Engineer - Information Security job at MAL Consultancy
New
Today
Linkedid Twitter Share on facebook
Engineer - Information Security
2026-10-06T20:06:10+00:00
MAL Consultancy
https://cdn.greatkenyanjobs.com/jsjobsdata/data/employer/comp_7822/logo/Picture4.jpg
FULL_TIME
Kenya
Nairobi
00100
Kenya
Consulting
Computer & IT, Science & Engineering
KES
MONTH
2026-10-14T17:00:00+00:00
8

Background information about the job or company

Our client, a real-time payment services company established under the National Payment System (NPS) Act, to address the challenge of inter-bank money transfers in the country and beyond, is seeking to onboard an Engineer – Information Security.

JOB SUMMARY

The Engineer - Information Security is responsible for designing, implementing, and maintaining security measures to protect the business payment infrastructure. S/he will be in charge of ensuring end-to-end network and application security assessments, integrating security into the software development lifecycle (DevSecOps), while ensuring compliance with industry regulations (e.g., CBK Cybersecurity Guidelines, PCI DSS). The Engineer – Information Security will also be responsible for the optimization of security tools for maximum effectiveness across both on-premise and cloud environments.

Responsibilities or duties

Security Architecture & Design

  • Develop secure architecture for new systems and services, ensuring alignment with best practices (e.g., Zero Trust principles, micro-segmentation) and regulatory requirements
  • Design and enforce cloud security controls (AWS, Azure, GCP) to protect resources, data, and services.

Endpoint Protection Management

  • Configure and manage endpoint protection solutions on all laptops and devices to prevent malware, viruses, shadow IT, and other security threats
  • Configure, monitor, and tune security tools (e.g., SIEM, EDR, WAF, IAM solutions) to ensure optimal coverage and timely threat detection
  • Evaluate emerging security technologies and make recommendations for improvements or replacements.

Secure Access Management

  • Deploy and manage Zero Trust Network Access (ZTNA) controls to provide secure access to applications and data, both on-prem and cloud, following identity management models such as least privilege and role-based access
  • Implement privileged access management (PAM) solutions to enforce least privilege principles and control access to sensitive systems and resources.

Enterprise Applications / Infrastructure

  • Fine-tune and operate vulnerability scanning tools, interpret reports, and prioritize remediation efforts. This will include coordinating patch management activities with system owners and track remediation progress to closure
  • Perform security hardening of the Google Workspace environment, including configuration of security settings, access controls, mobile device management, and data protection measures.

Network and Data Security:

  • Secure data at rest by implementing secure key management practices, encryption algorithms, and access controls to protect sensitive information. This includes implementation and management of secure key management solutions to safeguard cryptographic keys used for encryption and decryption
  • Manage security certificate lifecycle, including issuance, renewal, and revocation, to ensure the integrity and authenticity of digital certificates used for authentication and encryption
  • Collaborate with infrastructure teams to ensure network devices are hardened and monitored.

Secure Coding (DevSecOps)

  • Collaborate with DevOps teams to integrate security practices into the software development lifecycle (DevSecOps), including secure coding practices, code review, and automated security testing
  • Perform API and application security assessments; work closely with developers to integrate secure coding practices, conduct threat modeling, and perform code reviews
  • Collaborate with cross-functional teams to integrate security requirements into software development and infrastructure deployment processes.

Continuous Improvement

  • Stay updated on the latest security trends, threats, and technologies.
  • Identify and lead initiatives that enhance the organizations’ overall security posture and resilience.
  • Any other duties as required.

Qualifications or requirements

EDUCATION SKILS KNOWLEDGE & EXPERIENCE REQUIRED

  • Bachelor’s Degree in computer science, information security, or any other related field.
  • Certifications including but not limited to CISSP, CEH, CISM, or OSCP are a plus
  • Practical experience integrating security tools (SIEM, IDS/IPS, EDR) and frameworks (PCI DSS, ISO 27001, NIST)
  • Hands-on experience with cloud security (AWS, GCP, or Azure)
  • In-depth knowledge and understanding of network security concepts (firewalls, routing, network segmentation) and cloud security (AWS, GCP, Azure).
  • Proficiency and expertise in security tools and technologies (SIEM, IDS/IPS, EDR, WAF, IAM, vulnerability scanners)
  • Familiarity and expertise in DevSecOps tools and processes (CI/CD pipelines, containerization, automation scripting)
  • Understanding of modern application security (OWASP Top 10, API security, secure coding practices)
  • Knowledge of operating systems (Windows, Linux) and scripting languages (e.g., Python, Bash)
  • Expertise in security assessments and vulnerability management
  • Excellent verbal and written communication skills
  • Ability to collaborate effectively in cross-functional team environments
  • Strong documentation skills for maintaining security standards and teamwork records.

