IT Security Analyst
Summary
Performs security assessments, enforces baseline configurations, and manages vulnerability remediation for networks, servers, and cloud systems in a banking environment.
Technology Department,Rwanda.IT Security Analyst
Location: Rwanda
KEY RESPONSIBILITIES:
Conduct technical security assessments of infrastructure, systems, and platforms against defined minimum security baseline standards and report findings.
Support validation and enforcement of minimum-security configurations across infrastructure components before and after system deployment.
Identify, track, and follow up on remediation of vulnerabilities in collaboration with IT and SOC/CiSOC teams, ensuring adherence to defined SLAs.
Administer and support internal cybersecurity tools and solutions including handling operational tickets and routine changes addressed to information security
Assist in monitoring the security posture of networks, servers, endpoints, cloud, and IoT devices, and escalate identified risks.
Support cybersecurity reviews for ICT projects and changes, ensuring implementation of required security controls under guidance from the Cybersecurity Lead.
Work closely with IT teams to ensure systems are patched, hardened, and compliant with defined security standards.
Provide support for internal and external audits by preparing evidence, tracking findings, and ensuring timely remediation of assigned actions.
Collaborate with SOC/CiSOC in identifying, reporting, and supporting the response to security incidents affecting infrastructure.
Maintain accurate documentation of security assessments, vulnerabilities, and remediation status, and provide regular updates to the Cybersecurity Lead and Manager.
DAILY RESPONSIBILITIES:
Certifying user accounts and access.
Perform security checks and assessments on systems to validate compliance with baseline standards.
Manage and resolve operational tickets related to cybersecurity systems (e.g., firewall requests, endpoint issues, access controls).
Track and follow up on vulnerability remediation with IT teams.
Support enforcement of patching, hardening, and endpoint protection across the infrastructure.
Assist in monitoring alerts and escalate potential security threats or incidents.
MINIMUM POSITION QUALIFICATION REQUIREMENTS
Academic & Professional
Particulars | Detail | Specific Field or Qualification | Need Type[1] |
Education | Bachelor’s Degree | B.Sc. Information Technology / Computer Science / Telecommunications / Engineering or related field | RQ |
Education | Professional Qualifications | Offsec Certification for Penetration testing like PEN-200, or PEN-300, CCNA Security, CCPN Security, CEH: Certified Ethical Hacker; CISA: Certified Information Systems Auditor; CISM: Certified Information Security Manager; CISSP: Certified Information Systems Security Professional, or any other related certification | At least one RQ |
Education | Masters | MBA/MSc | AA |
Experience
Total Minimum No of Years’ Experience Required
|
3 |
Detail | Minimum No of Years | Need Type[2] |
| Security / System / Network / Database / Platform Administration | 3 | ES |
| Information security policies as well as applicable government regulations | 2 | ES |
| Security Baseline standards (Unix, Windows, Databases) | 2 | ES |
| Encryption and Certificate Management | 2 | ES |
| Identity and Access Management | 3 | ES |
Software Development, Security Assessment and Testing | 3 | ES |
| Computer network penetration testing and techniques | 3 | ES |
| IT or Information Security | 3 | ES |