Data Protection And Information Security Analyst
2026-09-29T20:00:11+00:00
CVPeople Tanzania
https://cdn.greattanzaniajobs.com/jsjobsdata/data/employer/comp_1903/logo/CVPeople%20Africa.png
https://www.greattanzaniajobs.com/jobs
FULL_TIME
Dar es Salaam
Dar es Salaam
00000
Tanzania
Consulting
Computer & IT, Business Operations, Legal
2026-10-11T17:00:00+00:00
8
JOB PURPOSE
The Data Protection and Information Security Analyst supports both internal operations and customer-facing engagements in ensuring compliance with the Personal Data Protection Act (PDPA) 2022, maintaining information security controls in line with ISO 27001, and protecting the confidentiality, integrity, and availability of information assets. The role involves monitoring, assessing, and improving data protection and information security practices across clients and within the organization, managing incidents, and conducting training and awareness initiatives to strengthen overall compliance and security posture.
Responsibilities
DATA PROTECTION & PRIVACY COMPLIANCE
- Support the implementation and maintenance of the organization’s data protection framework.
- Assist in developing and maintaining the Record of Processing Activities (ROPA).
- Conduct regular Data Protection Impact Assessments (DPIAs) and advise departments on mitigating privacy risks.
- Review data processing agreements and contracts to ensure compliance with PDPA 2022 requirements.
- Assist in responding to data subject access requests (DSARs) and managing privacy incidents or breaches.
- Monitor data transfer activities to ensure compliance with cross-border data flow restrictions.
- Support the DPO in preparing periodic compliance and audit reports for management and regulators.
INFORMATION SECURITY OPERATIONS
- Implement, monitor, and continually improve information security controls under the Integrated Management System (IMS) aligned with ISO 9001:2015 and ISO/IEC 27001:2022 standards.
- Conduct risk assessments and support the development of mitigation plans.
- Participate in vulnerability assessments and coordinate with relevant teams for remediation.
- Monitor system logs, alerts, and incidents to detect and respond to security threats.
- Support in developing and maintaining the Information Security Management System (ISMS) documentation.
- Coordinate internal and client security awareness and training programmes.
GOVERNANCE, POLICY & AWARENESS
- Develop and maintain policies, procedures, and guidelines on data protection and information security.
- Conduct awareness sessions for employees, customers, and third parties on privacy and cybersecurity best practices.
- Collaborate with IT, Legal, HR, and other departments to embed data protection and security in daily operations.
INCIDENT MANAGEMENT & REPORTING
- Participate in incident response activities, including investigation, containment, and reporting.
- Maintain the incident register and assist in preparing incident reports for the DPO and management.
- Support business continuity and disaster recovery initiatives.
Requirements
Knowledge and Experience
- Bachelor’s degree in Computer Science, Information Technology, Information Security, or related field.
- Foundational knowledge of data protection, information security, or quality management systems.
- Preferred certifications (any of the following would be an advantage but not mandatory): o ISO/IEC 27001 Foundation, Implementer, or Auditor o ISO 9001 Internal Auditor o CompTIA Security+, CEH, or equivalent cybersecurity certification o Data Protection or Privacy certification o ISACA certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA).
- Minimum of 3 years’ experience in information security, data protection, or related field.
- Familiarity with Tanzania’s PDPA 2022, GDPR, or similar privacy regulations.
- Good understanding of documentation and record-keeping within a structured management system.
- Support the implementation and maintenance of the organization’s data protection framework.
- Assist in developing and maintaining the Record of Processing Activities (ROPA).
- Conduct regular Data Protection Impact Assessments (DPIAs) and advise departments on mitigating privacy risks.
- Review data processing agreements and contracts to ensure compliance with PDPA 2022 requirements.
- Assist in responding to data subject access requests (DSARs) and managing privacy incidents or breaches.
- Monitor data transfer activities to ensure compliance with cross-border data flow restrictions.
- Support the DPO in preparing periodic compliance and audit reports for management and regulators.
- Implement, monitor, and continually improve information security controls under the Integrated Management System (IMS) aligned with ISO 9001:2015 and ISO/IEC 27001:2022 standards.
- Conduct risk assessments and support the development of mitigation plans.
- Participate in vulnerability assessments and coordinate with relevant teams for remediation.
- Monitor system logs, alerts, and incidents to detect and respond to security threats.
- Support in developing and maintaining the Information Security Management System (ISMS) documentation.
- Coordinate internal and client security awareness and training programmes.
- Develop and maintain policies, procedures, and guidelines on data protection and information security.
- Conduct awareness sessions for employees, customers, and third parties on privacy and cybersecurity best practices.
- Collaborate with IT, Legal, HR, and other departments to embed data protection and security in daily operations.
