326 Senior Information Security Auditor jobs in Kenya

Information Security Auditor

20201 Kapsuser KES140000 Annually WhatJobs remove_red_eye View All

Posted 14 days ago

Job Viewed

Tap Again To Close

Job Description

full-time
Our client is looking for a meticulous and analytical Information Security Auditor to join their team. This role will involve conducting comprehensive assessments of the organization's security controls, policies, and procedures to ensure compliance with industry standards and regulatory requirements. You will identify vulnerabilities, assess risks, and provide actionable recommendations for enhancing the overall security posture. The position offers a hybrid work arrangement, allowing for a balance between remote work and in-office collaboration. Your expertise will be vital in safeguarding sensitive data and maintaining the integrity of our IT systems.

Key Responsibilities:
  • Plan and execute information security audits across various IT systems and business processes.
  • Evaluate the effectiveness of existing security controls, including physical, technical, and administrative safeguards.
  • Review and assess compliance with relevant regulations and standards (e.g., GDPR, SOX, PCI DSS, ISO 27001).
  • Identify security risks, vulnerabilities, and non-compliance issues, and document findings clearly.
  • Develop detailed audit reports with prioritized recommendations for remediation.
  • Collaborate with IT and business departments to discuss audit findings and remediation plans.
  • Follow up on audit recommendations to ensure timely and effective implementation.
  • Stay current with emerging threats, security trends, and audit best practices.
  • Assist in the development and maintenance of audit programs and methodologies.
  • Contribute to the continuous improvement of the information security management system.

Qualifications:
  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field.
  • Minimum of 4 years of experience in information security, IT audit, or risk management.
  • Strong understanding of cybersecurity principles, frameworks, and best practices.
  • Experience with various IT systems, networks, and application security concepts.
  • Knowledge of common IT audit frameworks and methodologies.
  • Excellent analytical and problem-solving skills with a keen eye for detail.
  • Strong written and verbal communication skills, with the ability to present complex information clearly.
  • Proficiency in data analysis and reporting tools.
  • Ability to work effectively both independently and as part of a team.
  • Relevant certifications such as CISA, CISSP, or CRISC are highly desirable.

This hybrid role offers a significant opportunity to impact the security of a growing organization. If you possess a strong audit background and a passion for cybersecurity, we encourage you to apply.
This advertiser has chosen not to accept applicants from your region.

Senior Information Security Auditor

00200 Ngong KES220000 Annually WhatJobs remove_red_eye View All

Posted 19 days ago

Job Viewed

Tap Again To Close

Job Description

full-time
Our client, a rapidly growing technology firm, is seeking a highly experienced Senior Information Security Auditor to join their dedicated team in Ruiru, Kiambu, KE . This role is critical for ensuring the robust security of our client's digital assets and systems. You will be responsible for conducting comprehensive security audits, assessing vulnerabilities, and implementing corrective actions to mitigate risks. Key duties include evaluating IT controls, compliance with security policies and regulations, and developing security best practices. The ideal candidate will possess extensive knowledge of cybersecurity frameworks (e.g., ISO 27001, NIST), risk assessment methodologies, and audit procedures. You will play a pivotal role in identifying potential security threats and ensuring the integrity and confidentiality of sensitive data. This position requires excellent analytical skills, strong attention to detail, and the ability to communicate complex technical findings effectively to both technical and non-technical audiences. You will collaborate closely with IT and development teams to implement security enhancements and ensure compliance. We are looking for a proactive and detail-oriented professional with a proven track record in information security auditing. This is an exciting opportunity to contribute to a secure digital environment within a dynamic organization. The successful candidate will be instrumental in safeguarding our client's infrastructure and maintaining stakeholder trust. This role requires meticulous planning and execution of audit procedures. A strong understanding of penetration testing and vulnerability management is a plus.
This advertiser has chosen not to accept applicants from your region.

