Network & Security Engineer (1 Year Contract)

Company Details

Rating: No ratings yet — log in to rate this company
Industry: Banking
Description: Zamara is a financial services firm that primarily offers Actuarial Services, Pensions Administration and Consulting and Insurance Brokerage Services. Zamara has been in the Kenyan Market for over 23 years, initially operating as Hymans Robertson and more recently as Alexander Forbes. Working at Zam… Zamara is a financial services firm that primarily offers Actuarial Services, Pensions Administration and Consulting and Insurance Brokerage Services. Zamara has been in the Kenyan Market for over 23 years, initially operating as Hymans Robertson and more recently as Alexander Forbes. Working at Zamara offers our people the opportunity to work for a Truly Pan-African Financial Services firm. Our Values - Simplicity, Empathy and Trust, set a solid foundation for an environment that awards achievement and appreciates hard work, innovation and high levels of professionalism across all departments. We have an strong coaching and mentorship approach that enables us continuously grow our people. View more View less

Job Details

Job Type: Full Time
Workplace Type: On-site
Qualification: Diploma
Job Experience: Mandatory
Job Location: Nairobi County, Kenya
Closing Date: Undisclosed
Salary: Not specified
Other Pay: Benefits
Job Category: Telecommunications

Job Description

Role Overview

As Zamara's Network & Security Engineer, you will spend your days hardening the company's technology estate — servers, networks, cloud tenants, and end-user devices alike — so that protection is designed into systems rather than added after go-live. You will be the person tuning controls, triaging alerts, driving vulnerabilities to closure, and keeping the evidence trail ready for audits and regulators. The role matters because Zamara's strategic ambitions depend on keeping client and business data trustworthy, available, and defensible at all times.

Key Responsibilities

  • Define and enforce hardened configuration baselines across servers, network equipment, cloud workloads, and endpoints, so nothing enters production on default or unverified settings.
  • Turn recognised standards such as ISO 27001, NIST, and CIS benchmarks into documented, workable controls, then test them on a regular cycle to confirm they still hold.
  • Operate identity and access management day to day — administering roles in Active Directory and Azure AD, applying least privilege across environments, and strengthening sign-in through MFA and conditional access policies.
  • Run the monitoring stack, including SIEM, endpoint detection, and log collection; investigate suspicious activity, unauthorised access attempts, and anomalies; and maintain alerting and incident reporting that reaches the right people quickly.
  • Protect sensitive data against unauthorised access, corruption, deletion, or exfiltration, and keep backup, disaster recovery, and ransomware defences exercised rather than assumed.
  • Conduct vulnerability assessments, coordinate penetration testing, and track remediation through to closure with the teams who own each affected system.
  • Maintain the risk register and mitigation tracker, support DPIAs and regulatory audits, and govern third-party and vendor access so external parties reach only what their work requires.
  • Build security awareness across IT and the wider business, and embed security checks into DevOps pipelines and system development workflows so new work starts secure.

Requirements & Qualifications

  • Bachelor's degree in information security, computer science, or a closely related field.
  • Five or more years in cybersecurity or IT security operations, including hands-on delivery of security controls in an enterprise environment.
  • Applied knowledge of ISO 27001, NIST, and CIS Controls, with the ability to convert framework language into procedures colleagues can actually follow.
  • Practical experience with identity and access management, Active Directory, and Azure AD, plus authentication design covering MFA and conditional access.
  • Familiarity with endpoint security tooling, SIEM platforms, and logging and monitoring solutions.
  • Exposure to vulnerability management tools and to coordinating penetration testing engagements.
  • Cloud security experience, with Azure preferred, supported by solid network security fundamentals.
  • Understanding of backup, disaster recovery, and data protection technologies.
  • Core competencies: strong analytical and risk assessment ability, close attention to detail, a proactive rather than reactive mindset, sound judgement in balancing security against business needs, confident stakeholder engagement and communication, and a high standard of integrity and personal ownership.
823 open positions on Semasocial right now · 11153 open positions in Nairobi County, Kenya · 38 posted in the last 7 days
Contact Information
CV Job Description Matcher See how well your CV matches this job and get tips to improve your chances AI Tool

This tool helps you see how closely your CV matches a job description. It also gives you simple suggestions on what to improve so you have a better chance of getting shortlisted.

Similar Jobs

AirKenya Express Ltd Nairobi County, Kenya
View Job Oct 30, 2026
View Job Sep 24, 2026
View Job Sep 24, 2026
Beware of Fraudsters!
Never pay anyone for job applications, interview tests, or job interviews. A genuine employer will never ask you for payment under any circumstances.
Disclaimer & TOS: We do not guarantee the authenticity of every single job posting and are not responsible for any fraudulent activity or misrepresentation by third parties. We are not involved in any stage of the interview or recruitment process and do not charge any fees from job seekers. For further details, please read the rest of the Terms of Service.