Lead Application Security
1 day ago
Job Purpose
The Group Head Application Security & Red Team Operations is responsible for embedding security across the software development lifecycle, driving secure engineering practices, and leading proactive offensive security operations. This role will ensure applications and infrastructure are built, deployed, and operated securely while driving a robust red team program to continuously assess and improve the Bank's cyber resilience.
The role requires a strategic, hands-on cyber leader with deep expertise in threat emulation, vulnerability exploitation, and adversary simulation, as well as the ability to partner closely with other security and technology teams to strengthen the Group's defensive posture.
Key Responsibilities
- Develop, implement, and maintain the Group's Red Team strategy, ensuring realistic simulation of cyber threats, including advanced persistent threats (APTs), insider threats, and emerging attack vectors.
- Assist with CyberSecurity Forensics.
- Oversee targeted threat hunting initiatives, leveraging threat intelligence and advanced analytics to identify potential breaches and vulnerabilities.
- Collaborate with the Group SOC team to translate intelligence into actionable detection and defence improvements.
- Direct incident simulation and adversarial testing exercises to validate the effectiveness of security controls, processes, and incident response readiness.
- Lead red team/purple team engagements to evaluate the resilience of critical assets and infrastructure.
- Partner with the SOC, Technology, Risk, and Compliance teams to ensure defensive measures align with regulatory requirements, internal policies, and industry best practices.
- Establish and maintain key cyber resilience metrics, reporting to executive leadership and governance forums on threat trends, testing outcomes, and operational readiness.
- Select, deploy, and optimise advanced testing and adversary simulation tools and platforms to enhance operational capability.
- Embed cloud security controls in CI/CD. Build, mentor, and retain a high-performing red team and application security workforce capable of countering evolving and sophisticated threats.
Job Dimensions
Financial Responsibility:
N/A
Job Specifications
Academic Qualifications
- Bachelor's Degree in IT, Technology, Cyber Security, or a related field – mandatory
- Master's Degree in Cyber Security, Information Assurance or a related field – desirable
Professional Qualifications / Membership To Professional Bodies/ Publication
- Offensive Security Certifications
- Certified Red Team Certifications
- Certified Secure Software Lifecycle Proffessional (CSSLP)
- Cloud Pentester Certifications
- ISO/IEC 27001 Lead Implementer/Auditor
- Membership in recognised cyber security professional associations (e.g., ISACA, SANS, ISC2)
Work Experience Required
- 10+ years of progressive experience in cyber security, with at least 5 years in a senior leadership role focused on Red Teaming, threat hunting, and adversary simulation within the financial services sector.
- Proven track record in planning and executing complex red team and penetration testing engagements against advanced threat actors.
- Hands-on expertise in exploitation techniques, attack path development, and evasion tactics.
- Strong background in vulnerability assessment, adversarial emulation frameworks (e.g., MITRE ATT&CK, CALDERA, C2 frameworks), and purple teaming.
- Demonstrated experience in integrating threat intelligence into testing and defence strategies.
- Familiarity with banking regulations, data protection laws, and industry cyber security standards (e.g., NIST, ISO
Competencies
- Deep technical knowledge of Application, DevSecOps and offensive security.
- Strong understanding of adversarial tactics, techniques, and procedures (TTPs) and their countermeasures.
- Strong technical expertise in cloud security, CI/CD pipelines, secure SDLC, SAST/DAST, penetration testing, threat modeling, and container security.
- Exceptional analytical and problem-solving skills, with the ability to design and execute creative attack simulations.
- Hands-on knowledge of offensive security tools, frameworks, and red team methodologies.
- Excellent leadership skills, with the ability to inspire and develop high-performing teams.
- Strong stakeholder engagement and communication skills, capable of influencing executive decision-making.
- Strategic mindset, aligning cyber defence and testing capabilities with business objectives and evolving threat landscapes.
- High ethical standards, integrity, and commitment to responsible security testing practices.
If you believe you meet the above requirements log onto our
and click on careers and apply for the position. Your application should reach us as soon as possible but not later than 3rd September 2025.
-
Cyber Security Analyst
1 day ago
Nairobi, Nairobi Area, Kenya Tezza Business Solutions Ltd Full timeJob PurposeThe role holder is responsible for ensuring information systems developed and deployed meet the Bank's set cybersecurity policies, standards, and requirements as well as complying to applicable cybersecurity regulations and industry standards.The role holder will ensure that security requirements are well captured and embedded in the SDLC process...
