Summary: Cybersecurity Governance and Assurance Officer, Nairobi, Kenya

Job Details

  • Company: International Livestock Research Institute (ILRI)
  • Location: Kenya

Job Description

Cybersecurity Governance and Assurance Officer, Nairobi, Kenya

Organization

International Livestock Research Institute (ILRI)

Country

Kenya

City

Nairobi

Office

ILRI Nairobi

The International Livestock Research Institute (ILRI) seeks to

recruit a Cybersecurity Governance and Assurance Officer to

coordinate and support cybersecurity governance, risk management

assurance and cyber resilience activities across ILRI and the CGIAR

System.

ILRI is an international organisation working for better lives

and better planet through livestock. ILRI's mission emphasises the

interconnections between people, animals, and the environment

aiming to improve the lives of more than 300 million people in low

and middle-income countries through livestock science that supports

equitable and resilient livestock systems, ultimately contributing

to food systems transformation with climate and environmental

benefits. This mission is delivered through two core strategic

objectives: co-designing and deploying sustainable, science-based

livestock solutions, and leveraging science to inform and influence

policy and investment decisions.

ILRI is a member of CGIAR, a global research alliance that works

to transform food, land and water systems in a climate crisis and

is the only CGIAR center dedicated to addressing multiple

development challenges through sustainable livestock solutions.

About the position

The position combines a 60% allocation to the CGIAR System-wide

Cybersecurity Assurance Lead function, hosted by ILRI, and a 40%

allocation to ILRI Cybersecurity Governance and Assurance

responsibilities.

At the CGIAR level, the position will support the implementation

and ongoing coordination of the Integrated Cybersecurity Governance

Framework (ICGF), maintain cybersecurity standards, coordinate

cybersecurity reporting and dashboards, facilitate collaboration

among CGIAR cybersecurity focal points, and provide cybersecurity

assurance reporting to CGIAR leadership.

At the ILRI level, the position will support cybersecurity

governance, risk management, compliance, security assurance

cybersecurity strategy implementation, security awareness and cyber

resilience initiatives to strengthen ILRI's cybersecurity posture

and support digital transformation objectives.

The role serves as ILRI's focal point for cybersecurity

governance and assurance and provides system-wide cybersecurity

coordination, reporting and assurance support across the CGIAR

Key Responsibilities

  • CGIAR CYBERSECURITY ASSURANCE LEAD RESPONSIBILITIES

(60%)

1.

Standards &

Catalogue

  • Collate, document, co-develop, and maintain a minimum CGIAR

Cybersecurity Standards Catalogue (feasible monitorable controls

only).

  • Define and publish incident severity levels and SLA

expectations as system-wide standards.

  • Coordinate with Centre focal points to ensure standards are

understood, adopted, and evidenced.

2.

Scorecards &

Dashboards

  • Design, build, and maintain a central CGIAR Cybersecurity

Scorecard and dashboards (Power BI or equivalent) using centrally

accessible telemetry and metrics data.

  • Aggregate data from Centre security platforms (e.g.

SentinelOne, Volexity MDR, Microsoft Defender, KnowB4) into unified

reporting views.

3.

Reporting &

Governance

  • Produce and present quarterly cyber-risk reports to GLT, the

Audit and Risk Committee (AFRC/IPB), and ICT leaders —

ensuring cybersecurity visibility extends beyond the IT

function.

  • Prepare ad-hoc briefings for senior leadership and Boards as

required.

  • Maintain a one-page Decision Rights Charter (RACI &

escalation) for system-wide cybersecurity.

  • Coordination and Network Leadership
  • Convene and lead the distributed cybersecurity focal-point

network (one focal point per Centre, each ~20% FTE).

  • Establish a regular meeting cadence (monthly or as agreed) for

focal points to share threat intelligence, coordinate remediation

and align on standards.

  • Liaise with the Managed Security Service Provider (MSSP) and

the 1CGSec working group.

  • Coordinate with Internal Audit, the Digital Transformation

Accelerator (DTA), and other relevant governance bodies to avoid

duplication.

5.

Monitoring Integration (Year 1

Setup)

  • Oversee the one-time integration project to connect Centre

security-platform outputs into the central reporting

infrastructure.

  • Specify minimum telemetry and metrics-reporting requirements

for all Centres.

  • Roadmap & Continuous Improvement
  • Track and document lessons learned, gaps, and readiness

indicators for selective adoption of Model 2 elements (shared

playbooks, harmonised incident classification, SLAs).

  • Prepare a recommendation paper for the 12-18-month review

gateway on whether and how to advance to Model 2.

  • Procurement and Vendor Relations

Coordination

  • Support cybersecurity procurement activities, cost distribution

and payment follow-up.

  • Maintain an inventory of cybersecurity solutions, vendors

contracts and Centre adoption of these solutions.

  • ILRI CYBERSECURITY GOVERNANCE AND ASSURANCE

RESPONSIBILITIES (40%)

  • Cybersecurity Strategy and Governance
  • Support the development and implementation of ILRI's

cybersecurity strategy, roadmap and annual work plans.

  • Coordinate implementation of the institutional Cybersecurity

Roadmap, monitor delivery against agreed milestones, track benefits

realised and report progress to management.

  • Coordinate the development, review and maintenance of

cybersecurity policies, standards, procedures and guidelines.

  • Provide trusted cybersecurity advice to Executive Management

project sponsors and business leaders to support informed

risk-based decision-making.

