Job Details
Job Type:
Full Time
Workplace Type:
On-site
Qualification:
Diploma
Job Experience:
Mandatory
Job Location:
Nairobi County, Kenya
Closing Date:
Undisclosed
Salary:
Estimated: KES 45,000 - KES 300,000 / month
Other Pay:
Benefits
Role Overview
This position centers on continuously examining live production systems to uncover weaknesses in general IT controls before they become compliance findings. You will serve as an internal early-warning function, validating access permissions, system hardening, and control effectiveness, then ensuring that unresolved risks are logged and managed through the organisation's formal risk register. Your work directly supports the company’s ability to pass external audits and maintain a credible security posture while keeping production operations stable.
Key Responsibilities
- Perform scheduled and ad-hoc assessments of production environments, reviewing whether IT general controls are correctly configured, enforced, and aligned with internal policy and external standards.
- Inspect user access rights, privileged accounts, segregation of duties, data integrity safeguards, and baseline configurations to detect deviations that could expose the organisation to attack or non-compliance.
- Translate audit observations into concrete remediation guidance, prioritising findings by severity and practical impact, and following up with system owners to confirm fixes are applied.
- Work alongside governance and compliance colleagues to capture issues that cannot be resolved immediately in the Risk Control Self-Assessment, including detailed action plans and ownership for each item.
- Keep the RCSA documentation current so it accurately reflects the security and compliance condition of production systems as changes occur over time.
- Deliver status updates and summary reports to management, highlighting progress on audit cycles, open risks, and any emerging themes that require executive attention.
- Advise internal infrastructure, security, and operations teams on control gaps and support broader compliance projects, including preparations for external assessments and certifications.
- Contribute to internal penetration testing exercises and other security validation efforts, while also proposing refinements to audit procedures, tooling, and methodologies to improve coverage and efficiency.
Requirements & Qualifications
- At least four years of hands-on experience auditing IT controls, with specific focus on GITC, vulnerability identification, and security control testing within production environments.
- Familiarity with leading security and regulatory frameworks including ISO 27001, NIST, SOC 2, and GDPR, and the ability to interpret their requirements in practical audit scenarios.
- A bachelor’s degree in cybersecurity, information technology, computer science, or a related discipline; professional certifications such as CISA, CISSP, or CISM are strongly preferred.
- Demonstrated background as an IT auditor covering production systems, access control mechanisms, and the complete audit lifecycle from planning through reporting and closure.
- Strong attention to detail and methodical work habits, with the ability to spot subtle control weaknesses and articulate their business impact clearly.
- Excellent written and verbal communication skills for producing audit findings and collaborating across infrastructure, engineering, security, and compliance teams.
- Proven analytical and problem-solving capability, including managing multiple concurrent audit tasks, prioritising competing demands, and driving issues to resolution.
729 open positions on Semasocial right now
· 10224 open positions in Nairobi County, Kenya
· 32 posted in the last 7 days
Contact Information