Security and Compliance Analyst

2 days ago


Nairobi, Nairobi Area, Kenya PYCS Full time

Job Description

SECURITY & COMPLIANCE ANALYST JOB DESCRIPTION

Job Title:
 Security&Compliance Analyst

Department:
 Software Engineering

Reports to:
 Head of Technology

Direct Reports:
 0

Location:
 Nairobi Kenya

Job Purpose

The Security and Compliance Officer is responsible for keeping our systems, applications, and data secure. This person will champion all security-related work-setting up policies, handling incidents, checking for risks, and making sure we follow important standards like PCI DSS, ISO 27001, GDPR, and any other relevant guidelines. They will also train staff, manage access controls, and respond to client and audit requests.

The role is hands-on and requires someone who can take full ownership of security and compliance from the ground up.

Key Roles and Responsibilities

  • Establish and manage the company's security processes, including policies, tools, workflows, and documentation.
  • Monitor all applications and systems daily to identify and respond to potential threats or unusual activity.
  • Monitor, manage, and update the SIEM system to detect and respond to security threats. This includes setting up alerts, reviewing logs, investigating incidents, and ensuring all key systems are sending data to the SIEM.
  • Maintain access control mechanisms including user provisioning, de-provisioning, and role-based access
  • Handle all reported security issues-investigate, resolve, and ensure proper communication and follow-up within the SLA.
  • Develop clear security playbooks and procedures for incident response, access control, and reporting.
  • Conduct regular system and application checks to identify vulnerabilities and work with the team to resolve them.
  • Identify and mitigate security vulnerabilities in coordination with relevant teams.
  • Ensure compliance with relevant standards and regulations, including PCI DSS, ISO 27001, GDPR, CBK guidelines, and others as required.
  • Maintain detailed records of incidents, and actions taken, and prepare periodic security reports for management.
  • Manage access rights across systems,ensure proper permissions, regular reviews, and timely updates.
  • Support the implementation of encryption and secure communication protocols to ensure the security of data in transit.
  • Support client and auditor requests related to security by providing clear responses and documentation.
  • Train staff on basic security practices and ensure team members follow the company's security policies.
  • Actively support employee onboarding by leading training sessions on relevant topics and providing departmental introductions to new hires.
  • Stay updated on evolving security threats, tools, and regulatory changes, and ensure internal practices are updated accordingly.
  • Support access control management within infrastructure environments, ensuring appropriate permissions are granted and reviewed periodically.
  • Participate in daily stand-ups, planning meetings, and retrospectives to learn agile development rhythms.
  • Perform any other duties as required to support the business in response to evolving needs, changes, and growth.

Requirements

Qualifications

  • Bachelor's or Master's degree in Cybersecurity, Information Technology, Computer Science, or a related field.
  • At least 4 years of experience in information security, cybersecurity, or IT risk management.
  • Knowledge of firewalls, intrusion detection systems, SIEM, and antivirus software.
  • Experience with security frameworks (ISO 27001, NIST, CIS Controls, etc.).
  • Familiarity with network security, penetration testing, and incident response.
  • Strong understanding of cloud security (AWS, Azure, GCP).
  • Certifications such as CISSP, CISM, CEH, or CompTIA Security+ (preferred).
  • Excellent problem-solving, analytical, and communication skills.

Preferred Skills

  • Experience in application and system security.
  • Knowledge of PCI DSS, ISO 27001, GDPR and regulatory guidelines.
  • Familiar with common security risks and how to prevent them.
  • Strong incident response skills, including investigation and reporting.
  • Able to set up and manage security tools (e.g., vulnerability scanners, monitoring tools).
  • Clear communicator, able to explain risks and requirements to different teams.
  • ​Proficiency in Wazuh management for effective threat detection, log analysis, and compliance reporting.


