Principal Engineer Cybersecurity Assurance

Company Details

Name:NCBA Group
Rating: No ratings yet log in to rate this company
Industry: Banking
Description: On 6th December 2018, it was announced that NIC Bank, an institution with a rich history of retail banking; and CBA Bank, a forerunner of innovation in the banking space, would be merging to form a new bank with unmatched strength, expertise and regional reach.
,,,,
,,,The new NCBA has harnessed t…
On 6th December 2018, it was announced that NIC Bank, an institution with a rich history of retail banking; and CBA Bank, a forerunner of innovation in the banking space, would be merging to form a new bank with unmatched strength, expertise and regional reach. ,,,, ,,,The new NCBA has harnessed the power of both NIC and CBA to create a bank that brings together the best of both worlds — from cutting edge mobile banking to good old-fashioned relationship management; from scalable business banking to financial services that grow as your business does; from best-in-class choice of products to investment solutions tailored to your specific needs. ,,,, ,,,Our extensive branch network and friendly service mean that you are part of the most universal yet personal bank in East Africa. View more View less

Job Details

Job Type: Full Time
Workplace Type: On-site
Qualification: Diploma
Job Experience: Mandatory
Job Location: Nairobi County, Kenya
Closing Date: Undisclosed
Salary: Estimated: KES 45,000 - KES 300,000 / month
Other Pay: Benefits
Job Category: Telecommunications

Job Description

Role Overview

This position centers on continuously examining live production systems to uncover weaknesses in general IT controls before they become compliance findings. You will serve as an internal early-warning function, validating access permissions, system hardening, and control effectiveness, then ensuring that unresolved risks are logged and managed through the organisation's formal risk register. Your work directly supports the company’s ability to pass external audits and maintain a credible security posture while keeping production operations stable.

Key Responsibilities

  • Perform scheduled and ad-hoc assessments of production environments, reviewing whether IT general controls are correctly configured, enforced, and aligned with internal policy and external standards.
  • Inspect user access rights, privileged accounts, segregation of duties, data integrity safeguards, and baseline configurations to detect deviations that could expose the organisation to attack or non-compliance.
  • Translate audit observations into concrete remediation guidance, prioritising findings by severity and practical impact, and following up with system owners to confirm fixes are applied.
  • Work alongside governance and compliance colleagues to capture issues that cannot be resolved immediately in the Risk Control Self-Assessment, including detailed action plans and ownership for each item.
  • Keep the RCSA documentation current so it accurately reflects the security and compliance condition of production systems as changes occur over time.
  • Deliver status updates and summary reports to management, highlighting progress on audit cycles, open risks, and any emerging themes that require executive attention.
  • Advise internal infrastructure, security, and operations teams on control gaps and support broader compliance projects, including preparations for external assessments and certifications.
  • Contribute to internal penetration testing exercises and other security validation efforts, while also proposing refinements to audit procedures, tooling, and methodologies to improve coverage and efficiency.

Requirements & Qualifications

  • At least four years of hands-on experience auditing IT controls, with specific focus on GITC, vulnerability identification, and security control testing within production environments.
  • Familiarity with leading security and regulatory frameworks including ISO 27001, NIST, SOC 2, and GDPR, and the ability to interpret their requirements in practical audit scenarios.
  • A bachelor’s degree in cybersecurity, information technology, computer science, or a related discipline; professional certifications such as CISA, CISSP, or CISM are strongly preferred.
  • Demonstrated background as an IT auditor covering production systems, access control mechanisms, and the complete audit lifecycle from planning through reporting and closure.
  • Strong attention to detail and methodical work habits, with the ability to spot subtle control weaknesses and articulate their business impact clearly.
  • Excellent written and verbal communication skills for producing audit findings and collaborating across infrastructure, engineering, security, and compliance teams.
  • Proven analytical and problem-solving capability, including managing multiple concurrent audit tasks, prioritising competing demands, and driving issues to resolution.
729 open positions on Semasocial right now · 10224 open positions in Nairobi County, Kenya · 32 posted in the last 7 days
Contact Information
CV Job Description Matcher See how well your CV matches this job and get tips to improve your chances AI Tool

This tool helps you see how closely your CV matches a job description. It also gives you simple suggestions on what to improve so you have a better chance of getting shortlisted.

Beware of Fraudsters!
Never pay anyone for job applications, interview tests, or job interviews. A genuine employer will never ask you for payment under any circumstances.
Disclaimer & TOS: We do not guarantee the authenticity of every single job posting and are not responsible for any fraudulent activity or misrepresentation by third parties. We are not involved in any stage of the interview or recruitment process and do not charge any fees from job seekers. For further details, please read the rest of the Terms of Service.