Security Audit Terms Of Reference (TOR) Job at Living Goods - Career Opportunity in Kenya
Website :
1490 Days Ago
Linkedid Twitter Share on facebook

Vacancy title:
Security Audit Terms Of Reference (TOR)

[ Type: FULL TIME , Industry: Nonprofit, and NGO , Category: Admin & Office ]

 

Jobs at:

Living Goods

Deadline of this Job:
10 April 2020  

Duty Station:
Within Kenya , Nairobi , East Africa

Summary
Date Posted: Saturday, March 28, 2020 , Base Salary: Not Disclosed


JOB DETAILS:
At Living Goods we empower people to improve the health of their families, friends and communities. Living Goods supports networks of 'Avon-like’ health entrepreneurs who go door to door to teach families how to improve their health and wealth and sell life-changing products such as simple treatments for malaria and diarrhea, safe delivery kits, fortified foods, clean cook stoves, water filters, and solar lights. By combining the best practices from business and public health, we are dramatically lowering child mortality AND creating livelihoods for thousands of enterprising women. Living Goods supports a network of over 2,000 micro-entrepreneurs in Uganda and Kenya who teach families in their communities how to improve health and well-being while selling affordable, high-impact products like basic medicines, fortified foods, water filters, clean cook-stoves, and solar lights. As part of the Branch Team, you will play a key role in supporting Community Health Volunteers (CHVs) to deliver high quality health care to their communities and generate sales of critical products. .

Key Tasks:
The purpose of IT security audit is to provide an independent evaluation of Applications, Database, Server Architecture and Network infrastructure to identify any gaps in systems and an adequate IT security framework in accordance with best practices of industrial Enterprise Architecture Framework. The scope would include assessment of Living Goods’ applications, security settings, server, Network and associated IT infrastructure. The main goals of the security audit are the following:
State of affairs report: To review the overall application and network technical design and deployment with a view to determining whether these designs are fit for purpose and what gaps and holes exist within these designs and deployments.
Application software architecture review: To provide assurance that the technical architecture of the SmartHealth, Supervisor and other operational and ancillary applications meet the current and future needs of the organization. The auditor must assess control and authorizations, error and exception handling, business process flows within the application software and complementary controls (enterprise level, general, application and specialist IT control) and procedures and validation of reports (both operational and financial) generated from the system.
Network architecture and security review: Given that the environments that Living Goods operates in possess different policy frameworks dictating the storage and transmission of healthcare and financial data, we are keen to have the consultant perform a network and data transmission security audit to outline the threats and gaps that are presented by this. The aim of this audit is to provide assurance that the components of our deployments (databases, web and application servers, cache systems, along with other systems) are fully secure and are corresponding to the controls objectives of the control system. Review of internal and external connections to the system, perimeter security, firewall review, router access control lists, port scanning and intrusion detection are some typical areas of coverage.
Data integrity review: To provide assurance that the database design and structure provides the best possible design for the organizational needs and corresponding application and future integration needs. The purpose is the scrutiny of live data to verify adequacy of controls and impact of weaknesses, as noticed from any of the above reviews.
Business continuity review: The review includes existence and maintenance of fault tolerant and redundant hardware, backup procedures and storage, and documented and tested disaster recovery/business continuity plan, effectiveness of disaster recovery plan, as well as ensuring existence of well-defined I.S Audit manual and its compliance thereon.


Job Skills: Not Specified


Minimum qualifications and experience:
• Technically sound. You have a Masters-level degree in public health, international development, and/or university degree in information and communication technology or computer science. You have 5+ years of experience implementing digital health or large-scale projects at global level, as well as providing technical assistance to government, donors and/or implementing partners.
• Stakeholder Management. You understand how national stakeholders operate and can corelate expectations of the key players i.e. government staff, implementing partners, donors, etc. in digital and/or community health. You are well versed with the stakeholder landscape, coordination norms, and decision-making protocol to ensure efficient alignment.
• Articulate. You are fluent in written and spoken English. You have excellent communications skills, both orally and written, for policy briefs, PowerPoint presentations, et cetera.
• Analytical. You have exceptional analytical skills. You possess critical thinking skills to enable troubleshooting in unpredictable environments.
• Adaptable. You are eager to work with people of different technical backgrounds: the private sector, social entrepreneurial sector, non-profit sector and public health community. You have proven ability to contribute and to succeed in a fast-paced setting that requires independent thinking. You are solutions oriented.
• Project management master. You are disciplined, methodical, and organized. You are detail-oriented in your knowledge management and information systems, from email to Dropbox folders. You keep your eyes on the prize, but also set and achieve collective goals with others along the way. You are self-directed and able to move things forward with limited input from others.
• Team player. You play well with others and enjoy seeing the impact of our work as a team.
• Multitasker. You’re able to juggle multiple tasks at once while ‘keeping calm and carrying on.’ You think strategically, handle ambiguity, and work well in a multicultural environment.


Job Education Requirements: Not Specified


Job Education Experience: Not Specified


Work Hours: 8

 

{module 312}

Job application procedure
  click here to apply

All Jobs

QUICK ALERT SUBSCRIPTION

{module 316}

Job Info
Job Category: Security, Homeland Security jobs in Kenya
Job Type: Full-time
Deadline of this Job: 10th April 2020
Duty Station: Nairobi
Posted: 28-03-2020
No of Jobs: 1
Start Publishing: 28-03-2020
Stop Publishing (Put date of 2030): 28-03-2065
Apply Now
Notification Board

Join a Focused Community on job search to uncover both advertised and non-advertised jobs that you may not be aware of. A jobs WhatsApp Group Community can ensure that you know the opportunities happening around you and a jobs Facebook Group Community provides an opportunity to discuss with employers who need to fill urgent position. Click the links to join. You can view previously sent Email Alerts here incase you missed them and Subscribe so that you never miss out.

Caution: Never Pay Money in a Recruitment Process.

Some smart scams can trick you into paying for Psychometric Tests.