Employer and vacancy source: Zambia National Commercial Bank Plc
Zambia Job Alerts publishes the vacancy details and application instructions for this listing. Use the employer details, deadline and application section below to verify the opportunity before applying.
- EmployerZambia National Commercial Bank Plc
- LocationLusaka
- Employer websitezambiajobalerts.com
- Application methodExternal application link
- Listing sourceZambia Job Alerts
Key details for this vacancy
- Employer
- Zambia National Commercial Bank Plc
- Location
- Lusaka
- Posted
- August 1, 2026
- Job type
- Full Time
- Category
- Human Resources, IT & Telecoms
- Application method
- External application link
Job description
Position Overview
Zanaco Bank Plc is inviting applications from suitably qualified and experienced individuals for the following job aimed at contributing to the Bank’s strategic vision, in the Information Technology Division under the IT Security at Head Office – Support Functions:
Role Description
This role is responsible for safeguarding the Bank’s digital assets, information, and systems from various cyber threats and attacks. The safeguards include, but not limited to Data Loss prevention, Vulnerability Assessments and Penetration Testing (VAPT), Network Security, Endpoint Security, Mobile Device Management, Email Security, Database Security, Cyber threat intelligence, Security in projects implementation. The role focuses on ensuring that adequate Security Controls, Cyber Risk Management and Compliance is applied and monitored across the enterprise in all IT related projects, systems, automated processes, and people involved in running automated process. The role enforces all security policies, procedures, and control objectives to mitigate risks to the Bank.
Reporting to the Cybersecurity & Threat Intelligence Senior Specialist, the Cybersecurity Specialist executes his/ her roles and responsibilities in close collaboration with the IT Function to ensure that controls are implemented and effectively monitored ensuring no conflict of interest exists.
Requirements
Cyber Security
• Security Architecture Design: Collaborate with the IT function to design and implement secure bank network and system architectures. This includes selecting appropriate security technologies and integrating them into the Bank’s infrastructure.
• Vulnerability Assessment and Penetration Testing: Regularly assess the bank’s IT infrastructure for vulnerabilities and ensure prompt remediations are carried out by the relevant IT Function teams.
• Working with business and support functions to ensure correct implementation of IT control requirements on various processes.
• Implementation and management of the Bank’s Public Key Infrastructure (PKI).
• Collaboration with Fraud Risk function to conduct digital forensic investigations.
• Spearhead the implementation and monitoring of advanced security controls ensuring no conflict of interest in management of implemented controls to ensure availability, integrity, and confidentiality of data.
• Offer continuous assurance in the deployment and maintenance of native IT Security controls such as intrusion detection/ prevention systems, firewalls to ensure availability, integrity, and confidentiality of data.
• Oversight, planning and execution of any required independent cybersecurity assessments and audits.
• Ensure compliance activities and reports associated with regulatory requirements are maintained.
• Involvement in arranging staff training in security awareness skills.
• Research, evaluate, and recommend new security technologies, processes, and methodologies.
• Participate in the implementation of an IT cyber-security strategy and proactively identify cyber-security threats.
• Applying information security foundations to complex network architectures
• Cyber Threat Intelligence: Monitor cyber threat intelligence sources to understand emerging threats and adapt security measures accordingly.
• Threat modelling: Identify and enumerate potential threats, such as structural vulnerabilities or the absence of appropriate safeguards, to recommend and communicate prioritized countermeasures for implementation by appropriate teams.
2. Security Operations Centre
Threat Detection: Monitor the bank’s network, systems, and applications to identify and analyse potential security threats and vulnerabilities.
• Cyber Incident Management: Lead the cyber incident management efforts in the event of a security breach or cyberattack by investigating the incident, assessing the extent of the damage, taking steps to mitigate the impact, documenting all relevant details, including the incident’s cause, impact, and steps taken for remediation.
• Work closely with third party managed security services providers (MSSPs) to ensure bank is protected on a 24/7 basis.
3. Risk Management
• Conduct Information Security Risk and Controls Self Assessments
• Maintain up to date Information Security Risk Registers
• Responsible for maintaining an up-to-date understanding of emerging trends in information security risks.
• Support for timely reporting of all IT risk events ensuring that root cause analysis is conducted.
• Responsible for monitoring control effectiveness where there are material risks of process control failure.
4. Audit and Compliance Management
• Supports the coordination of internal and external information security assessments by internal and external partners.
• Supports the tracking and closure of internal and external assessment issues.
• Make recommendations for action plans addressing management commitments.
|
1. Cyber Security • Security Architecture Design: Collaborate with the IT function to design and implement secure bank network and system architectures. This includes selecting appropriate security technologies and integrating them into the Bank’s infrastructure. • Vulnerability Assessment and Penetration Testing: Regularly assess the bank’s IT infrastructure for vulnerabilities and ensure prompt remediations are carried out by the relevant IT Function teams. • Working with business and support functions to ensure correct implementation of IT control requirements on various processes. • Implementation and management of the Bank’s Public Key Infrastructure (PKI). • Collaboration with Fraud Risk function to conduct digital forensic investigations. • Spearhead the implementation and monitoring of advanced security controls ensuring no conflict of interest in management of implemented controls to ensure availability, integrity, and confidentiality of data. • Offer continuous assurance in the deployment and maintenance of native IT Security controls such as intrusion detection/ prevention systems, firewalls to ensure availability, integrity, and confidentiality of data. • Oversight, planning and execution of any required independent cybersecurity assessments and audits. • Ensure compliance activities and reports associated with regulatory requirements are maintained. • Involvement in arranging staff training in security awareness skills. • Research, evaluate, and recommend new security technologies, processes, and methodologies. • Participate in the implementation of an IT cyber-security strategy and proactively identify cyber-security threats. • Applying information security foundations to complex network architectures • Cyber Threat Intelligence: Monitor cyber threat intelligence sources to understand emerging threats and adapt security measures accordingly. • Threat modelling: Identify and enumerate potential threats, such as structural vulnerabilities or the absence of appropriate safeguards, to recommend and communicate prioritized countermeasures for implementation by appropriate teams.
2. Security Operations Centre Threat Detection: Monitor the bank’s network, systems, and applications to identify and analyse potential security threats and vulnerabilities. • Cyber Incident Management: Lead the cyber incident management efforts in the event of a security breach or cyberattack by investigating the incident, assessing the extent of the damage, taking steps to mitigate the impact, documenting all relevant details, including the incident’s cause, impact, and steps taken for remediation. • Work closely with third party managed security services providers (MSSPs) to ensure bank is protected on a 24/7 basis.
3. Risk Management • Conduct Information Security Risk and Controls Self Assessments • Maintain up to date Information Security Risk Registers • Responsible for maintaining an up-to-date understanding of emerging trends in information security risks. • Support for timely reporting of all IT risk events ensuring that root cause analysis is conducted. • Responsible for monitoring control effectiveness where there are material risks of process control failure.
4. Audit and Compliance Management • Supports the coordination of internal and external information security assessments by internal and external partners. • Supports the tracking and closure of internal and external assessment issues. • Make recommendations for action plans addressing management commitments.
|
Disclaimer
ONLY SHORTLISTED APPLICANTS WILL BE COMMUNICATED TO.
Zanaco provides equal opportunity in employment for all qualified persons and prohibits discrimination in employment (women are encouraged to apply).
Apply stronger for this role
Prepare a CV or cover letter using this job as context.
Apply for this job
To apply for this job please visit careers.zanaco.co.zm.
