Job Details
Job Type:
Full Time
Workplace Type:
On-site
Qualification:
Diploma
Job Experience:
Mandatory
Job Location:
Nairobi County, Kenya
Closing Date:
Undisclosed
Salary:
Estimated: KES 45,000 - KES 300,000 / month
Other Pay:
Benefits
Role Overview
This position sits at the intersection of cybersecurity and internal audit, with a mandate to inspect live production environments before external reviewers or compliance teams uncover weaknesses. Day to day, you will run recurring control assessments, scrutinize system configurations and access rights for drift, and convert unresolved findings into traceable remediation commitments within the Risk Control Self-Assessment (RCSA) framework. Your work directly reduces the likelihood of audit surprises and gives leadership an accurate, current view of operational risk across critical systems.
Key Responsibilities
- Plan and execute proactive audits of production systems, focusing on General IT Controls (GITC) such as authentication rules, privileged access, change management, backup resilience, and logging configurations.
- Compare live system settings and security controls against internal policy baselines and recognized industry standards; document deviations, misconfigurations, and exposure points with clear evidence.
- Translate audit observations into practical remediation guidance that system owners can act on quickly, prioritizing issues by severity, exploitability, and potential business impact.
- Work with Governance and Compliance colleagues to log unresolved control gaps in the RCSA, including root-cause summaries, proposed mitigation steps, ownership assignments, and target closure dates.
- Maintain the RCSA as a living document, periodically revisiting recorded issues to confirm that remediation is progressing and that control ratings reflect the actual state of production environments.
- Produce concise status summaries and trend reports for management, highlighting recurring problem areas, the effectiveness of previous fixes, and recommendations for systemic improvements.
- Partner with IT operations, security engineering, and application teams to validate that corrective actions are implemented without disrupting business processes, and assist with evidence gathering for external audits.
- Contribute to internal penetration testing and security assessment cycles by coordinating access, scoping test boundaries, and helping interpret results in the context of GITC.
Requirements & Qualifications
- A minimum of four years in IT auditing with hands-on experience covering GITC, vulnerability assessment, and security control testing in production or enterprise environments.
- Demonstrated familiarity with the full audit lifecycle: planning, fieldwork, evidence collection, issue reporting, and follow-up verification.
- Working knowledge of security frameworks and regulatory regimes including ISO 27001, NIST, SOC 2, and GDPR, including how these map to technical controls in real-world settings.
- Practical exposure to security assessment and auditing tools, such as vulnerability scanners, configuration review utilities, SIEM queries, and access review platforms.
- A bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a closely related discipline; relevant certifications such as CISA, CISSP, or CISM are preferred.
- Exceptional attention to detail, with the ability to distinguish minor configuration drift from material control deficiencies and articulate the difference to technical and non-technical audiences.
- Strong analytical and problem-solving skills, including the capacity to independently organize multiple audit tasks, meet deadlines, and coordinate with cross-functional teams.
729 open positions on Semasocial right now
· 10275 open positions in Nairobi County, Kenya
· 29 posted in the last 7 days
Contact Information