- Participate in incident response activities, including investigation, containment, and reporting.
- Maintain the incident register and assist in preparing incident reports for the DPO and management.
- Support business continuity and disaster recovery initiatives.
- Data protection
- Information security
- ISO 27001
- ISO 9001
- PDPA 2022
- GDPR
- Risk assessment
- Vulnerability assessment
- Incident response
- Security awareness training
- Policy development
- Procedure development
- Record keeping
- Bachelor’s degree in Computer Science, Information Technology, Information Security, or related field.
- Foundational knowledge of data protection, information security, or quality management systems.
- Preferred certifications: ISO/IEC 27001 Foundation, Implementer, or Auditor; ISO 9001 Internal Auditor; CompTIA Security+, CEH, or equivalent cybersecurity certification; Data Protection or Privacy certification; ISACA certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA).
- Familiarity with Tanzania’s PDPA 2022, GDPR, or similar privacy regulations.
- Good understanding of documentation and record-keeping within a structured management system.
JOB-6abc18cbd5635
Vacancy title:
Data Protection And Information Security Analyst
[Type: FULL_TIME, Industry: Consulting, Category: Computer & IT, Business Operations, Legal]
Jobs at:
CVPeople Tanzania
Deadline of this Job:
Sunday, October 11 2026
Duty Station:
Dar es Salaam | Dar es Salaam
Summary
Date Posted: Tuesday, September 29 2026, Base Salary: Not Disclosed
Similar Jobs in Tanzania
Learn more about CVPeople Tanzania
CVPeople Tanzania jobs in Tanzania
JOB DETAILS:
JOB PURPOSE
The Data Protection and Information Security Analyst supports both internal operations and customer-facing engagements in ensuring compliance with the Personal Data Protection Act (PDPA) 2022, maintaining information security controls in line with ISO 27001, and protecting the confidentiality, integrity, and availability of information assets. The role involves monitoring, assessing, and improving data protection and information security practices across clients and within the organization, managing incidents, and conducting training and awareness initiatives to strengthen overall compliance and security posture.
Responsibilities
DATA PROTECTION & PRIVACY COMPLIANCE
- Support the implementation and maintenance of the organization’s data protection framework.
- Assist in developing and maintaining the Record of Processing Activities (ROPA).
- Conduct regular Data Protection Impact Assessments (DPIAs) and advise departments on mitigating privacy risks.
- Review data processing agreements and contracts to ensure compliance with PDPA 2022 requirements.
- Assist in responding to data subject access requests (DSARs) and managing privacy incidents or breaches.
- Monitor data transfer activities to ensure compliance with cross-border data flow restrictions.
- Support the DPO in preparing periodic compliance and audit reports for management and regulators.
INFORMATION SECURITY OPERATIONS
- Implement, monitor, and continually improve information security controls under the Integrated Management System (IMS) aligned with ISO 9001:2015 and ISO/IEC 27001:2022 standards.
- Conduct risk assessments and support the development of mitigation plans.
- Participate in vulnerability assessments and coordinate with relevant teams for remediation.
- Monitor system logs, alerts, and incidents to detect and respond to security threats.
- Support in developing and maintaining the Information Security Management System (ISMS) documentation.
- Coordinate internal and client security awareness and training programmes.
GOVERNANCE, POLICY & AWARENESS
- Develop and maintain policies, procedures, and guidelines on data protection and information security.
- Conduct awareness sessions for employees, customers, and third parties on privacy and cybersecurity best practices.
- Collaborate with IT, Legal, HR, and other departments to embed data protection and security in daily operations.
INCIDENT MANAGEMENT & REPORTING
- Participate in incident response activities, including investigation, containment, and reporting.
- Maintain the incident register and assist in preparing incident reports for the DPO and management.
- Support business continuity and disaster recovery initiatives.
Requirements
Knowledge and Experience
- Bachelor’s degree in Computer Science, Information Technology, Information Security, or related field.
- Foundational knowledge of data protection, information security, or quality management systems.
- Preferred certifications (any of the following would be an advantage but not mandatory): o ISO/IEC 27001 Foundation, Implementer, or Auditor o ISO 9001 Internal Auditor o CompTIA Security+, CEH, or equivalent cybersecurity certification o Data Protection or Privacy certification o ISACA certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA).
- Minimum of 3 years’ experience in information security, data protection, or related field.
- Familiarity with Tanzania’s PDPA 2022, GDPR, or similar privacy regulations.
- Good understanding of documentation and record-keeping within a structured management system.
Work Hours: 8
Experience in Months: 36
Level of Education: bachelor degree
Job application procedure
Application Link: Click Here to Apply Now
All Jobs | QUICK ALERT SUBSCRIPTION