Security Testing and Assurance Engineer job at HFCB Group
15 Days Ago
Linkedid Twitter Share on facebook
Security Testing and Assurance Engineer
2026-07-29T13:46:57+00:00
HFCB Group
https://cdn.greatkenyanjobs.com/jsjobsdata/data/employer/comp_11895/logo/download%20-%202026-06-08T183350.829.png
FULL_TIME
Nairobi
Nairobi
00100
Kenya
Finance
Computer & IT, Science & Engineering, Protective Services
KES
MONTH
2026-08-07T17:00:00+00:00
8

HFCB Group Plc is an integrated financial solutions provider that is registered as a non–operating holding company (under the Banking Act Cap.488) and regulated by the Central Bank of Kenya (CBK) and the Capital Markets Authority (CMA). The Group is a public limited company with interests in Banking, Property and Insurance, and is listed at the Nairobi Securities Exchange. For more information on our banking, property and insurance solutions, please visit www.hfcb.co.ke The Group has 4 main entities: HFCB Limited – Full-Service Banking, HFCB Properties Limited – Property/Real Estate Solutions, HFCB Bancassurance Intermediary – Insurance Solutions & HFCB Foundation Limited – ESG/Sustainability.

On the back of a strong growth trajectory and in a bid to power the business, HFCB Limited is looking to recruit a dynamic and results-oriented Security Testing & Assurance Engineer.

About the Role

The Security Testing & Assurance Engineer is responsible for independently assessing the effectiveness of the organization’s cybersecurity controls, validating remediation activities, and ensuring continuous compliance with security baselines, regulatory standards, and internal policies. The role conducts technical assurance reviews, verifies CBK-required controls, supports secure system development lifecycle processes, and prepares assurance dashboards and reports for senior management and regulators. This position holder works closely with IT Security Operations, Engineering, and Risk teams while maintaining functional independence to ensure unbiased assurance outcomes.

Key Accountabilities

Security Assurance Reviews and Technical Assessments

- Conduct proactive internal and externally facing service based security assurance reviews across systems, infrastructure, networks and applications; perform technical assessments, configuration checks, access reviews and security control validations; identify weaknesses, document findings and recommend remediation actions; validate that systems meet internal information security policy requirements and baseline standards; research and develop automated testing and validation tools to enhance security testing and reporting across the Group; and support Group projects with security testing and assurance reviews to ensure new services are fit for purpose and aligned to documented policy and security best practice.

Vulnerability and Audit Findings Validation

- Validate closure of vulnerabilities identified through internal scans, penetration tests, red-team exercises and external assessments; track timely remediation of findings from Internal Audit, External Audit, regulators and risk assessments; and conduct independent technical validation to confirm remediation is effective and sustainable.

Configuration Compliance and Baseline Checks

- Perform configuration compliance assessments against security baseline standards, including CIS Benchmarks, internal hardening guides, operating system, database and network security configurations; maintain the configuration compliance repository; ensure periodic reassessment cycles; escalate deviations and follow up on remediation.

Secure SDLC and Change Assurance

- Support secure SDLC assurance for new systems, upgrades and major changes; review solution designs, security requirements, data flow diagrams and architecture documents for alignment with security standards; validate security testing results, including SAST, DAST and penetration testing, before go-live; participate in go-live readiness reviews and provide security assurance sign-off recommendations.

Independent Verification of CBK Cybersecurity Controls

- Independently verify compliance with CBK Cybersecurity Guidelines, Risk Management Guidelines and other applicable regulatory requirements; track and report deviations, control gaps and improvement areas; and provide assurance evidence for regulatory inspections and supervisory reviews.

Assurance Reporting and Scorecards

- Prepare security assurance scorecards, dashboards and management reports showing compliance status, exceptions, risk trends and remediation progress; develop structured reporting for regulators, internal committees, audit teams and senior leadership; and maintain accurate and complete assurance documentation and evidence repositories.

