Specialist Network Security job at CRDB
New
Website :
Today
Linkedid Twitter Share on facebook
Specialist Network Security
2026-08-09T15:45:47+00:00
CRDB
https://cdn.greattanzaniajobs.com/jsjobsdata/data/employer/comp_2278/logo/CRDB%20Bank%20Plc.jpg
FULL_TIME
Dar es Salaam
Dar es Salaam
00000
Tanzania
Finance
Computer & IT, Security, Science & Engineering
TZS
MONTH
2026-08-17T17:00:00+00:00
8

The Specialist: Network Security is responsible for the operation, hardening, and continuous improvement of the bank’s network security controls across corporate and branch environments. The role manages the bank’s Network Detection and Response (NDR), remote access (VPN), Network Access Control (NAC), DDoS protection, network segmentation, and Web Application Firewall (WAF) solutions, ensuring that network-based threats are detected, prevented, and contained in line with cybersecurity policy and regulatory requirements.

The Specialist works under the technical guidance of the Senior Specialist: Infrastructure Security, supports incident response activities for network-based events, and contributes to the broader objectives of the Cybersecurity Engineering function by maintaining a resilient and well-defended network security posture.

Principle Responsibilities

  • Review and maintain the bank’s network firewall platforms, including rule-based access controls, regular policy audits, and configuration management, to ensure firewall rulesets remain effective, current, and compliant.
  • Administer the Network Detection and Response (NDR) solution, ensuring continuous monitoring of network traffic, rapid detection of anomalies and threats, and timely escalation and response to network-based security incidents.
  • Manage secure remote access solutions (VPNs), ensuring secure, authenticated, and policy-compliant connectivity for employees, contractors, and third parties accessing the bank’s systems from remote or external locations.
  • Ensure the implementation and operation of Network Access Control (NAC) across corporate and branch networks, controlling device authentication and enforcing access policies to prevent unauthorized endpoints from connecting to the bank’s network.
  • Oversee DNS security tools and configurations to detect and prevent domain-based threats, including phishing, malware command-and-control activities, and DNS-based data exfiltration.
  • Administer the DDoS protection solution, ensuring the bank’s internet-facing services and critical infrastructure are protected against volumetric, protocol, and application-layer denial-of-service attacks, with appropriate alerting and response procedures in place.
  • Administer and manage the bank’s Public Key Infrastructure (PKI), including lifecycle management of SSL/TLS certificates across all systems and services, ensuring timely issuance, renewal, revocation, and compliance with cryptographic standards.
  • Support and maintain the bank’s email security solutions, including anti-phishing controls and DMARC, SPF, and DKIM configurations, ensuring effective protection against phishing, spoofing, and impersonation attacks.
  • Implement and maintain network segmentation strategies to isolate critical systems, limit lateral movement, and reduce the attack surface across the bank’s corporate, branch, and data center environments.
  • Administer, configure, and tune the Web Application Firewall (WAF) solution, maintaining rulesets to protect web-facing applications from common and emerging threats such as SQL injection, cross-site scripting (XSS), and application-layer DDoS attacks.
  • Conduct periodic reviews and clean-ups of firewall rules, NAC policies, and WAF configurations to remove redundant, expired, or overly permissive entries.
  • Support security incident response activities for network-based events by providing investigation support, containment actions, and remediation in coordination with the Senior Specialist: Infrastructure Security and the wider Cybersecurity team.
  • Track and remediate vulnerabilities, audit findings, and risk issues related to network security solutions within agreed Service Level Agreements (SLAs).
  • Maintain accurate and up-to-date documentation, including network security architecture diagrams, rule baselines, runbooks, and standard operating procedures.
  • Liaise with network engineering, ICT operations, and vendors on the deployment, support, tuning, patching, upgrading, and licensing of network security tools.
  • Support internal and external audit engagements by providing evidence, configuration extracts, and control narratives for network security solutions.
  • Contribute to the evaluation and implementation of new network security capabilities, including proof-of-concept activities and security tool selection.
  • Ensure compliance with internal cybersecurity policies, network security standards, and applicable regulatory requirements relevant to the bank’s network environment.

