About Old Mutual
Old Mutual is a premium African financial services organisation offering financial solutions to retail and corporate customers across key market segments in 14 countries, including Life and Savings, Property and Casualty, Asset Management, and Banking and Lending. The organisation is rooted in its purpose of Championing Mutually Positive Futures Every Day.
Job Summary
- Type: full-time
- Location: Harare
- Category: Information Technology
- Closing Date: 2026-08-13
Key Responsibilities
- Own the lifecycle management of enterprise firewall technologies and associated security controls.
- Design, implement, maintain and optimise network security architectures.
- Govern firewall rule administration, approvals, documentation, reviews and risk management.
- Lead network segmentation, perimeter security and VPN controls.
- Ensure PCI DSS-compliant segmentation between Cardholder Data Environments and other network environments.
- Perform regular firewall rule reviews and certifications.
- Identify and mitigate security risks arising from network architecture and firewall configurations.
- Develop and maintain firewall standards, procedures, technical baselines and operational documentation.
- Own and lead the enterprise Vulnerability Management Programme.
- Define, implement and continuously improve vulnerability management policies, processes, standards and reporting.
- Coordinate enterprise vulnerability scans across servers, endpoints, databases, applications, network infrastructure and cloud platforms.
- Assess and prioritise vulnerabilities based on risk, exploitability, business impact and threat intelligence.
- Drive remediation activities with infrastructure, application, cloud and business technology teams.
- Track exceptions, compensating controls and risk acceptance processes.
- Report remediation performance against agreed service levels and risk appetite thresholds.
- Lead management of penetration testing findings and validation of remediation efforts.
- The Senior Information Security Engineer will serve as the technical subject matter expert for firewall and vulnerability management requirements under PCI DSS.
- The role will support compliance with: Reserve Bank of Zimbabwe directives, Cyber and Data Protection Act, PCI DSS, ISO 27001, SWIFT Customer Security Programme requirements, where applicable, Internal information security standards.
- Maintain compliance evidence and security documentation required for audits and regulatory inspections.
- Act as the designated control owner for firewall security and vulnerability management.
- Develop and review policies, standards, procedures, technical guidelines and operational runbooks.
- Establish KRIs and KPIs for managed security domains.
- Produce monthly, quarterly and ad hoc reporting for executive management, cybersecurity committees, technology governance forums, risk committees and auditors.
- Provide leadership and direction to engineers, administrators and service providers.
- Drive continuous improvement to enhance security maturity and resilience.
- Ensure accountability for operational effectiveness, audit findings, remediation tracking and control performance.
- Engage with Technology, Risk, Compliance, Audit, Business Units and external service providers.
- Translate technical risks into business language for senior management and provide expert advice on network security architecture and vulnerability risk management.
Requirements
- A Bachelor’s Degree in one of the following is desirable:
- Cyber Security
- Computer Science
- Information Systems
- Computer Engineering
- Telecommunications
- A related discipline
- At least one of the following is highly desirable:
- CISSP
- CISM
- PCNSE
- Fortinet FCSS / NSE
- Check Point CCSE
- Cisco CCNP Security
- CompTIA Security+
- CEH
- GIAC Security Certifications
- PCI Professional (PCIP) or PCI-related certification
- Minimum 5-7 years’ experience in cybersecurity, network security or security engineering.
- Minimum 3 years’ experience in firewall administration and management within a complex enterprise environment.
- Demonstrated experience managing vulnerability management programmes.
- Experience developing policies, standards, procedures and governance artefacts.
- Ability to independently manage and lead a security function or area of responsibility.
- Experience within: Banking, Insurance, Fintech, Payments, Asset Management, Microfinance, Other regulated financial services environments
- Technical Competencies: Firewall Technologies, Vulnerability Management Technologies, Networking Technologies, Security Technologies, Cloud Security Technologies, Cyber Threat Intelligence, Governance, Risk and Compliance (GRC), Security Controls
How to Apply
REF Code: JR-82346
About the Company
Old Mutual Zimbabwe Limited is a leading integrated financial services group operating prominently within the Zimbabwean economy. The company offers a comprehensive range of solutions, including life assurance, wealth management, short-term insurance, and banking services through its well-known subsidiary, CABS. Dedicated to empowering individuals, businesses, and corporates, Old Mutual Zimbabwe plays a critical role in helping clients achieve their financial aspirations across the country. As a key part of the Old Mutual Limited pan-African group, it combines local insight with global best practices. The organisation is committed to fostering financial well-being and contributing to sustainable economic development throughout Zimbabwe.
Empowering Zimbabweans with integrated financial solutions.
Frequently Asked Questions
What are the essential qualifications and certifications for a Senior Information Security Engineer in Zimbabwe?
Typically, a Bachelor's degree in Computer Science, Information Technology, or a related field is required, often with significant practical experience. Industry certifications like CISSP, CISM, CEH, or CompTIA Security+ are highly valued and often expected for a senior role in Zimbabwe's financial sector. These demonstrate a strong foundational and advanced understanding of cybersecurity principles.
What does a typical day look like for a Senior Information Security Engineer at a financial institution in Zimbabwe?
Your day would involve monitoring security systems, responding to incidents, conducting vulnerability assessments, and implementing security controls. You'd also collaborate with various IT teams to ensure compliance with local regulations and organizational security policies. This often includes documenting security procedures and providing expert guidance on new projects.
What is the typical work culture like for a senior IT role in Zimbabwe, especially regarding work-life balance and team dynamics?
Work culture for senior IT roles in Zimbabwe often emphasizes professionalism, teamwork, and problem-solving, with an expectation for high performance and dedication. While a good work-life balance is generally sought, there can be periods requiring extended hours, especially during critical projects or incident responses. Collaboration across departments is crucial, and mentorship of junior staff is often an unwritten expectation.
What are the realistic career progression paths for a Senior Information Security Engineer within the Zimbabwean IT sector?
From a Senior Information Security Engineer, common progression paths include moving into a Lead Security Engineer, Security Architect, or even a Head of Information Security role. Specializing further into areas like GRC (Governance, Risk, and Compliance) or becoming a Chief Information Security Officer (CISO) are also viable long-term aspirations. Continuous professional development and acquiring advanced certifications are key to these advancements.
What typical benefits, such as medical aid, pension, and leave, can one expect for a senior-level IT position in Zimbabwe?
For a senior IT role in Zimbabwe, comprehensive benefits typically include a robust medical aid package, a structured pension or provident fund contribution, and generous annual leave entitlements. Many employers also offer performance-based bonuses, professional development opportunities, and sometimes additional allowances like transport or communication. These benefits are competitive to attract and retain experienced talent in the local market.
What are the key things Zimbabwean employers, particularly in financial services, look for when hiring a Senior Information Security Engineer, and what's the best way to apply?
Employers seek candidates with a strong technical background, proven experience in securing complex systems, and excellent problem-solving skills, often emphasizing relevant financial sector experience for this role. Demonstrating leadership potential, good communication, and adherence to regulatory compliance standards are also critical. Applying through official company career portals or reputable recruitment agencies is generally the most effective method, ensuring your CV highlights local market relevance and achievements.