management of the Bank’s Public Key Infrastructure (PKI). • Collaboration with Fraud Risk function to conduct digital forensic investigations. • Spearhead the implementation and monitoring of advanced security controls ensuring no conflict of interest in management of implemented controls to ensure availability, integrity, and confidentiality of data. • Offer continuous assurance in the deployment and maintenance of native IT Security controls such as intrusion detection/ prevention systems, firewalls to ensure availability, integrity, and confidentiality of data. • Oversight, planning and execution of any required independent cybersecurity assessments and audits. • Ensure compliance activities and reports associated with regulatory requirements are maintained. • Involvement in arranging staff training in security awareness skills. • Research, evaluate, and recommend new security technologies, processes, and methodologies. • Participate in the implementation of an IT cyber-security strategy and proactively identify cyber-security threats. • Applying information security foundations to complex network architectures • Cyber Threat Intelligence: Monitor cyber threat intelligence sources to understand emerging threats and adapt security measures accordingly. • Threat modelling: Identify and enumerate potential threats, such as structural vulnerabilities or the absence of appropriate safeguards, to recommend and communicate prioritized countermeasures for implementation by appropriate teams. 2. Security Operations Centre Threat Detection: Monitor the bank’s network, systems, and applications to identify and analyse potential security threats and vulnerabilities. • Cyber Incident Management: Lead the cyber incident management efforts in the event of a security breach or cyberattack by investigating the incident, assessing the extent of the damage, taking steps to mitigate the impact, documenting all relevant details, including the incident’s cause, impact, and steps taken for remediation. • Work closely with third party managed security services providers (MSSPs) to ensure bank is protected on a 24/7 basis. 3. Risk Management • Conduct Information Security Risk and Controls Self Assessments • Maintain up to date Information Security Risk Registers • Responsible for maintaining an up-to-date understanding of emerging trends in information security risks. • Support for timely reporting of all IT risk events ensuring that root cause analysis is conducted. • Responsible for monitoring control effectiveness where there are material risks of process control failure. 4. Audit and Compliance Management • Supports the coordination of internal and external information security assessments by internal and external partners. • Supports the tracking and closure of internal and external assessment issues. • Make recommendations for action plans addressing management commitments. Key Outputs Success Measures Inputs and Behaviors Measurement Method Privileged Access Management (PAM) Successful Implementation and management of PAM solution to ensure secure and controlled access to the bank’s information assets. Undertake relevant research and prepare the technical requirements to operationalize the department’s strategic initiatives. Cybersecurity scorecard Mature Cybersecurity Environment Secure IT Infrastructure resulting in reduced cybersecurity incidents and related losses. Undertake relevant research and prepare the technical requirements to ensure security controls are effectively implemented, managed, and continuously monitored. Cybersecurity Maturity Assessment Report Vulnerability Management Reduced risk of exploitation of Information systems Continuous and consistent vulnerability assessments and penetration testing and tracking of remediation activities. Vulnerability assessment reports Compliance with International Industry specific and other adopted Information Security Standards and Regulations Successful implementation, maintenance, and continuous improvement of technical controls making up SWIFT SC, PCI DSS and ISO/IEC 27001, Information Security Management Systems. Collaborate with relevant stakeholders to ensure all technical controls needed to comply with the standards and regulations are effectively met and continuously improved. SWIFT, PCI DSS and ISO/IEC 27001 Compliance Certificates or Reports. Compliance with local Information Security Laws and Regulations • Compliance with the Bank of Zambia’s Information Security Regulations and Guidelines • Compliance with Information Security laws, regulations, and guidelines of the Republic of Zambia Collaborate with relevant stakeholders to ensure all technical controls needed to comply with the laws and regulations are effectively met and continuously improved. Regulatory Examination/ Assessment Reports Compliance Management Prompt addressing of issues arising from assessments and audits from internal and external assurance partners. Collaborate with relevant stakeholders to close off all issues arising from the assessments and audits. Assessments/ Audit Reports Risk Management • Up to date Information Security Risk Register Cyber Incident Reporting Collaborate with relevant stakeholders to ensure Information Security risks are well captured and reported. Risk and Controls SelfAssessment Report ERM Dashboard JOB DIMENSIONS SUMMARY FINANCIAL DIMENSION Budget: Support the Cybersecurity & Threat Intelligence Senior Specialist in regulating the departmental budgets to maximize the return on investments. MANAGEMENT DIMENSION Planning: This is a strategic role (aligning to the long-term ambitions of the bank) and drives the Information Security Strategy from planning to execution alongside other units in the division. Organizing: This role requires a very highly self-organizing skillset to be able to effectively present the broader picture of where the Information Security Unit is driving towards in relation to the Bank’s strategy execution. It heavily contributes towards providing visibility to the Board members on the performance of the division and its contribution to the overall profitability of the bank. Direct Subordinates: • None Indirect Subordinates: • None COMMUNICATION/INFLUENCING Communication: This role requires interaction and communication at all levels (i.e., Internal & External). This involves stakeholder engagement at different levels within the bank and being able to communicate effectively thereof. External: Vendors and Consultants Internal: All internal Business Units DECISION MAKING Autonomous Decisions: • Solutions to operational problems • Business Impact • Controls effectiveness and criticality Non-Autonomous Decisions: • Strategic solutions QUALIFICATIONS/EXPERIENCE Skills and Qualifications: Required: • Bachelor’s degree (or equivalent) in Information Systems, Technology, or Security, Computer Science, or related field • Master’s degree is added advantage. • At least two (2) Information Security certifications such as GIAC, OSCP, CISSP, CRISC, CISM, CEH, ISO/IEC 27001 or equivalent. • Three to five years of experience in cybersecurity at a midsize or large company in the Banking or similar environment. Professional: • Digital Forensic Knowledge • Experience with cloud computing • Should possess high skills in implementing and maintaining cybersecurity controls. COMPLEXITY • Information Security/ Cybersecurity • Risk management • IT Audit management • Security in Strategic Projects • Complex Decision-Making Processes COMPETENCIES & PERSONAL ATTRIBUTES • Excellent verbal and written communication skills. • Self-starter and self-motivated • Ability to work successfully in both individual and team settings. • Leadership skills • Clinical and attentive to detail • Must aspire to a culture of Service Excellence • Stakeholder Management • Budget Management Reference Documents Information Security Policies, IT Policies, PMDS Policy, ISO/IEC 27001 Standard, PCI DSS Standard, BOZ Cyber and Information Risk Management Guidelines. Operating environment e.g., Physical Demands, Mental Requirements High stress environment, 24-hour operations on call always. Prepared by: Acting Head Information Security Approved by: Date: Date: Incumbent: Vacant Disclaimer ONLY SHORTLISTED APPLICANTS WILL BE COMMUNICATED TO. Zanaco provides equal opportunity in employment for all qualified persons and prohibits discrimination in employment (women are encouraged to apply). Application link: https://careers.zanaco.co.zm/jobs/9084db4f-7b4d-4595-aae3-8f69059e77f5

