Principal Engineer Cybersecurity Assurance
AI summary
NCBA Group is hiring a Principal Engineer Cybersecurity Assurance in Nairobi, Kenya. The role focuses on proactive GITC auditing of production systems, vulnerability identification, RCSA documentation, and collaboration with IT and compliance teams. Minimum 4 years IT auditing experience and relevant certifications preferred. Salary open. Deadline 15/09/2026.
- Proactive GITC auditing and vulnerability identification in production systems
- RCSA documentation and collaboration with governance and compliance teams
- Minimum 4 years IT auditing experience in GITC and security controls
- Bachelor's degree in Cybersecurity, IT, or related field; CISA, CISSP, or CISM preferred
- Salary open; full-time role based in Nairobi, Kenya
AI job guide
Use this guide to check salary signals, requirements, documents, application steps and safety before you apply.
AI salary guide
Source salary availableThe source lists Open. Confirm the final pay, benefits, contract terms and allowances directly with the employer before accepting an offer.
Can you qualify for this role?
- Required4+ years of relevant experienceThe job post includes a minimum experience signal.
- RequiredEducation or certification mentioned in the postThe captured text mentions education, a diploma, certificate, or licence.
- PreferredPractical evidence in security, internship, segurancaThe tags and summary point to skills connected with this role.
- RequiredAvailability to work in Not specifiedThe vacancy is associated with this location.
- UnclearComfort with the Full Time contract termsConfirm hours, duration, probation and benefits at the original source.
Documents to prepare
- Likely requiredUpdated CV
- Role specificCover letter or short employer message
- OptionalProfessional references
- Role specificAcademic or professional certificates
- VerifyID or passport only after verifying the employer
Application tips for this job
- Place your strongest Principal Engineer Cybersecurity Assurance evidence in the first half of your CV.
- In your cover letter or employer message, connect your experience to NCBA Group and the role in Not specified.
- Add concrete examples related to security, internship, seguranca, ideally with measurable outcomes or clear responsibilities.
- Follow the instructions from Corporate Staffing Kenya; avoid sending documents to unofficial contacts or copied links.
- Confirm the deadline, interview location and employer contact before sharing personal documents.
- Plan to submit before the listed deadline: 2026-09-15.
Source and safety check
- Corporate Staffing Kenya
- Original source link available
- Application method is clear
- Deadline is available: 2026-09-15
- No major risk signal was detected in the captured text.
Never pay for interviews, shortlisting, medical checks, uniforms, or job placement. Confirm every application at the original source before sharing personal documents. Report suspicious listing.
Interview preparation
- What experience makes you a strong fit for this Principal Engineer Cybersecurity Assurance role in security, internship?
- How have you handled responsibilities similar to those in this job post?
- Are you available to work in Not specified under the listed contract or schedule?
- Prepare examples with clear responsibilities, tools used and measurable outcomes.
- Review the source and research NCBA Group before the interview.
Ask what the first priorities will be in the role and how success will be measured.
Similar jobs to consider
Use AI to apply better
After confirming the original source, use Career Assistant to check role fit, tailor your CV and prepare a cover letter or employer message.
Original source description
Job Title: Principal Engineer Cybersecurity Assurance Date Posted: 07/09/2026 Job Type: Full Time Job Level: Middle Employer: NCBA Group Industry: IT Salary: Open Location: Nairobi Country: Kenya Deadline: 15/09/2026 Job Purpose Statement The Cybersecurity Assurance Specialist role will be responsible for conducting General IT Controls (GITC) assessments within production systems. This proactive role aims to audit production environments before compliance teams flag potential issues, ensuring vulnerabilities, gaps, and misconfigurations are identified and remediated. The primary focus will be on auditing critical IT controls and configurations to maintain and enhance the organization’s security posture. For issues that cannot be immediately addressed, the role will ensure they are properly documented in the Risk Control Self-Assessment (RCSA) for further remediation and mitigation. Key Responsibilities: Proactive GITC Auditing and Vulnerability Identification 30% Conduct regular audits of production systems to assess GITC and identify gaps in configurations, security controls, and vulnerabilities. Perform a thorough review of access controls, system configurations, data integrity, and compliance with internal policies and industry standards. Identify security risks and proactively recommend appropriate remediation actions to mitigate threats. Risk Control Self-Assessment (RCSA) Documentation 30% Work closely with Governance and Compliance teams to document key findings in the RCSA. For any gaps or issues that cannot be immediately resolved, ensure they are properly recorded and tracked in the RCSA, with clear action plans for resolution. Continuously review and update the RCSA to reflect the current security and compliance posture of production systems. Collaboration and Reporting 20% Provide regular reports and recommendations to management and stakeholders on the status of audits, security risks, and remediation efforts. Collaborate with internal teams such as the IT, security, and operations teams to ensure that gaps are effectively closed and issues are remediated in a timely manner. Support ongoing compliance initiatives by providing insights into security vulnerabilities and assisting with external audits. Support and Continuous Improvement 20% Assist in the preparation and execution of internal penetration tests and security assessments. Continuously assess and improve the current auditing and testing processes for efficiency and effectiveness. Provide recommendations on tools, processes, and methodologies to enhance the security posture of production systems. Qualifications Minimum of 4 years of experience: in IT auditing, specifically in GITC, vulnerability assessments, and security controls within production systems. Strong knowledge of security frameworks, regulatory standards (ISO 27001, NIST, SOC 2, GDPR), and security testing tools. Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or related field; certifications such as CISA, CISSP, or CISM are preferred. Experience: as an IT Auditor in GITC, with expertise in auditing production systems, access controls, and the general audit lifecycle. Strong attention to detail, communication skills, and ability to identify and resolve risks proactively. Excellent analytical and problem-solving skills, with the ability to manage multiple audit tasks and collaborate with cross-functional teams.
