{"id":105850,"date":"2026-08-05T06:01:25","date_gmt":"2026-08-05T06:01:25","guid":{"rendered":"https:\/\/jobs.dataaxisnode.com\/kenya\/uncategorized\/cybersecurity-governance-and-assurance-officer\/"},"modified":"2026-08-05T06:01:25","modified_gmt":"2026-08-05T06:01:25","slug":"cybersecurity-governance-and-assurance-officer","status":"publish","type":"post","link":"https:\/\/jobs.dataaxisnode.com\/kenya\/jobs\/nairobi\/cybersecurity-governance-and-assurance-officer\/","title":{"rendered":"Cybersecurity, Governance and Assurance Officer"},"content":{"rendered":"<p><script type=\"application\/ld+json\">{\"@context\": \"https:\/\/schema.org\/\", \"@type\": \"JobPosting\", \"title\": \"Cybersecurity, Governance and Assurance Officer\", \"description\": \"About the position\\nThe position combines a 60% allocation to the CGIAR System-wide Cybersecurity Assurance Lead function, hosted by ILRI, and a 40% allocation to ILRI Cybersecurity Governance and Assurance responsibilities.\\nAt the CGIAR level, the position will support the implementation and ongoing coordination of the Integrated Cybersecurity Governance Framework ICGF, maintain cybersecurity standards, coordinate cybersecurity reporting and dashboards, facilitate collaboration among CGIAR cybersecurity focal points, and provide cybersecurity assurance reporting to CGIAR leadership.\\nAt the ILRI level, the position will support cybersecurity governance, risk management, compliance, security assurance, cybersecurity strategy implementation, security awareness and cyber resilience initiatives to strengthen ILRI's cybersecurity posture and support digital transformation objectives.\\nThe role serves as ILRI's focal point for cybersecurity governance and assurance and provides system-wide cybersecurity coordination, reporting and assurance support across the CGIAR System.\\nKey Responsibilities\\nCGIAR CYBERSECURITY ASSURANCE LEAD RESPONSIBILITIES 60%\\nStandards & Catalogue\\nCollate, document, co-develop, and maintain a minimum CGIAR Cybersecurity Standards Catalogue feasible monitorable controls only.\\nDefine and publish incident severity levels and SLA expectations as system-wide standards.\\nCoordinate with Centre focal points to ensure standards are understood, adopted, and evidenced.\\nScorecards & Dashboards\\nDesign, build, and maintain a central CGIAR Cybersecurity Scorecard and dashboards Power BI or equivalent using centrally accessible telemetry and metrics data.\\nAggregate data from Centre security platforms e.g., SentinelOne, Volexity MDR, Microsoft Defender, KnowB4 into unified reporting views.\\nReporting & Governance\\nProduce and present quarterly cyber-risk reports to GLT, the Audit and Risk Committee AFRC\/IPB, and ICT leaders \u2014 ensuring cybersecurity visibility extends beyond the IT function.\\nPrepare ad-hoc briefings for senior leadership and Boards as required.\\nMaintain a one-page Decision Rights Charter RACI & escalation for system-wide cybersecurity.\\nCoordination and Network Leadership\\nConvene and lead the distributed cybersecurity focal-point network one focal point per Centre, each ~20% FTE.\\nEstablish a regular meeting cadence monthly or as agreed for focal points to share threat intelligence, coordinate remediation, and align on standards.\\nLiaise with the Managed Security Service Provider MSSP and the 1CGSec working group.\\nCoordinate with Internal Audit, the Digital Transformation Accelerator DTA, and other relevant governance bodies to avoid duplication.\\nMonitoring Integration Year 1 Setup\\nOversee the one-time integration project to connect Centre security-platform outputs into the central reporting infrastructure.\\nSpecify minimum telemetry and metrics-reporting requirements for all Centres.\\nRoadmap & Continuous Improvement\\nTrack and document lessons learned, gaps, and readiness indicators for selective adoption of Model 2 elements shared playbooks, harmonised incident classification, SLAs.\\nPrepare a recommendation paper for the 12\u201318-month review gateway on whether and how to advance to Model 2.\\nProcurement and Vendor Relations Coordination\\nSupport cybersecurity procurement activities, cost distribution and payment follow-up.\\nMaintain an inventory of cybersecurity solutions, vendors, contracts and Centre adoption of these solutions.\\nILRI CYBERSECURITY GOVERNANCE AND ASSURANCE RESPONSIBILITIES 40%\\nCybersecurity Strategy and Governance\\nSupport the development and implementation of ILRI's cybersecurity strategy, roadmap and annual work plans.\\nCoordinate implementation of the institutional Cybersecurity Roadmap, monitor delivery against agreed milestones, track benefits realised and report progress to management.