Information Security Auditor (Remote)

50200 Tuwan KES115000 Annually WhatJobs

Posted 12 days ago

Job Viewed

Tap Again To Close

Job Description

full-time
Our client is seeking a meticulous and knowledgeable Information Security Auditor to join their fully remote security team. This position is crucial for assessing and verifying the effectiveness of the company's security controls, policies, and procedures. You will be responsible for planning and conducting comprehensive security audits across various IT systems, applications, and infrastructure to identify vulnerabilities and ensure compliance with internal standards and external regulations. The ideal candidate will possess a strong understanding of information security frameworks (e.g., ISO 27001, NIST), risk assessment methodologies, and audit best practices. You will examine system logs, configuration settings, and access controls to detect potential security weaknesses and non-compliance issues. Developing detailed audit reports, documenting findings, and providing actionable recommendations for remediation to management and technical teams will be a core responsibility. Collaborating with IT and security personnel to implement corrective actions and track their progress towards resolution is also essential. Staying abreast of emerging threats, vulnerabilities, and regulatory changes to ensure audit scope remains relevant and effective is key. Experience with security auditing tools and techniques is highly desirable. Excellent analytical, problem-solving, and communication skills are required to effectively present audit findings and recommendations. This is an outstanding opportunity for a skilled auditor to contribute to the robust security posture of our client in a remote setting, focusing on security assurance for operations associated with Bungoma, Bungoma, KE .
This advertiser has chosen not to accept applicants from your region.

Lead Information Security Auditor (Remote)

30200 Tuwan KES480000 Annually WhatJobs

Posted 3 days ago

Job Viewed

Tap Again To Close

Job Description

full-time
Our client is seeking a highly experienced Lead Information Security Auditor to join their fully remote team. In this critical role, you will be responsible for conducting comprehensive security audits across our organization's IT infrastructure, applications, and processes. Your primary objective will be to ensure compliance with industry regulations, internal policies, and best practices in cybersecurity. You will lead audit engagements, manage audit teams, and provide strategic guidance on risk mitigation and security improvements. This position requires a deep understanding of various security domains, including network security, application security, data privacy, and cloud security. You will play a crucial role in identifying vulnerabilities, assessing risks, and recommending effective controls to protect sensitive information and maintain the integrity of our systems. The ideal candidate possesses exceptional analytical skills, a meticulous approach to detail, and a strong understanding of audit methodologies and frameworks such as ISO 27001, NIST, and SOC 2. You should be adept at communicating complex security findings to both technical and executive audiences. As a remote leader, you must be highly self-motivated, organized, and proficient in using collaboration tools to effectively manage distributed teams and projects. Your contributions will be essential in maintaining our robust security posture and fostering a culture of security awareness throughout the organization. This is an excellent opportunity for a seasoned security professional to make a significant impact from anywhere in the world.

Key Responsibilities:
  • Plan, execute, and report on information security audits across various technology domains.
  • Assess the effectiveness of security controls, policies, and procedures to ensure compliance with relevant regulations and standards.
  • Identify security vulnerabilities, assess associated risks, and develop actionable recommendations for remediation.
  • Lead and mentor junior auditors, providing technical guidance and oversight for audit engagements.
  • Develop and maintain audit programs and methodologies tailored to the organization's risk profile.
  • Review system configurations, network architectures, and application security practices for potential weaknesses.
  • Conduct security awareness training and phishing simulations to improve employee understanding of security threats.
  • Stay up-to-date with the latest security threats, vulnerabilities, and regulatory changes impacting the industry.
  • Collaborate with IT, compliance, and legal teams to address audit findings and implement corrective actions.
  • Prepare comprehensive audit reports detailing findings, risks, and recommendations for senior management.
  • Develop and implement metrics to track the progress of security remediation efforts.
  • Advise on the implementation of new security technologies and controls.
Qualifications:
  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field.
  • Minimum of 8 years of experience in information security, with at least 5 years in security auditing or risk management.
  • Proven experience leading and managing audit teams.
  • In-depth knowledge of security frameworks (ISO 27001, NIST, COBIT) and regulations (e.g., GDPR, CCPA).
  • Strong understanding of network security, cryptography, vulnerability management, and secure coding practices.
  • Experience with cloud security assessments (AWS, Azure, GCP).
  • Proficiency in security assessment tools and techniques.
  • Excellent analytical, problem-solving, and critical thinking skills.
  • Exceptional written and verbal communication skills, with the ability to present complex information clearly and concisely.
  • Relevant certifications such as CISA, CISSP, CISM, or CRISC are highly desirable.
  • Demonstrated ability to work independently and manage multiple priorities effectively in a remote setting.
This advertiser has chosen not to accept applicants from your region.

