Information Security Officer

Somali Payment Switch
Mogadishu, Somalia
Ict/technology/computers

Job Description

The position of Information Security Officer at Somali Payment Switch in Mogadishu is now open for applications. Candidates should bring 2 - 3 years of hands-on experience, preferably in the Ict/technology/computers sector. The application deadline is Aug, 17 — early applications are encouraged.

Position Title: Information Security Officer

Department: Information Technology

Position Level: Level 1 Officer

Reports To: Head of IT or Designated Supervisor

Employment Type: Full-time

Location: Mogadishu, Somalia

1.

Background

The Somali Payment Switch (SPS) is the national retail payment infrastructure responsible for real-time clearing and settlement of payments across Somali financial institutions. As a central component of Somalia’s financial ecosystem, SPS enables secure interoperability among banks, mobile money operators, government institutions, and other approved payment service providers.

As SPS operates critical national financial infrastructure, its systems and services are subject to strict requirements for availability, security, confidentiality, integrity, auditability, change control, and business continuity. SPS is therefore strengthening its information-security capacity through the appointment of a dedicated Information Security Officer.

2.

Position Summary

The Information Security Officer supports the implementation, operation, monitoring, and continuous improvement of the SPS information-security programme. The role contributes to protecting payment infrastructure, participant connections, cryptographic assets, sensitive information, and service availability. The Officer assists with security risk assessments, access control, security monitoring, incident response, vulnerability management, regulatory compliance, audit support, documentation, and management reporting.

3.

Key Responsibilities

Governance, Risk and Compliance

1.

Support the development and maintenance of the SPS information-security strategy, policies, standards, control framework, and annual security plan.

2.

Maintain accurate information-security risk, treatment, exception, accepted-risk, and compliance registers.

3.

Conduct or support security risk assessments for systems, participants, vendors, changes, products, and material incidents.

4.

Monitor compliance with applicable Central Bank of Somalia requirements, national law, contractual obligations, ISO 27001, PCI DSS where in scope, and adopted payment-security requirements.

5.

Support internal and external audits, regulatory assessments, evidence requests, remediation tracking, and evidence-based closure of findings.

6.

Escalate material security risks, control failures, policy exceptions, and overdue remediation to the designated executive in a timely manner.

Identity and Access Management

1.

Support implementation of identity lifecycle, least-privilege, multi-factor authentication, privileged-access, segregation-of-duties, service-account, and access-review controls.

2.

Ensure joiner, mover, leaver, emergency, vendor, dormant-account, and temporary-access processes are properly authorized and documented.

3.

Conduct periodic reviews of privileged and high-risk access and track identified conflicts or corrective actions to closure.

4.

Monitor shared and generic accounts and ensure they are eliminated or tightly controlled, attributable, logged, and reviewed.

5.

Maintain complete access-control records and evidence in accordance with SPS policies and audit requirements.

Security Monitoring and Incident Response

1.

Monitor security events and alerts from approved security tools, logs, networks, endpoints, applications, cloud services, and payment systems.

2.

Perform initial triage, classification, escalation, containment support, and evidence preservation for suspected cyber-security incidents.

3.

Maintain and exercise incident-response procedures and playbooks for credential compromise, malware, denial of service, data breach, insider threat, key compromise, fraudulent activity, and participant-originated attacks.

4.

Coordinate incident-response activities and authorized communications with management, regulators, participants, law enforcement, suppliers, and other approved stakeholders.

5.

Support post-incident reviews, document lessons learned, and track corrective and preventive actions to completion.

6.

Participate in approved maintenance windows, cyber exercises, incident response, and the security on-call rota when required.

Vulnerability, Configuration and Testing Assurance

1.

Conduct or coordinate risk-based vulnerability scanning, secure-configuration reviews, remediation verification, and control validation.

2.

Track vulnerabilities and security findings with assigned owners, severity ratings, deadlines, supporting evidence, and escalation status.

3.

Support penetration testing and security assessments of internet-facing, payment, identity, cryptographic, database, network, and privileged systems.

4.

Review security requirements for system architecture, new products, participant integrations, and high-risk changes before production implementation.

5.

Verify that security patches, configuration changes, and remediation actions are implemented in line with approved risk-based timelines.

Cryptography and PKI Control

1.

Maintain the authoritative inventory of certificates, encryption keys, digital signatures, hardware security modules, and other cryptographic assets.

2.

Monitor certificate and key ownership, custody, backup, rotation, renewal, revocation, expiry, and compromise procedures.

3.

Support key ceremonies and ensure dual control, split knowledge, access authorization, logging, and required evidence are maintained.