Qualifications Required

  • Bachelor's degree in computer science/engineering, Cyber Security, Software Engineering, or related academic field.
  • Industry certifications such as CCNP Security, CCNA Security, CompTIA Security+, CISSP, or equivalent are a plus.
  • Minimum of 3 years of hands-on experience in network security, cybersecurity operations, or related disciplines, OR.
  • In-depth knowledge of network security technologies including Next-Generation Firewalls (NGFW), IDS/IPS, Network Access Control (NAC), Network Detection and Response (NDR), DDoS protection, VPN, and network segmentation techniques.
  • Strong understanding of Web Application Firewall (WAF) technologies and protection against common web application threats such as those described in the OWASP Top 10.
  • Solid knowledge of remote access architectures and secure connectivity solutions for corporate, branch, and third-party environments.
  • Working knowledge of TCP/IP networking, routing, switching, and common network protocols, with the ability to troubleshoot network security issues.
  • Familiarity with security frameworks and standards (e.g., NIST CSF, ISO 27001, PCI DSS) and their application to network security in banking environments.
  • Understanding incident management processes and the role of network security controls in detection, containment, and response.
  • Strong analytical and problem-solving skills, with the ability to assess network-based risks and design effective, proportionate controls.
  • Commitment to staying current with evolving network security threats, technologies, and industry best practices.
  • Review and maintain the bank’s network firewall platforms, including rule-based access controls, regular policy audits, and configuration management, to ensure firewall rulesets remain effective, current, and compliant.
  • Administer the Network Detection and Response (NDR) solution, ensuring continuous monitoring of network traffic, rapid detection of anomalies and threats, and timely escalation and response to network-based security incidents.
  • Manage secure remote access solutions (VPNs), ensuring secure, authenticated, and policy-compliant connectivity for employees, contractors, and third parties accessing the bank’s systems from remote or external locations.
  • Ensure the implementation and operation of Network Access Control (NAC) across corporate and branch networks, controlling device authentication and enforcing access policies to prevent unauthorized endpoints from connecting to the bank’s network.
  • Oversee DNS security tools and configurations to detect and prevent domain-based threats, including phishing, malware command-and-control activities, and DNS-based data exfiltration.
  • Administer the DDoS protection solution, ensuring the bank’s internet-facing services and critical infrastructure are protected against volumetric, protocol, and application-layer denial-of-service attacks, with appropriate alerting and response procedures in place.
  • Administer and manage the bank’s Public Key Infrastructure (PKI), including lifecycle management of SSL/TLS certificates across all systems and services, ensuring timely issuance, renewal, revocation, and compliance with cryptographic standards.
  • Support and maintain the bank’s email security solutions, including anti-phishing controls and DMARC, SPF, and DKIM configurations, ensuring effective protection against phishing, spoofing, and impersonation attacks.
  • Implement and maintain network segmentation strategies to isolate critical systems, limit lateral movement, and reduce the attack surface across the bank’s corporate, branch, and data center environments.
  • Administer, configure, and tune the Web Application Firewall (WAF) solution, maintaining rulesets to protect web-facing applications from common and emerging threats such as SQL injection, cross-site scripting (XSS), and application-layer DDoS attacks.
  • Conduct periodic reviews and clean-ups of firewall rules, NAC policies, and WAF configurations to remove redundant, expired, or overly permissive entries.
  • Support security incident response activities for network-based events by providing investigation support, containment actions, and remediation in coordination with the Senior Specialist: Infrastructure Security and the wider Cybersecurity team.
  • Track and remediate vulnerabilities, audit findings, and risk issues related to network security solutions within agreed Service Level Agreements (SLAs).
  • Maintain accurate and up-to-date documentation, including network security architecture diagrams, rule baselines, runbooks, and standard operating procedures.
  • Liaise with network engineering, ICT operations, and vendors on the deployment, support, tuning, patching, upgrading, and licensing of network security tools.
  • Support internal and external audit engagements by providing evidence, configuration extracts, and control narratives for network security solutions.
  • Contribute to the evaluation and implementation of new network security capabilities, including proof-of-concept activities and security tool selection.
  • Ensure compliance with internal cybersecurity policies, network security standards, and applicable regulatory requirements relevant to the bank’s network environment.
  • Network security technologies (NGFW, IDS/IPS, NAC, NDR, DDoS protection, VPN, network segmentation)
  • Web Application Firewall (WAF) technologies
  • Remote access architectures
  • TCP/IP networking, routing, switching, common network protocols
  • Security frameworks and standards (NIST CSF, ISO 27001, PCI DSS)
  • Incident management processes
  • Analytical and problem-solving skills
  • Staying current with network security threats and technologies
  • Bachelor's degree in computer science/engineering, Cyber Security, Software Engineering, or related academic field.
  • Industry certifications such as CCNP Security, CCNA Security, CompTIA Security+, CISSP, or equivalent are a plus.
  • In-depth knowledge of network security technologies.
  • Strong understanding of Web Application Firewall (WAF) technologies.
  • Solid knowledge of remote access architectures.
  • Working knowledge of TCP/IP networking, routing, switching, and common network protocols.
  • Familiarity with security frameworks and standards.
  • Understanding incident management processes.
  • Strong analytical and problem-solving skills.
  • Commitment to staying current with evolving network security threats, technologies, and industry best practices.
bachelor degree
36
JOB-6a78a0ab1e64e

