FinSense Africa Cyber Security Analyst (DevSecOps) Jobs in Kenya; The Cyber Security Analyst ensures that information systems developed and deployed meet organizational cybersecurity policies, standards, and requirements, while complying with applicable regulations and industry standards.The role embeds security requirements within the Software Development Life Cycle (SDLC), enforces secure coding practices, and maintains secure configurations across applications and infrastructure.Key Responsibilities
FinSense Africa Cyber Security Analyst (DevSecOps) Jobs in Kenya;
Key Responsibilities
Work with scrum and project teams to capture security requirements during requirements analysis.
Provide input into secure design of information systems architecture throughout the project lifecycle.
Ensure system access is secure and based on leastprivilege principles.
Enforce minimum security baseline standards across technologies.
Perform or coordinate security assessments, vulnerability assessments, and penetration testing (VAPT).
Ensure security tools and controls operate effectively within development and deployment pipelines.
Report security gaps and follow up on remediation.
Identify and coordinate responses to security violations and incidents.
Integrate security tools to protect, detect, and respond to intrusions before and during golive.
Collaborate with teams to ensure user access matrices align with roles and responsibilities.
Participate in deployment activities and conduct postimplementation reviews (PIR).
Embed cybersecurity awareness initiatives throughout the project lifecycle.
Provide scheduled security reports to leadership, project teams, and steering committees.RequirementsEducation & Experience
Requirements
Bachelor’s degree in Computer Science, IT, or STEM discipline.
Master’s degree in Information Security or Cybersecurity is an added advantage.
Professional certifications such as CISA, CISM, CISSP, (adsbygoogle=window.adsbygoogle||[]).push({});CRISC, Security+, CSSLP, CEH, OSCP, CPT, GPEN, GWAPT, or eJPT.
3+ years of experience in technology roles.
1+ years of experience in information security.
1+ years of experience in Application Security within Secure SDLC and DevSecOps environments.Technical Competencies
Expertise in DevSecOps toolchains (Ansible, Jenkins, GitLab, Azure DevOps, Trivy, SonarQube, Terraform, Git).
Familiarity with frameworks and standards (PCIDSS, ISO 27001, SABSA).
Knowledge of API security, container security, and cloud security principles.
Experience in project implementation and user training.Core Skills
Ability to multitask and work under pressure.
Strong stakeholder influence and crossfunctional collaboration.
Excellent verbal and written communication skills.