Job Description

Key Responsibilities

Define, document, and implement software security policy, secure coding practices and guidelines for the bank in line with industry best practices and technologies commensurate with risk and regulatory requirements.

Develop, implement and maintain a software security assurance framework which that shall guide information security team in security and risk assessments of applications, as well as provide security requirements for developers and third parties to adhere to.

Lead Information Security involvement in all software and application implementation projects and scrum teams to ensure all applications and changes meet set information security requirements before introduction to production environments.

Collaborate with Enterprise Architecture and Business Application Development teams to identify application/software security improvements and plug-in identified security controls in DevOps tools.

Perform and coordinate regular trainings on secure coding, software security and application security practices for the development and other KCB technology teams at regular intervals.

Collaborate in the continuous monitoring and defence of the Bank’s critical applications, such as core banking, and digital channels, for cybersecurity threat indicators; report on violations and security measures taken to address threats.

Identify, integrate, and maintain security tools, such as SAST and DAST tools (Static/Dynamic Application Security Testing), standards, and processes into the software development or product life cycle (SDLC / PLC), and CI/CD pipelines.

Participate in performing risk assessments for business solutions for inherent security risks and provide recommendations for addressing such risks.

Define, create, and deliver software/application security compliance reports and relevant metrics to the Bank’s Senior Management.

Protects the bank’s applications and systems by defining access privileges and other security control structures.

 

The Person

For the above position, the successful applicant should have the following:

A Bachelor's degree in IT/ Computer Science/ Telecommunications/ Engineering (Electrical or Electronic) or related field from a recognized university.

Must possess at least one certification from the following list:

CDP: Certified DevSecOps Professional.

CSSLP: Certified Secure Software Lifecycle Professional.

CISM: Certified Information Security Manager.

CISA: Certified Information Systems Auditor.

CISSP: Certified Information Systems Security Professional.

A minimum of 5 years’ experience in Information Technology; with at least 2 years’ experience in Information Security.

At least 1 year experience within Secure SDLC and DevSecOps.

Good knowledge of Banking Operations.

Excellent planning and organizing skills.

Excellent problem analysis and attention to detail.

 

The above position is demanding; for which the Bank will provide a competitive remuneration package to the successful candidate. If you believe you can clearly demonstrate your abilities to meet the criteria given above, please log in to our Recruitment portal and submit your application with a detailed CV.

 

How To Apply

Interested and qualified candidates should make their applications through KCB Bank Job portal via the link https://ke.kcbgroup.com/about-us/careers

Apply for this Job Now

Related Jobs

Software Developer

We are pleased to announce the following Position in the Digital IT Department within the Technology Division. In keeping with our current business needs, we are looking for a person who meets the criteria indicated below. Reporting to the Product Owners in the respective Business Units, the position holder will be required to develop and publish enterprise solutions using best practice and new technologies including but not limited to web technologies for integration, mobile app, cloud solutions, data and source management adopting Agile in DevOps and team delivery.

software engineering Nairobi, Kenya Aug/24/2021

Process Automation Engineer

This is an exciting opportunity for an experienced Process Engineer to evolve and expand as part of center of excellence specific to Robotic Automation within Safaricom PLC

software engineering Nairobi, Kenya Aug/21/2021

Quality Assurance - Test Automation Engineer

Reporting to the Manager – Testing Automation, the position holder will lead the implementation and execution of software testing automation frameworks and ensure efficiencies are realized in the software testing lifecycle

software engineering Nairobi, Kenya Aug/21/2021

Business Intelligence (BI) Developer

Reporting to the Manager - Analytics System Support, the position holder will offer leading expert solutions and technical guidance in administration, service provision and availability of all the Safaricom Business Intelligence and analytics systems.

software engineering Nairobi, Kenya Aug/21/2021