Role Overview
This position sits at the offensive edge of Kenya Airways' security function, where the day-to-day work means deliberately probing networks, applications, cloud tenants, and endpoints the same way an intruder would — looking for the gaps that defenders have not yet noticed. Rather than stopping at discovery, the administrator carries each finding through to remediation: validating whether controls actually hold up, feeding detection logic back into the SOC, and helping teams understand the real-world risk behind a technical flaw. The role matters because the airline's passenger data, operational platforms, and supporting infrastructure are only as safe as the weakest seam an adversary can find first.
Key Responsibilities
- Scope, plan, and execute penetration tests, red team exercises, and adversary emulation against internal and external networks, web and mobile applications, APIs, cloud environments, and supporting infrastructure.
- Replicate advanced persistent threat behaviour and realistic attack chains to test whether existing preventive and detective controls hold under pressure.
- Run recurring vulnerability scans across airline systems, then rank what surfaces by exploitability, likelihood, and the operational impact of a successful compromise.
- Produce full written test reports covering severity ratings, reproducible proof-of-concept evidence, and prioritised fix guidance, and present those results to both engineering teams and senior leadership.
- Evaluate the strength of security controls on information and technology systems, including previously untested issues uncovered through continuous validation, and recommend improvements to the security engineering function.
- Translate offensive findings into SIEM tuning and new detection rules, and support incident response by reconstructing events from an attacker's point of view.
- Work alongside developers, systems and database engineers, project managers, SOC analysts, and other security administrators to ensure every project and system passes security checks before and after go-live.
- Collaborate with internal and external auditors on required assessments, and help define the offensive security standards, practices, and automation that keep testing efficient and repeatable.
Requirements & Qualifications
- Bachelor's degree in Information Technology or a comparable discipline.
- Three or more years of advanced IT experience with a substantial concentration in information security, including practical, hands-on offensive testing rather than purely administrative or compliance-focused work.
- Proven track record performing penetration tests, ethical hacking engagements, and vulnerability assessments, and familiarity with the toolset used to measure an organisation's defensive strength.
- Comfort working on Linux systems and writing scripts, paired with working knowledge of Windows security controls and how they are hardened.
- Solid grasp of networking protocols and the techniques adversaries use to abuse them.
- Ability to stand up and configure intrusion detection capabilities shaped around the organisation's own environment.
- Exposure to security auditing and risk assessment processes, including participation in audit-driven reviews.
- Experience responding to, analysing, and explaining information security incidents, including forensic investigation of what occurred.
- Familiarity with common standards and regulatory frameworks relevant to aviation and enterprise environments — NIST, ISO 27001, PCI DSS, GDPR, and IOSA — and the ability to enforce practices aligned with NIST guidance.
- Offensive security certifications are strongly preferred: OSCP, OSWE, CEH, GPEN, GWAPT, CRTP, or an equivalent credential.
- Strong written and verbal communication, including formal report writing and the confidence to present findings to mixed technical and executive audiences.
- Personal qualities that matter here: unquestionable integrity, composure under pressure, a genuine problem-solving instinct, an attacker's mindset balanced by ethical judgement, and the self-motivation to keep learning as threats evolve — including handling any flaw you discover responsibly and discreetly.
806 open positions on Semasocial right now
· 10941 open positions in Nairobi County, Kenya
· 42 posted in the last 7 days
Contact Information