K

Cyber Security Administrator (Operations)

Kenya Airways

Nairobi Full-time IT & Telecoms Engineering & Technology Mid Level
Salary: Open / Negotiable

Posted 8 hours ago

About the Company

Kenya Airways is a leading African airline that connects Africa to the world and the world to Africa through its hub at Nairobi Jomo Kenyatta International Airport.

Job Description

This role involves protecting Kenya Airways' information systems, digital assets, and supporting infrastructure through offensive security operations. The administrator will primarily conduct penetration testing, red team simulations, adversary emulation, and vulnerability assessments to identify and exploit weaknesses before malicious actors can. The position requires a hands-on professional with an attacker's mindset, capable of creative thinking and adapting to evolving threats, who can translate complex technical findings into clear, actionable remediation guidance to strengthen the organization's overall security posture.

Key Responsibilities

  1. Identify, assess, and manage cybersecurity risks through defensive analysis and offensive testing, evaluating both internal and external threats and vulnerabilities.
  2. Develop risk mitigation strategies based on threat monitoring and incident analysis, prioritizing security investments to protect critical assets.
  3. Develop and implement the system-wide Information Security function to ensure information security risks are identified and monitored.
  4. Continuously identify, assess, and monitor information security risks across the organization, escalating emerging threats to inform defensive priorities.
  5. Collaborate with developers, systems engineers, database engineers, security engineers, project managers, cybersecurity administrators, and SOC analysts.
  6. Implement and fine-tune security monitoring solutions, including SIEM systems, to detect and respond to security incidents.
  7. Collaborate with internal teams to investigate and mitigate security breaches.
  8. Triage, investigate, contain, eradicate, and recover from security incidents, coordinating with internal teams and external partners.
  9. Lead incident investigations using data-driven analysis, coordinate response efforts, and implement corrective actions to prevent recurrence.
  10. Maintain and continuously improve incident response plans and playbooks for common attack scenarios.
  11. Consume and operationalize threat intelligence feeds and adversary TTPs to proactively update detection rules, block emerging IOCs, and inform defensive priorities.
  12. Deploy and maintain SOAR workflows to automate alert triage, enrichment, and routine response tasks, reducing response times and analyst fatigue.
  13. Oversee the deployment, configuration, and maintenance of security technologies, including EDR/XDR and encryption solutions.
  14. Ensure all defensive systems are patched, updated, and operating at optimal performance with high availability.
  15. Assist in executing vulnerability assessments, penetration tests, and adversary emulation exercises mapped to the MITRE ATT&CK framework to validate and stress-test defensive controls.
  16. Collaborate with SOC analysts in purple team exercises and translate offensive findings into actionable defensive improvements.
  17. Work with Internal Audit and External Audit consultants on required security assessments and audits.
  18. Ensure all projects and systems undergo security checks to prevent potential security threats pre and post go-live.
  19. Respond promptly to all system and network security breaches, ensuring containment, eradication, and recovery according to documented procedures.
  20. Implement automation (SOAR) within the organization for efficient alert triage, incident response workflows, and routine security operations.
  21. Evaluate the organization's security needs and establish defensive best practices, hardening baselines, and configuration standards.
  22. Ensure the organization's data and infrastructure are protected through layered, defense-in-depth security controls across network, endpoint, application, and data layers.
  23. Assess the organization's security posture through continuous monitoring, vulnerability scanning, and control validation.
  24. Investigate breaches and incidents, conduct root cause analysis, and implement improvements to create robust defensive protocols.

Requirements

  1. Bachelor’s degree in Information Technology or a related field.
  2. At least 3 years of advanced IT skills with significant information security experience and expertise, specifically hands-on experience in defensive cybersecurity operations.
  3. Proven hands-on experience in security monitoring, incident detection and response, and vulnerability management.
  4. Proficiency with SIEM platforms and experience with vulnerability scanning and management tools.
  5. Experience in penetration testing, ethical hacking, and vulnerability assessments.
  6. Familiarity with security auditing processes.
  7. Well-versed with Linux commands, scripting, and Windows security controls adoption.
  8. Ability to set up systems to identify intrusions and configure them to suit organizational needs.
  9. Strong knowledge of networking protocols and common attack vectors.
  10. Experience performing information security audits or risk assessments.
  11. Industry certifications such as CEH, CDSA, CISSP, SSCP, or equivalent defensive and offensive security certifications are highly preferred.
  12. Knowledge of securing network technologies, applications, and operating systems.
  13. Experience responding to, analyzing, and communicating information security incidents and performing forensics.
  14. Excellent interpersonal, communication, and presentation skills, including formal report writing experience.
  15. Understanding of common security standards and regulations relevant to a higher education environment (e.g., PCI DSS, NIST, ISO27001, GDPR, IOSA).
  16. Capable of enforcing security best practices in line with the National Institute of Standards and Technology.
  17. Excellent communication, interpersonal, and problem-solving skills, with the ability to work confidently on high-priority problems.
  18. Strong analytical and critical-thinking skills with an attacker's mindset.
  19. Ability to handle pressure and difficult situations with resilience, calmly and effectively.
  20. Unquestionable integrity.
  21. Self-motivated with a passion for continuous learning in cybersecurity.
  22. Strong ethical standards and commitment to responsible disclosure practices.

Important Safety Tips

  • Do not make any payment to any job request or recruiter.
  • Be cautious of fraudulent job adverts and scams.
  • If you suspect this listing is not genuine, please report it immediately.

How to Apply

Sign in to view application details

Sign In to Apply

No account? Register free

Job Details

Function
Engineering & Technology
Industry
IT & Telecoms
Type
Full-time
Location
Nairobi
Experience
Mid Level
Salary
Open
Posted
Sep 21, 2026
Views
11

Share This Job

Related Jobs

B

Electronic Queue Management Systems (EQMS) Technician

Biometrics Technology Limited

Nairobi Full-time
View Job
B

Business Development Executive

Biometrics Technology Limited

Nairobi Full-time
View Job
D

Manager, Information Technology

DDD

Nairobi Full-time
View Job
ATS CV Builder