  • Support the implementation of cybersecurity governance

practices across the institution.

  • Cybersecurity Risk Management
  • Coordinate the maintenance of the institutional cybersecurity

risk register.

  • Conduct cybersecurity risk assessments and coordinate risk

mitigation activities.

  • Monitor emerging cyber threats and vulnerabilities affecting

ILRI.

  • Prepare regular cybersecurity risk reports for management and

governance committees.

  • Security Assurance and Compliance
  • Coordinate vulnerability assessments, penetration testing and

cybersecurity control reviews.

  • Track remediation of identified vulnerabilities and audit

findings.

  • Support compliance with regulatory, donor, CGIAR and

institutional cybersecurity requirements.

  • Coordinate cybersecurity-related internal and external

audits.

  • Coordinate periodic cybersecurity maturity assessments and

benchmarking exercises.

  • Support compliance with data protection, privacy and

information security requirements across the institution.

  • Coordinate cybersecurity risk assessments of third-party

service providers, cloud platforms, technology vendors and

strategic partners, and monitor remediation of identified

risks.

  • Cybersecurity Operations Coordination
  • Coordinate governance activities relating to cybersecurity

operations and security monitoring.

  • Coordinate cybersecurity incident reporting, investigations and

post-incident reviews.

  • Review security monitoring outputs from internal teams and

managed security service providers.

  • Recommend improvements to security controls and monitoring

capabilities.

  • Coordinate implementation of cybersecurity improvement

initiatives arising from incidents, audits, assessments and risk

reviews.

  • Security Architecture and Digital

Transformation

  • Support security reviews for new systems, projects and

technology initiatives.

  • Provide technical input on cybersecurity considerations for

cloud, data, AI and digital transformation initiatives.

  • Support the development and implementation of governance

assurance and risk management practices for AI-enabled solutions

and emerging technologies, ensuring their secure, responsible and

compliant adoption across the institution.

  • Support the adoption of secure-by-design principles across

institutional projects.

  • Cybersecurity Awareness and Culture
  • Develop and coordinate cybersecurity awareness and training

programmes.

  • Coordinate phishing simulations and security awareness

campaigns.

  • Promote cybersecurity awareness and responsible technology use

across the institution.

  • Business Continuity and Cyber Resilience
  • Support cyber resilience, business continuity and disaster

recovery planning and initiatives.

  • Coordinate cyber incident simulation and tabletop

exercises.

  • Participate in assessments of organisational preparedness for

cyber incidents and recommend improvements.

  • Other Duties
  • Perform any other related duties as may be assigned by the

supervisor.

Requirements

  • Bachelor's degree in Information Security, Cybersecurity

Computer Science, Information Systems, Information Technology, Risk

Management, or a related field.

  • Professional certification in one or more of the following

areas is required: CISSP, CISM, CRISC, CISA, ISO 27001 Lead

Implementer, ISO 27001 Lead Auditor, CCSP, or equivalent

cybersecurity certification.

  • Microsoft Security and GIAC Certifications will be an added

advantage.

  • At least seven (7) years of progressively responsible

experience in cybersecurity, information security, IT risk

management, security governance, compliance or IT audit, including

at least three (3) years in cybersecurity governance, risk

management and/or assurance.

  • Demonstrated experience implementing or assessing cybersecurity

frameworks including ISO 27001, NIST Cybersecurity Framework and

CIS Controls.

  • Experience coordinating cybersecurity governance, assurance

compliance or risk management activities within multi-stakeholder

environments.

  • Experience developing cybersecurity dashboards, scorecards or

management reports.

  • Experience preparing reports and presenting technical

information to management or governance committees.

  • Experience working with Managed Security Service Providers

(MSSPs) and third-party security vendors will be an added

  • Experience supporting Microsoft security technologies, cloud

security or endpoint security solutions will be an added

  • Experience working within international, research, development

NGO, CGIAR, or similarly federated organisations will be an added

Skills and Competencies

  • Knowledge of cybersecurity governance, risk management and

assurance practices.

  • Knowledge of cybersecurity frameworks and standards, including

ISO 27001, NIST Cybersecurity Framework and CIS Controls.

  • Knowledge of cybersecurity compliance, audit coordination and

risk assessment.

  • Knowledge of cloud, network, endpoint and identity security

principles.

  • Ability to coordinate cybersecurity governance and assurance

activities across multiple stakeholders.

  • Ability to prepare cybersecurity dashboards, reports and

presentations for management.

  • Strong communication, facilitation and stakeholder management

skills.

  • Strong analytical and problem-solving skills.
  • Ability to influence and collaborate without direct

authority.

  • Excellent written, presentation and interpersonal communication
  • Ability to operate effectively within multicultural

geographically dispersed and matrix-managed environments.

This position is at job level

HG15

is open to

Kenyan Nationals only.The position is a 3-year contract, renewable

subject to satisfactory performance and availability of funding.

ILRI offers a competitive salary and benefits package which

includes pension, medical and other insurances.

How to apply

Applicants should send a cover

letter and CV expressing their interest in the position, what they

can bring to the job and the names and addresses (including

telephone and email) of three referees who are knowledgeable about

the candidate's professional qualifications and work experience to

the Head of People and Culture through our recruitment portal by

clicking on "" on or before

19 August 2026.

The

position title and reference number

REF

Cyber-CS/2277-08/2026

should be clearly marked on the

subject line of the cover letter.

We thank all applicants for their interest in working for ILRI.

Due to the volume