-
Network Security Engineer
7 days ago
Nairobi, Nairobi Area, Kenya NTT DATA, Inc. Full time 1,200,000 - 2,400,000 per yearMake an impact with NTT DATAJoin a company that is pushing the boundaries of what is possible. We are renowned for our technical excellence and leading innovations, and for making a difference to our clients and society. Our workplace embraces diversity and inclusion – it's a place where you can grow, belong and thrive.Your day at NTT DATAThe Network...
-
Network Security Engineer
1 week ago
Nairobi, Nairobi Area, Kenya NTT Ltd. Full time 1,200,000 - 2,400,000 per yearMake an impact with NTT DATAJoin a company that is pushing the boundaries of what is possible. We are renowned for our technical excellence and leading innovations, and for making a difference to our clients and society. Our workplace embraces diversity and inclusion – it's a place where you can grow, belong and thrive. Your day at NTT DATAThe Network...
-
Security Manager
2 weeks ago
Nairobi, Nairobi Area, Kenya Old Mutual Limited Full time 900,000 - 1,200,000 per yearLets Write Africa's Story Together Old Mutual is a firm believer in the African opportunity and our diverse talent reflects this.Job DescriptionJOB SUMMARYThe security manager is responsible for keeping facilities and people safe and secure. The Job holder oversee and ensures security procedures, monitor and respond to incidents, secure entrances, and...
-
Network Security Engineer
7 days ago
Nairobi, Nairobi Area, Kenya NTT DATA Full time $90,000 - $120,000 per yearContinue to make an impact with a company that is pushing the boundaries of what is possible. At NTT DATA, we are renowned for our technical excellence, leading innovations, and making a difference for our clients and society. Our workplace embraces diversity and inclusion – it's a place where you can continue to grow, belong, and thrive.Your career here...
-
Readvertisement Security Associate G6
1 day ago
Nairobi, Nairobi Area, Kenya World Food Programme Full time $40,000 - $60,000 per yearDEADLINE FOR APPLICATIONS15 September :59-GMT+03:00 East Africa Time (Mogadishu)WFP celebrates and embraces diversity. It is committed to the principle of equal employment opportunity for all its employees and encourages qualified candidates to apply irrespective of race, colour, national origin, ethnic or social background, genetic information, gender,...
-
Senior Information Security Engineer
1 day ago
Nairobi, Nairobi Area, Kenya Indsafri Full time 104,000 - 130,878 per yearJob Role: Information Security EngineerExp Required: Atleast 3+ Years of relevant work experience as Information Security engineerJob type: Full time - PermanentJob Location: Nairobi, Kenya**************KINDLY DO NOT APPLY IF YOU HAVE LESS THAN 3+ YEARS OF RELEVANT WORK EXPERIENCE IN INFORMATION SECURITY ENGINEER ROLE *******************************KINDLY DO...
-
Systems Engineer Networks Security
1 day ago
Nairobi, Nairobi Area, Kenya NTT Ltd. Full time $104,000 - $130,878 per yearMake an impact with NTT DATAJoin a company that is pushing the boundaries of what is possible. We are renowned for our technical excellence and leading innovations, and for making a difference to our clients and society. Our workplace embraces diversity and inclusion – it's a place where you can grow, belong and thrive. Your day at NTT DATAThe Senior...
-
Regional Security Officer
1 day ago
Nairobi, Nairobi Area, Kenya Co-operative Bank of Kenya Full time 900,000 - 1,200,000 per yearAre you a security professional with a proven track record in law enforcement, intelligence gathering, and stakeholder engagement? Do you thrive in environments where vigilance, proactive risk management, and collaboration make all the difference? If so, this is your opportunity to play a critical role in protecting one of Kenya's most trusted financial...
-
Tier 2 Security Operations Centre
1 day ago
Nairobi, Nairobi Area, Kenya NTT DATA, Inc. Full time 1,200,000 - 2,400,000 per yearMake an impact with NTT DATAJoin a company that is pushing the boundaries of what is possible. We are renowned for our technical excellence and leading innovations, and for making a difference to our clients and society. Our workplace embraces diversity and inclusion – it's a place where you can grow, belong and thrive.Your day at NTT DATAThe Senior...