  • Nairobi, Nairobi Area, Kenya M365Connect Full time $100,000 - $120,000 per year

    Job Role: Microsoft 365 Security and Compliance Specialist Location: Remote We are a fast-growing European startup specializing in Microsoft solutions. Our team is passionate about innovation, collaboration, and building a strong brand presence across digital platforms. We're looking for motivated individuals eager to learn and grow with us Job...


  • Nairobi, Nairobi Area, Kenya Tezza Business Solutions Ltd Full time

    Job PurposeThe role holder is responsible for ensuring information systems developed and deployed meet the Bank's set cybersecurity policies, standards, and requirements as well as complying to applicable cybersecurity regulations and industry standards.The role holder will ensure that security requirements are well captured and embedded in the SDLC process...


  • Nairobi, Nairobi Area, Kenya Standard Bank Group Full time $30,000 - $60,000 per year

    Company Description Standard Bank Group is a leading Africa-focused financial services group, and an innovative player on the global stage, that offers a variety of career-enhancing opportunities – plus the chance to work alongside some of the sector's most talented, motivated professionals. Our clients range from individuals, to businesses of all sizes,...


  • Nairobi, Nairobi Area, Kenya Standard Bank Group Full time 1,200,000 - 3,600,000 per year

    Company DescriptionStandard Bank Group is a leading Africa-focused financial services group, and an innovative player on the global stage, that offers a variety of career-enhancing opportunities – plus the chance to work alongside some of the sector's most talented, motivated professionals. Our clients range from individuals, to businesses of all sizes,...


  • Nairobi, Nairobi Area, Kenya OpsArmy Careers Full time 3,600,000 - 4,000,000 per year

    Job DescriptionPosition Type:Full-TimeLocation:RemoteApply here:About The RoleWere seeking aTrust & Security Compliance Coordinatorto help us deliver clear, reliable, and professional responses to customer security inquiries. You will be an essential part of how we build confidence with prospective and existing clients by managing our compliance...

  • OSINT Analyst

    6 days ago


    Nairobi, Nairobi Area, Kenya Piedmont Global Full time $30,000 - $60,000 per year

    Position SummaryWe are seeking a detail-oriented and proactive OSINT Analyst/Researcher to support our Intelligence Unit by collecting, analysing, and interpreting publicly available information. The successful candidate will play a critical role in monitoring online sources, tracking geopolitical risks, and delivering actionable intelligence to our clients...

  • OSINT Analyst

    1 week ago


    Nairobi, Nairobi Area, Kenya Piedmont Global Full time 1,200,000 - 2,400,000 per year

    About Piedmont GlobalPiedmont Global is a leading provider of comprehensive multilingual Translation, Interpretation, and Language Training solutions in over 200 languages and dialects. The intelligence unit provides a range of services, including social media analytics, vulnerability reports, risk assessments, and extensive OSINT analysis of current...

  • Business Analyst

    2 days ago


    Nairobi, Nairobi Area, Kenya Millennium Partners Consulting Full time

    Millennium Partners (USA), and its consortium partnerCybernetica AS (Estonia), are preparing a proposal to the Kenya ICT Authority to support theKenya Revenue Authority (KRA)to simplify, enhance, and redesign itse-Invoicing platform (eTIMS)and to develop a tender for selection of a third party software developer to develop a new e-invoicing system under the...


  • Nairobi, Nairobi Area, Kenya Sibylline Ltd Full time

    Company Description About SibyllineSibylline is a leading intelligence and strategic risk consultancy in the security sector. Since 2010 we have supported businesses, governments and NGOs by providing high-quality risk analysis, due diligence and consultancy services.The firm provides an innovative, entrepreneurial and fast-growing working environment,...


  • Nairobi, Nairobi Area, Kenya Ubora Systems and Solutions Limited Full time

    Company DescriptionUbora Systems and Solutions, headquartered in Kenya, provides Integrated Solutions for ICT Infrastructure Software and SaaS Services. Founded by visionaries with 25+ years of experience in Africa's ICT Industry, we focus on aligning our Partner Eco-System to provide consistent levels of service and support. Our extensive engineering team...