Back to jobs
Job in Kenya

Cyber Security Administrator (Analysis)

Kenya Airways Nairobi Type not specified Posted 2026-09-21
CountyNairobiCityNairobiContractType not specifiedPosted2026-09-21Close date2026-10-03Experience3 yearsSourceJob in Kenya
cyber securitypenetration testingred teamvulnerability assessmentnairobikenya airwaysmid careersiemoffensive securityinformation securitysecurityinternship
Use AI for this job

AI summary

Kenya Airways is hiring a Cyber Security Administrator (Analysis) in Nairobi to safeguard its information systems through offensive security operations. The role focuses on penetration testing, red team simulations, adversary emulation, and vulnerability assessments. Mid-career professionals with 3-5 years of experience are encouraged to apply before the deadline.

  • Offensive security focus: penetration testing, red team simulations, and adversary emulation
  • Mid-career role requiring 3 to 5 years of experience
  • Deadline: October 3, 2026
  • Collaboration with developers, systems engineers, and SOC analysts
  • Produces detailed penetration testing reports with remediation recommendations

AI job guide

Use this guide to check salary signals, requirements, documents, application steps and safety before you apply.

AI salary guide

Not enough public data

Not enough public salary data is available for this exact role. Before applying, prepare to ask about gross pay, benefits, contract length, probation period, transport and any allowances.

Can you qualify for this role?

  • Required3+ years of relevant experienceThe job post includes a minimum experience signal.
  • RequiredEducation or certification mentioned in the postThe captured text mentions education, a diploma, certificate, or licence.
  • PreferredPractical evidence in security, internship, segurancaThe tags and summary point to skills connected with this role.
  • RequiredAvailability to work in NairobiThe vacancy is associated with this location.

Documents to prepare

  • Likely requiredUpdated CV
  • Role specificCover letter or short employer message
  • OptionalProfessional references
  • Role specificAcademic or professional certificates
  • VerifyID or passport only after verifying the employer

Application tips for this job

  • Place your strongest Cyber Security Administrator (Analysis) evidence in the first half of your CV.
  • In your cover letter or employer message, connect your experience to Kenya Airways and the role in Nairobi.
  • Add concrete examples related to security, internship, seguranca, ideally with measurable outcomes or clear responsibilities.
  • Follow the instructions from Job in Kenya; avoid sending documents to unofficial contacts or copied links.
  • Confirm the deadline, interview location and employer contact before sharing personal documents.
  • Plan to submit before the listed deadline: 2026-10-03.

Source and safety check

  • Job in Kenya
  • Original source link available
  • Application method is clear
  • Deadline is available: 2026-10-03
  • No major risk signal was detected in the captured text.

Never pay for interviews, shortlisting, medical checks, uniforms, or job placement. Confirm every application at the original source before sharing personal documents. Report suspicious listing.

Interview preparation

  • What experience makes you a strong fit for this Cyber Security Administrator (Analysis) role in security, internship?
  • How have you handled responsibilities similar to those in this job post?
  • Are you available to work in Nairobi under the listed contract or schedule?
  • Prepare examples with clear responsibilities, tools used and measurable outcomes.
  • Review the source and research Kenya Airways before the interview.

Ask what the first priorities will be in the role and how success will be measured.

Use AI to apply better

After confirming the original source, use Career Assistant to check role fit, tailor your CV and prepare a cover letter or employer message.

Original source description

Cyber Security Administrator (Analysis)

Purpose

The Cyber Security Administrator is responsible for safeguarding Kenya Airways' information systems, digital assets, and supporting infrastructure through offensive security operations primarily conducting penetration testing, red team simulations, adversary emulation, and vulnerability assessments to proactively identify and exploit weaknesses before malicious actors do. The role demands a hands-on, attacker-minded professional who can think creatively, adapt to evolving threat landscapes, and translate complex technical findings into clear, actionable remediation guidance that strengthens the organization's overall security posture.

