Engineer Cyber Security Assurance job at NCBA Group
New
Website :
Today
Linkedid Twitter Share on facebook
Engineer Cyber Security Assurance
2026-05-13T18:52:00+00:00
NCBA Group
https://cdn.greatkenyanjobs.com/jsjobsdata/data/employer/comp_7974/logo/NCBA%20Group.png
FULL_TIME
Nairobi
Nairobi
00100
Kenya
Banking
Computer & IT, Science & Engineering
KES
MONTH
2026-05-19T17:00:00+00:00
8

Background

The new NCBA has harnessed the power of both NIC and CBA to create a bank that brings together the best of both worlds from cutting edge mobile banking to good old-fashioned relationship management; from scalable business banking to financial services that grow as your business does; from best-in-class choice of products to investment solutions tailored to your specific needs.

Job Purpose Statement

The Cybersecurity Assurance Specialist role will be responsible for conducting General IT Controls (GITC) assessments within production systems. This proactive role aims to audit production environments before compliance teams flag potential issues, ensuring vulnerabilities, gaps, and misconfigurations are identified and remediated. The primary focus will be on auditing critical IT controls and configurations to maintain and enhance the organization’s security posture. For issues that cannot be immediately addressed, the role will ensure they are properly documented in the Risk Control Self-Assessment (RCSA) for further remediation and mitigation.

Key Accountabilities (Duties and Responsibilities)

Proactive GITC Auditing and Vulnerability Identification 30%

  • Conduct regular audits of production systems to assess GITC and identify gaps in configurations, security controls, and vulnerabilities.
  • Perform a thorough review of access controls, system configurations, data integrity, and compliance with internal policies and industry standards.
  • Identify security risks and proactively recommend appropriate remediation actions to mitigate threats.

Risk Control Self-Assessment (RCSA) Documentation 30%

  • Work closely with Governance and Compliance teams to document key findings in the RCSA.
  • For any gaps or issues that cannot be immediately resolved, ensure they are properly recorded and tracked in the RCSA, with clear action plans for resolution.
  • Continuously review and update the RCSA to reflect the current security and compliance posture of production systems.

Collaboration and Reporting 20%

  • Provide regular reports and recommendations to management and stakeholders on the status of audits, security risks, and remediation efforts.
  • Collaborate with internal teams such as the IT, security, and operations teams to ensure that gaps are effectively closed and issues are remediated in a timely manner.
  • Support ongoing compliance initiatives by providing insights into security vulnerabilities and assisting with external audits.

Support and Continuous Improvement 20%

  • Assist in the preparation and execution of internal penetration tests and security assessments.
  • Continuously assess and improve the current auditing and testing processes for efficiency and effectiveness.
  • Provide recommendations on tools, processes, and methodologies to enhance the security posture of production systems.

Job Specifications

Qualifications and Experience

  • Minimum of 4 years of experience in IT auditing, specifically in GITC, vulnerability assessments, and security controls within production systems.
  • Strong knowledge of security frameworks, regulatory standards (ISO 27001, NIST, SOC 2, GDPR), and security testing tools.
  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or related field; certifications such as CISA, CISSP, or CISM are preferred.
  • Experience as an IT Auditor in GITC, with expertise in auditing production systems, access controls, and the general audit lifecycle.
  • Strong attention to detail, communication skills, and ability to identify and resolve risks proactively.
  • Excellent analytical and problem-solving skills, with the ability to manage multiple audit tasks and collaborate with cross-functional teams.
  • Conduct regular audits of production systems to assess GITC and identify gaps in configurations, security controls, and vulnerabilities.
  • Perform a thorough review of access controls, system configurations, data integrity, and compliance with internal policies and industry standards.
  • Identify security risks and proactively recommend appropriate remediation actions to mitigate threats.
  • Work closely with Governance and Compliance teams to document key findings in the RCSA.
  • For any gaps or issues that cannot be immediately resolved, ensure they are properly recorded and tracked in the RCSA, with clear action plans for resolution.
  • Continuously review and update the RCSA to reflect the current security and compliance posture of production systems.
  • Provide regular reports and recommendations to management and stakeholders on the status of audits, security risks, and remediation efforts.
  • Collaborate with internal teams such as the IT, security, and operations teams to ensure that gaps are effectively closed and issues are remediated in a timely manner.
  • Support ongoing compliance initiatives by providing insights into security vulnerabilities and assisting with external audits.
  • Assist in the preparation and execution of internal penetration tests and security assessments.
  • Continuously assess and improve the current auditing and testing processes for efficiency and effectiveness.
  • Provide recommendations on tools, processes, and methodologies to enhance the security posture of production systems.
  • Strong knowledge of security frameworks, regulatory standards (ISO 27001, NIST, SOC 2, GDPR), and security testing tools.
  • Experience as an IT Auditor in GITC, with expertise in auditing production systems, access controls, and the general audit lifecycle.
  • Strong attention to detail, communication skills, and ability to identify and resolve risks proactively.
  • Excellent analytical and problem-solving skills, with the ability to manage multiple audit tasks and collaborate with cross-functional teams.
  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or related field; certifications such as CISA, CISSP, or CISM are preferred.
bachelor degree
48
JOB-6a04c850312b7

