Cyber Security Analyst

2 days ago


Nairobi, Nairobi Area, Kenya Tezza Business Solutions Ltd Full time

Job Purpose

The role holder is responsible for ensuring information systems developed and deployed meet the Bank's set cybersecurity policies, standards, and requirements as well as complying to applicable cybersecurity regulations and industry standards.

The role holder will ensure that security requirements are well captured and embedded in the SDLC process for all technology initiatives, secure coding practices are adhered to, and secure software and application configurations are maintained.

The specialist will carry out security testing across all technology stacks (mobile, web applications, APIs/ Microservices, code, web servers, containers, servers, databases, virtualization environments, network devices and connectivity) within assigned scrums and projects.

Responsibilities

·      Work with scrums and project teams to ensure that security requirements are adequately captured during requirements analysis phase.

·      Provide input into the secure design of information systems architecture during the project lifecycle.

·      Ensure that access to the Bank's systems during the project lifecycle by staff, contractors and vendors is secure and based on least privilege principle.

·      Enforce the implementation and adoption of the Bank's minimum security baseline standards across all technologies in use.

·      Facilitate the identification of security vulnerabilities through performing or coordinating security assessments or vulnerability assessment and penetration testing (VAPT).

·      Ensure security tools and checks are running as expected within all pipelines, review security reports from them.

·      Report any scrums & projects security gaps identified and follow up for closure as per the Bank's standards and procedures.

·      Identify any security violations and incidents during the project lifecycle and coordinate the response process.

·      Ensure effective integration of the Bank's security tools to protect, detect, and respond to any attempted intrusions prior to and during project go live.

·      Work together with scrums & projects units to ensure that user access matrices are well defined and in line with defined roles and responsibilities.

·      Participate in deployment sessions and perform post implementation review (PIR) to ensure that security configurations are done and gaps noted in testing do not permeate into production.

·      Embed the bank's cybersecurity awareness program during the project lifecycle, targeting secure coding training.

·      Provide scheduled security reports to the cybersecurity project lead, project team and steering committee on progress of security workstream activities.

Skills and Experience

·      Bachelor's degree in computer science, IT, or other STEM related Degree.

·      Master's degree in information security, Cyber Security or Related Fields will be an added advantage.

·      Information security certification in either of the following CISA/ CISM/ CISSP/CRISC/Security+; as well as testing certifications such as CSSLP/CEH/OSCP/ CPT/ GPEN/ GWAPT/eWPT/eJPT.

· years' experience in technology.

· years' experience in information security.

· years' experience in Application Security, within Secure SDLC and DevSecOps environments.

·      Comprehensive technical expertise in a variety of DevSecOps toolkits, including Ansible, Jenkins, Gitlab, Azure DevOps, Trivy, SonarQube, Terraform, Git/Version Control Software, or comparable technologies.

·      Familiarity with information security frameworks and standards such as PCI-DSS, ISO 27001, SABSA etc.

·      Familiarity with API Security, Container Security, Cloud Security

·      Experience in Project Implementation and user training.

·      Ability to multi-task, respond well to pressure and deadlines, influence others, work well individually and in a team environment.

·      Strong verbal and written communication skills.

·      Strong analytical and problem-solving skills, and the ability to work collaboratively with cross-functional teams.

Location: Nairobi

Terms
: Full Time, On site; Contract duration: 1 Year with possibility of extension

Please share your cv to:

Emai
l:

Subject
: Prefix the subject matter as –
Cyber Security Analyst (DevSecOps)

Format:
PDF ONLY (Any other format will be automatically disqualified)

Resume:
If sending via email, ensure your resume is clearly saved with your full names correctly indicated e.g. John Smith Cv not "Latest Cv" as this will lead to automatic disqualification

Deadline:
21
st
/ October /2025

N/B:
For this position, kindly
only
apply if your profile matches the above criteria and note the job is contract based



  • Nairobi, Nairobi Area, Kenya NTT DATA, Inc. Full time 1,200,000 - 2,400,000 per year

    Make an impact with NTT DATAJoin a company that is pushing the boundaries of what is possible. We are renowned for our technical excellence and leading innovations, and for making a difference to our clients and society. Our workplace embraces diversity and inclusion – it's a place where you can grow, belong and thrive.Your day at NTT DATAThe Senior...


