Job details
Posted Date
Yesterday
Expire Date
Aug, 17
Category
Ict/technology/computers
Location
Mogadishu
Type
Full Time
Salary
---
Education
Degree
Experience
2 - 3 years
Job description
Position Title: Information Security Officer
Department: Information Technology
Position Level: Level 1 Officer
Reports To: Head of IT or Designated Supervisor
Employment Type: Full-time
Location: Mogadishu, Somalia
1. Background The Somali Payment Switch (SPS) is the national retail payment infrastructure responsible for real-time clearing and settlement of payments across Somali financial institutions. As a central component of Somalia’s financial ecosystem, SPS enables secure interoperability among banks, mobile money operators, government institutions, and other approved payment service providers. As SPS operates critical national financial infrastructure, its systems and services are subject to strict requirements for availability, security, confidentiality, integrity, auditability, change control, and business continuity. SPS is therefore strengthening its information-security capacity through the appointment of a dedicated Information Security Officer. 2. Position Summary
The Information Security Officer supports the implementation, operation, monitoring, and continuous improvement of the SPS information-security programme. The role contributes to protecting payment infrastructure, participant connections, cryptographic assets, sensitive information, and service availability. The Officer assists with security risk assessments, access control, security monitoring, incident response, vulnerability management, regulatory compliance, audit support, documentation, and management reporting.
3. Key Responsibilities:
Governance, Risk and Compliance
1. Support the development and maintenance of the SPS information-security strategy, policies, standards, control framework, and annual security plan.
2. Maintain accurate information-security risk, treatment, exception, accepted-risk, and compliance registers.
3. Conduct or support security risk assessments for systems, participants, vendors, changes, products, and material incidents.
4. Monitor compliance with applicable Central Bank of Somalia requirements, national law, contractual obligations, ISO 27001, PCI DSS where in scope, and adopted payment-security requirements.
5. Support internal and external audits, regulatory assessments, evidence requests, remediation tracking, and evidence-based closure of findings.
6. Escalate material security risks, control failures, policy exceptions, and overdue remediation to the designated executive in a timely manner.
Identity and Access Management
1. Support implementation of identity lifecycle, least-privilege, multi-factor authentication, privileged-access, segregation-of-duties, service-account, and access-review controls.
2. Ensure joiner, mover, leaver, emergency, vendor, dormant-account, and temporary-access processes are properly authorized and documented.
3. Conduct periodic reviews of privileged and high-risk access and track identified conflicts or corrective actions to closure.
4. Monitor shared and generic accounts and ensure they are eliminated or tightly controlled, attributable, logged, and reviewed.
5. Maintain complete access-control records and evidence in accordance with SPS policies and audit requirements.
Security Monitoring and Incident Response
1. Monitor security events and alerts from approved security tools, logs, networks, endpoints, applications, cloud services, and payment systems.
2. Perform initial triage, classification, escalation, containment support, and evidence preservation for suspected cyber-security incidents.
3. Maintain and exercise incident-response procedures and playbooks for credential compromise, malware, denial of service, data breach, insider threat, key compromise, fraudulent activity, and participant-originated attacks.
4. Coordinate incident-response activities and authorized communications with management, regulators, participants, law enforcement, suppliers, and other approved stakeholders.
5. Support post-incident reviews, document lessons learned, and track corrective and preventive actions to completion.
6. Participate in approved maintenance windows, cyber exercises, incident response, and the security on-call rota when required.
Vulnerability, Configuration and Testing Assurance
1. Conduct or coordinate risk-based vulnerability scanning, secure-configuration reviews, remediation verification, and control validation.
2. Track vulnerabilities and security findings with assigned owners, severity ratings, deadlines, supporting evidence, and escalation status.
3. Support penetration testing and security assessments of internet-facing, payment, identity, cryptographic, database, network, and privileged systems.
4. Review security requirements for system architecture, new products, participant integrations, and high-risk changes before production implementation.
5. Verify that security patches, configuration changes, and remediation actions are implemented in line with approved risk-based timelines.
