INFORMATION SECURITY ANALYST AT IDINSIGHT
About This Opportunity
INFORMATION SECURITY ANALYST AT IDINSIGHT
SEO Title: Information Security Analyst at IDinsight – Nairobi | Apply Now
Meta Description: IDinsight is hiring an Information Security Analyst in Nairobi. The role requires 3–5 years of information security experience, security tooling expertise, incident response and data protection knowledge.
SEO Slug: information-security-analyst-idinsight
JOB DETAILS
Job Detail| Information
Job Title| Information Security Analyst
Company| IDinsight
Location| Nairobi, Kenya
Job Type| Full Time
Qualification| BA/BSc/HND
Experience| 3–5 years
Job Field| ICT / Computer, Data, Business Analysis and AI
Salary| Not specified
Posted Date| September 15, 2026
Deadline| Not specified
JOB OVERVIEW
IDinsight is seeking an experienced Information Security Analyst to join its Information Security and Systems team.
The role focuses on protecting organizational systems and data through security tooling, incident response, risk assessment, security awareness, data protection compliance, governance, risk and compliance, and AI governance.
The successful candidate will work across international and multicultural teams and will need to combine hands-on technical security expertise with the ability to communicate security risks clearly to both technical and non-technical stakeholders.
ABOUT IDINSIGHT
IDinsight is an international development organization that helps policymakers and managers make socially impactful decisions using rigorous evidence.
The organization applies analytical and quantitative approaches to help clients design policies, test ideas and make informed decisions intended to improve development outcomes.
Its Information Security and Systems team supports the systems and technology environment used by teams working across different locations and projects.
KEY RESPONSIBILITIES
Security Tooling Administration
- Administer and maintain the organization's security technology environment.
- Work with security tools including SASE, CASB, EDR, SIEM and MDM.
- Tune security policies and detection rules.
- Maintain security coverage across a distributed technology environment.
- Investigate and respond to security alerts.
- Ensure security tools remain effective and appropriately configured.
Security Education, Training and Awareness
- Design and support security education and awareness programmes.
- Deliver security training for new employees.
- Conduct phishing simulations.
- Provide targeted security awareness sessions for higher-risk teams.
- Develop practical security awareness materials for employees across different offices.
Incident Response
- Triage and investigate security incidents.
- Coordinate containment and recovery activities.
- Maintain and exercise the organization's incident response plan.
- Document security incidents and post-incident findings.
- Identify improvements required following security events.
Information Security Risk Assessment
- Conduct security risk assessments covering projects, systems, vendors and data flows.
- Identify information and data security risks.
- Translate technical findings into practical recommendations.
- Communicate risks and recommended actions to non-technical stakeholders.
Partner and Client Due Diligence
- Respond to security and data protection due diligence requests.
- Support requests from funders, government partners and clients.
- Maintain security evidence and documentation.
- Improve the efficiency of future due diligence responses through proper evidence management.
Security Policies and Guidance
- Develop and maintain information security policies.
- Create security standards and practical guidelines.
- Keep policies aligned with recognized security frameworks.
- Support compliance with applicable regulatory obligations.
Data Protection Compliance
- Support compliance with GDPR and applicable national data protection laws.
- Assist with data mapping and retention activities.
- Support handling of data subject rights requests.
- Contribute to assessments for new data processing activities.
Governance, Risk and Compliance
- Contribute to the organization's security control framework.
- Maintain and update the information security risk register.
- Support internal and external assurance activities.
- Contribute to governance, risk and compliance initiatives.
AI Governance
- Support responsible use of artificial intelligence within the organization.
- Participate in assessment of AI tools.
- Develop or support acceptable-use guidance.
- Help establish controls for responsible use of AI with project and organizational data.
SYSTEMS SUPPORT AND PROFESSIONAL DEVELOPMENT
The successful candidate may occasionally provide Systems Support through the organization's internal help desk.
This provides exposure to the technical challenges faced by employees and opportunities to develop practical solutions.
IDinsight also supports continuous learning and professional development. Employees are expected to build deeper expertise over time, with support for relevant security certifications and continuing professional education.
QUALIFICATIONS AND REQUIREMENTS
Applicants should have:
- 3–5 years of professional experience in information security, IT security operations or a closely related role.
- Hands-on administration experience with at least three of SASE, CASB, EDR, SIEM and MDM.
- Ability and willingness to become productive with additional security technologies.
- Practical experience in incident response, investigation and post-incident reporting.
- Experience conducting information or data security risk assessments.
- Ability to communicate security findings to non-technical audiences.
- Experience developing information security policies, standards or guidelines that have been adopted and used.
- Working knowledge of GDPR.
- Knowledge of at least one relevant national data protection law, such as Kenya's Data Protection Act.
- Familiarity with recognized security standards and frameworks such as NIST SP 800-171, NIST CSF or ISO/IEC 27001.
- Demonstrated interest in IT governance, risk and compliance.
- Interest in AI governance and responsible technology use.
