Role Overview
This role places you at the centre of the security operation behind a real-time interbank payments platform, where the systems you protect are the same ones moving money between institutions every second of the day. The work is a genuine mix of hands-on engineering and forward design: tuning detection tools and hardening endpoints on one hand, shaping Zero Trust architecture and secure development practices on the other. Because the organisation operates in a regulated payments environment, your judgement calls directly determine whether transactions keep flowing safely and whether the business stays aligned with central bank cybersecurity guidance and card industry standards.
Key Responsibilities
- Architect security for new systems and services using Zero Trust and micro-segmentation principles, and translate regulatory obligations into working controls across both on-premise and cloud estates.
- Build and maintain cloud security guardrails in AWS, Azure or GCP that protect workloads, data and services from misconfiguration and attack.
- Deploy, tune and monitor detection and response tooling such as SIEM, EDR, WAF and IAM, while rolling endpoint protection out to every laptop and device to shut down malware, viruses and shadow IT.
- Implement Zero Trust Network Access and privileged access management so that people and systems reach only what their role requires, applying least-privilege and role-based models.
- Run the vulnerability management cycle end to end — scanning, interpreting reports, prioritising fixes, coordinating patching with system owners and tracking every item through to closure.
- Harden the Google Workspace environment, covering security configuration, access controls, mobile device management and data protection settings.
- Protect data at rest through encryption, secure key management and access controls, and manage the full certificate lifecycle from issuance and renewal to revocation.
- Embed security into the software development lifecycle alongside DevOps teams through threat modelling, secure code review and automated testing in CI/CD pipelines, and assess API and application security in partnership with developers.
- Work with infrastructure colleagues to keep network devices hardened and monitored, and stay ahead of emerging threats by evaluating new security technologies and leading improvement initiatives.
Requirements & Qualifications
- A bachelor's degree in computer science, information security or a closely related discipline.
- At least three years in cybersecurity, ideally gained within payments, FinTech or broader financial services.
- Certifications such as CISSP, CEH, CISM or OSCP are a distinct advantage.
- Practical experience integrating security tooling (SIEM, IDS/IPS, EDR) and operating against frameworks including PCI DSS, ISO 27001 or NIST.
- Hands-on cloud security experience with AWS, GCP or Azure.
- Strong grounding in network security concepts — firewalls, routing, network segmentation — alongside cloud security fundamentals.
- Proficiency with SIEM, IDS/IPS, EDR, WAF, IAM and vulnerability scanning platforms.
- Familiarity with DevSecOps practice: CI/CD pipelines, containerisation and automation scripting.
- Working knowledge of modern application security, including the OWASP Top 10, API security and secure coding techniques.
- Comfort operating across Windows and Linux environments, with scripting ability in Python or Bash.
- Demonstrated expertise in security assessments and vulnerability management.
- Clear verbal and written communication, a collaborative approach in cross-functional teams, and the documentation discipline needed to maintain security standards and shared records.
If you bring comparable experience from a FinTech or financial services setting, we would like to hear from you. Send your CV and a cover letter in PDF format to the Recruiting Manager at [email protected], quoting Information Security as the subject of your application. The advert closes at 5.00pm EAT on Wednesday, 14th October, 2026. Every application goes through a fair and competitive recruitment process, and only shortlisted candidates will be contacted.
866 open positions on Semasocial right now
· 11658 open positions in Nairobi County, Kenya
· 28 posted in the last 7 days
Contact Information