Manager - Information Security at Diageo

--Powermax General Electrical Merchants Ltd--

Job Description

  • This is a mid-management role within Kenya reports directly to the Group Legal Director and is critical in managing, developing, and maintaining all business records and information assets of KBL, UDV, EABL and all other EABL affiliated business units.  
  • The job holder is tasked with ensuring the proper management of data, records and information across various formats including paper, cloud, digital, and electronic media, as and when directed. The role holder will also be responsible for ensuring data management in compliance with the data protection regulations.

Job Industry

Information And Communication Technology Services

Job Salary Currency

KES

Job Salary Fixed

No

Key Deliverables

  • The role holder will be a key member of the Kenya Legal Team, represent Legal in multi-functional meetings and will closely collaborate with the KBL, EABL and above market legal teams.
  • Lead and drive the EABL IM&S committee as per the company IM&S policy as a key deliverable.
  • Lead and drive the EABL Kenya Data Protection Governance Committee as per the Terms of Reference, applicable policies and the law.
  • Drive, embed, support, implement and achieve the strategic plans and objectives of IM&S and data protection and the Legal Function in line with the business strategy.
  • Continuously develop technical and managerial skills and acting as a leader and role model in the business. 
  • Fully implement and maintain information management and data governance controls, ensuring ongoing compliance with applicable laws and regulations, and maintaining an effective compliance environment in Kenya aligned with global and local requirements.
  • Identify, assess and handle IM&S and personal data processing risks, including remediation actions, and supervise regulatory developments to ensure timely updates to policies and practices.
  • Develop and maintain retention schedules and Information Asset Inventories, ensuring proper classification, handling and lifecycle management of personal data.
  • Lead and conduct IM&S and data protection audits in line with policies and the annual audit plan, and liaise with external auditors to support compliance reviews.
  • Provide leadership to the IM&S governance structure and coordinate governance committees, while guiding business units to ensure accountability, consistency and self-sufficiency in implementation.
  • Work closely with IT to ensure appropriate information security controls and system monitoring are in place and maintained to safeguard information, particularly personal data.

Professional Qualifications

Industry Qualification
Information And Communication Technology Services Bachelor’s degree or equivalent experience in information sciences, Information management, Information systems, Information Technologies, Law or any other related course. Proficiency in Information Technology Management and a great interest in developments in this field. Professional certification such as CIPP/E (Certified Information Privacy Professional) preferred.

Application Process

Close Date

30/04/2026