Digital Security Engineer
2026-09-16T13:32:36+00:00
Code for Africa
https://cdn.greatkenyanjobs.com/jsjobsdata/data/employer/comp_3961/logo/Code%20for%20Africa.png
https://www.greatkenyanjobs.com/jobs
FULL_TIME
Nairobi
Nairobi
00100
Kenya
Nonprofit, and NGO
Computer & IT, Science & Engineering, Social Services & Nonprofit
2026-10-15T17:00:00+00:00
TELECOMMUTE
8
Background
Code for Africa (CfA) uses technology and #OpenData to empower citizens. We give citizens actionable information for better-informed decision making and digital tools to amplify their voices, so that they can hold the authorities (both governmental and corporate) to account.
Code for Africa (CfA) is recruiting a bilingual full-time Digital Security Engineer to lead technical incident response and security assessments at TrustLab, our nonprofit digital security lab working to safeguard frontline human rights defenders (HRDs), journalists and civil society organisations across Africa and the majority world.
This is both an engineering and a duty-of-care role. The people who contact TrustLab may be non-technical, under significant stress, or facing threats that extend well beyond their devices. We practise consent-first, victim-centred and trauma-informed incident response: we explain what we propose to examine, respect the limits of the client’s consent, minimise what we collect, and communicate the confidence and limitations of our findings honestly.
Responsibilities
Lead technical incident response and security assessments.
Qualifications
Candidates should possess a strong background in endpoint security and incident response, with demonstrable experience in providing support, conducting security assessments, investigating breaches, and implementing hardening measures across various devices and operating systems. Ideally, you have a deep understanding of the threat landscape in Africa and experience working with non-profit organisations or in the development sector.
Candidates must be fluent in English and French, and candidates who are fluent in an additional international language, such as Arabic or Portuguese, will have an advantage.
Required: minimum requirements include:
- Bachelor’s degree in Information Technology, Computer Science, Computer Engineering, Cybersecurity, and similar technology degrees, or equivalent technology experience,
- Demonstrable experience supporting high-risk users like journalists and activists.
- 3+ years experience in security engineering, or a similar role, with a strong focus on incident response and endpoint and application security,
- Experience with endpoint security tools and techniques, such as Mobile Device Management and anti-malware,
- Hands-on experience investigating and responding to security incidents, including triage, forensic analysis, evidence preservation, containment, recovery and post-incident review, using SIEM, EDR or comparable security tools where appropriate,
- Experience conducting risk-based security assessments using techniques such as secure configuration review, vulnerability assessment, threat modelling or authorised penetration testing, and translating findings into practical, prioritised remediation,
- Experience with identity and access management such as MFA, SSO, least-privilege provisioning and deprovisioning,
- Experience with scripting languages for security automation (Python and shell scripting).
- Deep practical knowledge of macOS and iOS, including secure configuration, endpoint management, incident investigation and relevant security tooling, together with demonstrated ability to assess and support mixed-device environments,
- Passion for using technology to empower and protect civil society organisations,
- Strong organisational skills and ability to manage multiple priorities and tasks, and deliver results within deadlines,
- Excellent technical documentation and presentation skills, and
- Proven ability to work and communicate with both technical and non-technical stakeholders.
Preferred: candidates who can demonstrate the following will have an advantage:
- Master’s degree in Cybersecurity, Information Security, or similar technology postgraduate degrees,
- Expertise in one or more of the following domains is highly desirable: Penetration Testing, Cloud Security, and Cryptography,
- Familiarity with security risks involving generative-AI or agentic systems, and with the responsible, privacy-preserving use of AI-assisted tools in security workflows,
- Working knowledge of Windows, Linux and Android, including their secure configuration, common security controls and relevant investigation tooling,
- Hold one or more relevant security certifications such as eJPT, Security+, GCIH, CySA+, OSCP,
- Extensive knowledge of digital security issues and threat vectors in the African context,
- Experience working with non-profit organisations or in the development sector is a plus, and
- Experience working in a fully remote environment.
Language and Location Requirements:
Location: Remote. Candidates must be able to maintain at least four hours of overlap with the team’s core collaboration hours of 09:00–17:00 GMT+1.
Timezone: GMT-1 to GMT+5
Languages: English and French
Nice to have: Arabic or Portuguese.
- Lead technical incident response and security assessments.
