Senior Information Security Engineer
Old Mutual Limited · Harare, Harare, Zimbabwe
Financial Services · 10,001+ employees
About the role
The Senior Information Security Engineer will own and govern enterprise firewall security and vulnerability management programs to ensure operational excellence and risk reduction. The role involves leading technical security initiatives, maintaining regulatory compliance, and providing expert reporting to management and auditors.
What they look for
Requirements
Candidates must possess a bachelor's degree in a relevant field and at least 5 to 7 years of experience in cyber or network security. Strong expertise in firewall administration, vulnerability management, and knowledge of regulatory frameworks like PCI DSS is essential.
Full description
Lets Write Africa's Story Together!
Old Mutual is a firm believer in the African opportunity and our diverse talent reflects this.
Job Description
This is a senior individual contributor and technical leadership role for a security professional who combines deep technical expertise with strong governance, reporting, and control ownership capabilities. The incumbent will be expected to act as the single accountable owner for firewall security and vulnerability management, driving compliance, risk reduction, operational excellence, and continuous improvement across the organisation's cybersecurity landscape.
Job Purpose
The Senior Security Engineer is responsible for the strategic and operational management of the organisation's network security and vulnerability management capabilities within a highly regulated financial services environment.
The incumbent will own and govern all firewall security controls and vulnerability management processes across the enterprise, ensuring the confidentiality, integrity, and availability of business systems and customer information. The role requires a highly experienced security professional capable of independently leading their area of responsibility, driving risk reduction initiatives, maintaining compliance with PCI DSS and regulatory requirements, developing and maintaining standards and procedures, and providing accurate reporting to management, auditors, and regulators.
The position combines technical leadership, governance, risk management, and operational excellence, requiring an individual who can influence stakeholders across Technology, Risk, Audit, Compliance, and Business functions.
Key Accountabilities
Firewall Security Management
- Own the lifecycle management of all enterprise firewall technologies and associated security controls.
- Design, implement, maintain, and optimize network security architectures in line with industry best practice.
- Govern firewall rule administration processes, ensuring appropriate approvals, documentation, review, and risk management.
- Lead the implementation and management of at minimum:• Network segmentation controls
- Perimeter security controls
- VPN technologies
- Ensure PCI DSS-compliant segmentation between Cardholder Data Environments (CDE) and other network environments.
- Perform regular firewall rule reviews and certify firewall rules in accordance with policy requirements.
- Identify and mitigate security risks arising from network architecture, firewall configurations, and connectivity requirements.
- Develop and maintain firewall standards, procedures, technical baselines, and operational documentation.
Vulnerability Management Governance
- Own and lead the enterprise Vulnerability Management Programme.
- Define, implement, and continuously improve vulnerability management policies, processes, standards, and reporting.
- Ensure vulnerability management practices align with:• PCI DSS requirements
- Regulatory expectations
- Internal risk management standards
- Industry best practices
- Coordinate enterprise vulnerability scans across:• Servers
- Endpoints
- Databases
- Applications
- Network infrastructure
- Cloud platforms
- Assess and prioritise vulnerabilities based on risk, exploitability, business impact, and threat intelligence.
- Drive remediation activities with infrastructure, application, cloud, and business technology teams.
- Track exceptions, compensating controls, and risk acceptance processes.
- Report on remediation performance against agreed service levels and risk appetite thresholds.
- Lead management of penetration testing findings and validation of remediation efforts.
PCI DSS and Regulatory Compliance
- Serve as the technical subject matter expert for firewall and vulnerability management requirements under PCI DSS.
- Ensure security controls continuously support PCI DSS compliance objectives.
- Participate in PCI DSS assessments and engagements with Qualified Security Assessors (QSAs).
- Support compliance with:• Reserve Bank of Zimbabwe directives
- Cyber and Data Protection Act
- PCI DSS
- ISO 27001
- SWIFT Customer Security Programme requirements (where applicable)
- Internal information security standards
- Maintain compliance evidence and security documentation required for audits and regulatory inspections.
Governance, Ownership and Leadership
- Act as the designated control owner for firewall security and vulnerability management processes.
- Develop, maintain, and periodically review:• Policies
- Standards
- Procedures
- Technical guidelines
- Operational runbooks
- Establish Key Risk Indicators (KRIs) and Key Performance Indicators (KPIs) for the managed security domains.
- Produce monthly, quarterly, and ad hoc reporting for:• Executive Management
- Cyber Security Committees
- Technology Governance Forums
- Risk Committees
- Internal and External Auditors
- Provide leadership and direction to engineers, administrators, and service providers supporting firewall and vulnerability management activities.
- Drive continuous improvement initiatives to enhance the organisation's security maturity and resilience.
- Ensure accountability for operational effectiveness, audit findings, remediation tracking, and control performance within the managed domains.
Stakeholder Management
- Engage regularly with Technology, Risk, Compliance, Audit, Business Units, and external service providers.
- Translate technical risks into business language suitable for senior management consumption.
- Provide expert advice regarding network security architecture and vulnerability risk management.
- Influence remediation prioritisation through risk-based decision-making and stakeholder engagement.
Minimum Qualifications
Academic Qualifications
Bachelor's Degree in any one of the following is desirable:
- Cyber Security
- Computer Science
- Information Systems
- Computer Engineering
- Telecommunications
- Or a related discipline
Professional Certifications
At least one of the following are highly desirable:
- CISSP (Certified Information Systems Security Professional)
- CISM (Certified Information Security Manager)
- PCNSE (Palo Alto Networks Certified Network Security Engineer)
- Fortinet FCSS / NSE
- Check Point CCSE
- Cisco CCNP Security
- CompTIA Security+
- CEH (Certified Ethical Hacker)
- GIAC Security Certifications
- PCI Professional (PCIP) or PCI-related certification (advantageous)
Experience
Essential
- Minimum 5 to 7 years' experience in cyber security, network security, or security engineering.
- Minimum 3 years' experience in firewall administration and management within a complex enterprise environment.
- Demonstrated experience managing vulnerability management programmes.
- Proven experience developing policies, standards, procedures, and governance artefacts.
- Demonstrated ability to independently manage and lead a security function or area of responsibility.
Advantageous
Experience within:
- Banking
- Insurance
- Fintech
- Payments
- Asset Management
- Microfinance
- Other regulated financial services environments
Technical Competencies
- Firewall Technologies
- Vulnerability Management Technologies
- Networking Technologies
- Security Technologies
- Cloud Security Technologies
Key Performance Indicators (KPIs)
The role will be measured against:
- PCI DSS compliance outcomes.
- Reduction in critical and high-risk vulnerabilities.
- Vulnerability remediation SLA achievement rates.
- Firewall rule review and recertification completion rates.
- Number and severity of audit findings.
- Effectiveness of network segmentation controls.
- Timeliness and quality of executive and governance reporting.
- Closure of security risks and audit actions.
- Security control effectiveness and maturity improvements.
- Successful delivery of regulatory and compliance objectives.
na
Skills
Cyber Threat Intelligence, Governance Risk Compliance (GRC), Java (Programming Language), Security Controls
Competencies
Action Oriented
Business Insight
Cultivates Innovation
Drives Results
Ensures Accountability
Manages Complexity
Nimble Learning
Optimizes Work Processes
Education
Bachelors Degree (B), Diploma (Dip)
Closing Date
13 August 2026 , 23:59
The Old Mutual Story!