Information Security Compliance Manager

50100 Kakamega, Western KES170000 Annually WhatJobs

Posted 18 days ago

Job Viewed

Tap Again To Close

Job Description

full-time
Our client is seeking a dedicated and experienced Information Security Compliance Manager to lead their security compliance initiatives within a fully remote framework. This role is crucial for ensuring that our organization adheres to all relevant legal, regulatory, and industry standards concerning data protection and cybersecurity. You will be responsible for developing, implementing, and maintaining comprehensive compliance programs, conducting audits, and managing relationships with regulatory bodies. As a remote leader, you will foster a culture of security awareness across the organization and guide teams in meeting compliance objectives. This position demands a deep understanding of global security regulations and a proactive approach to risk management.

Key Responsibilities:
  • Develop, implement, and manage information security policies, procedures, and controls to ensure compliance with relevant regulations (e.g., GDPR, CCPA, HIPAA, PCI DSS).
  • Conduct regular internal and external security audits to assess compliance levels and identify areas for improvement.
  • Manage the process of external audits and certifications, acting as the primary point of contact for auditors and assessors.
  • Oversee the development and execution of risk management frameworks, including regular risk assessments and mitigation planning.
  • Stay informed about evolving legal and regulatory requirements related to data privacy and cybersecurity, and update compliance programs accordingly.
  • Develop and deliver security awareness training programs to employees across the organization.
  • Investigate and manage any compliance breaches or incidents, ensuring appropriate remediation steps are taken and documented.
  • Collaborate with legal, IT, and business units to ensure alignment on compliance strategies and initiatives.
  • Prepare regular reports for senior management on the status of information security compliance and identified risks.
  • Maintain documentation related to compliance policies, procedures, assessments, and training records.

Qualifications:
  • Bachelor's degree in Information Technology, Computer Science, Law, or a related field; Master's degree preferred.
  • Minimum of 6 years of experience in information security, with at least 3 years specifically focused on compliance and risk management.
  • In-depth knowledge of major data privacy and security regulations (GDPR, CCPA, HIPAA, PCI DSS, ISO 27001).
  • Proven experience in conducting security audits, risk assessments, and developing remediation plans.
  • Strong understanding of IT infrastructure, cybersecurity principles, and common security threats.
  • Excellent analytical, problem-solving, and strategic thinking skills.
  • Exceptional communication, presentation, and interpersonal skills, with the ability to effectively engage stakeholders at all levels in a remote environment.
  • Relevant certifications such as CISM, CISSP, CISA, or CIPP are highly desirable.
  • Ability to work independently, manage multiple projects, and meet deadlines in a remote setting.
  • Demonstrated leadership capabilities and experience in managing compliance programs.
This advertiser has chosen not to accept applicants from your region.

Remote Senior Information Security Auditor

90100 Mangu KES5800000 Annually WhatJobs remove_red_eye View All

Posted 12 days ago

Job Viewed

Tap Again To Close

Job Description

full-time
Our client, a prominent financial services institution, is seeking a highly experienced and meticulous Senior Information Security Auditor to join their fully remote audit and compliance team. This role is essential for evaluating the effectiveness of the organization's information security controls, ensuring compliance with regulatory requirements, and identifying potential risks across all IT systems and processes. You will be responsible for planning and executing comprehensive security audits, developing audit reports, and recommending improvements to security posture. The ideal candidate will have a deep understanding of information security principles, audit methodologies, and relevant regulatory frameworks (e.g., PCI DSS, GDPR, SOX). Your key responsibilities will include:

  • Planning, scoping, and executing information security audits across various IT environments, including cloud platforms, networks, applications, and databases.
  • Assessing the design and operating effectiveness of internal controls related to information security, data privacy, and IT governance.
  • Identifying control deficiencies, security risks, and non-compliance issues, and documenting findings in detailed audit reports.
  • Developing practical and actionable recommendations for remediation of identified risks and control weaknesses.
  • Following up on audit findings to ensure that management implements corrective actions effectively and in a timely manner.
  • Staying current with evolving threats, vulnerabilities, industry best practices, and regulatory requirements impacting information security.
  • Collaborating with internal stakeholders, including IT, security operations, and compliance teams, to gather information and discuss audit findings.
  • Conducting risk assessments to inform audit planning and prioritize audit activities.
  • Performing ad-hoc security reviews and investigations as needed.
  • Contributing to the continuous improvement of the internal audit function and its methodologies.

Qualifications:
  • Bachelor's degree in Computer Science, Information Systems, Accounting, or a related field. A Master's degree is a plus.
  • Minimum of 6 years of experience in information security auditing, IT audit, or a related security control function.
  • In-depth knowledge of information security principles, risk management frameworks (e.g., NIST, ISO 27001), and common security controls.
  • Experience with relevant regulatory and compliance frameworks such as PCI DSS, GDPR, SOX, HIPAA, etc.
  • Familiarity with audit methodologies, including risk-based auditing and control testing.
  • Proficiency in using audit management software and tools.
  • Strong analytical, critical thinking, and problem-solving skills.
  • Excellent written and verbal communication skills, with the ability to produce clear, concise audit reports and present findings effectively remotely.
  • Relevant certifications such as CISA, CISSP, CISM, or CRISC are highly desirable.
  • Ability to work independently, manage multiple audit engagements, and meet deadlines in a remote environment.
This is a crucial role for maintaining the security and integrity of our client's operations, offering a fully remote work arrangement. If you are a detail-oriented auditor with a passion for ensuring robust information security, we invite you to apply.
This advertiser has chosen not to accept applicants from your region.

Senior Information Security Analyst - Compliance

90100 Mangu KES5500000 Annually WhatJobs

Posted 17 days ago

Job Viewed

Tap Again To Close

Job Description

full-time
Our client is seeking a diligent and experienced Senior Information Security Analyst with a focus on compliance and risk management. This role is office-based, requiring your presence within our Machakos, Machakos, KE location to foster close collaboration and ensure robust security practices. You will be responsible for implementing and maintaining information security policies, procedures, and controls to protect the organization's assets and ensure compliance with relevant regulations (e.g., GDPR, ISO 27001, PCI DSS). The ideal candidate will have a strong understanding of security frameworks, risk assessment methodologies, and incident response. You will conduct security audits, vulnerability assessments, and penetration tests, and develop remediation plans. Key responsibilities include:
  • Developing, implementing, and enforcing information security policies and procedures.
  • Conducting regular risk assessments and vulnerability analyses to identify potential security threats.
  • Managing and overseeing security audits, ensuring compliance with industry standards and regulations.
  • Developing and executing incident response plans to effectively address security breaches.
  • Monitoring security systems and logs for suspicious activities.
  • Recommending and implementing security controls and technologies to mitigate risks.
  • Providing security awareness training to employees.
  • Staying current with emerging security threats, vulnerabilities, and best practices.
  • Collaborating with IT and other departments to integrate security into all aspects of operations.
  • Managing relationships with third-party security vendors.
The successful candidate will hold a Bachelor's degree in Computer Science, Information Technology, or a related field, and possess relevant security certifications such as CISSP, CISM, or CRISC. A minimum of 5 years of experience in information security, with a strong emphasis on compliance and risk management, is required. Demonstrated experience with security frameworks and regulatory requirements is essential. Excellent analytical, problem-solving, and communication skills are necessary. This role is critical to maintaining the security posture of our organization within the Machakos, Machakos, KE office.
This advertiser has chosen not to accept applicants from your region.
Be The First To Know

About the latest Senior information security auditor Jobs in Kenya !