Requirements

Requirements Cyber Security • Security Architecture Design: Collaborate with the IT function to design and implement secure bank network and system architectures. This includes selecting appropriate security technologies and integrating them into the Bank’s infrastructure. • Vulnerability Assessment and Penetration Testing: Regularly assess the bank’s IT infrastructure for vulnerabilities and ensure prompt remediations are carried out by the relevant IT Function teams. • Working with business and support functions to ensure correct implementation of IT control requirements on various processes. • Implementation and management of the Bank’s Public Key Infrastructure (PKI). • Collaboration with Fraud Risk function to conduct digital forensic investigations. • Spearhead the implementation and monitoring of advanced security controls ensuring no conflict of interest in management of implemented controls to ensure availability, integrity, and confidentiality of data. • Offer continuous assurance in the deployment and maintenance of native IT Security controls such as intrusion detection/ prevention systems, firewalls to ensure availability, integrity, and confidentiality of data. • Oversight, planning and execution of any required independent cybersecurity assessments and audits. • Ensure compliance activities and reports associated with regulatory requirements are maintained. • Involvement in arranging staff training in security awareness skills. • Research, evaluate, and recommend new security technologies, processes, and methodologies. • Participate in the implementation of an IT cyber-security strategy and proactively identify cyber-security threats. • Applying information security foundations to complex network architectures • Cyber Threat Intelligence: Monitor cyber threat intelligence sources to understand emerging threats and adapt security measures accordingly. • Threat modelling: Identify and enumerate potential threats, such as structural vulnerabilities or th

How to apply

Salary: Not specified

Application link: Open the employer application page

Get the latest alerts

Receive breaking news and new job notifications from ZinstaBlog.

You will only be asked for browser permission once.