Summary
Overview
Work history
Education
Skills
Accomplishments
Languages
Certification
References
Timeline
Generic
TOM MATOMOLA SANGANDU

TOM MATOMOLA SANGANDU

Lusaka

Summary

Accomplished Cybersecurity and ICT Professional with a strong background in risk management, business continuity management, systems implementation, and technical support within the financial services sector. Skilled in identifying and mitigating technology and operational risks, implementing cybersecurity frameworks, and enhancing control environments to safeguard critical assets. Proficient in SIEM tools, EDR, and corporate network design, with hands-on experience in router, switch, and access point configurations. Adept at bridging the gap between technical teams and business stakeholders, aligning with ISO 27001, ISO 22301 and other industry best practices, able to drive digital resilience through vulnerability management, incident response and continuous improvement. Known for clear communication, leadership, and fostering collaborative environments.

Overview

9
9
years of professional experience
6
6
years of post-secondary education
1
1
Certification

Work history

Cybersecurity and Digital Risk Analyst

ACCESS BANK ZAMBIA LIMITED
Lusaka, Lusaka Province
02.2025 - Current
  • Monitors and analyzes security alerts, logs, and threat intelligence to detect and respond to cyber threats in real time.
  • Conducts risk analysis on vulnerability & penetration tests (VAPT) findings & collaborates with InforSec & IT, recommending mitigation strategies aligned with industry standards ISO 27001, ISO 22301.
  • Assists in the development and implementation of cybersecurity policies, procedures, and controls to ensure regulatory compliance and protect organizational assets.
  • Handles the incident management process, which includes identifying, logging, categorizing, prioritizing, responding to, resolving, and closing incidents, as well as post-incident reviews and lessons learned.
  • Performs regular security audits to assess the effectiveness of existing controls.
  • Collaborates with cross-functional teams including IT, Legal, and Compliance to integrate security requirements into business operations and projects.
  • Produces clear and actionable risk reports for senior management, highlighting trends, critical risks, and recommendations.
  • Incident response and business continuity planning efforts, ensuring timely and effective resolution of security incidents.
  • Tracks developments in the cybersecurity landscape to keep the organization aware of emerging threats and technologies.
  • Utilizes tools such as Fraud Detection, GRC platform, SIEM and data analytics software to support proactive digital risk management.
  • Conducts cybersecurity awareness training sessions for members of staff to maintain a security conscious culture.
  • Maintains an information security risk register and assist with internal and external audits relating to information security on digital platforms, applications, and business processes.

Team Lead Systems Support-Hospital Operations

SMART APPLICATIONS INTERNATIONAL ZAMBIA LTD
Lusaka, Lusaka Province
01.2018 - 02.2025
  • Cybersecurity analysis, SIEM technologies, Log Management and Endpoint Detection & Responce
  • Built corporate ICT networks and maintained their infrastructure
  • Router configurations, firewall configurations and network troubleshooting diagnostics
  • Spearheaded the Medismart system implementation in medical facilities
  • MySql database installations, configurations and maintenance in medical facilities
  • Provided leadership on ICT engagements and technical systems support at healthcare providers
  • Facilitated technical training on the Medismart system end-users
  • Operating system installations such as Windows servers and desktop/laptop OS installations i.e windows 10, 11
  • Antivirus installations and ensuring computer programs and applications were frequently patched up to date and secure
  • Hardware installation such as office printers, IP phones and other network devices
  • Provided administrative assistance on the claims processing system between insurance companies namely: Prudential Life Assurance, Zsic Life Insurance, Metropolitan (Onelife) Zambia and Medical facilities namely: Coptic hospital, Victoria hospital, Medland hospital, Pearl of Health Hospital
  • Managed the call center support and generates monthly reports through Microsoft office tools, tables and data analytic graphs for internal consumption
  • Coordinated team members and provided direction on system related operations to be executed on site
  • Carried out presentations and system demos during meetings with customers and stakeholders i.e insurance companies namely; Prudential Life Assurance, Metropolitan Onelife Zambia and Hospitals namely; Mums Care Hospital, Lusaka Trust Hospital
  • Constantly applied cyber security awareness knowledge and skill that assisted in keeping a secure environment when dealing with emails, usb storage devices, software upgrades and passwords
  • Trained staff members to be aware of cybersecurity threats, such as email phishing, social engineering attacks etc.


ADDITIONAL TASKS

□ Prepared and updated the HCP list for all installed clients across Zambia and shares reports with customers and stakeholders

□ Managed and reviewed weekly reports for colleagues in my department

□ Facilitated internal office meetings, announcements and any other business

□ Updated and shared monthly service provider reports: i.e non-compliant system users needing attention and re-training

□ Monitored competitor systems on the market and ensured top notch delivery in customer service

□ Conversant with excel management report writing skills using pivot tables and graphs

□ Able to use system - Sage 300 People to do a self-appraisal and submit for performance review

□ Distributed newly installed facilities running on the Medismart system to colleagues for technical support (Service provider allocation and distribution)

IT Assistant and Sales Executive

WHEELS TIRES SERVICES LUSAKA
Lusaka, Lusaka Province
01.2017 - 01.2018
  • Installed and configured office programs and applications
  • Provided technical assistance to stuff on hardware and software issues
  • Assisted in sales of auto-spare products to customers
  • Engaging transport officers of various companies and distributing quotations of auto-spares i.e tires, engine oil, etc for their fleet of vehicles
  • Working towards monthly targets and generating monthly reports
  • Sensitize customers on motor accessories both premium and economic brands
  • Follow up on customers to get feedback on auto-spare products and services
  • Participate in management meetings of setting up strategies to find new prospects and business partners.

