CarePay
Cyber Security and Information Security Lead
Nairobi
• Kenya
Aga Khan Hospitals
Assistant Manager, Africa Fingers, Brain and Mind Institute
Nairobi
• Kenya
Aga Khan Hospitals
Senior Accounts Clerk , Debtors Department (Re-advertisement)
Nairobi
• Kenya
AIC Kijabe Hospital
Dentist
Nairobi
• Kenya
Chiromo Hospital Group
Patient Transfer and Attendance Staff
Nairobi
• Kenya
Equity Afia
Resident Medical Officer/Clinic Lead
Nairobi
• Kenya
Oasis Healthcare Group Limited
Sacco Manager
Nairobi
• Kenya
Valley Hospital
Customer Relations Officer (Locum)
Nakuru
• Kenya
Valley Hospital
Claims Officer
Nakuru
• Kenya

Get personalised job alerts directly to your inbox!
Aga Khan Hospitals
Senior House Officer, AKUH(ON) A&E
Nairobi
• Kenya
Top cities with open vacancies
Jobs in Nairobi, Jobs in Abuja, Jobs in Kampala, Jobs in Nakuru, Jobs in Lira, Jobs in Arua, Jobs in Meru, Jobs in Machakos, Jobs in Lagos, Jobs in Busia, Jobs in Ruiru, Jobs in Murang’a, Jobs in Moyale, Jobs in Kutus, Jobs in Kisumu, Jobs in Kisii, Jobs in Embu, Jobs in EntebbeCompanies hiring now
African Medical Centre of Excellence (AMCE), Aga Khan Hospitals, Equity Afia, Kenyatta University Teaching, Referral and Research Hospital (KUTRRH), Westlands Medical CentreProfession (Health care, medical, Mid-level)
Accounting, finance, banking, insurance,Administrative, clerical,Business, strategic management,Customer support, client care,Electrical engineering,Engineering, architecture,Food, nutrition,Government, community development, public services,Human resources,Information technology, software development, data,Legal,Manufacturing, operations, quality,Media, communications, languages,Medical, health,Project, program management,Research, academy,Restaurant, hospitality, travel,Sales, marketing, promotion,Security,Teaching, training,Transportation, logistics, driving,
Industry (Mid-level)
Aeronautics,Agriculture, fishing, forestry,Automotive,Banking, microfinance, insurance,Communications, media, radio, tv,Computers, software development and services,Construction, renovation, maintenance,Consulting, business support, auditing,Data/Research,Education, academic,Electronics,Energy, utilities, environment,Engineering, architecture,Entertainment, events,Finance & FinTech,Financial Services,Fitness, well-being and lifestyle,Governmental,Health care, medical,Housekeeping, maintenance,Human resources, talent development, recruiting,Legal, accounting,Manufacturing,Marketing, advertising,Non-profit, social work,Outsourcing, leasing,Raw materials, oil, chemicals,Real estate,Restaurant, hospitality, travel,Retail, wholesale, FMCG,Security,Telecommunications,Transportation, logistics, storage,
Seniority (Health care, medical)
© Fuzu Ltd
CarePay
Health care + 1 more
Description
Requirements
- 8+ years’ experience in cyber and information security and privacy function, including business continuity planning and risk management
- Solid understanding of:
- Information security frameworks (ISO 27001, NIST, SOC 2)
- Risk management and control design
- Application, cloud, and API security
- Incident response and vulnerability management
- Data protection and privacy (GDPR)
- Experience in regulated environments (insurtech, fintech, health, insurance, or financial services)
- Strong knowledge of business impact assessments, disaster recovery, RTOs/RPOs and system criticality mapping
- Hands-on experience with cloud-native environments and modern SaaS architectures
- Proven ability to work independently with excellent communication and interpersonal skills, including delivering effective training across the company
- Analytical and detail-oriented with a proactive approach to risk identification and mitigation
- Experience working across multiple countries or regions is a strong advantage
Nice to have:
- Relevant certifications (e.g. CISSP, CISM, ISO 27001 Lead Implementer/Auditor)
- Previous experience acting as a DPO
- Experience scaling security in a growing or mission-driven organisation
Responsibilities
Cyber Security & Information Security Leadership
- Own and continuously evolve CarePay’s information security and cyber security strategy
- Establish and maintain security policies, standards, and controls appropriate for a growing, international insurtech
- Turn policy into practice through effective implementation of policies, standards and controls
- Act as CarePay’s primary authority on cyber and information security
Data Protection and Privacy
- Ensure appropriate protection of sensitive data, including PII, financial, and health data
- Support or act as Data Protection Officer (DPO) where required
- Lead or support Data Protection Impact Assessments (DPIAs)
- Advise teams on privacy-by-design and data minimisation principles
Risk, Governance and Compliance
- Identify, assess, and manage security, technology and privacy risks across products, platforms, and operations
- Lead security risk assessments and define pragmatic mitigation plans
- Ensure alignment with relevant standards and regulations (e.g. ISO 27001, GDPR, SOC 2, local regulatory requirements)
- Prepare for and support audits, certifications, and customer security assessments
- Serve as a key point of contact for regulators, partners, and enterprise customers on security matters
Secure Product and Platform Enablement
- Partner closely with Engineering and Product teams to embed security by design and secure SDLC practices
- Advise on cloud, application, and API security architecture
- Oversee vulnerability management, penetration testing, and remediation efforts
- Proactively identify emerging threats and weaknesses in CarePay’s technology stack
Incident Preparedness and Response
- Design and maintain CarePay’s incident response and breach management processes
- Lead security and privacy incident response activities when required, ensuring calm, clear communication and effective coordination
- Drive post-incident reviews and continuous improvement
Culture, Awareness & Influence
- Build security and privacy awareness across CarePay through training, guidance and practical support
- Translate technical security risks into clear business impact for non-technical stakeholders
- Act as a trusted advisor to leadership, contributing to long-term technology and risk decisions
Start hiring with Fuzu
Recruit better talent faster - on your own or with our support.
Explore recruitment platformJob search tips from Fuzu
Selected articles on cover letters, CV structure, and interview preparation.