- Endpoint security tools and techniques (e.g., Mobile Device Management, anti-malware)
- Incident investigation and response (triage, forensic analysis, evidence preservation, containment, recovery, post-incident review)
- SIEM, EDR or comparable security tools
- Risk-based security assessments (secure configuration review, vulnerability assessment, threat modelling, penetration testing)
- Identity and access management (MFA, SSO, least-privilege provisioning and deprovisioning)
- Scripting languages for security automation (Python, shell scripting)
- macOS and iOS security (secure configuration, endpoint management, incident investigation)
- Technical documentation and presentation
- Communication with technical and non-technical stakeholders
- Bachelor’s degree in Information Technology, Computer Science, Computer Engineering, Cybersecurity, or equivalent technology experience
- Demonstrable experience supporting high-risk users (journalists, activists)
- 3+ years experience in security engineering or similar role with focus on incident response, endpoint and application security
- Deep practical knowledge of macOS and iOS
- Passion for using technology to empower and protect civil society organisations
- Strong organizational skills and ability to manage multiple priorities and tasks
- Master’s degree in Cybersecurity, Information Security, or similar technology postgraduate degrees (preferred)
- Expertise in Penetration Testing, Cloud Security, or Cryptography (highly desirable)
- Familiarity with security risks involving generative-AI or agentic systems (preferred)
- Working knowledge of Windows, Linux and Android (preferred)
- Relevant security certifications (e.g., eJPT, Security+, GCIH, CySA+, OSCP) (preferred)
- Extensive knowledge of digital security issues and threat vectors in the African context (preferred)
- Experience working with non-profit organisations or in the development sector (plus)
- Experience working in a fully remote environment (preferred)
JOB-6aaa9a7416dab
Vacancy title:
Digital Security Engineer
[Type: FULL_TIME, Industry: Nonprofit, and NGO, Category: Computer & IT, Science & Engineering, Social Services & Nonprofit]
Jobs at:
Code for Africa
Deadline of this Job:
Thursday, October 15 2026
Duty Station:
This Job is Remote
Summary
Date Posted: Wednesday, September 16 2026, Base Salary: Not Disclosed
Similar Jobs in Kenya
Learn more about Code for Africa
Code for Africa jobs in Kenya
JOB DETAILS:
Background
Code for Africa (CfA) uses technology and #OpenData to empower citizens. We give citizens actionable information for better-informed decision making and digital tools to amplify their voices, so that they can hold the authorities (both governmental and corporate) to account.
Code for Africa (CfA) is recruiting a bilingual full-time Digital Security Engineer to lead technical incident response and security assessments at TrustLab, our nonprofit digital security lab working to safeguard frontline human rights defenders (HRDs), journalists and civil society organisations across Africa and the majority world.
This is both an engineering and a duty-of-care role. The people who contact TrustLab may be non-technical, under significant stress, or facing threats that extend well beyond their devices. We practise consent-first, victim-centred and trauma-informed incident response: we explain what we propose to examine, respect the limits of the client’s consent, minimise what we collect, and communicate the confidence and limitations of our findings honestly.
Responsibilities
Lead technical incident response and security assessments.
Qualifications
Candidates should possess a strong background in endpoint security and incident response, with demonstrable experience in providing support, conducting security assessments, investigating breaches, and implementing hardening measures across various devices and operating systems. Ideally, you have a deep understanding of the threat landscape in Africa and experience working with non-profit organisations or in the development sector.
Candidates must be fluent in English and French, and candidates who are fluent in an additional international language, such as Arabic or Portuguese, will have an advantage.
Required: minimum requirements include:
- Bachelor’s degree in Information Technology, Computer Science, Computer Engineering, Cybersecurity, and similar technology degrees, or equivalent technology experience,
- Demonstrable experience supporting high-risk users like journalists and activists.
- 3+ years experience in security engineering, or a similar role, with a strong focus on incident response and endpoint and application security,
- Experience with endpoint security tools and techniques, such as Mobile Device Management and anti-malware,
- Hands-on experience investigating and responding to security incidents, including triage, forensic analysis, evidence preservation, containment, recovery and post-incident review, using SIEM, EDR or comparable security tools where appropriate,
- Experience conducting risk-based security assessments using techniques such as secure configuration review, vulnerability assessment, threat modelling or authorised penetration testing, and translating findings into practical, prioritised remediation,
- Experience with identity and access management such as MFA, SSO, least-privilege provisioning and deprovisioning,
- Experience with scripting languages for security automation (Python and shell scripting).
- Deep practical knowledge of macOS and iOS, including secure configuration, endpoint management, incident investigation and relevant security tooling, together with demonstrated ability to assess and support mixed-device environments,
- Passion for using technology to empower and protect civil society organisations,
- Strong organisational skills and ability to manage multiple priorities and tasks, and deliver results within deadlines,
- Excellent technical documentation and presentation skills, and
- Proven ability to work and communicate with both technical and non-technical stakeholders.
Preferred: candidates who can demonstrate the following will have an advantage:
- Master’s degree in Cybersecurity, Information Security, or similar technology postgraduate degrees,
- Expertise in one or more of the following domains is highly desirable: Penetration Testing, Cloud Security, and Cryptography,
- Familiarity with security risks involving generative-AI or agentic systems, and with the responsible, privacy-preserving use of AI-assisted tools in security workflows,
- Working knowledge of Windows, Linux and Android, including their secure configuration, common security controls and relevant investigation tooling,
- Hold one or more relevant security certifications such as eJPT, Security+, GCIH, CySA+, OSCP,
- Extensive knowledge of digital security issues and threat vectors in the African context,
- Experience working with non-profit organisations or in the development sector is a plus, and
- Experience working in a fully remote environment.
Language and Location Requirements:
Location: Remote. Candidates must be able to maintain at least four hours of overlap with the team’s core collaboration hours of 09:00–17:00 GMT+1.
Timezone: GMT-1 to GMT+5
Languages: English and French
Nice to have: Arabic or Portuguese.
Work Hours: 8
Experience in Months: 12
Level of Education: bachelor degree
Job application procedure
Application Link:
All Jobs | QUICK ALERT SUBSCRIPTION