Cyber Security Analyst
1 day ago
Job Purpose
The role holder is responsible for ensuring information systems developed and deployed meet the Bank's set cybersecurity policies, standards, and requirements as well as complying to applicable cybersecurity regulations and industry standards.
The role holder will ensure that security requirements are well captured and embedded in the SDLC process for all technology initiatives, secure coding practices are adhered to, and secure software and application configurations are maintained.
The specialist will carry out security testing across all technology stacks (mobile, web applications, APIs/ Microservices, code, web servers, containers, servers, databases, virtualization environments, network devices and connectivity) within assigned scrums and projects.
Responsibilities
· Work with scrums and project teams to ensure that security requirements are adequately captured during requirements analysis phase.
· Provide input into the secure design of information systems architecture during the project lifecycle.
· Ensure that access to the Bank's systems during the project lifecycle by staff, contractors and vendors is secure and based on least privilege principle.
· Enforce the implementation and adoption of the Bank's minimum security baseline standards across all technologies in use.
· Facilitate the identification of security vulnerabilities through performing or coordinating security assessments or vulnerability assessment and penetration testing (VAPT).
· Ensure security tools and checks are running as expected within all pipelines, review security reports from them.
· Report any scrums & projects security gaps identified and follow up for closure as per the Bank's standards and procedures.
· Identify any security violations and incidents during the project lifecycle and coordinate the response process.
· Ensure effective integration of the Bank's security tools to protect, detect, and respond to any attempted intrusions prior to and during project go live.
· Work together with scrums & projects units to ensure that user access matrices are well defined and in line with defined roles and responsibilities.
· Participate in deployment sessions and perform post implementation review (PIR) to ensure that security configurations are done and gaps noted in testing do not permeate into production.
· Embed the bank's cybersecurity awareness program during the project lifecycle, targeting secure coding training.
· Provide scheduled security reports to the cybersecurity project lead, project team and steering committee on progress of security workstream activities.
Skills and Experience
· Bachelor's degree in computer science, IT, or other STEM related Degree.
· Master's degree in information security, Cyber Security or Related Fields will be an added advantage.
· Information security certification in either of the following CISA/ CISM/ CISSP/CRISC/Security+; as well as testing certifications such as CSSLP/CEH/OSCP/ CPT/ GPEN/ GWAPT/eWPT/eJPT.
· years' experience in technology.
· years' experience in information security.
· years' experience in Application Security, within Secure SDLC and DevSecOps environments.
· Comprehensive technical expertise in a variety of DevSecOps toolkits, including Ansible, Jenkins, Gitlab, Azure DevOps, Trivy, SonarQube, Terraform, Git/Version Control Software, or comparable technologies.
· Familiarity with information security frameworks and standards such as PCI-DSS, ISO 27001, SABSA etc.
· Familiarity with API Security, Container Security, Cloud Security
· Experience in Project Implementation and user training.
· Ability to multi-task, respond well to pressure and deadlines, influence others, work well individually and in a team environment.
· Strong verbal and written communication skills.
· Strong analytical and problem-solving skills, and the ability to work collaboratively with cross-functional teams.
Location: Nairobi
Terms
: Full Time, On site; Contract duration: 1 Year with possibility of extension
Please share your cv to:
Emai
l:
Subject
: Prefix the subject matter as –
Cyber Security Analyst (DevSecOps)
Format:
PDF ONLY (Any other format will be automatically disqualified)
Resume:
If sending via email, ensure your resume is clearly saved with your full names correctly indicated e.g. John Smith Cv not "Latest Cv" as this will lead to automatic disqualification
Deadline:
21
st
/ October /2025
N/B:
For this position, kindly
only
apply if your profile matches the above criteria and note the job is contract based
-
Head of Security Operations
7 days ago
Nairobi, Nairobi Area, Kenya Canonical - Jobs Full time 120,000 - 180,000 per yearThis global leadership role in cyber security is to manage the Security Operations (SecOps) team responsible for design, implementation and evolution of Canonical security practices, techniques, tools, systems and policies. The team is the primary owner of strategy and practices that determine how Canonical secures its data, internal infrastructure and build...