Cryptography and PKI Control
1. Maintain the authoritative inventory of certificates, encryption keys, digital signatures, hardware security modules, and other cryptographic assets.
2. Monitor certificate and key ownership, custody, backup, rotation, renewal, revocation, expiry, and compromise procedures.
3. Support key ceremonies and ensure dual control, split knowledge, access authorization, logging, and required evidence are maintained.
4. Verify that participant communications, APIs, administrative access, and sensitive data use approved encryption and certificate-validation controls.
5. Immediately escalate suspected cryptographic compromise, unauthorized key access, or certificate-expiry risks and support containment and recovery.
Third-Party and Participant Security
1. Support security due diligence and assessment of participants, vendors, cloud providers, managed service providers, and other third parties.
2. Review security provisions relating to connectivity, data access, incident notification, continuity, subcontracting, and exit arrangements.
3. Support participant onboarding, security attestations, control-evidence reviews, and periodic reassessments.
4. Track third-party and participant security findings, remediation actions, and concentration or dependency risks.
5. Provide practical security guidance to participants and internal departments while maintaining SPS security requirements.
Continuity, Awareness and Reporting
1. Provide security requirements and assurance support for business continuity, disaster recovery, crisis management, and operational resilience arrangements.
2. Participate in cyber, operational, disaster-recovery, and crisis simulation exercises and document improvement actions.
3. Support role-based security awareness and training for employees, privileged users, developers, management, and other relevant stakeholders.
4. Prepare accurate periodic security reports covering risks, incidents, vulnerabilities, access reviews, cryptographic controls, audit findings, and remediation progress.
5. Maintain security procedures, records, evidence, and Standard Operating Procedures and contribute to continuous improvement of SPS security capabilities.
Other Duties
1. Perform other tasks assigned by the Head of IT or designated supervisor to support SPS information-security and institutional objectives.
2. Engage in continuous professional development and meet the annual professional-development requirements applicable to the position.
Skills and qualifications
1. Qualifications and Skills:
· Bachelor’s degree in Cybersecurity, Information Systems, Computer Science, Network Engineering, Information Technology, or a related field.
· Minimum of 2 years of relevant experience in cybersecurity or information security, preferably within financial services, payments, telecommunications, government, or other critical infrastructure.
· Practical exposure to security monitoring or SIEM, incident response, identity and access management, vulnerability management, network or Linux security, and public-key infrastructure.
· Working knowledge of ISO 27001, PCI DSS where applicable, business continuity, secure APIs, cryptography, and regulatory or audit assurance.
· Relevant certifications or training such as CompTIA Security+, Cisco CyberOps, CEH, ISO 27001 Foundation or Implementer, GIAC, or comparable credentials are preferred.
· Strong analytical, investigation, troubleshooting, documentation, and evidence-management skills with close attention to detail.
· Ability to manage multiple priorities, maintain confidentiality, and work effectively under pressure during security incidents.
· Proficiency in Microsoft Office and security reporting, documentation, and presentation tools.
· Ability to communicate professionally in written and spoken Somali and English.
2. Key Competencies
· Integrity, independence, sound judgment, and commitment to confidentiality
· Analytical thinking, professional skepticism, and evidence-based decision making
· Security awareness, attention to detail, and proactive risk identification
· Calm and disciplined incident response under uncertainty and operational pressure
· Clear communication of technical risks to technical and non-technical stakeholders
· Effective collaboration with management, participants, auditors, regulators, and technical teams
· Adaptability, continuous learning, and proactive problem-solving
· Willingness to escalate material or unresolved security risks appropriately
How to apply
Interested candidates should submit their CV and a cover letter detailing their relevant experience and qualifications. The selection process includes an interview, competency assessment, and background checks. Female candidates are strongly encouraged to apply.
Applications should be submitted through the following link: https://erp.sps.so/jobs
For any clarifications or questions regarding this vacancy, please contact [email protected] Applications submitted by email may not be considered; all applications should be submitted through the official SPS recruitment portal.
📅 Deadline for submission: 17th August 2026, 11:59 p.m. Mogadishu time.
Only shortlisted candidates will be contacted.