Experience needed

  • 3+ years of experience in cybersecurity, preferably within payments, FinTech, or financial services
  • Develop secure architecture for new systems and services, ensuring alignment with best practices (e.g., Zero Trust principles, micro-segmentation) and regulatory requirements
  • Design and enforce cloud security controls (AWS, Azure, GCP) to protect resources, data, and services.
  • Configure and manage endpoint protection solutions on all laptops and devices to prevent malware, viruses, shadow IT, and other security threats
  • Configure, monitor, and tune security tools (e.g., SIEM, EDR, WAF, IAM solutions) to ensure optimal coverage and timely threat detection
  • Evaluate emerging security technologies and make recommendations for improvements or replacements.
  • Deploy and manage Zero Trust Network Access (ZTNA) controls to provide secure access to applications and data, both on-prem and cloud, following identity management models such as least privilege and role-based access
  • Implement privileged access management (PAM) solutions to enforce least privilege principles and control access to sensitive systems and resources.
  • Fine-tune and operate vulnerability scanning tools, interpret reports, and prioritize remediation efforts. This will include coordinating patch management activities with system owners and track remediation progress to closure
  • Perform security hardening of the Google Workspace environment, including configuration of security settings, access controls, mobile device management, and data protection measures.
  • Secure data at rest by implementing secure key management practices, encryption algorithms, and access controls to protect sensitive information. This includes implementation and management of secure key management solutions to safeguard cryptographic keys used for encryption and decryption
  • Manage security certificate lifecycle, including issuance, renewal, and revocation, to ensure the integrity and authenticity of digital certificates used for authentication and encryption
  • Collaborate with infrastructure teams to ensure network devices are hardened and monitored.
  • Collaborate with DevOps teams to integrate security practices into the software development lifecycle (DevSecOps), including secure coding practices, code review, and automated security testing
  • Perform API and application security assessments; work closely with developers to integrate secure coding practices, conduct threat modeling, and perform code reviews
  • Collaborate with cross-functional teams to integrate security requirements into software development and infrastructure deployment processes.
  • Stay updated on the latest security trends, threats, and technologies.
  • Identify and lead initiatives that enhance the organizations’ overall security posture and resilience.
  • Any other duties as required.
  • CISSP, CEH, CISM, or OSCP (plus)
  • Practical experience integrating security tools (SIEM, IDS/IPS, EDR) and frameworks (PCI DSS, ISO 27001, NIST)
  • Hands-on experience with cloud security (AWS, GCP, or Azure)
  • In-depth knowledge and understanding of network security concepts (firewalls, routing, network segmentation) and cloud security (AWS, GCP, Azure).
  • Proficiency and expertise in security tools and technologies (SIEM, IDS/IPS, EDR, WAF, IAM, vulnerability scanners)
  • Familiarity and expertise in DevSecOps tools and processes (CI/CD pipelines, containerization, automation scripting)
  • Understanding of modern application security (OWASP Top 10, API security, secure coding practices)
  • Knowledge of operating systems (Windows, Linux) and scripting languages (e.g., Python, Bash)
  • Expertise in security assessments and vulnerability management
  • Excellent verbal and written communication skills
  • Ability to collaborate effectively in cross-functional team environments
  • Strong documentation skills for maintaining security standards and teamwork records.
  • Bachelor’s Degree in computer science, information security, or any other related field.
bachelor degree
12
JOB-6ac554b240fae

Vacancy title:
Engineer - Information Security

[Type: FULL_TIME, Industry: Consulting, Category: Computer & IT, Science & Engineering]

Jobs at:
MAL Consultancy

Deadline of this Job:
Wednesday, October 14 2026

Duty Station:
Kenya | Nairobi

Summary
Date Posted: Tuesday, October 6 2026, Base Salary: Not Disclosed

Similar Jobs in Kenya
Learn more about MAL Consultancy
MAL Consultancy jobs in Kenya

JOB DETAILS:

Background information about the job or company

Our client, a real-time payment services company established under the National Payment System (NPS) Act, to address the challenge of inter-bank money transfers in the country and beyond, is seeking to onboard an Engineer – Information Security.

JOB SUMMARY

The Engineer - Information Security is responsible for designing, implementing, and maintaining security measures to protect the business payment infrastructure. S/he will be in charge of ensuring end-to-end network and application security assessments, integrating security into the software development lifecycle (DevSecOps), while ensuring compliance with industry regulations (e.g., CBK Cybersecurity Guidelines, PCI DSS). The Engineer – Information Security will also be responsible for the optimization of security tools for maximum effectiveness across both on-premise and cloud environments.

Responsibilities or duties

Security Architecture & Design

  • Develop secure architecture for new systems and services, ensuring alignment with best practices (e.g., Zero Trust principles, micro-segmentation) and regulatory requirements
  • Design and enforce cloud security controls (AWS, Azure, GCP) to protect resources, data, and services.