Qualifications

  • Bachelor’s degree in information technology, Computer Science, Cybersecurity, Information Systems or related field.
  • Professional certifications preferred: CEH, Security+, OSCP as an advantage, ISO 27001 or similar.
  • Technical certifications in cloud or infrastructure security are an added advantage
  • Minimum 3–5 years’ experience in IT security, assurance or audit.
  • Experience conducting vulnerability assessments, technical reviews, or security compliance checks is essential.
  • Knowledge of IT infrastructure, web, database, networking technologies from a security assurance view
  • Understanding of techniques of cyber-attack and defense
  • Experience in a regulated industry, including banking, telecom, fintech or government, is an advantage.
  • Understanding software development tools, technologies, CI/CD, containerization, and agile methodology in relation to cyber security is an advantage
  • Familiarity with CBK Cybersecurity Guidelines, Data Protection Act, PCI-DSS and ISO 27001 control requirements.

Competencies

  • Hands-on understanding of security controls, network security, system administration, and secure configurations.
  • Understanding of securing cloud infrastructure, SOA (Service Oriented Architecture) and AI based technologies
  • Experience with vulnerability scanners, configuration checking tools, and assessment utilities.
  • Strong knowledge of ISO 27001, NIST CSF, CIS Benchmarks, and CBK Cybersecurity Guidelines.
  • Ability to review system designs, architectures and SDLC documentation for security compliance.
  • Analytical skills to assess complex technical environments and identify risks.
  • Ability to prepare structured assurance reports and dashboards
  • High level of integrity and confidentiality.
  • Strong communication and stakeholder management skills.
  • Analytical thinker with attention to detail.
  • Ability to manage multiple tasks and deadlines.
  • Proactive, with strong problem-solving skills.
  • Team player with the ability to work independently.
  • Conduct proactive internal and externally facing service based security assurance reviews across systems, infrastructure, networks and applications; perform technical assessments, configuration checks, access reviews and security control validations; identify weaknesses, document findings and recommend remediation actions; validate that systems meet internal information security policy requirements and baseline standards; research and develop automated testing and validation tools to enhance security testing and reporting across the Group; and support Group projects with security testing and assurance reviews to ensure new services are fit for purpose and aligned to documented policy and security best practice.
  • Validate closure of vulnerabilities identified through internal scans, penetration tests, red-team exercises and external assessments; track timely remediation of findings from Internal Audit, External Audit, regulators and risk assessments; and conduct independent technical validation to confirm remediation is effective and sustainable.
  • Perform configuration compliance assessments against security baseline standards, including CIS Benchmarks, internal hardening guides, operating system, database and network security configurations; maintain the configuration compliance repository; ensure periodic reassessment cycles; escalate deviations and follow up on remediation.
  • Support secure SDLC assurance for new systems, upgrades and major changes; review solution designs, security requirements, data flow diagrams and architecture documents for alignment with security standards; validate security testing results, including SAST, DAST and penetration testing, before go-live; participate in go-live readiness reviews and provide security assurance sign-off recommendations.
  • Independently verify compliance with CBK Cybersecurity Guidelines, Risk Management Guidelines and other applicable regulatory requirements; track and report deviations, control gaps and improvement areas; and provide assurance evidence for regulatory inspections and supervisory reviews.
  • Prepare security assurance scorecards, dashboards and management reports showing compliance status, exceptions, risk trends and remediation progress; develop structured reporting for regulators, internal committees, audit teams and senior leadership; and maintain accurate and complete assurance documentation and evidence repositories.
  • Hands-on understanding of security controls, network security, system administration, and secure configurations.
  • Understanding of securing cloud infrastructure, SOA (Service Oriented Architecture) and AI based technologies
  • Experience with vulnerability scanners, configuration checking tools, and assessment utilities.
  • Strong knowledge of ISO 27001, NIST CSF, CIS Benchmarks, and CBK Cybersecurity Guidelines.
  • Ability to review system designs, architectures and SDLC documentation for security compliance.
  • Analytical skills to assess complex technical environments and identify risks.
  • Ability to prepare structured assurance reports and dashboards
  • High level of integrity and confidentiality.
  • Strong communication and stakeholder management skills.
  • Analytical thinker with attention to detail.
  • Ability to manage multiple tasks and deadlines.
  • Proactive, with strong problem-solving skills.
  • Team player with the ability to work independently.
  • Bachelor’s degree in information technology, Computer Science, Cybersecurity, Information Systems or related field.
  • Professional certifications preferred: CEH, Security+, OSCP as an advantage, ISO 27001 or similar.
  • Technical certifications in cloud or infrastructure security are an added advantage
  • Experience conducting vulnerability assessments, technical reviews, or security compliance checks is essential.
  • Knowledge of IT infrastructure, web, database, networking technologies from a security assurance view
  • Understanding of techniques of cyber-attack and defense
  • Experience in a regulated industry, including banking, telecom, fintech or government, is an advantage.
  • Understanding software development tools, technologies, CI/CD, containerization, and agile methodology in relation to cyber security is an advantage
  • Familiarity with CBK Cybersecurity Guidelines, Data Protection Act, PCI-DSS and ISO 27001 control requirements.
bachelor degree
36
JOB-6a6a04515bcb9

