Hiring.Camp

Senior Information Security Engineer

Oldmutual

·

Today

Location
Harare, Zimbabwe
Department
Engineering
Seniority
Senior
Experience
3+ years
Education
Bachelor
Closing date
Today
Source
Workday

Description

Lets Write Africa's Story Together!

Old Mutual is a firm believer in the African opportunity and our diverse talent reflects this.

Job Description

This is a senior individual contributor and technical leadership role for a security professional who combines deep technical expertise with strong governance, reporting, and control ownership capabilities. The incumbent will be expected to act as the single accountable owner for firewall security and vulnerability management, driving compliance, risk reduction, operational excellence, and continuous improvement across the organisation's cybersecurity landscape.

Job Purpose

The Senior Security Engineer is responsible for the strategic and operational management of the organisation's network security and vulnerability management capabilities within a highly regulated financial services environment.

The incumbent will own and govern all firewall security controls and vulnerability management processes across the enterprise, ensuring the confidentiality, integrity, and availability of business systems and customer information. The role requires a highly experienced security professional capable of independently leading their area of responsibility, driving risk reduction initiatives, maintaining compliance with PCI DSS and regulatory requirements, developing and maintaining standards and procedures, and providing accurate reporting to management, auditors, and regulators.

The position combines technical leadership, governance, risk management, and operational excellence, requiring an individual who can influence stakeholders across Technology, Risk, Audit, Compliance, and Business functions.

Key Accountabilities

Firewall Security Management

  • Own the lifecycle management of all enterprise firewall technologies and associated security controls.
  • Design, implement, maintain, and optimize network security architectures in line with industry best practice.
  • Govern firewall rule administration processes, ensuring appropriate approvals, documentation, review, and risk management.
  • Lead the implementation and management of at minimum:
    • Network segmentation controls
    • Perimeter security controls
    • VPN technologies
  • Ensure PCI DSS-compliant segmentation between Cardholder Data Environments (CDE) and other network environments.
  • Perform regular firewall rule reviews and certify firewall rules in accordance with policy requirements.
  • Identify and mitigate security risks arising from network architecture, firewall configurations, and connectivity requirements.
  • Develop and maintain firewall standards, procedures, technical baselines, and operational documentation.

Vulnerability Management Governance

  • Own and lead the enterprise Vulnerability Management Programme.
  • Define, implement, and continuously improve vulnerability management policies, processes, standards, and reporting.
  • Ensure vulnerability management practices align with:
    • PCI DSS requirements
    • Regulatory expectations
    • Internal risk management standards
    • Industry best practices
  • Coordinate enterprise vulnerability scans across:
    • Servers
    • Endpoints
    • Databases
    • Applications
    • Network infrastructure
    • Cloud platforms
  • Assess and prioritise vulnerabilities based on risk, exploitability, business impact, and threat intelligence.
  • Drive remediation activities with infrastructure, application, cloud, and business technology teams.
  • Track exceptions, compensating controls, and risk acceptance processes.
  • Report on remediation performance against agreed service levels and risk appetite thresholds.
  • Lead management of penetration testing findings and validation of remediation efforts.

PCI DSS and Regulatory Compliance

  • Serve as the technical subject matter expert for firewall and vulnerability management requirements under PCI DSS.
  • Ensure security controls continuously support PCI DSS compliance objectives.
  • Participate in PCI DSS assessments and engagements with Qualified Security Assessors (QSAs).
  • Support compliance with:
    • Reserve Bank of Zimbabwe directives
    • Cyber and Data Protection Act
    • PCI DSS
    • ISO 27001
    • SWIFT Customer Security Programme requirements (where applicable)
    • Internal information security standards
  • Maintain compliance evidence and security documentation required for audits and regulatory inspections.

Governance, Ownership and Leadership

  • Act as the designated control owner for firewall security and vulnerability management processes.
  • Develop, maintain, and periodically review:
    • Policies
    • Standards
    • Procedures
    • Technical guidelines
    • Operational runbooks
  • Establish Key Risk Indicators (KRIs) and Key Performance Indicators (KPIs) for the managed security domains.
  • Produce monthly, quarterly, and ad hoc reporting for:
    • Executive Management
    • Cyber Security Committees
    • Technology Governance Forums
    • Risk Committees
    • Internal and External Auditors
  • Provide leadership and direction to engineers, administrators, and service providers supporting firewall and vulnerability management activities.
  • Drive continuous improvement initiatives to enhance the organisation's security maturity and resilience.
  • Ensure accountability for operational effectiveness, audit findings, remediation tracking, and control performance within the managed domains.

Stakeholder Management

  • Engage regularly with Technology, Risk, Compliance, Audit, Business Units, and external service providers.
  • Translate technical risks into business language suitable for senior management consumption.
  • Provide expert advice regarding network security architecture and vulnerability risk management.
  • Influence remediation prioritisation through risk-based decision-making and stakeholder engagement.

Minimum Qualifications

Academic Qualifications

Bachelor's Degree in any one of the following is desirable:

  • Cyber Security
  • Computer Science
  • Information Systems
  • Computer Engineering
  • Telecommunications
  • Or a related discipline

Professional Certifications

At least one of the following are highly desirable:

  • CISSP (Certified Information Systems Security Professional)
  • CISM (Certified Information Security Manager)
  • PCNSE (Palo Alto Networks Certified Network Security Engineer)
  • Fortinet FCSS / NSE
  • Check Point CCSE
  • Cisco CCNP Security
  • CompTIA Security+
  • CEH (Certified Ethical Hacker)
  • GIAC Security Certifications
  • PCI Professional (PCIP) or PCI-related certification (advantageous)

Experience

Essential

  • Minimum 5 to 7 years' experience in cyber security, network security, or security engineering.
  • Minimum 3 years' experience in firewall administration and management within a complex enterprise environment.
  • Demonstrated experience managing vulnerability management programmes.
  • Proven experience developing policies, standards, procedures, and governance artefacts.
  • Demonstrated ability to independently manage and lead a security function or area of responsibility.