\\nCoordinate the development, review and maintenance of cybersecurity policies, standards, procedures and guidelines.\\nProvide trusted cybersecurity advice to Executive Management, project sponsors and business leaders to support informed, risk-based decision-making.\\nSupport the implementation of cybersecurity governance practices across the institution.\\nCybersecurity Risk Management\\nCoordinate the maintenance of the institutional cybersecurity risk register.\\nConduct cybersecurity risk assessments and coordinate risk mitigation activities.\\nMonitor emerging cyber threats and vulnerabilities affecting ILRI.\\nPrepare regular cybersecurity risk reports for management and governance committees.\\nSecurity Assurance and Compliance\\nCoordinate vulnerability assessments, penetration testing and cybersecurity control reviews.\\nTrack remediation of identified vulnerabilities and audit findings.\\nSupport compliance with regulatory, donor, CGIAR and institutional cybersecurity requirements.\\nCoordinate cybersecurity-related internal and external audits.\\nCoordinate periodic cybersecurity maturity assessments and benchmarki\", \"datePosted\": \"2026-08-04\", \"hiringOrganization\": {\"@type\": \"Organization\", \"name\": \"International Livestock Research Institute ILRI\"}, \"jobLocation\": {\"@type\": \"Place\", \"address\": {\"@type\": \"PostalAddress\", \"addressLocality\": \"Nairobi\", \"addressCountry\": \"KE\"}}, \"directApply\": true, \"validThrough\": \"2026-08-19T23:59:59\", \"employmentType\": \"FULL_TIME\"}<\/script><\/p>\n<p><strong>Company:<\/strong> International Livestock Research Institute ILRI<\/p>\n<p><strong>Location:<\/strong> Nairobi<\/p>\n<p><strong>Job Type:<\/strong> Full Time<\/p>\n<p><strong>Apply Before:<\/strong> 2026-08-19<\/p>\n<h3>Job Description<\/h3>\n<p>About the position<br \/>The position combines a 60% allocation to the CGIAR System-wide Cybersecurity Assurance Lead function, hosted by ILRI, and a 40% allocation to ILRI Cybersecurity Governance and Assurance responsibilities.<br \/>At the CGIAR level, the position will support the implementation and ongoing coordination of the Integrated Cybersecurity Governance Framework ICGF, maintain cybersecurity standards, coordinate cybersecurity reporting and dashboards, facilitate collaboration among CGIAR cybersecurity focal points, and provide cybersecurity assurance reporting to CGIAR leadership.<br \/>At the ILRI level, the position will support cybersecurity governance, risk management, compliance, security assurance, cybersecurity strategy implementation, security awareness and cyber resilience initiatives to strengthen ILRI&#8217;s cybersecurity posture and support digital transformation objectives.<br \/>The role serves as ILRI&#8217;s focal point for cybersecurity governance and assurance and provides system-wide cybersecurity coordination, reporting and assurance support across the CGIAR System.<br \/>Key Responsibilities<br \/>CGIAR CYBERSECURITY ASSURANCE LEAD RESPONSIBILITIES 60%<br \/>Standards &#038; Catalogue<br \/>Collate, document, co-develop, and maintain a minimum CGIAR Cybersecurity Standards Catalogue feasible monitorable controls only.<br \/>Define and publish incident severity levels and SLA expectations as system-wide standards.<br \/>Coordinate with Centre focal points to ensure standards are understood, adopted, and evidenced.<br \/>Scorecards &#038; Dashboards<br \/>Design, build, and maintain a central CGIAR Cybersecurity Scorecard and dashboards Power BI or equivalent using centrally accessible telemetry and metrics data.<br \/>Aggregate data from Centre security platforms e.g., SentinelOne, Volexity MDR, Microsoft Defender, KnowB4 into unified reporting views.<br \/>Reporting &#038; Governance<br \/>Produce and present quarterly cyber-risk reports to GLT, the Audit and Risk Committee AFRC\/IPB, and ICT leaders \u2014 ensuring cybersecurity visibility extends beyond the IT function.<br \/>Prepare ad-hoc briefings for senior leadership and Boards as required.<br \/>Maintain a one-page Decision Rights Charter RACI &#038; escalation for system-wide cybersecurity.<br \/>Coordination and Network Leadership<br \/>Convene and lead the distributed cybersecurity focal-point network one focal point per Centre, each ~20% FTE.<br \/>Establish a regular meeting cadence monthly or as agreed for focal points to share threat intelligence, coordinate remediation, and align on standards.<br \/>Liaise with the Managed Security Service Provider MSSP and the 1CGSec working group.<br \/>Coordinate with Internal Audit, the Digital Transformation Accelerator DTA, and other relevant governance bodies to avoid duplication.<br \/>Monitoring Integration Year 1 Setup<br \/>Oversee the one-time integration project to connect Centre security-platform outputs into the central reporting infrastructure.