
Outsourcing + 1 more
Information Security & Investigations Analyst | TP Kenya
Description
As an Information Security & Investigations Analyst at TP Kenya, you will support the implementation, maintenance and continuous improvement of the Information Security Management System (ISMS) and Operational Security Management (OSM) at subsidiary level. Reporting to the Director – Information Security, Sub-Saharan Africa, your primary focus is security incident management, working in a shared-ownership arrangement with the Director to deliver incident management coverage across the Sub-Saharan Africa region. You will also partner with the Operations Security Manager (OSM), Sub-Saharan Africa, in the joint delivery of CCR evidence coordination, Security Risk Assessments (SRA) and security exceptions management, and will contribute to the team's GISP compliance activities as a shared responsibility of the whole Information Security function. Following onboarding and ramp-up, you will progressively support physical security management and other security workstreams, together with audit preparation and evidence support aligned to your performance objectives. You will collaborate cross-functionally with Operations, Facilities, HR and IT to uphold both corporate and client-specific security controls, enhancing the overall security posture of the organisation.
Key Responsibilities
- Partner with the Director – Information Security, Sub-Saharan Africa, in the shared ownership of security incident management across the Sub-Saharan Africa region, coordinating response activities under Teleperformance’s incident response procedures, including incident declaration, containment coordination, reporting, recovery and post-incident review.
- Support the investigation of security incidents, events and weaknesses, conducting root cause analysis, evidence handling and documentation in line with policy, and assist in corrective action planning to prevent recurrence.
- Work in partnership with the Operations Security Manager (OSM), Sub-Saharan Africa, on the joint delivery of CCR evidence coordination and submission, Security Risk Assessments (SRA) planning, execution and reporting, and security exceptions management; sharing ownership of these processes and building cross-capability across the team.
- Contribute to GISP compliance activities as a shared team responsibility, coordinating evidence gathering and reporting through the relevant internal security platforms and tools.
- Support internal, external and client audit and security assessment preparation, including the collection, validation and timely submission of required evidence to auditors and assessment teams.
- Track audit findings and remediation actions through to closure, coordinating with process owners and reporting progress to the Director – Information Security, Sub- Saharan Africa.
- Following onboarding and ramp-up, support physical security management in coordination with Facilities Management, including oversight of identity badge and visitor access governance, physical access exceptions, clean desk policy enforcement and security guard compliance audits.
- Assist in periodic Security Risk Assessments (SRA) in accordance with ISO 27001 and client security requirements, providing comprehensive reporting to relevant stakeholders and driving continuous improvement efforts.
- Serve as the liaison between local business units and the subsidiary audit team, coordinating internal and external audit activities (e.g. ISO 27001, PCI DSS) and facilitating evidence collection and submission.
- Develop and maintain consultative relationships across departments (Operations, HR, IT, Facilities) to promote adherence to company risk management frameworks, exception processes and regulatory standards.
- Promote organisation-wide security awareness by supporting the development and delivery of education, training and debriefing sessions on security-related matters.
- Drive proactive identification and mitigation of compliance and security risks during local projects, initiatives and operational activities, applying investigative and analytical judgement to emerging issues.
- Collaborate with cross-functional teams to collect feedback and improve the effectiveness of security systems, documentation and key performance indicators related to the security posture.
- Perform additional job-related duties as assigned in Information Security and Operational Security.
- Bachelor’s degree in information technology, Computer Science, Administration Management or equivalent.
- Foundational knowledge of information security principles and frameworks (e.g. ISO 27001, PCI DSS) and familiarity with regulations and standards related to information security and data protection.
- Exposure to physical security operations, such as access control systems, badge and visitor management, contractor and guard oversight, or site security compliance.
- Investigative or analytical skills demonstrated through incident investigation, root cause analysis, evidence handling, fraud examination or similar investigative work.
- Preferably holding or working towards one of the following certifications: Certified in Cybersecurity (CC), ISO/IEC 27001 Foundation, CompTIA Security+, ASIS Physical Security Professional (PSP) or Professional Certified Investigator (PCI), or ACFE Certified Fraud Examiner (CFE).
Total Experience & Relevant Experience
- Minimum 2 years of progressive professional experience in Information Security compliance, data protection, security audit and risk management, physical security operations, or an investigative or analytical role.
- Can easily transition to a fast-paced environment and must be able to learn new concepts quickly that affect the security posture of the company.
- Willingness to work on-call in the event of a security breach or other emergency. Perform effectively despite sudden deadlines and changing priorities.
Behavioural Competencies
- Strong organisational skills and attention to detail.
- Strong verbal and written communication skills in English (business fluent).
- Organisation sensitive and able to manoeuvre between various and conflicting interests.
- Having the drive to realize objectives and combine various goals as a personal ambition.
- Great ability to think outside set paths and able to produce several solutions to different situations.
- Highly skilled in presenting data, creating and presenting Power Point presentations to global audiences and industry leaders.
- Being able to build strong and positive relationships in a complex international environment.
- Excellent problem solving, judgment and decision-making skills.
- A composed, objective temperament suited to incident investigation and sensitive enquiries, with the discretion to handle confidential information.
- Empathic personality who can understand the feelings of others and reflect on them.
Start hiring with Fuzu
Recruit better talent faster - on your own or with our support.
Explore recruitment platformJob search tips from Fuzu
Selected articles on cover letters, CV structure, and interview preparation.