Vacancy title:
Security Testing and Assurance Engineer

[Type: FULL_TIME, Industry: Finance, Category: Computer & IT, Science & Engineering, Protective Services]

Jobs at:
HFCB Group

Deadline of this Job:
Friday, August 7 2026

Duty Station:
Nairobi | Nairobi

Summary
Date Posted: Wednesday, July 29 2026, Base Salary: Not Disclosed

Similar Jobs in Kenya
Learn more about HFCB Group
HFCB Group jobs in Kenya

JOB DETAILS:

HFCB Group Plc is an integrated financial solutions provider that is registered as a non–operating holding company (under the Banking Act Cap.488) and regulated by the Central Bank of Kenya (CBK) and the Capital Markets Authority (CMA). The Group is a public limited company with interests in Banking, Property and Insurance, and is listed at the Nairobi Securities Exchange. For more information on our banking, property and insurance solutions, please visit www.hfcb.co.ke The Group has 4 main entities: HFCB Limited – Full-Service Banking, HFCB Properties Limited – Property/Real Estate Solutions, HFCB Bancassurance Intermediary – Insurance Solutions & HFCB Foundation Limited – ESG/Sustainability.

On the back of a strong growth trajectory and in a bid to power the business, HFCB Limited is looking to recruit a dynamic and results-oriented Security Testing & Assurance Engineer.

About the Role

The Security Testing & Assurance Engineer is responsible for independently assessing the effectiveness of the organization’s cybersecurity controls, validating remediation activities, and ensuring continuous compliance with security baselines, regulatory standards, and internal policies. The role conducts technical assurance reviews, verifies CBK-required controls, supports secure system development lifecycle processes, and prepares assurance dashboards and reports for senior management and regulators. This position holder works closely with IT Security Operations, Engineering, and Risk teams while maintaining functional independence to ensure unbiased assurance outcomes.

Key Accountabilities

Security Assurance Reviews and Technical Assessments

- Conduct proactive internal and externally facing service based security assurance reviews across systems, infrastructure, networks and applications; perform technical assessments, configuration checks, access reviews and security control validations; identify weaknesses, document findings and recommend remediation actions; validate that systems meet internal information security policy requirements and baseline standards; research and develop automated testing and validation tools to enhance security testing and reporting across the Group; and support Group projects with security testing and assurance reviews to ensure new services are fit for purpose and aligned to documented policy and security best practice.

Vulnerability and Audit Findings Validation

- Validate closure of vulnerabilities identified through internal scans, penetration tests, red-team exercises and external assessments; track timely remediation of findings from Internal Audit, External Audit, regulators and risk assessments; and conduct independent technical validation to confirm remediation is effective and sustainable.

