Cyber Security Administrator (Analysis)

Company Details

Rating: No ratings yet log in to rate this company
Industry: Airlines/Aviation
Description: Kenya Airways, the leading African airline flying to more African destinations than any other carrier, takes pride in being at the forefront of connecting Africa to the world and the World to Africa through its hub Nairobi Jomo Kenyatta International Airport.

Job Details

Job Type: Full Time
Workplace Type: On-site
Qualification: Diploma
Job Experience: Mandatory
Job Location: Nairobi County, Kenya
Closing Date: Undisclosed
Salary: Not specified
Other Pay: Benefits
Job Category: Telecommunications

Job Description

Role Overview

This position sits at the offensive edge of Kenya Airways' security function, where the day-to-day work means deliberately probing networks, applications, cloud tenants, and endpoints the same way an intruder would — looking for the gaps that defenders have not yet noticed. Rather than stopping at discovery, the administrator carries each finding through to remediation: validating whether controls actually hold up, feeding detection logic back into the SOC, and helping teams understand the real-world risk behind a technical flaw. The role matters because the airline's passenger data, operational platforms, and supporting infrastructure are only as safe as the weakest seam an adversary can find first.

Key Responsibilities

  • Scope, plan, and execute penetration tests, red team exercises, and adversary emulation against internal and external networks, web and mobile applications, APIs, cloud environments, and supporting infrastructure.
  • Replicate advanced persistent threat behaviour and realistic attack chains to test whether existing preventive and detective controls hold under pressure.
  • Run recurring vulnerability scans across airline systems, then rank what surfaces by exploitability, likelihood, and the operational impact of a successful compromise.
  • Produce full written test reports covering severity ratings, reproducible proof-of-concept evidence, and prioritised fix guidance, and present those results to both engineering teams and senior leadership.
  • Evaluate the strength of security controls on information and technology systems, including previously untested issues uncovered through continuous validation, and recommend improvements to the security engineering function.
  • Translate offensive findings into SIEM tuning and new detection rules, and support incident response by reconstructing events from an attacker's point of view.
  • Work alongside developers, systems and database engineers, project managers, SOC analysts, and other security administrators to ensure every project and system passes security checks before and after go-live.
  • Collaborate with internal and external auditors on required assessments, and help define the offensive security standards, practices, and automation that keep testing efficient and repeatable.

Requirements & Qualifications

  • Bachelor's degree in Information Technology or a comparable discipline.
  • Three or more years of advanced IT experience with a substantial concentration in information security, including practical, hands-on offensive testing rather than purely administrative or compliance-focused work.
  • Proven track record performing penetration tests, ethical hacking engagements, and vulnerability assessments, and familiarity with the toolset used to measure an organisation's defensive strength.
  • Comfort working on Linux systems and writing scripts, paired with working knowledge of Windows security controls and how they are hardened.
  • Solid grasp of networking protocols and the techniques adversaries use to abuse them.
  • Ability to stand up and configure intrusion detection capabilities shaped around the organisation's own environment.
  • Exposure to security auditing and risk assessment processes, including participation in audit-driven reviews.
  • Experience responding to, analysing, and explaining information security incidents, including forensic investigation of what occurred.
  • Familiarity with common standards and regulatory frameworks relevant to aviation and enterprise environments — NIST, ISO 27001, PCI DSS, GDPR, and IOSA — and the ability to enforce practices aligned with NIST guidance.
  • Offensive security certifications are strongly preferred: OSCP, OSWE, CEH, GPEN, GWAPT, CRTP, or an equivalent credential.
  • Strong written and verbal communication, including formal report writing and the confidence to present findings to mixed technical and executive audiences.
  • Personal qualities that matter here: unquestionable integrity, composure under pressure, a genuine problem-solving instinct, an attacker's mindset balanced by ethical judgement, and the self-motivation to keep learning as threats evolve — including handling any flaw you discover responsibly and discreetly.
806 open positions on Semasocial right now · 10941 open positions in Nairobi County, Kenya · 42 posted in the last 7 days
Contact Information
CV Job Description Matcher See how well your CV matches this job and get tips to improve your chances AI Tool

This tool helps you see how closely your CV matches a job description. It also gives you simple suggestions on what to improve so you have a better chance of getting shortlisted.

Beware of Fraudsters!
Never pay anyone for job applications, interview tests, or job interviews. A genuine employer will never ask you for payment under any circumstances.
Disclaimer & TOS: We do not guarantee the authenticity of every single job posting and are not responsible for any fraudulent activity or misrepresentation by third parties. We are not involved in any stage of the interview or recruitment process and do not charge any fees from job seekers. For further details, please read the rest of the Terms of Service.