Terms of Reference (ToR)
Position Title: Network and Cybersecurity Expert
Project: Gambia National Interoperability Program
Location: The Gambia
Reporting to: Program Lead – Gambia National Interoperability Program
Duration: 36 months, with possibility of extension
1. Background
Gamswitch under the directive of the Central Bank of the Gambia and its partner IIDIA is leading the national implementation of Mojaloop, an open-source software for real-time payment interoperability. To ensure the security, efficiency, and compliance of this critical financial infrastructure, we are seeking a qualified Network and Cybersecurity Expert. This expert will play a key role in designing, implementing, and maintaining robust security measures to protect the system, user data, and financial transactions.
2. Objectives of the Role
The primary objective of the role is to safeguard the Mojaloop system against cyber threats and ensure compliance with relevant financial and data protection regulations. The expert will establish and maintain a secure network architecture while proactively identifying and mitigating vulnerabilities.
3. Key Responsibilities
The Network and Cybersecurity Expert will be responsible for:
- Protecting Sensitive Financial Data
- Implement data encryption, secure API communications, and end-to-end security.
- Guard against data breaches by applying industry best practices.
- Preventing Financial Fraud and Cyber Attacks
- Deploy fraud detection systems and perform penetration testing.
- Monitor threats and respond to incidents in real time.
- Ensuring Regulatory Compliance
- Ensure alignment with national regulations, GDPR, PCI-DSS, and other international standards.
- Prepare documentation and reports for audits and assessments.
- Securing Interoperability
- Manage the security of integrations between banks, mobile money operators, and fintech platforms.
- Evaluate third-party access risks and implement necessary controls.
- System Availability and Resilience
- Protect against DDoS and other disruptive cyberattacks.
- Configure firewalls, load balancers, and redundancy protocols.
- Public Trust and Confidence
- Promote and maintain trust by ensuring the security of all user-facing and backend components.
- Incident Response and Disaster Recovery
- Develop and regularly update an incident response and recovery plan.
- Conduct simulations and readiness drills.
- User Access and Identity Management
- Implement strong authentication mechanisms, including MFA and role-based access controls.
- Monitor and manage access privileges.
- Proactive Threat Management
- Stay current on threat intelligence and apply relevant security updates.
- Conduct vulnerability scans and implement patches regularly.
- Network Performance and Scalability
- Optimize the security architecture to support growing transaction volumes.
- Ensure secure scalability without performance degradation.
4. Qualifications and Experience
Required:
- Bachelor’s or Master’s degree in Computer Science, Information Security, or related field.
- Professional certifications (e.g., CISSP, CEH, CISM, CompTIA Security+, Cisco CCNP Security).
- Minimum of 5 years of hands-on experience in network security and cybersecurity management.
- Proven track record in securing financial or payment systems.
Desirable:
- Experience with Mojaloop or similar payment interoperability platforms.
- Knowledge of regulatory frameworks in the financial sector.
5. Deliverables
- Network and security architecture document.
- Security policy and procedures manual.
- Incident response and disaster recovery plan.
- Monthly security audit reports and threat assessments.
- Compliance assessment reports.
6. Reporting and Supervision
The Network and Cybersecurity Expert will report directly to the Program Lead and work closely with Gamswitch’s IT and compliance teams, as well as external stakeholders such as banks and regulatory bodies.
7. Duration and Level of Effort
The position is a full-time engagement for the duration of the Mojaloop implementation phase, with potential for extension based on performance and project needs.
8. Application Instructions
Interested candidates should submit:
- A detailed CV
- Cover letter highlighting relevant experience
- Copies of certifications
- Contact information for three professional references
Deadline: 20th July 2025.
Send applications to: ndabo@iidia.org and copy bdrammeh@gamswitch.com