| Title | IT Security Analyst | Vacancy Number | GB/EAD/62 |
|---|---|---|---|
| Location | Kabul | Closing Date | 2026-10-05 |
| Nationality | Afghan | Education | Qualifications Education • Bachelor’s degree in Information Technology, Computer Science, Cy bersecurity, or a related field. Professional Certifications (Preferred) • CISSP, CISM, CISA, CEH, ISO 27001, or equivalent information security certifications. Experience • Minimum 3–5 years of experience in IT security, cybersecurity, or information risk management. • Experience in banking, financial services, or regulated environments is a strong advantage. |
| Cont. Duration (Months) | 60 | Salary | Organization Salary Scale |
| Employment Type | Full Time | No. of Vacancy | 1 |
Job Summary: The IT Security Analyst is responsible for protecting the Bank’s information assets, systems, and infrastructure by implementing, monitoring, and enhancing information security controls. The role ensures that cybersecurity risks are effectively identified, managed, and escalated in line with Basel principles, regulatory requirements, and the Bank’s risk appetite. The position supports operational IT security under the Dy-CIO while ensuring indepndent risk oversight and incident escalation to the CRO. Job Description: A. Information Security Operations • Monitor IT systems, networks, and applications for security threats and vulnerabilities. • Implement and maintain security controls, tools, and configurations. • Support secure system configurations across CBS, applications, servers, and networks. • Ensure compliance with approved IT security standards and policies. B. Cyber Risk & Incident Management • Detect, analyze, and respond to information security incidents and cyber threats. • Escalate material security incidents, cyber risks, and control weaknesses to the CRO in a timely manner. • Support incident investigation, root-cause analysis, and remediation actions. • Maintain incident logs and prepare incident reports. C. Governance, Risk & Compliance Support • Support the implementation of the Bank’s Information Security Policy, IT governance framework, and risk controls. • Coordinate with Risk Management to: o Identify IT and cyber risks o Support risk assessments and KRIs o Align controls with the Bank’s risk appetite • Support Compliance requirements related to data protection, access controls, and regulatory expectations. D. Access Control & Security Monitoring • Monitor and review user access rights to critical systems (including CBS). • Support periodic access reviews and segregation of duties controls. • Ensure timely removal or modification of access for staff movements and terminations. E. Vulnerability Management & Security Testing • Conduct or coordinate vulnerability assessments and security testing. • Track remediation of identified vulnerabilities. • Support implementation of security patches and system hardening. F. Audit & Regulatory Support • Act as a focal point for IT security matters during: o Internal Audit o External Audit o Regulatory examinations • Support closure of IT security-related audit findings and regulatory observations. G. Awareness & Capacity Building • Support IT security awareness initiatives and training programs for staff. • Promote a strong security culture and compliance with security policies. 7. Authority & Escalation • Recommend security improvements and corrective actions. • Escalate high-risk security incidents and systemic weaknesses to Dy-CIO and CRO. • No authority to override business or system decisions without approval.
| Currency | Buy | Sell |
|---|---|---|
| USD | 68.38 | 71.28 |
| EUR | 71.13 | 75.13 |
| GBP | 84.77 | 88.77 |
