Jobless Developer
Zamara logo

Posted 1 day ago

Open

Network & Security Engineer (1 Year Contract)

NairobiOn-siteContract

AI Summary

Establishes and enforces foundational security controls across Zamara's technology landscape, ensuring systems and infrastructure are secured by design and compliant with regulatory requirements.

About this role

ABOUT ZAMARA

The Zamara Group is a diversified financial services business specialising in pensions, medical services, insurance and actuarial solutions. Headquartered in Nairobi, Kenya, the Group has a presence in eight countries and a Pan-African ambition. Zamara has a rich heritage in Kenya spanning over 30 years.

Since its inception, the firm has significantly grown in terms of size, client base and range of services. The Group has been at the forefront of industry, influencing the way it works and at the cutting edge of innovation.

Zamara’s higher purpose is to create a financially secure and prosperous society. The Zamara culture is based on the values of Simplicity, Empathy and Trust.


KEY ROLES AND RESPONSIBILITIES

Achieving Zamara’s ambitious strategic priorities will be complex and challenging. Its continued success will be dependent on building and retaining a world-class team.


We are seeking a Network & Security Engineer to be responsible for establishing, implementing, and continuously improving foundational security controls across Zamara’s technology landscape. The role will ensure systems, applications, and infrastructure are secured by design, compliant with regulatory requirements, and aligned to industry best practices.

Key Responsibilities Include:


Security Baseline Implementation

  • Define and enforce baseline security standards across infrastructure, applications, and endpoints
  • Implement controls aligned to frameworks such as ISO 27001, NIST, and CIS benchmarks
  • Ensure secure configurations for servers, networks, cloud environments, and end-user devices


Access Control & Identity Management

  • Enforce the principle of least privilege across systems and environments
  • Implement and monitor identity and access management (IAM) controls
  • Strengthen authentication mechanisms (e.g., MFA, conditional access policies)


Monitoring & Threat Detection

  • Implement and manage security monitoring tools (SIEM, endpoint detection, logging)
  • Detect and respond to suspicious activities, unauthorized access, and anomalies
  • Establish alerts and reporting for security incidents and control breaches


Data Protection & Resilience

  • Implement controls to safeguard sensitive data from unauthorized access or loss
  • Support backup, disaster recovery, and ransomware protection strategies
  • Ensure safeguards against data corruption, deletion, or exfiltration


Vulnerability & Risk Management

  • Conduct vulnerability assessments and coordinate remediation efforts
  • Support penetration testing and track closure of identified gaps
  • Maintain a risk register and track mitigation actions


Security Governance & Compliance

  • Support DPIAs, audits, and regulatory compliance requirements
  • Develop and maintain security policies, standards, and procedures
  • Ensure third-party/vendor access is controlled and compliant


Security Awareness & Continuous Improvement

  • Drive security awareness across IT teams and business users
  • Continuously assess and improve security posture and controls
  • Embed security into DevOps and system development processes


QUALIFICATION & EXPERIENCE

  • Bachelor’s degree in information security, Computer Science, or related field
  • 5+ years of experience in cybersecurity or IT security operations
  • Experience implementing security controls in enterprise environments
  • Security frameworks: ISO 27001, NIST, CIS Controls
  • Identity & Access Management (IAM), Active Directory, Azure AD
  • Endpoint security, SIEM tools, logging and monitoring solutions
  • Vulnerability management tools and penetration testing coordination
  • Cloud security (Azure preferred) and network security fundamentals
  • Backup, disaster recovery, and data protection technologies

CORE COMPETENCIES

  • Strong analytical and risk assessment skills
  • Attention to detail and proactive mindset
  • Ability to balance security with business needs
  • Strong stakeholder engagement and communication
  • High integrity and ownership

Skills

Active DirectoryAzureAzure ADBackupCIS ControlsCloud SecurityData ProtectionDisaster RecoveryDPIAEndpoint DetectionIAMISO 27001MFANetwork SecurityNISTPenetration TestingSIEMVulnerability Management

Explore related jobs

Browse these categories

Market data for security engineer roles

All reports →