Your safety comes first — read before you go. Taf4All only lists job offers published by third parties. We are not the employer, we do not conduct these recruitments, and we cannot guarantee what happens once you make contact — you deal directly with the person or company behind the offer, at your own risk.
Position Overview Zanaco Bank Plc is inviting applications from suitably qualified and experienced individuals for the following job aimed at contributing to the Bank’s strategic vision, in the Information Technology Division under the IT Security at Head Office – Support Functions: Role Description This role is responsible for safeguarding the Bank’s digital assets, information, and systems from various cyber threats and attacks. The safeguards include, but not limited to Data Loss prevention, Vulnerability Assessments and Penetration Testing (VAPT), Network Security, Endpoint Security, Mobile Device Management, Email Security, Database Security, Cyber threat intelligence, Security in projects implementation. The role focuses on ensuring that adequate Security Controls, Cyber Risk Management and Compliance is applied and monitored across the enterprise in all IT related projects, systems, automated processes, and people involved in running automated process. The role enforces all security policies, procedures, and control objectives to mitigate risks to the Bank. Reporting to the Cybersecurity & Threat Intelligence Senior Specialist, the Cybersecurity Specialist executes his/ her roles and responsibilities in close collaboration with the IT Function to ensure that controls are implemented and effectively monitored ensuring no conflict of interest exists. Requirements Cyber Security
Security Architecture Design: Collaborate with the IT function to design and implement secure bank network and system architectures. This includes selecting appropriate security technologies and integrating them into the Bank’s infrastructure.
Vulnerability Assessment and Penetration Testing: Regularly assess the bank’s IT infrastructure for vulnerabilities and ensure prompt remediations are carried out by the relevant IT Function teams.
Working with business and support functions to ensure correct implementation of IT control requirements on various processes.
Implementation and management of the Bank’s Public Key Infrastructure (PKI).
Collaboration with Fraud Risk function to conduct digital forensic investigations.
Spearhead the implementation and monitoring of advanced security controls ensuring no conflict of interest in management of implemented controls to ensure availability, integrity, and confidentiality of data.
Offer continuous assurance in the deployment and maintenance of native IT Security controls such as intrusion detection/ prevention systems, firewalls to ensure availability, integrity, and confidentiality of data.
Oversight, planning and execution of any required independent cybersecurity assessments and audits.
Ensure compliance activities and reports associated with regulatory requirements are maintained.
Involvement in arranging staff training in security awareness skills.
Research, evaluate, and recommend new security technologies, processes, and methodologies.
Participate in the implementation of an IT cyber-security strategy and proactively identify cyber-security threats.
Formation / Diplômes
Applying information security foundations to complex network architectures
Cyber Threat Intelligence: Monitor cyber threat intelligence sources to understand emerging threats and adapt security measures accordingly.
Threat modelling: Identify and enumerate potential threats, such as structural vulnerabilities or the absence of appropriate safeguards, to recommend and communicate prioritized countermeasures for implementation by appropriate teams. 2. Security Operations Centre Threat Detection: Monitor the bank’s network, systems, and applications to identify and analyse potential security threats and vulnerabilities.
Cyber Incident Management: Lead the cyber incident management efforts in the event of a security breach or cyberattack by investigating the incident, assessing the extent of the damage, taking steps to mitigate the impact, documenting all relevant details, including the incident’s cause, impact, and steps taken for remediation.
Work closely with third party managed security services providers (MSSPs) to ensure bank is protected on a 24/7 basis. 3. Risk Management
Conduct Information Security Risk and Controls Self Assessments
Maintain up to date Information Security Risk Registers
Responsible for maintaining an up-to-date understanding of emerging trends in information security risks.
Support for timely reporting of all IT risk events ensuring that root cause analysis is conducted.
Responsible for monitoring control effectiveness where there are material risks of process control failure. 4. Audit and Compliance Management
Supports the coordination of internal and external information security assessments by internal and external partners.
Supports the tracking and closure of internal and external assessment issues.
Make recommendations for action plans addressing management commitments. 1. Cyber Security
Security Architecture Design: Collaborate with the IT function to design and implement secure bank network and system architectures. This includes selecting appropriate security technologies and integrating them into the Bank’s infrastructure.
Vulnerability Assessment and Penetration Testing: Regularly assess the bank’s IT infrastructure for vulnerabilities and ensure prompt remediations are carried out by the relevant IT Function teams.
Working with business and support functions to ensure correct implementation of IT control requirements on various processes.
Implementation and management of the Bank’s Public Key Infrastructure (PKI).
Collaboration with Fraud Risk function to conduct digital forensic investigations.