  • Nairobi, Nairobi Area, Kenya I&M Bank Uganda Full time $150,000 - $200,000 per year

    Job PurposeThe Group Head Application Security & Red Team Operations is responsible for embedding security across the software development lifecycle, driving secure engineering practices, and leading proactive offensive security operations. This role will ensure applications and infrastructure are built, deployed, and operated securely while driving a robust...


  • Nairobi, Nairobi Area, Kenya HFC Kenya Full time 900,000 - 1,200,000 per year

    HFC Limited, the banking and property finance subsidiary of HF Group, has an exciting opportunity in our ICT Department. We are seeking a talented, dynamic, self-driven, and results-oriented individual who is committed to performance, excellence, and participating in our growth strategy.The SOC Analyst's role is to monitor, detect, and respond to security...


  • Nairobi, Nairobi Area, Kenya Sun King Full time 900,000 - 1,200,000 per year

    Mobile Security EngineerDepartment: Global Analytics and TechnologyEmployment Type: Permanent - Full TimeLocation: KenyaReporting To: Head of Cyber SecurityDescription Location: Nairobi, Kenya​​About the role:We are looking for a Security Engineer to join our Cyber Security Team, which provides intelligence on hacking of Sun King devices that in turn...


  • Nairobi, Nairobi Area, Kenya CloudFactory Full time 1,200,000 - 2,400,000 per year

    Role SummaryTo support the administration and management of Security Services across the Global IT function. Working within the SecOps function, the role will serve to grow and maintain a disciplined IT security function which safeguards IT assets, business information and workers from security and compliance breaches.Responsibilities:Manage and maintain the...

  • Data Analyst

    2 days ago


    Nairobi, Nairobi Area, Kenya TEZZRA TECHNOLOGIES Full time 1,200,000 - 2,400,000 per year

    Company DescriptionTezzra Technologies is your partner in digital transformation, offering customized IT solutions to drive efficiency, enhance security, and foster growth in a rapidly evolving digital landscape. Our expertise spans IT support, cloud solutions, integrations, and AI, providing businesses with the tools needed to thrive. We are committed to...

  • OSINT Analyst

    1 week ago


    Nairobi, Nairobi Area, Kenya Piedmont Global Full time 1,200,000 - 2,400,000 per year

    About Piedmont GlobalPiedmont Global is a leading provider of comprehensive multilingual Translation, Interpretation, and Language Training solutions in over 200 languages and dialects. The intelligence unit provides a range of services, including social media analytics, vulnerability reports, risk assessments, and extensive OSINT analysis of current...


  • Nairobi, Nairobi Area, Kenya I&M Bank Limited Full time 1,200,000 - 2,400,000 per year

    Job PurposeThe DevSecOps specialist is responsible for embedding security into the software development lifecycle (SDLC) and CI/CD pipelines, ensuring applications and cloud-native workloads are secure by design. Reporting to the Head Application Security & Red Team Operations, this role acts as a technical enabler for development teams, integrating...


  • Nairobi, Nairobi Area, Kenya I&M Bank Uganda Full time 1,500,000 - 3,000,000 per year

    Job PurposeThe DevSecOps specialist is responsible for embedding security into the software development lifecycle (SDLC) and CI/CD pipelines, ensuring applications and cloud-native workloads are secure by design. Reporting to the Head Application Security & Red Team Operations, this role acts as a technical enabler for development teams, integrating...

  • ICT Analyst

    2 weeks ago


    Nairobi, Nairobi Area, Kenya International Fund for Agricultural Development (IFAD) Full time 900,000 - 1,200,000 per year

    This job is based in Rome, Italy.Organizational SettingThe International Fund for Agricultural Development (IFAD) is an international financial institution and a specialized United Nations agency dedicated to eradicating rural poverty and hunger. It does so by investing in rural people. IFAD finances programmes and projects that increase agricultural...