Responsibilities

  • Identify, assess, and manage cybersecurity risks through offensive testing and defensive analysis. This includes evaluating both internal and external threats and vulnerabilities.
  • Develop strategies for risk mitigation and prioritize security investments to protect critical assets.
  • Identify and manage cybersecurity risks through penetration testing and adversary emulations to uncover vulnerabilities, validate security controls, and drive remediation across the organization.
  • Internally assess, evaluate, and make recommendations to the cybersecurity engineer regarding the adequacy of the security controls for the airline information and technology systems.
  • Collaborate with developers, Systems engineers, database engineers, security engineers, project managers, cybersecurity administrators and SOC analysts.
  • Plan, scope, and execute penetration tests on internal and external networks, web applications, APIs, mobile applications, cloud environments, and infrastructure.
  • Simulate advanced persistent threats (APTs) and real-world attacks.
  • Conduct regular vulnerability scans across all KQ systems and infrastructure.
  • Analyze and prioritize vulnerabilities based on risk, exploitability, and business impact.
  • Collect, analyze, and interpret security-related data from various sources to identify patterns, anomalies, and potential security threats.
  • Develop and maintain custom security analytics models and algorithms.
  • Produce detailed penetration testing reports with findings, risk ratings, proof-of-concept evidence, and actionable remediation recommendations.
  • Present findings to technical teams and senior management clearly and concisely.
  • Contribute to SIEM tuning and detection rule development based on offensive findings.
  • Support incident response investigations by providing attacker-perspective analysis.
  • Work with Internal Audit and External Audit consultants as appropriate on required security assessments and audits.
  • Ensure all projects and systems are subjected to security checks to avert possible security threats pre and post go-live.
  • Assessing existing security issues within the organization through continuous testing and validation.
  • Evaluating the organization’s security needs and establishing offensive best practices and standards accordingly.
  • Responding to all system and/or network security breaches.
  • Ensuring that the organization’s data and infrastructure are protected by enabling the appropriate security controls.
  • Implementing a system of automation within the organization to ensure effective and efficient security protocols.
  • Investigating breaches and implementing solid plans of incident response, learning from past shortcomings to create ever more robust security protocols.
  • Skills
  • Excellent communication, interpersonal & problem-solving skills with the ability to work confidently on high-priority problems.
  • Strong analytical and critical-thinking skills with an attacker's mindset.
  • Ability to handle pressure and difficult situations with resilience, calmly and effectively.
  • Must be a person of unquestionable integrity.
  • Self-motivated with a passion for continuous learning in cybersecurity.
  • Strong ethical standards and commitment to responsible disclosure practices.
  • Qualifications
  • Bachelor’s degree in Information Technology or another related field.
  • 3+ years of advanced IT skills with high level of information security

Experience

  • and expertise (hands-on testing and offensive security experience).
  • Proven
  • in penetration testing, ethical hacking, and vulnerability assessments.
  • with various security tools to assess the organization’s security posture.
  • Familiarity with security auditing processes.
  • Well versed with Linux commands, scripting as well as windows security controls adoption.
  • Ability to set up systems to identify intrusions, configuring these to suit the needs of the organization.
  • Strong knowledge of networking protocols and common attack vectors.
  • performing information security audits or risk assessments.
  • Industry certifications highly
  • responding to, analyzing, and communicating information security incidents and performing forensic.
  • Excellent interpersonal, communication, and presentation skills, including formal report writing experience.
  • Understanding of common security standards and regulations relating to a higher

Preferred Qualifications

  • OSCP, OSWE, CEH, GPEN, GWAPT, CRTP, or equivalent offensive security certifications.
  • Knowledge of securing network technologies, applications, and operating systems.

Education

  • environment (e.g., PCI DSS, NIST, ISO27001, GDPR, IOSA etc.).
  • Capable of enforcing security best practices in line with the National Institute of Standards and Technology (NIST).
  • Method of application
  • If you are interested and qualified, kindly submit your application via the link provided below,
  • https://careers.kenya-airways.com/anonymous/listing/a64beedb-c5a2-4ebf-8e7b-5eb704f794f1/details?division=6fef853f-d078-4aa9-8642-79d61dc68585&utm_source=Jobinkenya
  • Deadline Oct 3, 2026 06:24pm
Source and provenanceSource: Job in Kenya. Last checked: 2026-09-23.Kazi Connect is a job discovery service, not the employer. Always confirm the vacancy at the original source.Summaries may be AI-assisted. Report inaccurate content.
Never pay to apply. Always confirm the original source and watch for payment requests, sensitive document requests, or unrealistic promises.