Senior Information Security Architect - Cloud Security & Compliance

00100 Abothuguchi West KES1200000 Annually WhatJobs

Posted 15 days ago

Job Viewed

Tap Again To Close

Job Description

full-time
Our client is seeking a highly skilled and experienced Senior Information Security Architect with a specialization in cloud security and compliance to join their fully remote, cutting-edge security team. This pivotal role will involve designing, implementing, and maintaining robust security architectures for cloud-based environments, ensuring the confidentiality, integrity, and availability of sensitive data. You will be responsible for developing security policies, standards, and procedures that align with industry best practices and regulatory requirements. Key responsibilities include conducting security risk assessments, threat modeling, and vulnerability management for cloud infrastructures (AWS, Azure, GCP). You will design and implement security controls, including identity and access management (IAM), network security, data encryption, and security monitoring solutions. Collaboration with development, operations, and compliance teams will be essential to integrate security seamlessly into the software development lifecycle and ensure adherence to compliance frameworks (e.g., ISO 27001, SOC 2, GDPR). The ideal candidate will possess deep expertise in cloud security principles, container security, and DevSecOps methodologies. Strong knowledge of security automation and orchestration tools is highly desirable. This is a fully remote position requiring exceptional analytical, problem-solving, and communication skills to effectively lead security initiatives and advise stakeholders across the organization. You will play a crucial role in safeguarding our client's digital assets and ensuring a strong security posture for their operations, impacting the **Nairobi, Nairobi, KE** region and their global presence. This role offers an exciting opportunity to architect and implement advanced security solutions in a dynamic, remote environment.
This advertiser has chosen not to accept applicants from your region.

Senior Information Security Analyst (Information Security)

20110 Mwembe KES750000 Annually WhatJobs

Posted 11 days ago

Job Viewed

Tap Again To Close

Job Description

full-time
Our client is looking for a proactive and skilled Senior Information Security Analyst to bolster their cybersecurity defenses. This role is integral to protecting the organization's digital assets, ensuring the confidentiality, integrity, and availability of sensitive information. The ideal candidate will possess a deep understanding of cybersecurity principles, threat landscapes, and vulnerability management. Key responsibilities include monitoring security systems for suspicious activities, conducting in-depth security investigations, and responding to security incidents. You will perform regular vulnerability assessments and penetration tests, identify potential weaknesses, and develop remediation plans. This role also involves staying abreast of the latest cybersecurity threats and trends, implementing security best practices, and contributing to the development and refinement of security policies and procedures. You will collaborate with IT teams to ensure secure system configurations and assist in security awareness training for employees. Experience with security information and event management (SIEM) tools, intrusion detection/prevention systems (IDPS), and firewalls is essential. A strong understanding of network security, cloud security, and data privacy regulations is highly desirable. This position requires excellent analytical and problem-solving skills, attention to detail, and the ability to work effectively both independently and as part of a team. This role offers the flexibility of remote work, allowing you to contribute to enhancing security posture from anywhere, supporting operations in Nakuru, Nakuru, KE .
This advertiser has chosen not to accept applicants from your region.

Information Security Analyst

10100 Nyeri Town KES85000 Annually WhatJobs remove_red_eye View All

Posted 19 days ago

Job Viewed

Tap Again To Close

Job Description

full-time
Our client, a rapidly expanding technology firm, is seeking a vigilant and skilled Information Security Analyst to join their fully remote cybersecurity team. This critical role involves protecting the organization's digital assets from cyber threats, ensuring data integrity, and maintaining the confidentiality and availability of information systems. You will be responsible for monitoring security systems, detecting and responding to security incidents, conducting vulnerability assessments, and implementing security measures to mitigate risks. A deep understanding of cybersecurity principles, network security, and threat intelligence is essential. The ideal candidate will possess strong analytical and problem-solving skills, with the ability to stay ahead of evolving cyber threats. This is a remote-first position, allowing you to work effectively from Nyeri, Nyeri, KE , and collaborate with a global team. We are looking for a proactive individual who is passionate about cybersecurity and committed to maintaining a secure digital environment. Responsibilities include developing and enforcing security policies, conducting security awareness training, and staying current with the latest security technologies and best practices. If you are an experienced security professional looking for a challenging and rewarding remote career, we encourage you to apply.

