Engineer - Information Security
Real-time Payment Services Company
Posted 15 hours ago
Deadline: Oct 14, 2026 7 days leftAbout the Company
This company operates under the National Payment System (NPS) Act, providing real-time payment services to address inter-bank money transfer challenges within the country and beyond.
Job Description
The Information Security Engineer plays a critical role in safeguarding the business payment infrastructure by designing, implementing, and maintaining comprehensive security measures. This involves conducting end-to-end network and application security assessments, integrating security practices into the software development lifecycle (DevSecOps), and ensuring strict adherence to industry regulations such as CBK Cybersecurity Guidelines and PCI DSS. The role also includes optimizing various security tools for maximum effectiveness across both on-premise and cloud environments.
Key Responsibilities
- Develop and implement secure architectures for new systems and services, adhering to best practices like Zero Trust principles and micro-segmentation, and meeting regulatory requirements.
- Design and enforce cloud security controls across AWS, Azure, and GCP to protect resources, data, and services.
- Configure and manage endpoint protection solutions on all devices to prevent malware, viruses, shadow IT, and other security threats.
- Configure, monitor, and fine-tune security tools such as SIEM, EDR, WAF, and IAM solutions for optimal coverage and timely threat detection.
- Evaluate emerging security technologies and recommend improvements or replacements.
- Deploy and manage Zero Trust Network Access (ZTNA) controls for secure access to applications and data, both on-premise and in the cloud, following least privilege and role-based access models.
- Implement privileged access management (PAM) solutions to enforce least privilege and control access to sensitive systems.
- Fine-tune and operate vulnerability scanning tools, interpret reports, and prioritize remediation efforts, coordinating patch management with system owners.
- Perform security hardening of the Google Workspace environment, including configuring security settings, access controls, mobile device management, and data protection.
- Secure data at rest by implementing secure key management, encryption algorithms, and access controls, including managing cryptographic key lifecycles.
- Manage the lifecycle of security certificates, including issuance, renewal, and revocation, to ensure integrity and authenticity.
- Collaborate with infrastructure teams to harden and monitor network devices.
- Integrate security practices into the software development lifecycle (DevSecOps) with DevOps teams, including secure coding, code reviews, and automated security testing.
- Conduct API and application security assessments, working with developers on secure coding, threat modeling, and code reviews.
- Collaborate with cross-functional teams to embed security requirements into software development and infrastructure deployment.
- Stay current with the latest security trends, threats, and technologies.
- Identify and lead initiatives to enhance the organization’s overall security posture and resilience.
Requirements
- Hold a Bachelor’s Degree in computer science, information security, or a related field.
- Possess professional certifications such as CISSP, CEH, CISM, or OSCP (advantageous).
- Have a minimum of 3 years of experience in cybersecurity, preferably within the payments, FinTech, or financial services sectors.
- Demonstrate practical experience integrating security tools (SIEM, IDS/IPS, EDR) and frameworks (PCI DSS, ISO 27001, NIST).
- Possess hands-on experience with cloud security platforms (AWS, GCP, or Azure).
- Exhibit in-depth knowledge of network security concepts (firewalls, routing, network segmentation) and cloud security.
- Be proficient in security tools and technologies including SIEM, IDS/IPS, EDR, WAF, IAM, and vulnerability scanners.
- Be familiar with DevSecOps tools and processes (CI/CD pipelines, containerization, automation scripting).
- Understand modern application security principles (OWASP Top 10, API security, secure coding practices).
- Have knowledge of operating systems (Windows, Linux) and scripting languages (e.g., Python, Bash).
- Possess expertise in security assessments and vulnerability management.
- Demonstrate excellent verbal and written communication skills.
- Be able to collaborate effectively within cross-functional team environments.
- Possess strong documentation skills for maintaining security standards and teamwork records.
Important Safety Tips
- Do not make any payment to any job request or recruiter.
- Be cautious of fraudulent job adverts and scams.
- If you suspect this listing is not genuine, please report it immediately.
How to Apply
Job Details
- Function
- Software & Data
- Industry
- Banking, Finance & Insurance
- Type
- Full-time
- Location
- Nairobi
- Experience
- Mid Level
- Salary
- Open
- Posted
- Oct 07, 2026
- Views
- 21
- Deadline
- Oct 14, 2026