Kazi Connect
Jobs in Kenya
Back to jobs
Job in Kenya

Cyber Security Analyst (DevSecOps) Job FinSense Africa

Corporate Staffing client Kenya Full Time Posted 2026-07-23
Apply at source
CountyNairobi
CityNot specified
DeadlineNot specified
SourceCorporate Staffing Kenya
cyber security analystDevSecOpsITNairobifull timemiddle levelvulnerability assessmentsecure codingapplication securitysecurityCyber Security AnalystDevSecOps

AI summary

FinSense Africa is hiring a Cyber Security Analyst (DevSecOps) in Nairobi. The role ensures security is embedded in the SDLC, conducts security testing across all technology stacks, and collaborates with scrum teams. Requires a Bachelor's degree in Computer Science, IT, or STEM, and proficiency in DevSecOps, application security, and vulnerability assessment.

  • Responsible for embedding security requirements within the Software Development Life Cycle (SDLC).
  • Conducts security testing across mobile, web, APIs, source code, servers, and more.
  • Requires proficiency in DevSecOps, application security, and vulnerability assessment.
  • Full-time permanent position based in Nairobi, Kenya.
  • Bachelor's degree in Computer Science, IT, or related STEM field required; Master's is an added advantage.
  • Must have professional information security certification (unspecified).

Description

Home » Jobs In Kenya » IT Jobs In Kenya » Cyber Security Analyst (DevSecOps) Job FinSense Africa Job Title: Cyber Security Analyst (DevSecOps) Date Posted: 17/07/2026 Job Type: Full Time Job Level: Middle Employer: FinSense Africa Industry: IT Salary: Open Location: Nairobi Country: Kenya Deadline: 23/07/2026 Summary: IT Jobs. FinSense Africa Jobs. Looking for an IT job in Kenya? FinSense Africa is recruiting a Cyber Security Analyst (DevSecOps) position. Proficiency in DevSecOps, application security, and vulnerability assessment is required. Job Purpose The role holder is responsible for ensuring information systems developed and deployed meet the organization’s cybersecurity policies, standards, and requirements, as well as complying with applicable cybersecurity regulations and industry standards. The role holder will ensure that security requirements are properly captured and embedded within the Software Development Life Cycle (SDLC) for all technology initiatives, secure coding practices are adhered to, and secure software and application configurations are maintained. The specialist will carry out security testing across all technology stacks (mobile, web applications, APIs/microservices, source code, web servers, containers, servers, databases, virtualization environments, network devices, and connectivity) within assigned scrum teams and projects. Responsibilities Work with scrum and project teams to ensure that security requirements are adequately captured during the requirements analysis phase. Provide input into the secure design of information systems architecture throughout the project lifecycle. Ensure that access to systems during the project lifecycle by staff, contractors, and vendors is secure and based on the principle of least privilege. Enforce the implementation and adoption of minimum security baseline standards across all technologies in use. Facilitate the identification of security vulnerabilities by performing or coordinating security assessments, vulnerability assessments, and penetration testing (VAPT). Ensure security tools and controls are operating as expected within development and deployment pipelines and review security reports generated from them. Report security gaps identified within scrum teams and projects and follow up on remediation in accordance with organizational standards and procedures. Identify security violations and incidents during the project lifecycle and coordinate the response process. Ensure effective integration of security tools to protect, detect, and respond to attempted intrusions before and during project go-live. Collaborate with project teams to ensure user access matrices are properly defined and aligned with established roles and responsibilities. Participate in deployment activities and conduct post-implementation reviews (PIR) to ensure security configurations are implemented and identified gaps do not progress into production environments. Embed cybersecurity awareness initiatives throughout the project lifecycle, with a focus on secure coding practices. Provide scheduled security reports to cybersecurity leadership, project teams, and steering committees on the progress of security workstream activities. Requirements Skills and Experience Bachelor’s degree in Computer Science, Information Technology, or other STEM-related discipline. Master’s degree in Information Security, Cyber Security, or related field will be an added advantage. Professional information security certifications such as CISA, CISM, CISSP, CRISC, or Security+, as well as application/security testing certifications such as CSSLP, CEH, OSCP, CPT, GPEN, GWAPT, or eJPT. 3+ years of experience in technology roles. 1+ years of experience in information security. 1+ years of experience in Application Security within Secure SDLC and DevSecOps environments. Strong technical expertise in DevSecOps toolchains, including tools such as Ansible, Jenkins, GitLab, Azure DevOps, Trivy, SonarQube, Terraform, Git/version control systems, or similar technologies. Familiarity with information security frameworks and standards such as PCI-DSS, ISO 27001, and SABSA. Knowledge of API security, container security, and cloud security principles. Experience in project implementation and user training. Ability to multitask, work effectively under pressure and tight deadlines, influence stakeholders, and operate both independently and within cross-functional teams. Strong verbal and written communication skills. Strong analytical and problem-solving skills with the ability to collaborate effectively across teams. How to Apply Click Here to Apply 🎯 Applying for This Job? Don’t Send a Generic CV. Don’t send the same CV to every job/employer. Have our recruitment team customize your CV to match the requirements of this specific job and improve your chances of getting an interview. Customise My CV For This Job . ⭐ 5-Star Reviews . Job Seeker Testimonials: Professionals Who Got Jobs Through Corporate S

Never pay to apply. Always confirm the original source and watch for payment requests, sensitive document requests, or unrealistic promises.