-
Senior Security Operations Engineer
7 days ago
Nairobi, Nairobi Area, Kenya Canonical - Jobs Full time $100,000 - $200,000 per yearWe have opened several senior/staff Security Operations Engineer (SOC) positions, creating a new team reporting to the CISO. We are looking for a range of experience in these positions - at the high end we are looking for deep experience defending highly contested critical assets and high-value cyber targets against advanced persistent threats and...
-
Staff Security Operations Engineer
7 days ago
Nairobi, Nairobi Area, Kenya Canonical - Jobs Full time $120,000 - $240,000 per yearWe have opened several senior/staff Security Operations Engineer (SOC) positions, creating a new team reporting to the CISO. We are looking for a range of experience in these positions - at the high end we are looking for deep experience defending highly contested critical assets and high-value cyber targets against advanced persistent threats and...
-
IT & Security Lead
1 day ago
Nairobi, Nairobi Area, Kenya Cadmus Full time $60,000 - $120,000 per yearEqual Access to High-Quality Education Moves Our World ForwardMeet CadmusAt Cadmus, we believe every student should have equal opportunity to achieve academic excellence; that's why we're changing how the world learnsCadmus is a global EdTech company purposefully built for the higher education sector to break down global learning barriers by providing...
-
IT & Security Lead
1 day ago
Nairobi, Nairobi Area, Kenya Cadmus Full time 120,000 - 180,000 per yearEqual Access to High-Quality Education Moves Our World ForwardMeet CadmusAt Cadmus, we believe every student should have equal opportunity to achieve academic excellence; that's why we're changing how the world learnsCadmus is a global EdTech company purposefully built for the higher education sector to break down global learning barriers by providing...
-
Security Risk Management Specialist
7 days ago
Nairobi, Nairobi Area, Kenya Canonical - Jobs Full time $120,000 - $180,000 per yearIn security risk management we're looking to harness the power of industry best practice combined with driving new innovation on how we do security risk assessments and modelling. Our security risk management team is the primary owner of the strategy and practices of how we identify, track and reduce our security risk across everything we do. To support...
-
Embedded Intelligence Analyst
1 day ago
Nairobi, Nairobi Area, Kenya Sibylline Ltd Full timeCompany Description About SibyllineSibylline is a leading intelligence and strategic risk consultancy in the security sector. Since 2010 we have supported businesses, governments and NGOs by providing high-quality risk analysis, due diligence and consultancy services.The firm provides an innovative, entrepreneurial and fast-growing working environment,...
-
OSINT Analyst
1 day ago
Nairobi, Nairobi Area, Kenya Piedmont Global Full time 120,000 - 180,000 per yearPosition SummaryWe are seeking a detail-oriented and proactive OSINT Analyst/Researcher to support our Intelligence Unit by collecting, analysing, and interpreting publicly available information. The successful candidate will play a critical role in monitoring online sources, tracking geopolitical risks, and delivering actionable intelligence to our clients...
-
Product Security Engineer- Mobile
1 week ago
Nairobi, Nairobi Area, Kenya Sun King Full time $30,000 - $60,000 per yearDepartment Global Analytics and Technology Employment Type Permanent - Full Time Location Kenya Workplace type Onsite Reporting To Head of Cyber Security What you would be expected to do: You might be a strong candidate if you: What we offer: About Sun King Sun King is the world's leading off-grid solar energy company, combining cutting-edge...
-
OSINT Analyst
2 weeks ago
Nairobi, Nairobi Area, Kenya Piedmont Global Full time 1,200,000 - 2,400,000 per yearAbout Piedmont GlobalPiedmont Global is a leading provider of comprehensive multilingual Translation, Interpretation, and Language Training solutions in over 200 languages and dialects. The intelligence unit provides a range of services, including social media analytics, vulnerability reports, risk assessments, and extensive OSINT analysis of current...