Cybersecurity Specialist, Security Testing

nairobiKE

Full-time

Bachelor

2 months ago08/11/202509/10/2025

- Accepting Applications

KEY RESPONSIBILITIES: MUST NOT BE MORE THAN 10

  • Conduct regular penetration tests and vulnerability assessments on networks, web applications, and other critical infrastructure.
  • Develop, implement, and manage penetration testing schedules to identify, classify, report, and prioritize remediation of security vulnerabilities across the Group resulting in timely and effective security assessments.
  • Use a variety of tools and techniques to simulate attacks on systems and uncover vulnerabilities.
  • Develop and deliver reports on the status and effectiveness of the security testing program to internal leadership and all relevant stakeholders.
  • Perform in-depth analysis of penetration testing results and create reports that describe findings, exploitation procedures, risks, and recommendations.
  • Provide technical VAPT related support to projects in a bid to ensure compliance to technical security policies and standards. Execute penetration testing projects using the established methodology, tools, and rules of engagements.
  • Develop, research, and maintain proficiency in tools, techniques, countermeasures, and trends in computer and network vulnerabilities, data hiding, and encryption.
  • Cross-Functional Collaboration with other teams and departments to enable effective defence-in-depth controls through Red Team, Purple Team and Blue Team exercises. 
  • Emulate advanced threat actors by planning, executing, and analysing complex attack scenarios. Help develop and refine tactics, techniques, and procedures (TTPs) used by adversaries.

DAILY RESPONSIBILITIES: NOT MORE THAN 5 OF THE MOST TYPICAL

  • Perform authorized attack surface reviews and penetration testing which includes internet, intranet, wireless, web application, social engineering and physical penetration testing as per schedule and on request at the direction of the Senior Managers Cybersecurity Assurance and Head, Group Cybersecurity.
  • Deliver status reports and relevant metrics on vulnerability management across the group.
  • Conduct or guide deep testing of the Groups systems to uncover security issues both manually and using automation tools as needed to support your work.

CHALLENGES: GIVE ONE EXAMPLE OF THE CHALLENGES ENCOUNTERED IN THIS JOB

  • The advancement of zero-day exploits is on the rise with little to no turn around time to identify, mitigate and remediate identified vulnerabilities. While it is common for security testers to get satisfactory result for known attacks, zero-day attacks can prove adversarial in nature due to the limited available knowledge and expertise. By virtue of the challenge, this job would require a robust well-seasoned penetration tester to stay on top and ahead of these security concerns.

MINIMUM POSITION QUALIFICATION REQUIREMENTS

Academic & Professional

  • Education     Bachelor’s Degree    B.Sc. Information Technology / Computer Science / Cybersecurity / Engineering (Electrical, Electronic) or related field    RQ

Professional Qualifications    

  • Cybersecurity certification in either CISA/ CISM/ CISSP/ Security+ /
  • Cybersecurity certification in either CEH/CPT/CRT/GPEN/OSCP/ OSWA/OSWE/ LPT/ PenTest+/ ECSA/ CHFI/ or a relevant equivalent certification/Certified Red Team Expert (CRTE)/Certified Red Team Operator (CRTO)/ Bug Bounty Researcher (ICBBR)/ Certified Information Systems Security Tester (CISST)/PECB ISO/IEC 27001 Lead Auditor/
  • AT least one RQ or equivalent
  • Penetration Testing / Cybersecurity Assurance Certification   /Cisco Cyberops Associate & Professional or any relevant equivalent certification    AA
  • Master’s Degree    MBA / MSc     AA

Experience

  • Total Minimum No of Years of Experience Required  4

Detail    Minimum No of Years    Need Type[

  • Experience in Cybersecurity    3    ES
  • Experience in Penetration Testing and Ethical hacking    3    ES
  • Experience in Offensive Security and Red Teaming    2    DE
  • Experience in System/ Network/ Database/ Containerization and Cloud Platform Administration    2    DE
  • Experience with penetration testing frameworks and tools, such as Kali Linux, The Penetration Testers Framework, Metasploit, Canvas, Cobalt Strike, Burp Suite Pro, Nexpose, Nessus, Wireshark, Nmap    2    DE
  • Experience in code review    2    DE
     

Interested and qualified? Go to KCB Bank Kenya on eoin.fa.em3.oraclecloud.com to apply

Elevolt does not charge job seekers any fees for job applications or consideration. Do not make any payments without doing your due diligence. If you think this posting is not genuine, please flag it below orcontact us

Share:

KCB Bank

KCB Bank

KCB Bank Kenya Limited is a financial services provider headquartered in Nairobi, Kenya. It is licensed as a commercial bank, by the Central Bank of Kenya, the national banking regulator. The bank has...