Advantageous

Experience within:

  • Banking
  • Insurance
  • Fintech
  • Payments
  • Asset Management
  • Microfinance
  • Other regulated financial services environments

Technical Competencies

  • Firewall Technologies
  • Vulnerability Management Technologies
  • Networking Technologies
  • Security Technologies
  • Cloud Security Technologies

Key Performance Indicators (KPIs)

The role will be measured against:

  • PCI DSS compliance outcomes.
  • Reduction in critical and high-risk vulnerabilities.
  • Vulnerability remediation SLA achievement rates.
  • Firewall rule review and recertification completion rates.
  • Number and severity of audit findings.
  • Effectiveness of network segmentation controls.
  • Timeliness and quality of executive and governance reporting.
  • Closure of security risks and audit actions.
  • Security control effectiveness and maturity improvements.
  • Successful delivery of regulatory and compliance objectives.

na

 

Skills

Cyber Threat Intelligence, Governance Risk Compliance (GRC), Java (Programming Language), Security Controls

Competencies

Action Oriented

Business Insight

Cultivates Innovation

Drives Results

Ensures Accountability

Manages Complexity

Nimble Learning

Optimizes Work Processes

Education

Bachelors Degree (B), Diploma (Dip)

Closing Date

13 August 2026 , 23:59

The Old Mutual Story!

Skills

JavaCybersecurityPenetration TestingRisk ManagementComplianceISO 27001CISSPCompTIA

Similar Jobs

30

Senior Information Security Engineer

Farmers and Merchants Bank of Long Beach · Seal Beach, CA

Today

Senior Information Security Analyst - Attack Surface Management Lead

Massgeneralbrigham · 399 Revolution Drive Somerville (Assembly Row Main Building), United States of America · Hybrid

Yesterday

Senior Information Security Specialist

Secfix · Remote-Europe · Remote

Yesterday

Senior Information Security GRC Specialist

Reconomy · Bucharest

Yesterday

Senior Information Security Engineer

Mastercard · Dublin, Ireland

2 days ago

Senior Information Security (INFOSEC) Specialist

Acquired Data Solutions · Washington, DC · Onsite

2 days ago

Senior Information Security Analyst

Td · 310/320 Front Street West Corporate, Toronto, Ontario, Canada · Onsite

2 days ago

Senior Information Security Manager (GRC)

Deepl · Munich +2

2 days ago

Senior Information Security Engineer (Detection, Automation & AI)

Zoox · Foster City, CA · Hybrid

2 days ago

Senior Information Security Analyst

OneAZ Credit Union · 2355 W Pinnacle Peak Rd, Phoenix, AZ 85027

2 days ago

Senior Information Security Analyst

Wood River Federal · San Antonio, Texas

3 days ago

Senior Information Security Engineer - Vulnerability Management

Wells Fargo · 111443-IND-HYDERABAD-INTL HYD WF CENTRE BLK B8 Twr-4, India

4 days ago

Senior Information Security Analyst

Ameriprise Financial · 11068 Ameriprise India - Udyog Vihar · Hybrid

4 days ago

Senior Information Security Analyst

Td · One Molesworth Street, Dublin, Ireland · Onsite

1 week ago

Senior Information Security Analyst

Hdsupply · GA250 - Atlanta GA, United States of America

1 week ago

Senior Information Security Analyst

Bonterra · Remote-US-District of Columbia, United States of America · Remote

1 week ago

Senior Information Security Engineer

Wf · 111443-IND-HYDERABAD-INTL HYD WF CENTRE BLK B8 Twr-4, India

1 week ago

Senior Information Security Engineer

Wf · 110380-IND-BENGALURU-INTL BLR Twr-1&2 CARNATION, India

1 week ago

Senior Information Security Engineer

Wells Fargo · 110380-IND-BENGALURU-INTL BLR Twr-1&2 CARNATION, India

1 week ago

Senior Information Security Engineer

Betsson · Malta

1 week ago

Senior Information Security Engineer - IS Mod

Mayo Clinic · Rochester, MN, United States, US

1 week ago

Senior Information Security Analyst

GDIT · USA VA Crystal City - 2521 S Clark St (VAC119), United States of America

1 week ago

Senior Information Security Engineer

Wf · 110384-IND-HYDERABAD-INTL HYD WF CENTRE BLK 2 Twr-3, India

1 week ago

Senior Information Security Risk Analyst

Warnerbros · GA Atlanta 1050 Techwood Drive NW, United States of America · Hybrid

1 week ago

Senior Information Security Consultant

Truist · Atlanta GA - 303 Peachtree Center Avenue - Garden Offices, United States of America +2

1 week ago

Senior Information Security Analyst

ServiceNow · Santa Clara, California, United States · Remote

1 week ago

Senior Information Security Manager

Ebury · Madrid · Hybrid

1 week ago

Senior Information Security Engineer - Source Code Review

Wells Fargo · 110380-IND-BENGALURU-INTL BLR Twr-1&2 CARNATION, India

1 week ago

Associate Senior Information Security Engineering Analyst

Global Payments · Pune, India · Onsite

1 week ago

Senior Information Security Engineer

Swib · 4703 Madison Yards Way, Suite 700, Madison, Wisconsin, 53705, United States, United States of America · Hybrid

1 week ago
Senior Information Security Engineer at Oldmutual | Hiring.Camp