Specialist Network Security at CRDB Bank Tanzania

Job Role Insights

  • Date posted

    2026-08-09

  • Closing date

    2026-08-17

  • Hiring location

    Dar es Salaam

  • Career level

    Middle

  • Qualification

    Bachelor Degree

  • Experience

    3 - 5 Years

  • Quantity

    1 person

  • Gender

    both

  • Job ID

    140718

Job Description

Reporting Line

MANAGER CYBERSECURITY RISK AND ASSURANCE

Location

Tanzania Head Office

Department

CYBERSECURITY UNIT

Number of openings

1

Job Purpose

The Specialist: Network Security is responsible for the operation, hardening, and continuous improvement of the bank’s network security controls across corporate and branch environments. The role manages the bank’s Network Detection and Response (NDR), remote access (VPN), Network Access Control (NAC), DDoS protection, network segmentation, and Web Application Firewall (WAF) solutions, ensuring that network-based threats are detected, prevented, and contained in line with cybersecurity policy and regulatory requirements.

The Specialist works under the technical guidance of the Senior Specialist: Infrastructure Security, supports incident response activities for network-based events, and contributes to the broader objectives of the Cybersecurity Engineering function by maintaining a resilient and well-defended network security posture.

Principle Responsibilities

  • Review and maintain the bank’s network firewall platforms, including rule-based access controls, regular policy audits, and configuration management, to ensure firewall rulesets remain effective, current, and compliant.
  • Administer the Network Detection and Response (NDR) solution, ensuring continuous monitoring of network traffic, rapid detection of anomalies and threats, and timely escalation and response to network-based security incidents.
  • Manage secure remote access solutions (VPNs), ensuring secure, authenticated, and policy-compliant connectivity for employees, contractors, and third parties accessing the bank’s systems from remote or external locations.
  • Ensure the implementation and operation of Network Access Control (NAC) across corporate and branch networks, controlling device authentication and enforcing access policies to prevent unauthorized endpoints from connecting to the bank’s network.
  • Oversee DNS security tools and configurations to detect and prevent domain-based threats, including phishing, malware command-and-control activities, and DNS-based data exfiltration.
  • Administer the DDoS protection solution, ensuring the bank’s internet-facing services and critical infrastructure are protected against volumetric, protocol, and application-layer denial-of-service attacks, with appropriate alerting and response procedures in place.
  • Administer and manage the bank’s Public Key Infrastructure (PKI), including lifecycle management of SSL/TLS certificates across all systems and services, ensuring timely issuance, renewal, revocation, and compliance with cryptographic standards.
  • Support and maintain the bank’s email security solutions, including anti-phishing controls and DMARC, SPF, and DKIM configurations, ensuring effective protection against phishing, spoofing, and impersonation attacks.
  • Implement and maintain network segmentation strategies to isolate critical systems, limit lateral movement, and reduce the attack surface across the bank’s corporate, branch, and data center environments.
  • Administer, configure, and tune the Web Application Firewall (WAF) solution, maintaining rulesets to protect web-facing applications from common and emerging threats such as SQL injection, cross-site scripting (XSS), and application-layer DDoS attacks.
  • Conduct periodic reviews and clean-ups of firewall rules, NAC policies, and WAF configurations to remove redundant, expired, or overly permissive entries.
  • Support security incident response activities for network-based events by providing investigation support, containment actions, and remediation in coordination with the Senior Specialist: Infrastructure Security and the wider Cybersecurity team.
  • Track and remediate vulnerabilities, audit findings, and risk issues related to network security solutions within agreed Service Level Agreements (SLAs).
  • Maintain accurate and up-to-date documentation, including network security architecture diagrams, rule baselines, runbooks, and standard operating procedures.
  • Liaise with network engineering, ICT operations, and vendors on the deployment, support, tuning, patching, upgrading, and licensing of network security tools.
  • Support internal and external audit engagements by providing evidence, configuration extracts, and control narratives for network security solutions.
  • Contribute to the evaluation and implementation of new network security capabilities, including proof-of-concept activities and security tool selection.
  • Ensure compliance with internal cybersecurity policies, network security standards, and applicable regulatory requirements relevant to the bank’s network environment.

Qualifications Required

  • Bachelor's degree in computer science/engineering, Cyber Security, Software Engineering, or related academic field.
  • Industry certifications such as CCNP Security, CCNA Security, CompTIA Security+, CISSP, or equivalent are a plus.
  • Minimum of 3 years of hands-on experience in network security, cybersecurity operations, or related disciplines, OR.
  • In-depth knowledge of network security technologies including Next-Generation Firewalls (NGFW), IDS/IPS, Network Access Control (NAC), Network Detection and Response (NDR), DDoS protection, VPN, and network segmentation techniques.
  • Strong understanding of Web Application Firewall (WAF) technologies and protection against common web application threats such as those described in the OWASP Top 10.
  • Solid knowledge of remote access architectures and secure connectivity solutions for corporate, branch, and third-party environments.
  • Working knowledge of TCP/IP networking, routing, switching, and common network protocols, with the ability to troubleshoot network security issues.
  • Familiarity with security frameworks and standards (e.g., NIST CSF, ISO 27001, PCI DSS) and their application to network security in banking environments.
  • Understanding incident management processes and the role of network security controls in detection, containment, and response.
  • Strong analytical and problem-solving skills, with the ability to assess network-based risks and design effective, proportionate controls.
  • Commitment to staying current with evolving network security threats, technologies, and industry best practices.

CRDB Commitment

CRDB Bank is dedicated to upholding Sustainability and ESG practices and encourage applicants who share this commitment. The Bank also promotes an inclusive workplace, hence applications from women and individual with disabilities are encouraged.

It is important to note that CRDB Bank does not charge any fees for the application or recruitment process, and any requests for payment should be disregarded as they do not represent the bank’s practices.

Only Shortlisted Candidates will be Contacted.

Deadline

2026-08-17

Employment Terms

PERMANENT

Interested in this job?

7 days left to apply

Apply now

Your job search, in your pocket

Get the ZoomTanzania Jobs app - apply on the go, get instant job alerts, and chat with our AI assistant anytime, anywhere.

How to Apply

Apply now