Vacancy title:
Specialist Network Security

[Type: FULL_TIME, Industry: Finance, Category: Computer & IT, Security, Science & Engineering]

Jobs at:
CRDB

Deadline of this Job:
Monday, August 17 2026

Duty Station:
Dar es Salaam | Dar es Salaam

Summary
Date Posted: Sunday, August 9 2026, Base Salary: Not Disclosed

Similar Jobs in Tanzania
Learn more about CRDB
CRDB jobs in Tanzania

JOB DETAILS:

The Specialist: Network Security is responsible for the operation, hardening, and continuous improvement of the bank’s network security controls across corporate and branch environments. The role manages the bank’s Network Detection and Response (NDR), remote access (VPN), Network Access Control (NAC), DDoS protection, network segmentation, and Web Application Firewall (WAF) solutions, ensuring that network-based threats are detected, prevented, and contained in line with cybersecurity policy and regulatory requirements.

The Specialist works under the technical guidance of the Senior Specialist: Infrastructure Security, supports incident response activities for network-based events, and contributes to the broader objectives of the Cybersecurity Engineering function by maintaining a resilient and well-defended network security posture.

Principle Responsibilities

  • Review and maintain the bank’s network firewall platforms, including rule-based access controls, regular policy audits, and configuration management, to ensure firewall rulesets remain effective, current, and compliant.
  • Administer the Network Detection and Response (NDR) solution, ensuring continuous monitoring of network traffic, rapid detection of anomalies and threats, and timely escalation and response to network-based security incidents.
  • Manage secure remote access solutions (VPNs), ensuring secure, authenticated, and policy-compliant connectivity for employees, contractors, and third parties accessing the bank’s systems from remote or external locations.
  • Ensure the implementation and operation of Network Access Control (NAC) across corporate and branch networks, controlling device authentication and enforcing access policies to prevent unauthorized endpoints from connecting to the bank’s network.
  • Oversee DNS security tools and configurations to detect and prevent domain-based threats, including phishing, malware command-and-control activities, and DNS-based data exfiltration.
  • Administer the DDoS protection solution, ensuring the bank’s internet-facing services and critical infrastructure are protected against volumetric, protocol, and application-layer denial-of-service attacks, with appropriate alerting and response procedures in place.
  • Administer and manage the bank’s Public Key Infrastructure (PKI), including lifecycle management of SSL/TLS certificates across all systems and services, ensuring timely issuance, renewal, revocation, and compliance with cryptographic standards.
  • Support and maintain the bank’s email security solutions, including anti-phishing controls and DMARC, SPF, and DKIM configurations, ensuring effective protection against phishing, spoofing, and impersonation attacks.
  • Implement and maintain network segmentation strategies to isolate critical systems, limit lateral movement, and reduce the attack surface across the bank’s corporate, branch, and data center environments.
  • Administer, configure, and tune the Web Application Firewall (WAF) solution, maintaining rulesets to protect web-facing applications from common and emerging threats such as SQL injection, cross-site scripting (XSS), and application-layer DDoS attacks.
  • Conduct periodic reviews and clean-ups of firewall rules, NAC policies, and WAF configurations to remove redundant, expired, or overly permissive entries.