<br \/>Specify minimum telemetry and metrics-reporting requirements for all Centres.<br \/>Roadmap &#038; Continuous Improvement<br \/>Track and document lessons learned, gaps, and readiness indicators for selective adoption of Model 2 elements shared playbooks, harmonised incident classification, SLAs.<br \/>Prepare a recommendation paper for the 12\u201318-month review gateway on whether and how to advance to Model 2.<br \/>Procurement and Vendor Relations Coordination<br \/>Support cybersecurity procurement activities, cost distribution and payment follow-up.<br \/>Maintain an inventory of cybersecurity solutions, vendors, contracts and Centre adoption of these solutions.<br \/>ILRI CYBERSECURITY GOVERNANCE AND ASSURANCE RESPONSIBILITIES 40%<br \/>Cybersecurity Strategy and Governance<br \/>Support the development and implementation of ILRI&#8217;s cybersecurity strategy, roadmap and annual work plans.<br \/>Coordinate implementation of the institutional Cybersecurity Roadmap, monitor delivery against agreed milestones, track benefits realised and report progress to management.<br \/>Coordinate the development, review and maintenance of cybersecurity policies, standards, procedures and guidelines.<br \/>Provide trusted cybersecurity advice to Executive Management, project sponsors and business leaders to support informed, risk-based decision-making.<br \/>Support the implementation of cybersecurity governance practices across the institution.<br \/>Cybersecurity Risk Management<br \/>Coordinate the maintenance of the institutional cybersecurity risk register.<br \/>Conduct cybersecurity risk assessments and coordinate risk mitigation activities.<br \/>Monitor emerging cyber threats and vulnerabilities affecting ILRI.<br \/>Prepare regular cybersecurity risk reports for management and governance committees.<br \/>Security Assurance and Compliance<br \/>Coordinate vulnerability assessments, penetration testing and cybersecurity control reviews.<br \/>Track remediation of identified vulnerabilities and audit findings.<br \/>Support compliance with regulatory, donor, CGIAR and institutional cybersecurity requirements.<br \/>Coordinate cybersecurity-related internal and external audits.<br \/>Coordinate periodic cybersecurity maturity assessments and benchmarking exercises.<br \/>Support compliance with data protection, privacy and information security requirements across the institution.<br \/>Coordinate cybersecurity risk assessments of third-party service providers, cloud platforms, technology vendors and strategic partners, and monitor remediation of identified risks.<br \/>Cybersecurity Operations Coordination<br \/>Coordinate governance activities relating to cybersecurity operations and security monitoring.<br \/>Coordinate cybersecurity incident reporting, investigations and post-incident reviews.<br \/>Review security monitoring outputs from internal teams and managed security service providers.<br \/>Recommend improvements to security controls and monitoring capabilities.<br \/>Coordinate implementation of cybersecurity improvement initiatives arising from incidents, audits, assessments and risk reviews.<br \/>Security Architecture and Digital Transformation<br \/>Support security reviews for new systems, projects and technology initiatives.<br \/>Provide technical input on cybersecurity considerations for cloud, data, AI and digital transformation initiatives.<br \/>Support the development and implementation of governance, assurance and risk management practices for AI-enabled solutions and emerging technologies, ensuring their secure, responsible and compliant adoption across the institution.<br \/>Support the adoption of secure-by-design principles across institutional projects.<br \/>Cybersecurity Awareness and Culture<br \/>Develop and coordinate cybersecurity awareness and training programmes.<br \/>Coordinate phishing simulations and security awareness campaigns.<br \/>Promote cybersecurity awareness and responsible technology use across the institution.<br \/>Business Continuity and Cyber Resilience<br \/>Support cyber resilience, business continuity and disaster recovery planning and initiatives.<br \/>Coordinate cyber incident simulation and tabletop exercises.<br \/>Participate in assessments of organisational preparedness for cyber incidents and recommend improvements.<br \/>Other Duties<br \/>Perform any other related duties as may be assigned by the supervisor.<br \/>Requirements<br \/>Bachelor\u2019s degree in Information Security, Cybersecurity, Computer Science, Information Systems, Information Technology, Risk Management, or a related field.