Jobs Career Advice Post Job
X

Send this job to a friend

X

Did you notice an error or suspect this job is scam? Tell us.

  • Posted: Jul 29, 2026
    Deadline: Not specified
    • @gmail.com
    • @yahoo.com
    • @outlook.com
  • Never pay for any notarisation, certificate or assessment as part of any recruitment process. When in doubt, contact us

    Housing Finance Company of Kenya was incorporated as the premier mortgage Finance Institution in Kenya licensed under the Banking Act with the CDC and the GoK owning 60% and 40% respectively.

    Housing Finance started operations with the main objective of implementing the government’s policy of promoting thrift and home ownership by lending ...
    Read more about this company

     

    Security Testing & Assurance Engineer

    About the Role

    The Security Testing & Assurance Engineer is responsible for independently assessing the effectiveness of the organization’s cybersecurity controls, validating remediation activities, and ensuring continuous compliance with security baselines, regulatory standards, and internal policies. The role conducts technical assurance reviews, verifies CBK-required controls, supports secure system development lifecycle processes, and prepares assurance dashboards and reports for senior management and regulators. This position holder works closely with IT Security Operations, Engineering, and Risk teams while maintaining functional independence to ensure unbiased assurance outcomes.

    Key Accountabilities

    • Security Assurance Reviews and Technical Assessments - Conduct proactive internal and externally facing service based security assurance reviews across systems, infrastructure, networks and applications; perform technical assessments, configuration checks, access reviews and security control validations; identify weaknesses, document findings and recommend remediation actions; validate that systems meet internal information security policy requirements and baseline standards; research and develop automated testing and validation tools to enhance security testing and reporting across the Group; and support Group projects with security testing and assurance reviews to ensure new services are fit for purpose and aligned to documented policy and security best practice.
    • Vulnerability and Audit Findings Validation - Validate closure of vulnerabilities identified through internal scans, penetration tests, red-team exercises and external assessments; track timely remediation of findings from Internal Audit, External Audit, regulators and risk assessments; and conduct independent technical validation to confirm remediation is effective and sustainable.
    • Configuration Compliance and Baseline Checks - Perform configuration compliance assessments against security baseline standards, including CIS Benchmarks, internal hardening guides, operating system, database and network security configurations; maintain the configuration compliance repository; ensure periodic reassessment cycles; escalate deviations and follow up on remediation.
    • Secure SDLC and Change Assurance - Support secure SDLC assurance for new systems, upgrades and major changes; review solution designs, security requirements, data flow diagrams and architecture documents for alignment with security standards; validate security testing results, including SAST, DAST and penetration testing, before go-live; participate in go-live readiness reviews and provide security assurance sign-off recommendations.
    • Independent Verification of CBK Cybersecurity Controls - Independently verify compliance with CBK Cybersecurity Guidelines, Risk Management Guidelines and other applicable regulatory requirements; track and report deviations, control gaps and improvement areas; and provide assurance evidence for regulatory inspections and supervisory reviews.
    • Assurance Reporting and Scorecards - Prepare security assurance scorecards, dashboards and management reports showing compliance status, exceptions, risk trends and remediation progress; develop structured reporting for regulators, internal committees, audit teams and senior leadership; and maintain accurate and complete assurance documentation and evidence repositories.

    Qualifications

    • Bachelor’s degree in information technology, Computer Science, Cybersecurity, Information Systems or related field.
    • Professional certifications preferred: CEH, Security+, OSCP as an advantage, ISO 27001 or similar.
    • Technical certifications in cloud or infrastructure security are an added advantage
    • Minimum 3–5 years’ experience in IT security, assurance or audit.
    • Experience conducting vulnerability assessments, technical reviews, or security compliance checks is essential.
    • Knowledge of IT infrastructure, web, database, networking technologies from a security assurance view
    • Understanding of techniques of cyber-attack and defense
    • Experience in a regulated industry, including banking, telecom, fintech or government, is an advantage.
    • Understanding software development tools, technologies, CI/CD, containerization, and agile methodology in relation to cyber security is an advantage
    • Familiarity with CBK Cybersecurity Guidelines, Data Protection Act, PCI-DSS and ISO 27001 control requirements.

    Check how your CV aligns with this job

    Method of Application

    Interested and qualified? Go to HF Group on hfcb.co.ke to apply

    Build your CV for free. Download in different templates.

  • Get new ICT / Computer jobs like this on Telegram.Subscribe on Telegram
  • Send your application

    View All Vacancies at HF Group Back To Home
Average Salary at HF Group
KSh 85K from 2 employees
Mysalaryscale.com

Career Advice

View All Career Advice
 

Subscribe to Job Alert

 

Join our happy subscribers

 
 
Send your application through

GmailGmail YahoomailYahoomail