Manager, Cybersecurity & Business Continuity Management (BCM) Job Vacancy at NCBA Bank –  Dar es Salaam August 2026

Website NCBA Bank

NCBA Bank

JOB VACANCY: MANAGER, CYBERSECURITY & BCM

Company: NCBA Bank
Location: Tanzania
Job Type: Full-Time
Requisition ID: 4407
Posted: 05 August 2026

Job Purpose Statement

The Manager, Cybersecurity & Business Continuity Management (BCM) is responsible for ensuring continuous security monitoring of technology assets, managing cybersecurity incidents, and strengthening the bank’s resilience against system failures.

The role focuses on maintaining the confidentiality, integrity, and availability (CIA) of the bank’s systems by implementing security policies, managing incident response programs, supporting business continuity processes, and ensuring effective cybersecurity controls across technology environments.

The position will drive cybersecurity monitoring, incident response, vulnerability management, security awareness, and disaster recovery readiness through appropriate people, processes, and technology.


Key Responsibilities

1. Patch & Vulnerability Management and Security Monitoring (20%)

  • Maintain technology assets within security management platforms, including:
    • Vulnerability scanners
    • Antivirus solutions
    • SIEM platforms
    • Patch management tools
    • Network Access Control (NAC)
    • Asset management systems
  • Monitor and analyze security activities across:
    • Networks
    • Servers
    • Endpoints
    • Databases
    • Applications
    • Websites
  • Conduct regular vulnerability assessments and review security reports to identify weaknesses.
  • Analyze system and network architectures, including:
    • Firewalls
    • Routers
    • Switches
    • IDS/IPS solutions
  • Recommend improvements to security controls and configurations.
  • Perform vulnerability scanning and penetration testing across systems, applications, and IT assets.
  • Work with IT teams to ensure timely remediation of identified vulnerabilities.
  • Conduct security reviews for projects and system changes.
  • Support closure of audit findings through remediation activities.

2. Cyber Incident Response & Malware Management (20%)

  • Manage and continuously improve the cybersecurity incident response plan.
  • Respond to security incidents according to approved procedures.
  • Act as the main point of contact for cybersecurity incidents.
  • Ensure timely escalation, communication, containment, and recovery during incidents.
  • Implement effective malware detection and response practices.
  • Ensure endpoints and servers are protected with appropriate anti-malware solutions.
  • Monitor, analyze, and report malware threats, trends, and statistics.
  • Coordinate incident investigations and recovery activities.

3. Information Security Policies & Procedures (20%)

  • Develop, review, and maintain information security policies, procedures, and standards.
  • Ensure compliance with security service-level agreements (SLAs).
  • Monitor adherence to cybersecurity processes and operational requirements.
  • Develop cybersecurity metrics, dashboards, and reports for management.
  • Design and implement information security awareness programs.
  • Promote cybersecurity best practices across the organization.

4. Customer & Stakeholder Support (10%)

  • Work with internal teams and outsourced partners to resolve cybersecurity incidents within agreed timelines.
  • Coordinate cybersecurity activities with assigned staff and vendors.
  • Monitor and track cybersecurity incidents and remediation actions.
  • Provide cybersecurity guidance, training, and awareness support.
  • Ensure professional communication and timely service delivery.

5. Business Continuity Management & Technology Risk Management (20%)

  • Coordinate business continuity and disaster recovery testing activities.
  • Review testing results and recommend improvements.
  • Ensure system runbooks are updated, tested, and properly documented.
  • Verify critical systems have appropriate disaster recovery solutions.
  • Ensure systems are tested according to the annual BCM plan.
  • Monitor backup strategies and validate restoration tests.
  • Track and close technology audit findings within agreed timelines.
  • Maintain technology risk registers within the Governance, Risk, and Compliance (GRC) system.
  • Support technology risk management initiatives.

6. Learning & Development (10%)

  • Deliver assigned performance objectives and manage personal development.
  • Complete a minimum of 50 annual training hours for self and direct reports.
  • Stay updated with emerging cybersecurity threats, technologies, and industry best practices.
  • Train and mentor employees on cybersecurity awareness and technology risks.

Job Specifications

Academic Qualifications

  • Bachelor’s Degree in:
    • Information Security
    • Information Systems
    • Computer Science
    • Information Technology
    • Or any related field.

Professional Certifications

Relevant cybersecurity certifications are required or highly desirable, including:

  • Certified Ethical Hacker (CEH)
  • Certified Information Systems Auditor (CISA)
  • Certified Information Security Manager (CISM)
  • Certified Information Systems Security Professional (CISSP)

Technical Experience & Skills

Candidates should have:

  • Minimum 3–5 years of professional experience, including at least 3 years in an IT security environment.
  • Experience managing security technologies and network security devices.
  • Practical knowledge of:
    • Security Information and Event Management (SIEM)
    • Intrusion Prevention/Detection Systems (IPS/IDS)
    • Data Loss Prevention (DLP)
    • Active Directory
    • Identity and Access Management (IAM)
    • Endpoint Security
    • Firewalls
    • Web Content Filtering
    • Database Activity Monitoring (DAM)
  • Strong understanding of:
    • Operating systems
    • Networks
    • Databases
    • Middleware technologies
    • Enterprise infrastructure security
  • Knowledge of information security standards, policies, and best practices.
  • Experience with vulnerability assessment and penetration testing tools.
  • Strong reporting, dashboard creation, and documentation skills.
  • Banking industry cybersecurity experience will be an added advantage.
  • Systems audit experience will be an added advantage.

Key Competencies

Technical Competencies

  • Cybersecurity Monitoring and Incident Response
  • Vulnerability Management
  • Security Operations Management
  • Business Continuity Management
  • Disaster Recovery Planning
  • IT Risk Management
  • Security Policy Development
  • Security Audit Support
  • SIEM Administration
  • Threat Intelligence
  • Network and Infrastructure Security
  • Security Reporting and Documentation

Behavioural Competencies

  • Strong analytical and problem-solving skills
  • Excellent communication skills
  • Ability to work under pressure during security incidents
  • Collaboration and stakeholder management
  • Attention to detail
  • Continuous learning mindset
  • Strong decision-making ability
  • Ability to influence cybersecurity culture

Reporting Relationships

Direct Reports: None
Indirect Reports: Outsourced cybersecurity partners and vendors


Stakeholder Management

Internal Stakeholders

  • Information Security Department
  • IT Department
  • Enterprise Risk Management (ERM) & Compliance Department
  • Internal Audit

External Stakeholders

  • Managed Service Providers
  • External Auditors
  • Regulators
  • Digital Forensics Experts

Decision-Making Authority

Operational Responsibilities

  • Continuous cybersecurity monitoring.
  • Security incident response and coordination.

Managerial Responsibilities

  • Cybersecurity vendor and managed service provider management.

Work Cycle & Impact

Planning Horizon: 6–12 months

The role contributes to long-term cybersecurity resilience by strengthening security controls, improving incident response capabilities, and ensuring technology continuity across the bank.


NCBA Bank Core Value Behaviours

  • Technical Excellence
  • Driving Results
  • Collaboration
  • Building Trust
  • Responsiveness
  • Continuous Improvement
  • Coaching and Knowledge Sharing
  • Business Awareness

Only shortlisted candidates will be contacted.

CLICK/TAP HERE TO APPLY:

To apply for this job please visit career5.successfactors.eu.

Spread the love