  • Support security incident response activities for network-based events by providing investigation support, containment actions, and remediation in coordination with the Senior Specialist: Infrastructure Security and the wider Cybersecurity team.
  • Track and remediate vulnerabilities, audit findings, and risk issues related to network security solutions within agreed Service Level Agreements (SLAs).
  • Maintain accurate and up-to-date documentation, including network security architecture diagrams, rule baselines, runbooks, and standard operating procedures.
  • Liaise with network engineering, ICT operations, and vendors on the deployment, support, tuning, patching, upgrading, and licensing of network security tools.
  • Support internal and external audit engagements by providing evidence, configuration extracts, and control narratives for network security solutions.
  • Contribute to the evaluation and implementation of new network security capabilities, including proof-of-concept activities and security tool selection.
  • Ensure compliance with internal cybersecurity policies, network security standards, and applicable regulatory requirements relevant to the bank’s network environment.

Qualifications Required

  • Bachelor's degree in computer science/engineering, Cyber Security, Software Engineering, or related academic field.
  • Industry certifications such as CCNP Security, CCNA Security, CompTIA Security+, CISSP, or equivalent are a plus.
  • Minimum of 3 years of hands-on experience in network security, cybersecurity operations, or related disciplines, OR.
  • In-depth knowledge of network security technologies including Next-Generation Firewalls (NGFW), IDS/IPS, Network Access Control (NAC), Network Detection and Response (NDR), DDoS protection, VPN, and network segmentation techniques.
  • Strong understanding of Web Application Firewall (WAF) technologies and protection against common web application threats such as those described in the OWASP Top 10.
  • Solid knowledge of remote access architectures and secure connectivity solutions for corporate, branch, and third-party environments.
  • Working knowledge of TCP/IP networking, routing, switching, and common network protocols, with the ability to troubleshoot network security issues.
  • Familiarity with security frameworks and standards (e.g., NIST CSF, ISO 27001, PCI DSS) and their application to network security in banking environments.
  • Understanding incident management processes and the role of network security controls in detection, containment, and response.
  • Strong analytical and problem-solving skills, with the ability to assess network-based risks and design effective, proportionate controls.
  • Commitment to staying current with evolving network security threats, technologies, and industry best practices.

Work Hours: 8

Experience in Months: 36

Level of Education: bachelor degree

Job application procedure

Application Link: Click Here to Apply Now

All Jobs | QUICK ALERT SUBSCRIPTION

Job Info
Job Category: Computer/ IT jobs in Tanzania
Job Type: Full-time
Deadline of this Job: Monday, August 17 2026
Duty Station: Dar es Salaam | Dar es Salaam
Posted: 09-08-2026
No of Jobs: 1
Start Publishing: 09-08-2026
Stop Publishing (Put date of 2030): 10-10-2076
Apply Now
Notification Board

Join a Focused Community on job search to uncover both advertised and non-advertised jobs that you may not be aware of. A jobs WhatsApp Group Community can ensure that you know the opportunities happening around you and a jobs Facebook Group Community provides an opportunity to discuss with employers who need to fill urgent position. Click the links to join. You can view previously sent Email Alerts here incase you missed them and Subscribe so that you never miss out.

Caution: Never Pay Money in a Recruitment Process.

Some smart scams can trick you into paying for Psychometric Tests.