Cyber Security Analyst job at Bank of Africa Kenya Limited
7 Days Ago
Linkedid Twitter Share on facebook
Cyber Security Analyst
2026-03-05T13:59:49+00:00
Bank of Africa Kenya Limited
https://cdn.greatkenyanjobs.com/jsjobsdata/data/employer/comp_8316/logo/download%20(2).jpg
FULL_TIME
Nairobi
Nairobi
00100
Kenya
Banking
Computer & IT, Science & Engineering
KES
MONTH
2026-03-21T17:00:00+00:00
8

BANK OF AFRICA - KENYA LIMITED (BOA-KENYA) is a commercial bank providing banking services to corporate, SME and retail clientele.

Read more about this company

Responsibilities and Accountabilities.

Information Security & Risk Management

  • Participate in identifying, assessing, and documenting IT/cyber risks.
  • Assist in updating and maintaining the IT risk register.
  • Track risk treatment plans and follow up with control owners.
  • Support vulnerability tracking and assist in coordinating remediation activities.
  • Help monitor and log security incidents and ensure timely reporting.

ISO 27001:2022 Implementation Support

  • Assist in drafting and updating ISMS documents (policies, procedures, SOPs, risk assessments).
  • Help conduct ISMS gap assessments and internal audits.
  • Collect, organize, and maintain compliance evidence for ISO controls.
  • Assist in tracking corrective and preventive actions (CAPA).
  • Conduct periodic reviews to ensure departments maintain ISMS alignment.

PCI DSS Certification Support

  • Assist in mapping cardholder data flows and maintaining network diagrams.
  • Help prepare and update PCI DSS evidence (screenshots, process documents, change logs).
  • Participate in internal readiness assessments and support Qualified Security Assessor (QSA) activities.
  • Track remediation tasks for PCI requirements and follow up with IT teams.
  • Monitor compliance with ongoing PCI DSS activities (log reviews, vulnerability scans, patching).

Governance, Risk & Compliance (GRC)

  • Assist in monitoring compliance with internal IT and security policies.
  • Support third‑party risk assessments of IT vendors and service providers.
  • Assist in compiling periodic information security and risk reports.

Operational Support

  • Maintain organized documentation repositories (ISMS library, SharePoint, etc.).
  • Track deadlines, deliverables, and progress for certification projects.
  • Assist in convening risk and security meetings, preparing minutes and follow‑up actions.
  • Coordinate with teams across IT, operations, business units, and external auditors.

Minimum Requirements; Work Experience, Academic and Professional Qualifications.

  • Bachelor’s degree in IT, Information Systems, Computer Science, Cyber Security, or related fields.
  • Basic knowledge of information security and risk management concepts.
  • Familiarity with ISO 27001 and PCI DSS is an advantage.
  • Understanding of networks, servers, operating systems, and databases.
  • Ability to analyze logs, configurations, and security events.

Added Advantage Certifications.

  • ISO 27001 Internal Auditor / Implementer
  • CompTIA Security+
  • ISC2 Certified in Cybersecurity (CC)
  • ITIL Foundation
  • Beginner‑level GRC or cybersecurity courses
  • Participate in identifying, assessing, and documenting IT/cyber risks.
  • Assist in updating and maintaining the IT risk register.
  • Track risk treatment plans and follow up with control owners.
  • Support vulnerability tracking and assist in coordinating remediation activities.
  • Help monitor and log security incidents and ensure timely reporting.
  • Assist in drafting and updating ISMS documents (policies, procedures, SOPs, risk assessments).
  • Help conduct ISMS gap assessments and internal audits.
  • Collect, organize, and maintain compliance evidence for ISO controls.
  • Assist in tracking corrective and preventive actions (CAPA).
  • Conduct periodic reviews to ensure departments maintain ISMS alignment.
  • Assist in mapping cardholder data flows and maintaining network diagrams.
  • Help prepare and update PCI DSS evidence (screenshots, process documents, change logs).
  • Participate in internal readiness assessments and support Qualified Security Assessor (QSA) activities.
  • Track remediation tasks for PCI requirements and follow up with IT teams.
  • Monitor compliance with ongoing PCI DSS activities (log reviews, vulnerability scans, patching).
  • Assist in monitoring compliance with internal IT and security policies.
  • Support third‑party risk assessments of IT vendors and service providers.
  • Assist in compiling periodic information security and risk reports.
  • Maintain organized documentation repositories (ISMS library, SharePoint, etc.).
  • Track deadlines, deliverables, and progress for certification projects.
  • Assist in convening risk and security meetings, preparing minutes and follow‑up actions.
  • Coordinate with teams across IT, operations, business units, and external auditors.
  • Basic knowledge of information security and risk management concepts.
  • Familiarity with ISO 27001 and PCI DSS is an advantage.
  • Understanding of networks, servers, operating systems, and databases.
  • Ability to analyze logs, configurations, and security events.
  • Bachelor’s degree in IT, Information Systems, Computer Science, Cyber Security, or related fields.
  • ISO 27001 Internal Auditor / Implementer
  • CompTIA Security+
  • ISC2 Certified in Cybersecurity (CC)
  • ITIL Foundation
  • Beginner‑level GRC or cybersecurity courses
bachelor degree
12
JOB-69a98c55c8163