4.

Verify that participant communications, APIs, administrative access, and sensitive data use approved encryption and certificate-validation controls.

5.

Immediately escalate suspected cryptographic compromise, unauthorized key access, or certificate-expiry risks and support containment and recovery.

Third-Party and Participant Security

1.

Support security due diligence and assessment of participants, vendors, cloud providers, managed service providers, and other third parties.

2.

Review security provisions relating to connectivity, data access, incident notification, continuity, subcontracting, and exit arrangements.

3.

Support participant onboarding, security attestations, control-evidence reviews, and periodic reassessments.

4.

Track third-party and participant security findings, remediation actions, and concentration or dependency risks.

5.

Provide practical security guidance to participants and internal departments while maintaining SPS security requirements.

Continuity, Awareness and Reporting

1.

Provide security requirements and assurance support for business continuity, disaster recovery, crisis management, and operational resilience arrangements.

2.

Participate in cyber, operational, disaster-recovery, and crisis simulation exercises and document improvement actions.

3.

Support role-based security awareness and training for employees, privileged users, developers, management, and other relevant stakeholders.

4.

Prepare accurate periodic security reports covering risks, incidents, vulnerabilities, access reviews, cryptographic controls, audit findings, and remediation progress.

5.

Maintain security procedures, records, evidence, and Standard Operating Procedures and contribute to continuous improvement of SPS security capabilities.

Other Duties

1.

Perform other tasks assigned by the Head of IT or designated supervisor to support SPS information-security and institutional objectives.

2.

Engage in continuous professional development and meet the annual professional-development requirements applicable to the position.

About Mogadishu

Mogadishu, known locally as Muqdisho, is the capital of Somalia and the country's largest city. It serves as the political, economic, and cultural heart of the nation. The city hosts the headquarters of numerous UN agencies, international NGOs, and government institutions, offering diverse career opportunities for development and humanitarian professionals.

Ereyada Soomaaliga (Somali Keywords): Tiknoolajiyada • Shaqo Muqdisho • Shaqo Cusub • Shaqo Buuxda

Qualifications & Requirements

1.

Qualifications

and Skills:

Bachelor’s degree in Cybersecurity, Information Systems, Computer Science, Network Engineering, Information Technology, or a related field.

Minimum of 2 years of relevant experience in cybersecurity or information security, preferably within financial services, payments, telecommunications, government, or other critical infrastructure.

Practical exposure to security monitoring or SIEM, incident response, identity and access management, vulnerability management, network or Linux security, and public-key infrastructure.

Working knowledge of ISO 27001, PCI DSS where applicable, business continuity, secure APIs, cryptography, and regulatory or audit assurance.

Relevant certifications or training such as CompTIA Security+, Cisco CyberOps, CEH, ISO 27001 Foundation or Implementer, GIAC, or comparable credentials are preferred.

Strong analytical, investigation, troubleshooting, documentation, and evidence-management skills with close attention to detail.

Ability to manage multiple priorities, maintain confidentiality, and work effectively under pressure during security incidents.

Proficiency in Microsoft Office and security reporting, documentation, and presentation tools.

Ability to communicate professionally in written and spoken Somali and English.

2.

Key Competencies

Integrity, independence, sound judgment, and commitment to confidentiality

Analytical thinking, professional skepticism, and evidence-based decision making

Security awareness, attention to detail, and proactive risk identification

Calm and disciplined incident response under uncertainty and operational pressure

Clear communication of technical risks to technical and non-technical stakeholders

Effective collaboration with management, participants, auditors, regulators, and technical teams

Adaptability, continuous learning, and proactive problem-solving

Willingness to escalate material or unresolved security risks appropriately

How to Apply

Interested candidates should submit their CV and a cover letter detailing their relevant experience and qualifications. The selection process includes an interview, competency assessment, and background checks. Female candidates are strongly encouraged to apply.

Applications should be submitted through the following link:

https: //erp.sps.so/jobs

For any clarifications or questions regarding this vacancy, please contact

HR@sps.so" rel="noopener noreferrer" target="_blank">HR@sps.so

Applications submitted by email may not be considered; all applications should be submitted through the official SPS recruitment portal.

📅

Deadline for submission: 17th August 2026, 11:59 p.m. Mogadishu time.

Only shortlisted candidates will be contacted.

Apply on employer site

Apply at: https://erp.sps.so/jobs

Job Details

Posted: August 3, 2026
Organization: Somali Payment Switch
Location: Mogadishu, Somalia
Sector: Ict/technology/computers