Configuration Compliance and Baseline Checks

- Perform configuration compliance assessments against security baseline standards, including CIS Benchmarks, internal hardening guides, operating system, database and network security configurations; maintain the configuration compliance repository; ensure periodic reassessment cycles; escalate deviations and follow up on remediation.

Secure SDLC and Change Assurance

- Support secure SDLC assurance for new systems, upgrades and major changes; review solution designs, security requirements, data flow diagrams and architecture documents for alignment with security standards; validate security testing results, including SAST, DAST and penetration testing, before go-live; participate in go-live readiness reviews and provide security assurance sign-off recommendations.

Independent Verification of CBK Cybersecurity Controls

- Independently verify compliance with CBK Cybersecurity Guidelines, Risk Management Guidelines and other applicable regulatory requirements; track and report deviations, control gaps and improvement areas; and provide assurance evidence for regulatory inspections and supervisory reviews.

Assurance Reporting and Scorecards

- Prepare security assurance scorecards, dashboards and management reports showing compliance status, exceptions, risk trends and remediation progress; develop structured reporting for regulators, internal committees, audit teams and senior leadership; and maintain accurate and complete assurance documentation and evidence repositories.

Qualifications

  • Bachelor’s degree in information technology, Computer Science, Cybersecurity, Information Systems or related field.
  • Professional certifications preferred: CEH, Security+, OSCP as an advantage, ISO 27001 or similar.
  • Technical certifications in cloud or infrastructure security are an added advantage
  • Minimum 3–5 years’ experience in IT security, assurance or audit.
  • Experience conducting vulnerability assessments, technical reviews, or security compliance checks is essential.
  • Knowledge of IT infrastructure, web, database, networking technologies from a security assurance view
  • Understanding of techniques of cyber-attack and defense
  • Experience in a regulated industry, including banking, telecom, fintech or government, is an advantage.
  • Understanding software development tools, technologies, CI/CD, containerization, and agile methodology in relation to cyber security is an advantage
  • Familiarity with CBK Cybersecurity Guidelines, Data Protection Act, PCI-DSS and ISO 27001 control requirements.

Competencies

  • Hands-on understanding of security controls, network security, system administration, and secure configurations.
  • Understanding of securing cloud infrastructure, SOA (Service Oriented Architecture) and AI based technologies
  • Experience with vulnerability scanners, configuration checking tools, and assessment utilities.
  • Strong knowledge of ISO 27001, NIST CSF, CIS Benchmarks, and CBK Cybersecurity Guidelines.
  • Ability to review system designs, architectures and SDLC documentation for security compliance.
  • Analytical skills to assess complex technical environments and identify risks.
  • Ability to prepare structured assurance reports and dashboards
  • High level of integrity and confidentiality.
  • Strong communication and stakeholder management skills.
  • Analytical thinker with attention to detail.
  • Ability to manage multiple tasks and deadlines.
  • Proactive, with strong problem-solving skills.
  • Team player with the ability to work independently.

Work Hours: 8

Experience in Months: 36

Level of Education: bachelor degree

Job application procedure

Click here to apply: https://www.hfcb.co.ke/careers/342

All Jobs | QUICK ALERT SUBSCRIPTION

Job Info
Job Category: Engineering jobs in Kenya
Job Type: Full-time
Deadline of this Job: Friday, August 7 2026
Duty Station: Nairobi | Nairobi
Posted: 29-07-2026
No of Jobs: 1
Start Publishing: 29-07-2026
Stop Publishing (Put date of 2030): 10-10-2076
Apply Now
Notification Board

Join a Focused Community on job search to uncover both advertised and non-advertised jobs that you may not be aware of. A jobs WhatsApp Group Community can ensure that you know the opportunities happening around you and a jobs Facebook Group Community provides an opportunity to discuss with employers who need to fill urgent position. Click the links to join. You can view previously sent Email Alerts here incase you missed them and Subscribe so that you never miss out.

Caution: Never Pay Money in a Recruitment Process.

Some smart scams can trick you into paying for Psychometric Tests.