Vacancy title:
Cyber Security Analyst

[Type: FULL_TIME, Industry: Banking, Category: Computer & IT, Science & Engineering]

Jobs at:
Bank of Africa Kenya Limited

Deadline of this Job:
Saturday, March 21 2026

Duty Station:
Nairobi | Nairobi

Summary
Date Posted: Thursday, March 5 2026, Base Salary: Not Disclosed

Similar Jobs in Kenya
Learn more about Bank of Africa Kenya Limited
Bank of Africa Kenya Limited jobs in Kenya

JOB DETAILS:

BANK OF AFRICA - KENYA LIMITED (BOA-KENYA) is a commercial bank providing banking services to corporate, SME and retail clientele.

Read more about this company

Responsibilities and Accountabilities.

Information Security & Risk Management

  • Participate in identifying, assessing, and documenting IT/cyber risks.
  • Assist in updating and maintaining the IT risk register.
  • Track risk treatment plans and follow up with control owners.
  • Support vulnerability tracking and assist in coordinating remediation activities.
  • Help monitor and log security incidents and ensure timely reporting.

ISO 27001:2022 Implementation Support

  • Assist in drafting and updating ISMS documents (policies, procedures, SOPs, risk assessments).
  • Help conduct ISMS gap assessments and internal audits.
  • Collect, organize, and maintain compliance evidence for ISO controls.
  • Assist in tracking corrective and preventive actions (CAPA).
  • Conduct periodic reviews to ensure departments maintain ISMS alignment.

PCI DSS Certification Support

  • Assist in mapping cardholder data flows and maintaining network diagrams.
  • Help prepare and update PCI DSS evidence (screenshots, process documents, change logs).
  • Participate in internal readiness assessments and support Qualified Security Assessor (QSA) activities.
  • Track remediation tasks for PCI requirements and follow up with IT teams.
  • Monitor compliance with ongoing PCI DSS activities (log reviews, vulnerability scans, patching).

Governance, Risk & Compliance (GRC)

  • Assist in monitoring compliance with internal IT and security policies.
  • Support third‑party risk assessments of IT vendors and service providers.
  • Assist in compiling periodic information security and risk reports.

Operational Support

  • Maintain organized documentation repositories (ISMS library, SharePoint, etc.).
  • Track deadlines, deliverables, and progress for certification projects.
  • Assist in convening risk and security meetings, preparing minutes and follow‑up actions.
  • Coordinate with teams across IT, operations, business units, and external auditors.

Minimum Requirements; Work Experience, Academic and Professional Qualifications.

  • Bachelor’s degree in IT, Information Systems, Computer Science, Cyber Security, or related fields.
  • Basic knowledge of information security and risk management concepts.
  • Familiarity with ISO 27001 and PCI DSS is an advantage.
  • Understanding of networks, servers, operating systems, and databases.
  • Ability to analyze logs, configurations, and security events.

Added Advantage Certifications.

  • ISO 27001 Internal Auditor / Implementer
  • CompTIA Security+
  • ISC2 Certified in Cybersecurity (CC)
  • ITIL Foundation
  • Beginner‑level GRC or cybersecurity courses

Work Hours: 8

Experience in Months: 12

Level of Education: bachelor degree

Job application procedure

Application Link:Click Here to Apply Now

All Jobs | QUICK ALERT SUBSCRIPTION

Job Info
Job Category: Data, Monitoring, and Research jobs in Kenya
Job Type: Full-time
Deadline of this Job: Saturday, March 21 2026
Duty Station: Nairobi | Nairobi
Posted: 05-03-2026
No of Jobs: 1
Start Publishing: 05-03-2026
Stop Publishing (Put date of 2030): 10-10-2076
Apply Now
Notification Board

Join a Focused Community on job search to uncover both advertised and non-advertised jobs that you may not be aware of. A jobs WhatsApp Group Community can ensure that you know the opportunities happening around you and a jobs Facebook Group Community provides an opportunity to discuss with employers who need to fill urgent position. Click the links to join. You can view previously sent Email Alerts here incase you missed them and Subscribe so that you never miss out.

Caution: Never Pay Money in a Recruitment Process.

Some smart scams can trick you into paying for Psychometric Tests.