S

Manager, Fintech and Cyber Audit

Safaricom PLC

Nairobi Full-time IT & Telecoms Engineering & Technology Senior Level
Salary: Open / Negotiable

Posted 2 hours ago

Deadline: Oct 04, 2026

About the Company

Safaricom PLC is a leading telecommunications company based in Nairobi, Kenya, founded in 1997.

Job Description

Reporting to the Internal Audit Senior Managers based on Flow to Work, the Manager, Fintech and Cyber Audit is responsible for providing independent, risk-based assurance over the effectiveness of the Group’s technology governance, digital ecosystem, enterprise applications, infrastructure, cloud environments, data management, technology-enabled business processes and IT general controls. The role evaluates whether technology risks are effectively identified, assessed and managed through appropriate governance, risk management and internal control frameworks that support secure, resilient, reliable and efficient business operations.

Key Responsibilities

  1. Uphold the company code of conduct, policies and procedures, ensuring integrity and accountability in every aspect of your work.
  2. All employees have a responsibility to adhere to safety, health, and wellbeing policies, guidelines and procedures in all actions and decisions.
  3. Develop and execute risk-based audit and technical security testing engagements covering technology and cyber risks across the Financial Services ecosystem.
  4. Execute technology audit assignments, including VAPT engagements, from planning, scoping and fieldwork through reporting, escalation and remediation validation.
  5. Evaluate the adequacy and effectiveness of technology controls supporting critical business processes through control assessment, technical testing, vulnerability validation and other appropriate assurance procedures.
  6. Evaluate application controls, system configuration, authentication, authorisation, transaction integrity, processing reliability, data protection and operational resilience using both control-based and technical testing techniques.
  7. Assess the effectiveness of controls relating to: Cybersecurity governance, Security Operations Centre (SOC), Identity and Access Management (IAM), Privileged Access Management (PAM), Multi-factor authentication, Endpoint protection, Network security, Cloud security, Vulnerability management, Penetration testing governance, threat intelligence, Security monitoring, Incident response, Cyber resilience, Encryption and key management, Data Loss Prevention (DLP), and Security awareness programmes.
  8. Assess Financial Services’ readiness to prevent, detect, respond to and recover from evolving cyber threats and emerging attack vectors, supported where appropriate by technical security testing.
  9. Ensure audit engagements comply with the Global Internal Audit Standards (IIA), Internal Audit Methodology and quality assurance requirements.
  10. Perform data-driven audits and technology-enabled security testing using analytics, automation, scripts and continuous auditing techniques to identify control weaknesses, vulnerabilities, anomalous activity and emerging risk trends.
  11. Deliver clear assurance reports, including reports on VAPT engagements, containing practical, risk-based recommendations that strengthen security, operational resilience and business performance.
  12. Support the development of the annual risk assessment and audit planning process.
  13. Coach and provide technical guidance to junior auditors where assigned.
  14. Plan and execute risk-based vulnerability assessments and penetration tests, as part of Internal Audit assurance engagements, across Financial Services applications, mobile platforms, APIs, networks, infrastructure and cloud environments, in accordance with approved scope and rules of engagement.
  15. Apply automated and manual security-testing techniques to identify vulnerabilities, eliminate false positives, validate exploitability and assess technical, business and customer impact.
  16. Assess the security of fintech and payment journeys, including customer-facing services and third-party integrations.
  17. Maintain sufficient technical evidence and deliver clear VAPT reports covering confirmed vulnerabilities, affected assets, exploitability, business impact, risk ratings and practical remediation actions.
  18. Immediately escalate critical vulnerabilities and perform technical retesting to confirm that agreed remediation actions have effectively addressed identified weaknesses.
  19. Review the scope, methodology, execution quality and results of penetration tests performed by external service providers.
  20. Assess compliance with applicable technology and cyber-related regulations, standards and industry frameworks including: Data Protection and Privacy legislation, Cybersecurity regulations, Central Bank technology requirements, Payment industry security requirements, Information security policies, Technology governance standards and Internal technology policies.
  21. Monitor regulatory developments and assess organisational readiness.
  22. Evaluate effectiveness of controls over technology risks associated with: Cloud service providers, Technology vendors, Fintech partners, Managed service providers, Outsourced technology services, API partners and Digital ecosystem participants
  23. Assess fraud prevention, detection, monitoring, and response controls.
  24. Evaluate governance, contractual controls, security obligations and operational resilience across the extended technology ecosystem.
  25. Assess compliance monitoring processes and governance arrangements.
  26. Support continuous improvement of Fintech and Cyber control maturity.
  27. Conduct controls-by-design and risk-based technical security reviews for Financial Services system implementations, major system changes and new products.
  28. Support cloud migration programmes through independent assessment of cloud governance, configuration, identity, network security, data protection and vulnerability exposure.
  29. Assess digital transformation initiatives.
  30. Reviewing cybersecurity enhancement programmes.
  31. Evaluating new technology implementations before production deployment.
  32. Utilize data analytics and technology-enabled assurance techniques.
  33. Monitor emerging technology and Cyber risks affecting financial services.
  34. Support continuous auditing and monitoring initiatives.
  35. Validate effectiveness of remediation actions and control improvements.
  36. Contribute to development of an AI-enabled continuous assurance model.
  37. Use advanced analytics to identify emerging Fintech and Cyber risks.
  38. Provide objective advice while maintaining audit independence.
  39. Build strong relationships with Financial Services leadership teams to drive awareness and culture of controls ownership.
  40. Provide advisory insights that strengthen Fintech controls and business performance.
  41. Track and validate closure of audit findings.
  42. Escalate significant Fintech control weaknesses and emerging risks.
  43. Promote awareness of Fintech and Cyber control responsibilities.
  44. Share industry best practices and emerging risk insights.
  45. Communicate complex technology risks clearly to both technical and non-technical stakeholders.

