Information Security and Systems Lead, Associate Director
- IDinsight
- Kenya
- $110,000 – $150,000
Location: Dakar, Senegal; Rabat, Morocco; Nairobi, Kenya; Lusaka, Zambia; Delhi, India, or Manila, Philippines
About the Information Security and Systems Lead Role
The Information Security and Systems team is the engine driving our uniquely dynamic, high-achieving, multicultural, multi-continental team at the cutting edge of how evidence is used to improve global development programs. This team's mandate is to build and maintain systems that enable IDinsight teams across 7+ countries to achieve social impact. We are looking for an Information Security and Enterprise Systems Leader to own that mandate end-to-end. You will lead a small, capable team of security and systems specialists, fractional resources, and external implementation partners. You will report to and advise the executive team. This role could be a fit if you have high-quality experience running both security and enterprise systems initiatives at a global organisation and you’re comfortable being the most senior technical voice in the room without being the only person who understands the decision.
Enterprise Systems Leadership
- Strategy and roadmap — Define and own the multi-year enterprise systems strategy for a remote-first, globally distributed organisation, and the priorities that follow from it.
- Systems implementation — Lead identification, selection, and implementation of new enterprise systems such as CRMs, ERPs, etc. Own architecture and integration decisions and the master data model that holds them together.
- Implementation partner management — Select, contract, and manage external implementation and support partners, including scope, commercial terms, and delivery accountability.
- Budget ownership — Lead annual budgeting and financial planning for organisational systems, and make the trade-offs that a non-profit budget requires.
- Change management — Champion adoption across regions and functions, so that systems investments produce behaviour change.
- Operational effectiveness — Identify bottlenecks and inefficiencies across the estate, streamline usage to reduce shadow IT, and ensure systems and support functions operate reliably across time zones.
- Leadership partnership — Work with functional and regional leadership on requirements, prioritisation, and the systems implications of organisational strategy.
Information Security Program Management
- Security strategy — Define and own the information security strategy in alignment with organisational strategy and recognised frameworks, and monitor delivery against the roadmap.
- Control framework — Lead implementation of security and privacy controls as regulation, client obligations, and risk require.
- Governance — Coordinate the Information Security Steering Committee and contribute to Enterprise Risk Management.
- Incident response — Own incident response planning, lead coordination during incidents, and drive the changes that follow.
- External assurance — Commission and support penetration tests, vulnerability assessments, audits, and own remediation.
- Risk management — Lead periodic risk assessment exercises and the ongoing identification, mitigation, and monitoring of information security risk.
- Due diligence — Serve as senior point of contact for funder, client, and government partner security and data protection due diligence.
- Investigations — Support Legal, Compliance, and Operations where digital evidence is relevant to policy violations.
Data Protection and AI Governance
- Multi-jurisdiction compliance — Own compliance with GDPR and the national data protection regimes in the countries where we operate, including data mapping, retention, subject rights, and impact assessments.
- AI governance — Define how IDinsight governs AI use on project and organisational data: tool assessment, acceptable use, and the controls that make responsible use the default.
- Policy — Own the information security and data protection policy set, and keep it usable enough that colleagues consult it rather than route around it.
Team and Function Leadership
- People management — Manage, develop, and grow full-time technology staff and fractional resources, including hiring and performance management.
- Capability building — Build depth and redundancy in the team so that critical knowledge is not concentrated in one person.
- Organisational contribution — Contribute to cross-functional leadership initiatives and to IDinsight's institutional practice on data ethics and responsible technology use.
Qualifications
We're looking for an entrepreneurial, “get stuff done” teammate with substantial leadership experience. Desired qualifications include:
- 8+ years of professional experience in technology roles, including at least 5 years of Information Security or Enterprise IT leadership experience (involving people management).
- Demonstrated ownership of an information security programme at organisational scale — strategy, control framework, governance forum, and incident response, not solely operations;
- Experience leading the selection and implementation of major enterprise systems such as ERP, CRM, including partner management and budget ownership;
- Hands-on depth across enterprise security controls — endpoint protection, network security, vulnerability management — sufficient to make architecture decisions and evaluate your team's work credibly;
- Strong command of identity and access management in enterprise environments, including SSO, MFA, LDAP, and federation protocols such as SAML;
- Experience with control configuration and security architecture in common cloud environments;
- Working knowledge of GDPR and of national data protection regimes in Africa or Asia, and of security frameworks such as NIST CSF, NIST SP 800-171, or ISO/IEC 27001;
- Experience administering enterprise systems for a globally distributed team, including workspace collaboration and human capital management platforms;
- Experience with enterprise systems architecture and data modelling;
- Information security leadership certification preferred — CISM, CISSP, CISA, or equivalent;
- Excellent collaboration, interpersonal, communication, and facilitation skills, with the ability to present to and influence audiences of varying technical fluency, including senior leadership;
- Strong internal and external stakeholder management skills, including with funders, government partners, and vendors;
- Experience managing change in a fast-moving, remote-first environment.
- Detail- and execution-oriented, able to take a task from high-level strategic idea to rapid execution with a large amount of autonomy and conscientiousness;
- Demonstrated track record as a self-starter and leader, including comfort with ambiguity and dynamic environments and work streams;
- Ability to handle sensitive information, data, and issues with mature and discreet professionalism;
- Ability to work with international, cross-cultural, and diverse teams across time zones.
Nuts & bolts
Start date
The start date for this position is as soon as possible, with preference given to candidates who can start immediately. We expect a minimum two-year commitment, with regular professional development conversations and the potential for a long-term career at IDinsight.
Work Authorization
IDinsight is able to sponsor employment visas for all nationalities in the locations listed above; however, we will prioritize candidates who do not require IDinsight to sponsor work authorization in the aforementioned countries. All candidates who are not currently located in our country offices listed above will be expected to relocate to their office locations at the onset of their employment.
Compensation
Compensation is commensurate with relevant experience and background and is competitive within the social sector. Please note that, as a non-profit, we are unable to provide compensation similar to leading technology firms.
How to apply
This application includes several questions and requires a CV (one to two pages) covering your professional and personal experience as well as academic qualifications. Please omit headshots, parental details, birth dates, marital status, and similar personal information — these aren't relevant to our review. For more on IDinsight's hiring process, our commitment to reducing power asymmetries, and FAQs, visit www.IDinsight.org.
IDinsight’s commitment to reducing power asymmetries
IDinsight is committed to reducing power asymmetries in the social sector. Our commitment to diversity, equity, and inclusion reflects our understanding of the need for the sector to abandon unhealthy practices of the past. We wish to be part of a new generation of international NGOs who are honest about this history and transparent about our role in the present. Our commitment is also aligned with the impact of our work.
We seek a workforce that is inclusive of a variety of perspectives that will help us refine and improve our methods and relationships, and strengthen the services we provide our clients and their communities or constituencies. The following commitments represent our vision for the IDinsight team:
- IDinsight will have greater representation from the populations with whom we work and clients we serve.
- IDinsight will have greater representation from the countries in which we work.
- Across all countries in which we recruit, we will seek greater representation from historically excluded communities.
- IDinsight will foster an inclusive work culture that empowers a diverse team to do their best work.
IDinsight is committed to non-discrimination in our recruitment, employment practices, and organizational culture, regardless of people's age, disability, gender, gender identity, national origin, race, religion or belief, or sexual orientation, or any other status protected by applicable law.
Skills
- Enterprise Systems Architecture
- Security Strategy
- CRM Implementation
- ERP Implementation
- Vendor Management
- Team Leadership
- IT Governance







