Cyber Security Administrator (Operations)
Kenya Airways
Posted 8 hours ago
About the Company
Kenya Airways is a leading African airline that connects Africa to the world and the world to Africa through its hub at Nairobi Jomo Kenyatta International Airport.
Job Description
This role involves protecting Kenya Airways' information systems, digital assets, and supporting infrastructure through offensive security operations. The administrator will primarily conduct penetration testing, red team simulations, adversary emulation, and vulnerability assessments to identify and exploit weaknesses before malicious actors can. The position requires a hands-on professional with an attacker's mindset, capable of creative thinking and adapting to evolving threats, who can translate complex technical findings into clear, actionable remediation guidance to strengthen the organization's overall security posture.
Key Responsibilities
- Identify, assess, and manage cybersecurity risks through defensive analysis and offensive testing, evaluating both internal and external threats and vulnerabilities.
- Develop risk mitigation strategies based on threat monitoring and incident analysis, prioritizing security investments to protect critical assets.
- Develop and implement the system-wide Information Security function to ensure information security risks are identified and monitored.
- Continuously identify, assess, and monitor information security risks across the organization, escalating emerging threats to inform defensive priorities.
- Collaborate with developers, systems engineers, database engineers, security engineers, project managers, cybersecurity administrators, and SOC analysts.
- Implement and fine-tune security monitoring solutions, including SIEM systems, to detect and respond to security incidents.
- Collaborate with internal teams to investigate and mitigate security breaches.
- Triage, investigate, contain, eradicate, and recover from security incidents, coordinating with internal teams and external partners.
- Lead incident investigations using data-driven analysis, coordinate response efforts, and implement corrective actions to prevent recurrence.
- Maintain and continuously improve incident response plans and playbooks for common attack scenarios.
- Consume and operationalize threat intelligence feeds and adversary TTPs to proactively update detection rules, block emerging IOCs, and inform defensive priorities.
- Deploy and maintain SOAR workflows to automate alert triage, enrichment, and routine response tasks, reducing response times and analyst fatigue.
- Oversee the deployment, configuration, and maintenance of security technologies, including EDR/XDR and encryption solutions.
- Ensure all defensive systems are patched, updated, and operating at optimal performance with high availability.
- Assist in executing vulnerability assessments, penetration tests, and adversary emulation exercises mapped to the MITRE ATT&CK framework to validate and stress-test defensive controls.
- Collaborate with SOC analysts in purple team exercises and translate offensive findings into actionable defensive improvements.
- Work with Internal Audit and External Audit consultants on required security assessments and audits.
- Ensure all projects and systems undergo security checks to prevent potential security threats pre and post go-live.
- Respond promptly to all system and network security breaches, ensuring containment, eradication, and recovery according to documented procedures.
- Implement automation (SOAR) within the organization for efficient alert triage, incident response workflows, and routine security operations.
- Evaluate the organization's security needs and establish defensive best practices, hardening baselines, and configuration standards.
- Ensure the organization's data and infrastructure are protected through layered, defense-in-depth security controls across network, endpoint, application, and data layers.
- Assess the organization's security posture through continuous monitoring, vulnerability scanning, and control validation.
- Investigate breaches and incidents, conduct root cause analysis, and implement improvements to create robust defensive protocols.
Requirements
- Bachelor’s degree in Information Technology or a related field.
- At least 3 years of advanced IT skills with significant information security experience and expertise, specifically hands-on experience in defensive cybersecurity operations.
- Proven hands-on experience in security monitoring, incident detection and response, and vulnerability management.
- Proficiency with SIEM platforms and experience with vulnerability scanning and management tools.
- Experience in penetration testing, ethical hacking, and vulnerability assessments.
- Familiarity with security auditing processes.
- Well-versed with Linux commands, scripting, and Windows security controls adoption.
- Ability to set up systems to identify intrusions and configure them to suit organizational needs.
- Strong knowledge of networking protocols and common attack vectors.
- Experience performing information security audits or risk assessments.
- Industry certifications such as CEH, CDSA, CISSP, SSCP, or equivalent defensive and offensive security certifications are highly preferred.
- Knowledge of securing network technologies, applications, and operating systems.
- Experience responding to, analyzing, and communicating information security incidents and performing forensics.
- Excellent interpersonal, communication, and presentation skills, including formal report writing experience.
- Understanding of common security standards and regulations relevant to a higher education environment (e.g., PCI DSS, NIST, ISO27001, GDPR, IOSA).
- Capable of enforcing security best practices in line with the National Institute of Standards and Technology.
- Excellent communication, interpersonal, and problem-solving skills, with the ability to work confidently on high-priority problems.
- Strong analytical and critical-thinking skills with an attacker's mindset.
- Ability to handle pressure and difficult situations with resilience, calmly and effectively.
- Unquestionable integrity.
- Self-motivated with a passion for continuous learning in cybersecurity.
- Strong ethical standards and commitment to responsible disclosure practices.
Important Safety Tips
- Do not make any payment to any job request or recruiter.
- Be cautious of fraudulent job adverts and scams.
- If you suspect this listing is not genuine, please report it immediately.
How to Apply
Job Details
- Function
- Engineering & Technology
- Industry
- IT & Telecoms
- Type
- Full-time
- Location
- Nairobi
- Experience
- Mid Level
- Salary
- Open
- Posted
- Sep 21, 2026
- Views
- 11