Lead Application Security & Red Team Operations

or Register to apply for this job
Company Details
Name: I&M Bank
Industry: Banking
Description: I&M Bank is a wholly owned subsidiary of I&M Holdings Limited, a publicly quoted company at the Nairobi Securities Exchange (NSE). The bank possesses a rich heritage in banking. Started in 1974, it evolved from a community financial institution to a publicly listed major regional commercial bank offering a full range of corporate and retail banking services, 35 branches in Kenya and international operations in 3 other countries. I&M Bank is a dominant player in the Kenyan market that has been consistently growing, and is innovative in terms of the type and range of products and services it offers. CDC Group plc, a development finance institution wholly owned by the government of the United Kingdom owns approximately 10.68% of I&M Holdings, the holding company of I&M Bank Ltd. In addition, I&M Bank has a technical support agreement with International Finance Corporation for staff training, product development and risk management. I&M Bank also enjoys medium term foreign currency credit facilities from European Development Financial Institutions - Proparco, DEG and FMO. I&M Bank’s international correspondent banks include major multinational banks such as Bank One Ltd, Citibank NA, CommerzBank AG, Deutsche Bank AG, ICICI Limited Mumbai, Mashreq Bank PLC, Standard Bank of South Africa and Standard Chartered Bank NY. I&M Bank’s international network includes Bank One Limited (Mauritius), I&M Bank Tanzania Limited and I&M Bank Rwanda Specialties Banking Services, Commercial Banking, Asset Finance, Mobile Banking, Internet Banking, Investment Management Services, Diaspora Banking, Credit / Debit / Prepaid cards, Wealth Management
Job Description

The role requires a strategic, hands-on cyber leader with deep expertise in threat emulation, vulnerability exploitation, and adversary simulation, as well as the ability to partner closely with other security and technology teams to strengthen the Group’s defensive posture.

 

Key Responsibilities

 

Develop, implement, and maintain the Group’s Red Team strategy, ensuring realistic simulation of cyber threats, including advanced persistent threats (APTs), insider threats, and emerging attack vectors.

 

Assist with CyberSecurity Forensics.

 

Oversee targeted threat hunting initiatives, leveraging threat intelligence and advanced analytics to identify potential breaches and vulnerabilities.

 

Collaborate with the Group SOC team to translate intelligence into actionable detection and defence improvements.

 

Direct incident simulation and adversarial testing exercises to validate the effectiveness of security controls, processes, and incident response readiness.

 

Lead red team/purple team engagements to evaluate the resilience of critical assets and infrastructure.

 

Partner with the SOC, Technology, Risk, and Compliance teams to ensure defensive measures align with regulatory requirements, internal policies, and industry best practices.

 

Establish and maintain key cyber resilience metrics, reporting to executive leadership and governance forums on threat trends, testing outcomes, and operational readiness.

 

Select, deploy, and optimise advanced testing and adversary simulation tools and platforms to enhance operational capability.

 

Embed cloud security controls in CI/CD.  Build, mentor, and retain a high-performing red team and application security workforce capable of countering evolving and sophisticated threats.

 

Job Specifications

 

Academic Qualifications

 

Bachelor’s Degree in IT, Technology, Cyber Security, or a related field – mandatory

 

Master’s Degree in Cyber Security, Information Assurance or a related field – desirable

 

Professional Qualifications / Membership to professional bodies/ Publication  

 

Offensive Security Certifications

 

Certified Red Team Certifications

 

Certified Secure Software Lifecycle Proffessional (CSSLP)

 

Cloud Pentester Certifications

 

ISO/IEC 27001 Lead Implementer/Auditor 

 

Membership in recognised cyber security professional associations (e.g., ISACA, SANS, ISC2)

 

Work Experience Required

 

10+ years of progressive experience in cyber security, with at least 5 years in a senior leadership role focused on Red Teaming, threat hunting, and adversary simulation within the financial services sector.

 

Proven track record in planning and executing complex red team and penetration testing engagements against advanced threat actors.

 

Hands-on expertise in exploitation techniques, attack path development, and evasion tactics.

 

Strong background in vulnerability assessment, adversarial emulation frameworks (e.g., MITRE ATT&CK, CALDERA, C2 frameworks), and purple teaming.

 

Demonstrated experience in integrating threat intelligence into testing and defence strategies.

 

Familiarity with banking regulations, data protection laws, and industry cyber security standards (e.g., NIST, ISO 27001).

 

 

 

Education: Degree, Diploma
Employment Type: Full Time

Recent Jobs