Key Responsibilities:
  • Monitor security infrastructure for suspicious activities and potential threats.
  • Investigate and respond to security incidents in a timely and effective manner.
  • Conduct vulnerability assessments and penetration testing.
  • Implement and manage security controls and technologies.
  • Develop and update security policies and procedures.
  • Perform regular security audits and compliance checks.
  • Stay abreast of emerging cybersecurity threats and trends.
  • Provide security awareness training to employees.
  • Collaborate with IT teams to ensure secure system configurations.
  • Contribute to the development of the organization's overall security strategy.

Qualifications:
  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field.
  • Minimum of 3 years of experience in information security or cybersecurity.
  • Strong knowledge of network security, firewalls, intrusion detection/prevention systems.
  • Familiarity with security frameworks (e.g., NIST, ISO 27001).
  • Experience with security monitoring tools and SIEM solutions.
  • Certifications such as CISSP, Security+, CEH are a plus.
  • Excellent analytical, problem-solving, and communication skills.
  • Ability to work independently and effectively in a remote environment.
This advertiser has chosen not to accept applicants from your region.
 

Nearby Locations

Other Jobs Near Me

Industry

  1. request_quote Accounting
  2. work Administrative
  3. eco Agriculture Forestry
  4. smart_toy AI & Emerging Technologies
  5. school Apprenticeships & Trainee
  6. apartment Architecture
  7. palette Arts & Entertainment
  8. directions_car Automotive
  9. flight_takeoff Aviation
  10. account_balance Banking & Finance
  11. local_florist Beauty & Wellness
  12. restaurant Catering
  13. volunteer_activism Charity & Voluntary
  14. science Chemical Engineering
  15. child_friendly Childcare
  16. foundation Civil Engineering
  17. clean_hands Cleaning & Sanitation
  18. diversity_3 Community & Social Care
  19. construction Construction
  20. brush Creative & Digital
  21. currency_bitcoin Crypto & Blockchain
  22. support_agent Customer Service & Helpdesk
  23. medical_services Dental
  24. medical_services Driving & Transport
  25. medical_services E Commerce & Social Media
  26. school Education & Teaching
  27. electrical_services Electrical Engineering
  28. bolt Energy
  29. local_mall Fmcg
  30. gavel Government & Non Profit
  31. emoji_events Graduate
  32. health_and_safety Healthcare
  33. beach_access Hospitality & Tourism
  34. groups Human Resources
  35. precision_manufacturing Industrial Engineering
  36. security Information Security
  37. handyman Installation & Maintenance
  38. policy Insurance
  39. code IT & Software
  40. gavel Legal
  41. sports_soccer Leisure & Sports
  42. inventory_2 Logistics & Warehousing
  43. supervisor_account Management
  44. supervisor_account Management Consultancy
  45. supervisor_account Manufacturing & Production
  46. campaign Marketing
  47. build Mechanical Engineering
  48. perm_media Media & PR
  49. local_hospital Medical
  50. local_hospital Military & Public Safety
  51. local_hospital Mining
  52. medical_services Nursing
  53. local_gas_station Oil & Gas
  54. biotech Pharmaceutical
  55. checklist_rtl Project Management
  56. shopping_bag Purchasing
  57. home_work Real Estate
  58. person_search Recruitment Consultancy
  59. store Retail
  60. point_of_sale Sales
  61. science Scientific Research & Development
  62. wifi Telecoms
  63. psychology Therapy
  64. pets Veterinary
View All Senior Information Security Auditor Jobs