Risk and Loss Officer

ZAMBIA SUGAR PRIVATE LIMITED COMPANY-MAZABUKA
Mazabuka, Southern Province
04.2016 - 11.2016
  • CCTv surveillance monitoring
  • Provided reports of daily surveillance activities
  • Summited reports of suspicious actions on site
  • Authorized entrance of people and vehicles into estates premise
  • Ensured all entry and exit points in the factory premise were secured
  • Inspected and patrolled the production site regularly
  • Provided monthly reports on security activities and occurrences in the factory premise.

Education

BSC HONORS IN SCIENCE AND COMPUTING -

UNIVERSITY OF GREENWICH
United Kingdom
01.2021 - 02.2022

LEVEL 5 DIPLOMA IN COMPUTER STUDIES -

NCC EDUCATION
U.K
01.2018 - 01.2020

INTERNATIONAL L4 DEPLOMA IN COMPUTER STUDIES -

NCC EDUCATION
U.K
01.2010 - 01.2013

ZAMBIAN ECZ GRADE 12 CERTIFICATE -

DAVID KAUNDA NATIONAL TECHINICAL HIGH SCHOOL
Lusaka, Zambia
/2006 - /2008

Skills

    SKILLS

  • Digital Forensic Analysis
  • Governance Risk & Compliance
  • Review of Policies & Procedures
  • Risk Control Self Assessments (RCSA)
  • Incident Management
  • Key Risk Indicators (KRIs)
  • Business Continuity Management (BCM)
  • Cyber Awareness Trainings
  • SIEM Tools
  • Log Management
  • Endpoint Detection & Response
  • Systems Implementation
  • Builds Networks
  • Firewall, Router & Switch Configurations
  • Access Point Setups
  • Troubleshooting & Diagnostics

  • SOFT SKILLS

  • Management Skills
  • Creativity
  • Team Player
  • Critical Thinking
  • Negotiation
  • Leadership
  • Training and Development
  • Good Communicator

Accomplishments

  • 2022, Reward and Recognition - Certificate of Outstanding Performance, Commitment & Dedicated Service to the organization awarded by Smart Applications International Zambia Ltd
  • 2022, Cybersecurity & Leadership Program - Certificate awarded by Smart Applications International Zambia Ltd after having completed the cyber awareness training program

Languages

English
Fluent
Nyanja
Fluent
Bemba
Upper intermediate

Certification

  • 2025, ISACA Governance Risk & Compliance (GRC)- Certified by the Information System Audit and Control Association ISACA Zambia.
  • 2025 ICTAZ Membership - License by the Information and Communication Technology Association of Zambia.
  • 2024, IBM Cybersecurity Analyst - Certification by the International Business Machines IBM Corporation, USA.
  • 2024 Project Management (Lifecycle, Information Sharing, and Risk Management) -Certification by the International Business Machines IBM Corporation, USA.


References

1. Mr. Kabwe Kandeke, Head Operational Risk Dept, Access Bank Zambia Limited,

Head Office Access House Corner of Church Road and Nasser Road, Ridgeway Lusaka,

+260977845193, kabwe.kandeke@accessbankplc.com


2. Mr. Joseph Wahome, Country Manager, Smart Applications International Limited Zambia, 

P.O Box 31355, A501 Northgate Gardens, NAPSA Complex, Lusaka, Zambia, 

+260 96 6752047, joseph.wahome@smartapplicationsgroup.com


3. Mr. Abraham Maane, ICT Technical Operations, Smart Applications International Limited Zambia, P.O Box 31355, A501 Northgate Gardens, NAPSA Complex, Lusaka, Zambia, +260972058588, +260760538598, maaneabraham@gmail.com


4. Mr Jonathan Zulu, ICT Head of Department, Zambia Center For Accountancy Studies (ZCAS) University, Box 35243 Off Dedan Kimathi Road, Lusaka, Zambia, +260975140019, jzulu@zcas.edu.zm


5. Mr Gideon Mwanza, Senior IT Lecturer/Cisco Instructor, Zambia Center For Accountancy Studies (ZCAS) University, Box 35243 Off Dedan Kimathi Road, Lusaka, Zambia, +260964622644, gmwanza@zcas.edu.zm


6. Mr Longa, Director Wheels Tyres Services, Wheels Tyres Services Ltd, P.O Box 37079, Lusaka, Zambia, +260 977 405 920


7. Mr Mathews Benny Lilumba, Department of Security, Zambia Sugar Plc Head Office, P.O Box 670240, Mazabuka, Zambia, +260 976 869 208

Timeline

Cybersecurity and Digital Risk Analyst

ACCESS BANK ZAMBIA LIMITED
02.2025 - Current

BSC HONORS IN SCIENCE AND COMPUTING -

UNIVERSITY OF GREENWICH
01.2021 - 02.2022

LEVEL 5 DIPLOMA IN COMPUTER STUDIES -

NCC EDUCATION
01.2018 - 01.2020

Team Lead Systems Support-Hospital Operations

SMART APPLICATIONS INTERNATIONAL ZAMBIA LTD
01.2018 - 02.2025

IT Assistant and Sales Executive

WHEELS TIRES SERVICES LUSAKA
01.2017 - 01.2018

Risk and Loss Officer

ZAMBIA SUGAR PRIVATE LIMITED COMPANY-MAZABUKA
04.2016 - 11.2016

INTERNATIONAL L4 DEPLOMA IN COMPUTER STUDIES -

NCC EDUCATION
01.2010 - 01.2013

ZAMBIAN ECZ GRADE 12 CERTIFICATE -

DAVID KAUNDA NATIONAL TECHINICAL HIGH SCHOOL
/2006 - /2008
TOM MATOMOLA SANGANDU