Endpoint Protection Management

  • Configure and manage endpoint protection solutions on all laptops and devices to prevent malware, viruses, shadow IT, and other security threats
  • Configure, monitor, and tune security tools (e.g., SIEM, EDR, WAF, IAM solutions) to ensure optimal coverage and timely threat detection
  • Evaluate emerging security technologies and make recommendations for improvements or replacements.

Secure Access Management

  • Deploy and manage Zero Trust Network Access (ZTNA) controls to provide secure access to applications and data, both on-prem and cloud, following identity management models such as least privilege and role-based access
  • Implement privileged access management (PAM) solutions to enforce least privilege principles and control access to sensitive systems and resources.

Enterprise Applications / Infrastructure

  • Fine-tune and operate vulnerability scanning tools, interpret reports, and prioritize remediation efforts. This will include coordinating patch management activities with system owners and track remediation progress to closure
  • Perform security hardening of the Google Workspace environment, including configuration of security settings, access controls, mobile device management, and data protection measures.

Network and Data Security:

  • Secure data at rest by implementing secure key management practices, encryption algorithms, and access controls to protect sensitive information. This includes implementation and management of secure key management solutions to safeguard cryptographic keys used for encryption and decryption
  • Manage security certificate lifecycle, including issuance, renewal, and revocation, to ensure the integrity and authenticity of digital certificates used for authentication and encryption
  • Collaborate with infrastructure teams to ensure network devices are hardened and monitored.

Secure Coding (DevSecOps)

  • Collaborate with DevOps teams to integrate security practices into the software development lifecycle (DevSecOps), including secure coding practices, code review, and automated security testing
  • Perform API and application security assessments; work closely with developers to integrate secure coding practices, conduct threat modeling, and perform code reviews
  • Collaborate with cross-functional teams to integrate security requirements into software development and infrastructure deployment processes.

Continuous Improvement

  • Stay updated on the latest security trends, threats, and technologies.
  • Identify and lead initiatives that enhance the organizations’ overall security posture and resilience.
  • Any other duties as required.

Qualifications or requirements

EDUCATION SKILS KNOWLEDGE & EXPERIENCE REQUIRED

  • Bachelor’s Degree in computer science, information security, or any other related field.
  • Certifications including but not limited to CISSP, CEH, CISM, or OSCP are a plus
  • Practical experience integrating security tools (SIEM, IDS/IPS, EDR) and frameworks (PCI DSS, ISO 27001, NIST)
  • Hands-on experience with cloud security (AWS, GCP, or Azure)
  • In-depth knowledge and understanding of network security concepts (firewalls, routing, network segmentation) and cloud security (AWS, GCP, Azure).
  • Proficiency and expertise in security tools and technologies (SIEM, IDS/IPS, EDR, WAF, IAM, vulnerability scanners)
  • Familiarity and expertise in DevSecOps tools and processes (CI/CD pipelines, containerization, automation scripting)
  • Understanding of modern application security (OWASP Top 10, API security, secure coding practices)
  • Knowledge of operating systems (Windows, Linux) and scripting languages (e.g., Python, Bash)
  • Expertise in security assessments and vulnerability management
  • Excellent verbal and written communication skills
  • Ability to collaborate effectively in cross-functional team environments
  • Strong documentation skills for maintaining security standards and teamwork records.

Experience needed

  • 3+ years of experience in cybersecurity, preferably within payments, FinTech, or financial services

Work Hours: 8

Experience in Months: 12

Level of Education: bachelor degree

Job application procedure
Interested in applying for this job? Click here to submit your application now.

If you are interested in applying for this exciting opportunity and have the requisite work experience, skills, and education and have worked within the FinTech or financial services sector holding a similar role, we are interested in meeting you. Please share with us your CV and cover letter in PDF format addressed to the Recruiting Manager at  with the subject of your application being: Information Security

All applications received will be subjected to a fair and competitive recruitment process.

Only shortlisted candidates shall be contacted.

This advertisement will close on Wednesday, 14th October, 2026, at 5.00pm EAT.

All Jobs | QUICK ALERT SUBSCRIPTION

Job Info
Job Category: Engineering jobs in Kenya
Job Type: Full-time
Deadline of this Job: Wednesday, October 14 2026
Duty Station: Kenya | Nairobi
Posted: 06-10-2026
No of Jobs: 1
Start Publishing: 06-10-2026
Stop Publishing (Put date of 2030): 10-10-2076
Apply Now
Notification Board

Join a Focused Community on job search to uncover both advertised and non-advertised jobs that you may not be aware of. A jobs WhatsApp Group Community can ensure that you know the opportunities happening around you and a jobs Facebook Group Community provides an opportunity to discuss with employers who need to fill urgent position. Click the links to join. You can view previously sent Email Alerts here incase you missed them and Subscribe so that you never miss out.

Caution: Never Pay Money in a Recruitment Process.

Some smart scams can trick you into paying for Psychometric Tests.