Spearhead the implementation and monitoring of advanced security controls ensuring no conflict of interest in management of implemented controls to ensure availability, integrity, and confidentiality of data.
Offer continuous assurance in the deployment and maintenance of native IT Security controls such as intrusion detection/ prevention systems, firewalls to ensure availability, integrity, and confidentiality of data.
Oversight, planning and execution of any required independent cybersecurity assessments and audits.
Ensure compliance activities and reports associated with regulatory requirements are maintained.
Involvement in arranging staff training in security awareness skills.
Research, evaluate, and recommend new security technologies, processes, and methodologies.
Participate in the implementation of an IT cyber-security strategy and proactively identify cyber-security threats.
Applying information security foundations to complex network architectures
Cyber Threat Intelligence: Monitor cyber threat intelligence sources to understand emerging threats and adapt security measures accordingly.
Threat modelling: Identify and enumerate potential threats, such as structural vulnerabilities or the absence of appropriate safeguards, to recommend and communicate prioritized countermeasures for implementation by appropriate teams. 2. Security Operations Centre Threat Detection: Monitor the bank’s network, systems, and applications to identify and analyse potential security threats and vulnerabilities.
Cyber Incident Management: Lead the cyber incident management efforts in the event of a security breach or cyberattack by investigating the incident, assessing the extent of the damage, taking steps to mitigate the impact, documenting all relevant details, including the incident’s cause, impact, and steps taken for remediation.
Work closely with third party managed security services providers (MSSPs) to ensure bank is protected on a 24/7 basis. 3. Risk Management
Conduct Information Security Risk and Controls Self Assessments
Maintain up to date Information Security Risk Registers
Responsible for maintaining an up-to-date understanding of emerging trends in information security risks.
Support for timely reporting of all IT risk events ensuring that root cause analysis is conducted.
Responsible for monitoring control effectiveness where there are material risks of process control failure. 4. Audit and Compliance Management
Supports the coordination of internal and external information security assessments by internal and external partners.
Supports the tracking and closure of internal and external assessment issues.
Make recommendations for action plans addressing management commitments. Key Outputs Success Measures Inputs and Behaviors Measurement Method Privileged Access Management (PAM) Successful Implementation and management of PAM solution to ensure secure and controlled access to the bank’s information assets. Undertake relevant research and prepare the technical requirements to operationalize the department’s strategic initiatives. Cybersecurity scorecard Mature Cybersecurity Environment Secure IT Infrastructure resulting in reduced cybersecurity incidents and related losses. Undertake relevant research and prepare the technical requirements to ensure security controls are effectively implemented, managed, and continuously monitored. Cybersecurity Maturity Assessment Report Vulnerability Management Reduced risk of exploitation of Information systems Continuous and consistent vulnerability assessments and penetration testing and tracking of remediation activities. Vulnerability assessment reports Compliance with International Industry specific and other adopted Information Security Standards and Regulations Successful implementation, maintenance, and continuous improvement of technical controls making up SWIFT SC, PCI DSS and ISO/IEC 27001, Information Security Management Systems. Collaborate with relevant stakeholders to ensure all technical controls needed to comply with the standards and regulations are effectively met and continuously improved. SWIFT, PCI DSS and ISO/IEC 27001 Compliance Certificates or Reports. Compliance with local Information Security Laws and Regulations
Compliance with the Bank of Zambia’s Information Security Regulations and Guidelines
Compliance with Information Security laws, regulations, and guidelines of the Republic of Zambia Collaborate with relevant stakeholders to ensure all technical controls needed to comply with the laws and regulations are effectively met and continuously improved. Regulatory Examination/ Assessment Reports Compliance Management Prompt addressing of issues arising from assessments and audits from internal and external assurance partners. Collaborate with relevant stakeholders to close off all issues arising from the assessments and audits. Assessments/ Audit Reports Risk Management
Up to date Information Security Risk Register Cyber Incident Reporting Collaborate with relevant stakeholders to ensure Information Security risks are well captured and reported. Risk and Controls SelfAssessment Report ERM Dashboard JOB DIMENSIONS SUMMARY FINANCIAL DIMENSION Budget: Support the Cybersecurity & Threat Intelligence Senior Specialist in regulating the departmental budgets to maximize the return on investments. MANAGEMENT DIMENSION Planning: This is a strategic role (aligning to the long-term ambitions of the bank) and drives the Information Security Strategy from planning to execution alongside other units in the division. Organizing: This role requires a very highly self-organizing skillset to be able to effectively present the broader picture of where the Information Security Unit is driving towards in relation to the Bank’s strategy execution. It heavily contributes towards providing visibility to the Board members on the performance of the division and its contribution to the overall profitability of the bank. Direct Subordinates:
None Indirect Subordinates:
None COMMUNICATION/INFLUENCING Communication: This role requires interaction and communication at all levels (i.e., Internal & External). This involves stakeholder engagement at different levels within the bank and being able to communicate effectively thereof. External: Vendors and Consultants Internal: All internal Business Units DECISION MAKING Autonomous Decisions:
Solutions to operational problems
Business Impact
Controls effectiveness and criticality Non-Autonomous Decisions:
Strategic solutions QUALIFICATIONS/EXPERIENCE Skills and Qualifications: Required:
Bachelor’s degree (or equivalent) in Information Systems, Technology, or Security, Computer Science, or related field
Master’s degree is added advantage.
