The position of Information Security Officer at Somali Payment Switch in Mogadishu is now open for applications. Candidates should bring 2 - 3 years of hands-on experience, preferably in the Ict/technology/computers sector. The application deadline is Aug, 17 — early applications are encouraged.
Position Title: Information Security Officer
Department: Information Technology
Position Level: Level 1 Officer
Reports To: Head of IT or Designated Supervisor
Employment Type: Full-time
Location: Mogadishu, Somalia
1.
Background
The Somali Payment Switch (SPS) is the national retail payment infrastructure responsible for real-time clearing and settlement of payments across Somali financial institutions. As a central component of Somalia’s financial ecosystem, SPS enables secure interoperability among banks, mobile money operators, government institutions, and other approved payment service providers.
As SPS operates critical national financial infrastructure, its systems and services are subject to strict requirements for availability, security, confidentiality, integrity, auditability, change control, and business continuity. SPS is therefore strengthening its information-security capacity through the appointment of a dedicated Information Security Officer.
2.
Position Summary
The Information Security Officer supports the implementation, operation, monitoring, and continuous improvement of the SPS information-security programme. The role contributes to protecting payment infrastructure, participant connections, cryptographic assets, sensitive information, and service availability. The Officer assists with security risk assessments, access control, security monitoring, incident response, vulnerability management, regulatory compliance, audit support, documentation, and management reporting.
3.
Key Responsibilities
Governance, Risk and Compliance
1.
Support the development and maintenance of the SPS information-security strategy, policies, standards, control framework, and annual security plan.
2.
Maintain accurate information-security risk, treatment, exception, accepted-risk, and compliance registers.
3.
Conduct or support security risk assessments for systems, participants, vendors, changes, products, and material incidents.
4.
Monitor compliance with applicable Central Bank of Somalia requirements, national law, contractual obligations, ISO 27001, PCI DSS where in scope, and adopted payment-security requirements.
5.
Support internal and external audits, regulatory assessments, evidence requests, remediation tracking, and evidence-based closure of findings.
6.
Escalate material security risks, control failures, policy exceptions, and overdue remediation to the designated executive in a timely manner.
Identity and Access Management
1.
Support implementation of identity lifecycle, least-privilege, multi-factor authentication, privileged-access, segregation-of-duties, service-account, and access-review controls.
2.
Ensure joiner, mover, leaver, emergency, vendor, dormant-account, and temporary-access processes are properly authorized and documented.
3.
Conduct periodic reviews of privileged and high-risk access and track identified conflicts or corrective actions to closure.
4.
Monitor shared and generic accounts and ensure they are eliminated or tightly controlled, attributable, logged, and reviewed.
5.
Maintain complete access-control records and evidence in accordance with SPS policies and audit requirements.
Security Monitoring and Incident Response
1.
Monitor security events and alerts from approved security tools, logs, networks, endpoints, applications, cloud services, and payment systems.
2.
Perform initial triage, classification, escalation, containment support, and evidence preservation for suspected cyber-security incidents.
3.
Maintain and exercise incident-response procedures and playbooks for credential compromise, malware, denial of service, data breach, insider threat, key compromise, fraudulent activity, and participant-originated attacks.
4.
Coordinate incident-response activities and authorized communications with management, regulators, participants, law enforcement, suppliers, and other approved stakeholders.
5.
Support post-incident reviews, document lessons learned, and track corrective and preventive actions to completion.
6.
Participate in approved maintenance windows, cyber exercises, incident response, and the security on-call rota when required.
Vulnerability, Configuration and Testing Assurance
1.
Conduct or coordinate risk-based vulnerability scanning, secure-configuration reviews, remediation verification, and control validation.
2.
Track vulnerabilities and security findings with assigned owners, severity ratings, deadlines, supporting evidence, and escalation status.
3.
Support penetration testing and security assessments of internet-facing, payment, identity, cryptographic, database, network, and privileged systems.
4.
Review security requirements for system architecture, new products, participant integrations, and high-risk changes before production implementation.
5.
Verify that security patches, configuration changes, and remediation actions are implemented in line with approved risk-based timelines.
Cryptography and PKI Control
1.
Maintain the authoritative inventory of certificates, encryption keys, digital signatures, hardware security modules, and other cryptographic assets.
2.
Monitor certificate and key ownership, custody, backup, rotation, renewal, revocation, expiry, and compromise procedures.
3.
Support key ceremonies and ensure dual control, split knowledge, access authorization, logging, and required evidence are maintained.
4.
Verify that participant communications, APIs, administrative access, and sensitive data use approved encryption and certificate-validation controls.
5.
Immediately escalate suspected cryptographic compromise, unauthorized key access, or certificate-expiry risks and support containment and recovery.
Third-Party and Participant Security
1.
Support security due diligence and assessment of participants, vendors, cloud providers, managed service providers, and other third parties.
2.
Review security provisions relating to connectivity, data access, incident notification, continuity, subcontracting, and exit arrangements.
3.
Support participant onboarding, security attestations, control-evidence reviews, and periodic reassessments.
4.
Track third-party and participant security findings, remediation actions, and concentration or dependency risks.
5.
Provide practical security guidance to participants and internal departments while maintaining SPS security requirements.
Continuity, Awareness and Reporting
1.
Provide security requirements and assurance support for business continuity, disaster recovery, crisis management, and operational resilience arrangements.
2.
Participate in cyber, operational, disaster-recovery, and crisis simulation exercises and document improvement actions.
3.
Support role-based security awareness and training for employees, privileged users, developers, management, and other relevant stakeholders.
4.
Prepare accurate periodic security reports covering risks, incidents, vulnerabilities, access reviews, cryptographic controls, audit findings, and remediation progress.
5.
Maintain security procedures, records, evidence, and Standard Operating Procedures and contribute to continuous improvement of SPS security capabilities.
Other Duties
1.
Perform other tasks assigned by the Head of IT or designated supervisor to support SPS information-security and institutional objectives.
2.
Engage in continuous professional development and meet the annual professional-development requirements applicable to the position.
About Mogadishu
Mogadishu, known locally as Muqdisho, is the capital of Somalia and the country's largest city. It serves as the political, economic, and cultural heart of the nation. The city hosts the headquarters of numerous UN agencies, international NGOs, and government institutions, offering diverse career opportunities for development and humanitarian professionals.
Ereyada Soomaaliga (Somali Keywords): Tiknoolajiyada • Shaqo Muqdisho • Shaqo Cusub • Shaqo Buuxda