<br \/>Professional certification in one or more of the following areas is required: CISSP, CISM, CRISC, CISA, ISO 27001 Lead Implementer, ISO 27001 Lead Auditor, CCSP, or equivalent cybersecurity certification.<br \/>Microsoft Security and GIAC Certifications will be an added advantage.<br \/>At least seven 7 years of progressively responsible experience in cybersecurity, information security, IT risk management, security governance, compliance or IT audit, including at least three 3 years in cybersecurity governance, risk management and\/or assurance.<br \/>Demonstrated experience implementing or assessing cybersecurity frameworks including ISO 27001, NIST Cybersecurity Framework and CIS Controls.<br \/>Experience coordinating cybersecurity governance, assurance, compliance or risk management activities within multi-stakeholder environments.<br \/>Experience developing cybersecurity dashboards, scorecards or management reports.<br \/>Experience preparing reports and presenting technical information to management or governance committees.<br \/>Experience working with Managed Security Service Providers MSSPs and third-party security vendors will be an added advantage.<br \/>Experience supporting Microsoft security technologies, cloud security or endpoint security solutions will be an added advantage.<br \/>Experience working within international, research, development, NGO, CGIAR, or similarly federated organisations will be an added advantage.<br \/>Skills and Competencies<br \/>Knowledge of cybersecurity governance, risk management and assurance practices.<br \/>Knowledge of cybersecurity frameworks and standards, including ISO 27001, NIST Cybersecurity Framework and CIS Controls.<br \/>Knowledge of cybersecurity compliance, audit coordination and risk assessment.<br \/>Knowledge of cloud, network, endpoint and identity security principles.<br \/>Ability to coordinate cybersecurity governance and assurance activities across multiple stakeholders.<br \/>Ability to prepare cybersecurity dashboards, reports and presentations for management.<br \/>Strong communication, facilitation and stakeholder management skills.<br \/>Strong analytical and problem-solving skills.<br \/>Ability to influence and collaborate without direct authority.<br \/>Excellent written, presentation and interpersonal communication skills.<br \/>Ability to operate effectively within multicultural, geographically dispersed and matrix-managed environments.<\/p>\n<h3>How to Apply<\/h3>\n<p>Interested and qualified? Go to International Livestock Research Institute (ILRI) on www.ilri.org to apply<br \/>Build your CV for free. Download in different templates.<\/p>\n<p><a href=\"https:\/\/www.myjobmag.co.ke\/apply-now\/1297017\" target=\"_blank\" rel=\"noopener\" style=\"display:inline-block;padding:10px 20px;background:#2271b1;color:#fff;text-decoration:none;border-radius:4px;\">Apply Now<\/a><\/p>\n<p><small>Source: MyJobMag<\/small><\/p>\n<p><!-- job-expiry: 2026-08-19 --><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Company: International Livestock Research Institute ILRI Location: Nairobi Job Type: Full Time Apply Before: 2026-08-19 Job Description About the positionThe position combines a 60% allocation to the CGIAR System-wide Cybersecurity Assurance Lead function, hosted by ILRI, and a 40% allocation to ILRI Cybersecurity Governance and Assurance responsibilities.At the CGIAR level, the position will support the [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1408,1409],"tags":[1425,1764,1413,1412],"class_list":["post-105850","post","type-post","status-publish","format-standard","hentry","category-jobs","category-nairobi","tag-full-time","tag-international-livestock-research-institute-ilri","tag-job-listing","tag-myjobmag"],"_links":{"self":[{"href":"https:\/\/jobs.dataaxisnode.com\/kenya\/wp-json\/wp\/v2\/posts\/105850","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/jobs.dataaxisnode.com\/kenya\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/jobs.dataaxisnode.com\/kenya\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/jobs.dataaxisnode.com\/kenya\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/jobs.dataaxisnode.com\/kenya\/wp-json\/wp\/v2\/comments?post=105850"}],"version-history":[{"count":0,"href":"https:\/\/jobs.dataaxisnode.com\/kenya\/wp-json\/wp\/v2\/posts\/105850\/revisions"}],"wp:attachment":[{"href":"https:\/\/jobs.dataaxisnode.com\/kenya\/wp-json\/wp\/v2\/media?parent=105850"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/jobs.dataaxisnode.com\/kenya\/wp-json\/wp\/v2\/categories?post=105850"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/jobs.dataaxisnode.com\/kenya\/wp-json\/wp\/v2\/tags?post=105850"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}