At least two (2) Information Security certifications such as GIAC, OSCP, CISSP, CRISC, CISM, CEH, ISO/IEC 27001 or equivalent.
Expérience
Three to five years of experience in cybersecurity at a midsize or large company in the Banking or similar environment. Professional:
Digital Forensic Knowledge
Experience with cloud computing
Should possess high skills in implementing and maintaining cybersecurity controls. COMPLEXITY
Information Security/ Cybersecurity
Risk management
IT Audit management
Security in Strategic Projects
Complex Decision-Making Processes COMPETENCIES & PERSONAL ATTRIBUTES
Excellent verbal and written communication skills.
Self-starter and self-motivated
Ability to work successfully in both individual and team settings.
Leadership skills
Clinical and attentive to detail
Must aspire to a culture of Service Excellence
Stakeholder Management
Budget Management Reference Documents Information Security Policies, IT Policies, PMDS Policy, ISO/IEC 27001 Standard, PCI DSS Standard, BOZ Cyber and Information Risk Management Guidelines. Operating environment e.g., Physical Demands, Mental Requirements High stress environment, 24-hour operations on call always. Prepared by: Acting Head Information Security Approved by: Date: Date: Incumbent: Vacant Disclaimer ONLY SHORTLISTED APPLICANTS WILL BE COMMUNICATED TO. Zanaco provides equal opportunity in employment for all qualified persons and prohibits discrimination in employment (women are encouraged to apply).
---
**
[Click the Apply button below to apply, and Create my CV to build a CV tailored to this offer, professionally]
Always tailor your CV to mirror the language used in the job description for Zambia National Commercial Bank Plc. If you meet the key requirement of les compétences demandées dans l'annonce, place it prominently near the top of your profile. This immediate alignment shows you understand their specific needs.
Positioning — Your cover letter must answer one question: why YOU for THIS specific role right NOW? Avoid generic templates — one sentence on what you specifically bring beats three generic paragraphs.
Targeted application — Align your CV to this offer's exact keywords and back every claimed skill with a concrete example. A cover letter showing you understand the specific challenges of this role consistently makes the difference.
🎯 Make your application ATS-ready
ATS (Applicant Tracking Systems) are the software recruiters use to automatically filter CVs before any human reads them. Our CV builder is specifically designed to pass these filters — and it takes under 3 minutes.
Taf4All only lists job offers published by third parties. We are not the employer, we do not conduct these recruitments, and we cannot guarantee what happens once you make contact — you deal directly with the person or company behind the offer, at your own risk.
•Never pay any amount of money — for a file, a training, a uniform, or an interview. A real employer never asks the candidate to pay.
•Never send a photo of your ID card, passport, or banking details before you have physically verified the employer exists.
•Always meet in a public place, during the day — never an isolated address, a private home, or a location you cannot verify in advance.
•Tell a relative or friend exactly where you are going, with whom, and at what time — and share your live location if possible.
•Search the company name online before going: a real business has a trace (website, reviews, other employees, an official address).
•A salary that is far above the market rate for the position and the city is a red flag — be extra cautious.
🧠 Profil recherché We are in search of a meticulous, research focused Data Quality Analyst to uphold and improve the precision, comprehensiveness, and dependability of our dental industry data. Responsibilities: Verify DSO locations, dentist affiliations, corporate contacts, and associated records to ensure their accu
🧠 Profil recherché We invite applications for the position of Data Quality Analyst, a role that demands meticulous attention to detail and a strong foundation in research driven methodologies. In this capacity, you will be responsible for upholding the precision, comprehensiveness, and dependability of our dental indu
🧠 Profil recherché We invite applications for the position of Data Quality Analyst, a role that demands meticulous attention to detail and a commitment to rigorous research methodologies to ensure the precision, comprehensiveness, and dependability of our data within the dental industry. Responsibilities: Verify the p