{"id":102218,"date":"2026-07-17T12:48:20","date_gmt":"2026-07-17T12:48:20","guid":{"rendered":"https:\/\/jobs.dataaxisnode.com\/kenya\/uncategorized\/cyber-security-analyst-devsecops\/"},"modified":"2026-07-17T12:48:20","modified_gmt":"2026-07-17T12:48:20","slug":"cyber-security-analyst-devsecops","status":"publish","type":"post","link":"https:\/\/jobs.dataaxisnode.com\/kenya\/jobs\/nairobi\/cyber-security-analyst-devsecops\/","title":{"rendered":"Cyber Security Analyst (DevSecOps)"},"content":{"rendered":"<p><script type=\"application\/ld+json\">{\"@context\": \"https:\/\/schema.org\/\", \"@type\": \"JobPosting\", \"title\": \"Cyber Security Analyst (DevSecOps)\", \"description\": \"Job Purpose\\nThe role holder is responsible for ensuring information systems developed and deployed meet the organization's cybersecurity policies, standards, and requirements, as well as complying with applicable cybersecurity regulations and industry standards.\\nThe role holder will ensure that security requirements are properly captured and embedded within the Software Development Life Cycle SDLC for all technology initiatives, secure coding practices are adhered to, and secure software and application configurations are maintained.\\nThe specialist will carry out security testing across all technology stacks mobile, web applications, APIs\/microservices, source code, web servers, containers, servers, databases, virtualization environments, network devices, and connectivity within assigned scrum teams and projects.\\nResponsibilities\\nWork with scrum and project teams to ensure that security requirements are adequately captured during the requirements analysis phase.\\nProvide input into the secure design of information systems architecture throughout the project lifecycle.\\nEnsure that access to systems during the project lifecycle by staff, contractors, and vendors is secure and based on the principle of least privilege.\\nEnforce the implementation and adoption of minimum security baseline standards across all technologies in use.\\nFacilitate the identification of security vulnerabilities by performing or coordinating security assessments, vulnerability assessments, and penetration testing VAPT.\\nEnsure security tools and controls are operating as expected within development and deployment pipelines and review security reports generated from them.\\nReport security gaps identified within scrum teams and projects and follow up on remediation in accordance with organizational standards and procedures.\\nIdentify security violations and incidents during the project lifecycle and coordinate the response process.\\nEnsure effective integration of security tools to protect, detect, and respond to attempted intrusions before and during project go-live.\\nCollaborate with project teams to ensure user access matrices are properly defined and aligned with established roles and responsibilities.\\nParticipate in deployment activities and conduct post-implementation reviews PIR to ensure security configurations are implemented and identified gaps do not progress into production environments.\\nEmbed cybersecurity awareness initiatives throughout the project lifecycle, with a focus on secure coding practices.\\nProvide scheduled security reports to cybersecurity leadership, project teams, and steering committees on the progress of security workstream activities.\\nRequirements\\nSkills and Experience\\nBachelor\u2019s degree in Computer Science, Information Technology, or other STEM-related discipline.\\nMaster\u2019s degree in Information Security, Cyber Security, or related field will be an added advantage.\\nProfessional information security certifications such as CISA, CISM, CISSP, CRISC, or Security+, as well as application\/security testing certifications such as CSSLP, CEH, OSCP, CPT, GPEN, GWAPT, or eJPT.\\n3+ years of experience in technology roles.\\n1+ years of experience in information security.\\n1+ years of experience in Application Security within Secure SDLC and DevSecOps environments.\\nStrong technical expertise in DevSecOps toolchains, including tools such as Ansible, Jenkins, GitLab, Azure DevOps, Trivy, SonarQube, Terraform, Git\/version control systems, or similar technologies.\\nFamiliarity with information security frameworks and standards such as PCI-DSS, ISO 27001, and SABSA.\\nKnowledge of API security, container security, and cloud security principles.\\nExperience in project implementation and user training.\\nAbility to multitask, work effectively under pressure and tight deadlines, influence stakeholders, and operate both independently and within cross-functional teams.\\nStrong verbal and written communication skills.\\nStrong analytical and problem-solving skills with the ability to collaborate effectively across teams.\", \"datePosted\": \"2026-07-16\", \"hiringOrganization\": {\"@type\": \"Organization\", \"name\": \"FinSense Africa\"}, \"jobLocation\": {\"@type\": \"Place\", \"address\": {\"@type\": \"PostalAddress\", \"addressLocality\": \"Nairobi\", \"addressCountry\": \"KE\"}}, \"directApply\": true, \"validThrough\": \"2026-07-30T23:59:59\", \"employmentType\": \"FULL_TIME\"}<\/script><\/p>\n<p><strong>Company:<\/strong> FinSense Africa<\/p>\n<p><strong>Location:<\/strong> Nairobi<\/p>\n<p><strong>Job Type:<\/strong> Full Time<\/p>\n<p><strong>Apply Before:<\/strong> 2026-07-30<\/p>\n<h3>Job Description<\/h3>\n<p>Job Purpose<br \/>The role holder is responsible for ensuring information systems developed and deployed meet the organization&#8217;s cybersecurity policies, standards, and requirements, as well as complying with applicable cybersecurity regulations and industry standards.<br \/>The role holder will ensure that security requirements are properly captured and embedded within the Software Development Life Cycle SDLC for all technology initiatives, secure coding practices are adhered to, and secure software and application configurations are maintained.