Information Security Officer positions focus on delivering results in their domain. This page aggregates open Information Security Officer roles and what employers typically expect.
Do you believe information security is about building rigid fortress walls that grind product innovation to a halt, or about architecting intelligent guardrails that allow a global platform to move fast securely? If you are a security leader who prefers pragmatic risk mitigation over dogmatic compliance checklists, we have an ecosystem for you to protect. About Tiko Tiko is an African nonprofit committed to strengthening the potential and resilience of adolescent girls across Africa. We address the “Triple Threat” of unintended pregnancy, HIV infection, and sexual and gender-based violence by building local health ecosystems that provide stigma-free, no-cost, quality-assured services. Our model brings together key local actors: community-based organizations (CBO) with peer mobilisers who act as health companions to girls; public and private health clinics that deliver care; and retail partners that redeem Tiko Miles -our behaviour-change incentive programme that rewards service uptake and feedback. We invest in partners by strengthening CBO capacity, training frontline workers and providers, supporting clinic quality improvement, and compensating partners based on performance. Our technology platform connects all actors by enabling referrals, verifying service delivery, facilitating payments, and generating real-time data. Tiko operates in six countries: Kenya, Ethiopia, Uganda, Burkina Faso, South Africa, and Nigeria, with additional offices in Portugal, the Netherlands, and the United Kingdom. For a clear overview of our work, we recommend watching this short [video](https://www.youtube.com/watch?v=9nxt4LcByn0). Globally, our team consists of +250 enthusiastic, international colleagues. Whether you are working from our biggest office in Nairobi, the fast-growing office in South Africa, or from home, our people are young, and our culture is global and dynamic. Our work environment is fast-paced, informal, and friendly. *For this position we will happily accept applicants from South Africa, Kenya, and Portugal.* The Job We are looking for an Information Security Officer (ISO) to take complete ownership of protecting Tiko’s global digital assets. In this role, you will be the definitive authority on security risk, providing expert guidance to ensure our employees, systems, and third-party partners protect the sensitive data of the communities we serve. Operating at the intersection of infrastructure, compliance, and emerging technology, you will design and enforce our security frameworks (such as ISO 27001 and NIST) across all active and future markets. You will partner closely with our IT, Engineering, and Privacy teams to embed a culture of security into everything we build—from baseline network defense to advanced AI governance. Key Responsibilities Security Architecture, Risk & AI Governance - Secure Design: Partner directly with IT and development teams to integrate information security into the architecture of new systems and services from the ground up, promoting secure coding practices throughout the SDLC. - Threat Modelling & Risk: Lead comprehensive risk assessments, vulnerability management, penetration testing, and threat modelling to systematically isolate and mitigate technical infrastructure risks. - AI & Privacy Alignment: Collaborate with the Privacy team to assess and mitigate security risks associated with emerging AI tools, establishing safeguards that promote the secure, responsible, and compliant use of artificial intelligence. Infrastructure, Network & Vendor Security - Technical Controls: Design, implement, and maintain robust technical measures to safeguard our network, servers, and endpoints (including firewalls, IDS/IPS, anti-malware, and advanced encryption solutions). - Supply Chain Security: Oversee information security due diligence for all external vendors, ensuring appropriate security clauses, data protection standards, and SLAs are contractually locked in before onboarding third parties. - Po…