- Bachelor's degree in Computer Science or another quantitative discipline.
PROFESSIONAL CERTIFICATIONS
A security certification is valued. Relevant certifications include:
- Security+
- SSCP
- CISM
- CISSP
The vacancy indicates that the organization can support professional development toward advanced certifications.
KEY SKILLS AND COMPETENCIES
The successful candidate should demonstrate:
- Information security operations.
- Security tooling administration.
- Incident response and investigation.
- Risk assessment.
- Data protection compliance.
- Security governance.
- Policy development.
- Security awareness training.
- Strong written communication.
- Public speaking and presentation skills.
- Stakeholder management.
- Problem-solving skills.
- Strong attention to detail.
- Execution and task-management ability.
- Ability to work independently.
- Ability to operate effectively in ambiguous and changing environments.
- Integrity and confidentiality.
- Ability to handle sensitive information discreetly.
- Empathy and strong interpersonal skills.
- Ability to collaborate with international and multicultural teams across time zones.
IDEAL CANDIDATE
The position is suited to a hands-on information security professional who can combine technical security operations with governance, risk and compliance responsibilities.
The candidate should be comfortable investigating security incidents, administering security technologies, assessing risks and developing practical security guidance. Strong communication is particularly important because the role involves explaining security risks and recommendations to people with different technical backgrounds and competing priorities.
The candidate should also demonstrate initiative, continuous-learning ability, sound judgement and discretion when handling sensitive information.
SALARY AND WORK ARRANGEMENT
Salary: Not specified in the vacancy announcement.
Employment Type: Full Time.
Location: Nairobi, Kenya.
The role involves working with international and cross-cultural teams across different time zones.
HOW TO PREPARE YOUR CV
Applicants should tailor their CV toward information security by clearly highlighting:
- 3–5 years of relevant security or IT security operations experience.
- Security tools you have administered.
- Experience with SASE, CASB, EDR, SIEM and/or MDM.
- Incident response and investigation experience.
- Security risk assessments.
- Information security policies and standards developed or implemented.
- GDPR and national data protection knowledge.
- NIST or ISO/IEC 27001 experience.
- Governance, risk and compliance work.
- Security awareness and training.
- AI governance or responsible AI experience.
- Relevant security certifications.
- Experience working with international or distributed teams.
Where possible, demonstrate measurable outcomes rather than simply listing responsibilities.
APPLICATION DETAILS
Interested and qualified candidates should apply through IDinsight's recruitment platform.
Application Platform: IDinsight on BambooHR.
Application Deadline: Not specified in the vacancy information provided.
Applicants should ensure their CV accurately reflects their security operations, governance and technical experience before submitting their application.
JOB SUMMARY
Category| Details
Position| Information Security Analyst
Company| IDinsight
Location| Nairobi, Kenya
Job Type| Full Time
Qualification| Bachelor's degree in Computer Science or quantitative discipline
Experience| 3–5 years
Job Field| ICT / Computer, Data, Business Analysis and AI
Salary| Not specified
Posted| September 15, 2026
Deadline| Not specified
Application| IDinsight BambooHR
FREQUENTLY ASKED QUESTIONS
1. What position is IDinsight hiring for?
IDinsight is hiring an Information Security Analyst.
2. Where is the position based?
The vacancy lists Nairobi, Kenya.
3. How much experience is required?
Applicants should have 3–5 years of professional experience in information security, IT security operations or a related field.
4. What security technologies are relevant?
The vacancy specifically mentions SASE, CASB, EDR, SIEM and MDM, with hands-on administration experience in at least three of these expected.
5. Is incident response experience required?
Yes. Applicants should have experience investigating security incidents and preparing post-incident reports.
6. Is knowledge of data protection legislation required?
Yes. Working knowledge of GDPR and at least one national data protection law is requested. Kenya's Data Protection Act is given as one example.
7. Which security frameworks are relevant?
The vacancy mentions NIST SP 800-171, NIST CSF and ISO/IEC 27001.
8. Are security certifications required?
The vacancy states that security certification is valued. Security+ and SSCP are mentioned, while CISM and CISSP are identified as further professional development paths.
9. What is the salary?
The vacancy does not specify a salary.
10. What is the application deadline?
No deadline is specified in the vacancy information provided.
11. How do I apply?
Interested candidates should apply through IDinsight's BambooHR recruitment platform.
IMPORTANT JOB SEEKER NOTICE
Never pay money to secure a job, interview, shortlisting or recruitment opportunity. Be cautious of anyone requesting payment for registration, training, certificates, assessments or placement.
Applicants should use the employer's stated recruitment platform and verify recruitment communications before sharing sensitive personal or financial information.
For more job description visit: jobopenings.co.ke
Application & Safety Advice
Key tips for applying to IDINSIGHT
Quick Info
Type
JobCompany
IDINSIGHT
Location
Nairobi
Deadline
Rolling Basis
Open until filled
Ready to Apply?
Don't miss this opportunity.
Share
Help others discover this