Vacancy title:
Engineer Cyber Security Assurance

[Type: FULL_TIME, Industry: Banking, Category: Computer & IT, Science & Engineering]

Jobs at:
NCBA Group

Deadline of this Job:
Tuesday, May 19 2026

Duty Station:
Nairobi | Nairobi

Summary
Date Posted: Wednesday, May 13 2026, Base Salary: Not Disclosed

Similar Jobs in Kenya
Learn more about NCBA Group
NCBA Group jobs in Kenya

JOB DETAILS:

Background

The new NCBA has harnessed the power of both NIC and CBA to create a bank that brings together the best of both worlds from cutting edge mobile banking to good old-fashioned relationship management; from scalable business banking to financial services that grow as your business does; from best-in-class choice of products to investment solutions tailored to your specific needs.

Job Purpose Statement

The Cybersecurity Assurance Specialist role will be responsible for conducting General IT Controls (GITC) assessments within production systems. This proactive role aims to audit production environments before compliance teams flag potential issues, ensuring vulnerabilities, gaps, and misconfigurations are identified and remediated. The primary focus will be on auditing critical IT controls and configurations to maintain and enhance the organization’s security posture. For issues that cannot be immediately addressed, the role will ensure they are properly documented in the Risk Control Self-Assessment (RCSA) for further remediation and mitigation.

Key Accountabilities (Duties and Responsibilities)

Proactive GITC Auditing and Vulnerability Identification 30%

  • Conduct regular audits of production systems to assess GITC and identify gaps in configurations, security controls, and vulnerabilities.
  • Perform a thorough review of access controls, system configurations, data integrity, and compliance with internal policies and industry standards.
  • Identify security risks and proactively recommend appropriate remediation actions to mitigate threats.

Risk Control Self-Assessment (RCSA) Documentation 30%

  • Work closely with Governance and Compliance teams to document key findings in the RCSA.
  • For any gaps or issues that cannot be immediately resolved, ensure they are properly recorded and tracked in the RCSA, with clear action plans for resolution.
  • Continuously review and update the RCSA to reflect the current security and compliance posture of production systems.

Collaboration and Reporting 20%

  • Provide regular reports and recommendations to management and stakeholders on the status of audits, security risks, and remediation efforts.
  • Collaborate with internal teams such as the IT, security, and operations teams to ensure that gaps are effectively closed and issues are remediated in a timely manner.
  • Support ongoing compliance initiatives by providing insights into security vulnerabilities and assisting with external audits.

Support and Continuous Improvement 20%

  • Assist in the preparation and execution of internal penetration tests and security assessments.
  • Continuously assess and improve the current auditing and testing processes for efficiency and effectiveness.
  • Provide recommendations on tools, processes, and methodologies to enhance the security posture of production systems.

Job Specifications

Qualifications and Experience

  • Minimum of 4 years of experience in IT auditing, specifically in GITC, vulnerability assessments, and security controls within production systems.
  • Strong knowledge of security frameworks, regulatory standards (ISO 27001, NIST, SOC 2, GDPR), and security testing tools.
  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or related field; certifications such as CISA, CISSP, or CISM are preferred.
  • Experience as an IT Auditor in GITC, with expertise in auditing production systems, access controls, and the general audit lifecycle.
  • Strong attention to detail, communication skills, and ability to identify and resolve risks proactively.
  • Excellent analytical and problem-solving skills, with the ability to manage multiple audit tasks and collaborate with cross-functional teams.

Work Hours: 8

Experience in Months: 48

Level of Education: bachelor degree

Job application procedure

Application Link:Click Here to Apply Now

All Jobs | QUICK ALERT SUBSCRIPTION

Job Info
Job Category: Computer/ IT jobs in Kenya
Job Type: Full-time
Deadline of this Job: Tuesday, May 19 2026
Duty Station: Nairobi | Nairobi
Posted: 13-05-2026
No of Jobs: 1
Start Publishing: 13-05-2026
Stop Publishing (Put date of 2030): 10-10-2076
Apply Now
Notification Board

Join a Focused Community on job search to uncover both advertised and non-advertised jobs that you may not be aware of. A jobs WhatsApp Group Community can ensure that you know the opportunities happening around you and a jobs Facebook Group Community provides an opportunity to discuss with employers who need to fill urgent position. Click the links to join. You can view previously sent Email Alerts here incase you missed them and Subscribe so that you never miss out.

Caution: Never Pay Money in a Recruitment Process.

Some smart scams can trick you into paying for Psychometric Tests.