Requirements

  1. Bachelor’s Degree in Computer Science, Information Systems, Information Technology, Cybersecurity, Engineering or a related discipline.
  2. Minimum of six years’ relevant experience in Internal Audit, Technology Risk, IT Audit, Cybersecurity, Information Security or technical security testing, including demonstrable hands-on experience planning and executing vulnerability assessments and penetration tests.
  3. Experience auditing and technically testing fintech platforms, digital financial services, payment systems or other high-value transactional environments, including web and mobile applications, APIs, networks and cloud environments.
  4. Strong experience conducting cybersecurity and technology audits.
  5. Experience assessing cloud environments, application controls and technology governance.
  6. Experience using audit analytics, automation and continuous auditing techniques, including automated and manual security-testing approaches.
  7. Experience engaging senior leadership and communicating complex technical risks to technical and non-technical stakeholders.
  8. Experience working in highly regulated financial services, banking, fintech or telecommunications environments is highly desirable.
  9. The successful candidate should possess one or more relevant professional certifications, including Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP), Certified Ethical Hacker (CEH), Offensive Security Certified Professional (OSCP) or a recognised hands-on penetration-testing certification.
  10. Cloud security certifications covering AWS, Microsoft Azure or Google Cloud are an added advantage.
  11. Strong analytical, stakeholder-management and report-writing skills.

Important Safety Tips

  • Do not make any payment to any job request or recruiter.
  • Be cautious of fraudulent job adverts and scams.
  • If you suspect this listing is not genuine, please report it immediately.

How to Apply

Sign in to view application details

Sign In to Apply

No account? Register free

Job Details

Function
Engineering & Technology
Industry
IT & Telecoms
Type
Full-time
Location
Nairobi
Experience
Senior Level
Salary
Open
Posted
Aug 03, 2026
Views
4
Deadline
Oct 04, 2026

Share This Job

Related Jobs

S

Technical Product Manager – Payments & Partner Integrations

Safaricom PLC

Nairobi Full-time
View Job
A

ITOM Configuration Specialist

Absa Bank Kenya PLC

Nairobi Full-time
View Job
S

Engineer – Enterprise Customer Support

Safaricom PLC

Nairobi Full-time
View Job
ATS CV Builder