Role Overview
As Zamara's Network & Security Engineer, you will spend your days hardening the company's technology estate — servers, networks, cloud tenants, and end-user devices alike — so that protection is designed into systems rather than added after go-live. You will be the person tuning controls, triaging alerts, driving vulnerabilities to closure, and keeping the evidence trail ready for audits and regulators. The role matters because Zamara's strategic ambitions depend on keeping client and business data trustworthy, available, and defensible at all times.
Key Responsibilities
- Define and enforce hardened configuration baselines across servers, network equipment, cloud workloads, and endpoints, so nothing enters production on default or unverified settings.
- Turn recognised standards such as ISO 27001, NIST, and CIS benchmarks into documented, workable controls, then test them on a regular cycle to confirm they still hold.
- Operate identity and access management day to day — administering roles in Active Directory and Azure AD, applying least privilege across environments, and strengthening sign-in through MFA and conditional access policies.
- Run the monitoring stack, including SIEM, endpoint detection, and log collection; investigate suspicious activity, unauthorised access attempts, and anomalies; and maintain alerting and incident reporting that reaches the right people quickly.
- Protect sensitive data against unauthorised access, corruption, deletion, or exfiltration, and keep backup, disaster recovery, and ransomware defences exercised rather than assumed.
- Conduct vulnerability assessments, coordinate penetration testing, and track remediation through to closure with the teams who own each affected system.
- Maintain the risk register and mitigation tracker, support DPIAs and regulatory audits, and govern third-party and vendor access so external parties reach only what their work requires.
- Build security awareness across IT and the wider business, and embed security checks into DevOps pipelines and system development workflows so new work starts secure.
Requirements & Qualifications
- Bachelor's degree in information security, computer science, or a closely related field.
- Five or more years in cybersecurity or IT security operations, including hands-on delivery of security controls in an enterprise environment.
- Applied knowledge of ISO 27001, NIST, and CIS Controls, with the ability to convert framework language into procedures colleagues can actually follow.
- Practical experience with identity and access management, Active Directory, and Azure AD, plus authentication design covering MFA and conditional access.
- Familiarity with endpoint security tooling, SIEM platforms, and logging and monitoring solutions.
- Exposure to vulnerability management tools and to coordinating penetration testing engagements.
- Cloud security experience, with Azure preferred, supported by solid network security fundamentals.
- Understanding of backup, disaster recovery, and data protection technologies.
- Core competencies: strong analytical and risk assessment ability, close attention to detail, a proactive rather than reactive mindset, sound judgement in balancing security against business needs, confident stakeholder engagement and communication, and a high standard of integrity and personal ownership.
823 open positions on Semasocial right now
· 11153 open positions in Nairobi County, Kenya
· 38 posted in the last 7 days
Contact Information