<br \/>The specialist will carry out security testing across all technology stacks mobile, web applications, APIs\/microservices, source code, web servers, containers, servers, databases, virtualization environments, network devices, and connectivity within assigned scrum teams and projects.<br \/>Responsibilities<br \/>Work with scrum and project teams to ensure that security requirements are adequately captured during the requirements analysis phase.<br \/>Provide input into the secure design of information systems architecture throughout the project lifecycle.<br \/>Ensure that access to systems during the project lifecycle by staff, contractors, and vendors is secure and based on the principle of least privilege.<br \/>Enforce the implementation and adoption of minimum security baseline standards across all technologies in use.<br \/>Facilitate the identification of security vulnerabilities by performing or coordinating security assessments, vulnerability assessments, and penetration testing VAPT.<br \/>Ensure security tools and controls are operating as expected within development and deployment pipelines and review security reports generated from them.<br \/>Report security gaps identified within scrum teams and projects and follow up on remediation in accordance with organizational standards and procedures.<br \/>Identify security violations and incidents during the project lifecycle and coordinate the response process.<br \/>Ensure effective integration of security tools to protect, detect, and respond to attempted intrusions before and during project go-live.<br \/>Collaborate with project teams to ensure user access matrices are properly defined and aligned with established roles and responsibilities.<br \/>Participate in deployment activities and conduct post-implementation reviews PIR to ensure security configurations are implemented and identified gaps do not progress into production environments.<br \/>Embed cybersecurity awareness initiatives throughout the project lifecycle, with a focus on secure coding practices.<br \/>Provide scheduled security reports to cybersecurity leadership, project teams, and steering committees on the progress of security workstream activities.<br \/>Requirements<br \/>Skills and Experience<br \/>Bachelor\u2019s degree in Computer Science, Information Technology, or other STEM-related discipline.<br \/>Master\u2019s degree in Information Security, Cyber Security, or related field will be an added advantage.<br \/>Professional information security certifications such as CISA, CISM, CISSP, CRISC, or Security+, as well as application\/security testing certifications such as CSSLP, CEH, OSCP, CPT, GPEN, GWAPT, or eJPT.<br \/>3+ years of experience in technology roles.<br \/>1+ years of experience in information security.<br \/>1+ years of experience in Application Security within Secure SDLC and DevSecOps environments.<br \/>Strong technical expertise in DevSecOps toolchains, including tools such as Ansible, Jenkins, GitLab, Azure DevOps, Trivy, SonarQube, Terraform, Git\/version control systems, or similar technologies.<br \/>Familiarity with information security frameworks and standards such as PCI-DSS, ISO 27001, and SABSA.<br \/>Knowledge of API security, container security, and cloud security principles.<br \/>Experience in project implementation and user training.<br \/>Ability to multitask, work effectively under pressure and tight deadlines, influence stakeholders, and operate both independently and within cross-functional teams.<br \/>Strong verbal and written communication skills.<br \/>Strong analytical and problem-solving skills with the ability to collaborate effectively across teams.<\/p>\n<h3>How to Apply<\/h3>\n<p>Interested and qualified? Go to FinSense Africa on finsense.zohorecruit.com to apply<br \/>Build your CV for free. Download in different templates.<\/p>\n<p><a href=\"https:\/\/www.myjobmag.co.ke\/apply-now\/1281153\" target=\"_blank\" rel=\"noopener\" style=\"display:inline-block;padding:10px 20px;background:#2271b1;color:#fff;text-decoration:none;border-radius:4px;\">Apply Now<\/a><\/p>\n<p><small>Source: MyJobMag<\/small><\/p>\n<p><!-- job-expiry: 2026-07-30 --><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Company: FinSense Africa Location: Nairobi Job Type: Full Time Apply Before: 2026-07-30 Job Description Job PurposeThe role holder is responsible for ensuring information systems developed and deployed meet the organization&#8217;s cybersecurity policies, standards, and requirements, as well as complying with applicable cybersecurity regulations and industry standards.The role holder will ensure that security requirements are properly [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1408,1409],"tags":[2237,1425,1413,1412],"class_list":["post-102218","post","type-post","status-publish","format-standard","hentry","category-jobs","category-nairobi","tag-finsense-africa","tag-full-time","tag-job-listing","tag-myjobmag"],"_links":{"self":[{"href":"https:\/\/jobs.dataaxisnode.com\/kenya\/wp-json\/wp\/v2\/posts\/102218","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/jobs.dataaxisnode.com\/kenya\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/jobs.dataaxisnode.com\/kenya\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/jobs.dataaxisnode.com\/kenya\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/jobs.dataaxisnode.com\/kenya\/wp-json\/wp\/v2\/comments?post=102218"}],"version-history":[{"count":0,"href":"https:\/\/jobs.dataaxisnode.com\/kenya\/wp-json\/wp\/v2\/posts\/102218\/revisions"}],"wp:attachment":[{"href":"https:\/\/jobs.dataaxisnode.com\/kenya\/wp-json\/wp\/v2\/media?parent=102218"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/jobs.dataaxisnode.com\/kenya\/wp-json\/wp\/v2\/categories?post=102218"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/jobs.dataaxisnode.com\/kenya\/wp-json\/wp\/v2\/tags?post=102218"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}