SN
Accounting

Manager, Fintech & Cyber Audit Job Safaricom, Nairobi, Kenya

Safaricom, Nairobi, Kenya

Kenya Full-time On-site
Posted: 1 hour ago
Expires: Sep 18, 2026
Salary: Not listed

Job description

Reporting to the Internal Audit Senior Managers based on Flow to Work, the Manager, Fintech and Cyber  Audit is responsible for providing independent, risk-based assurance over the effectiveness of the Group’s technology governance, digital ecosystem, enterprise applications, infrastructure, cloud environments, data management, technology-enabled business processes and IT general controls. The role evaluates whether technology risks are effectively identified, assessed and managed through appropriate governance, risk management and internal control frameworks that support secure, resilient, reliable and efficient business operations.

This includes assessing the effectiveness of governance, risk management, internal controls, cyber resilience, technology architecture, operational resilience, and regulatory compliance across Safaricom’s digital financial ecosystem. The role supports the organisation in safeguarding critical technology assets while enabling innovation through secure-by-design and controls-by-design principles.

The role is responsible for planning and executing independent, risk-based vulnerability assessments and penetration tests across the Group’s Financial Services technology environment. This includes hands-on testing of web applications, mobile applications, APIs, networks, cloud environments, infrastructure and supporting technology platforms to identify vulnerabilities, validate exploitability, assess potential business impact and confirm the effectiveness of remediation.

Aligned to the Group Internal Audit strategy and Safaricom’s ambition of building a world-class, AI-enabled Internal Audit function, the role provides proactive assurance and advisory support across digital transformation initiatives, emerging technologies, cloud adoption, enterprise systems, artificial intelligence, automation and technology innovation. The role partners with Technology, Digital Engineering, Enterprise Architecture, M-PESA Technology, Data and Business Leadership teams to provide forward-looking insights that strengthen governance, improve operational effectiveness and enable secure technology-enabled growth.

The Manager is accountable for developing and executing risk-based audit plans, monitoring the implementation of agreed management actions and evaluating emerging technology risks across the Group.  The role provides independent assurance on the adequacy and effectiveness of technology governance, system controls, project delivery, digital transformation, data governance and operational resilience while identifying opportunities to improve efficiency, control effectiveness and business value.

Through high-quality assurance, insight and innovation, the role contributes to strengthening stakeholder confidence, enhancing operational resilience and supporting the achievement of the Group’s strategic objectives.

The role contributes to maintaining compliance with applicable regulatory requirements and industry standards, including ISO/IEC 27001, ISO 22301, COBIT, NIST Cybersecurity Framework, CIS Critical Security Controls, PCI DSS, GSMA security requirements, data privacy regulations and other relevant technology governance frameworks applicable across the Safaricom Group.

Responsibilities

Health and Safety

  • Uphold the company code of conduct, policies and procedures, ensuring integrity and accountability in every aspect of your work.
  • All employees have a responsibility to adhere to safety, health, and wellbeing policies, guidelines and procedures in all actions and decisions.

Risk-Based Fintech & Cyber Audit

  • Develop and execute risk-based audit and technical security testing engagements covering technology and cyber risks across the Financial Services ecosystem.
  • Execute technology audit assignments, including VAPT engagements, from planning, scoping and fieldwork through reporting, escalation and remediation validation.
  • Evaluate the adequacy and effectiveness of technology controls supporting critical business processes through control assessment, technical testing, vulnerability validation and other appropriate assurance procedures.
  • Evaluate application controls, system configuration, authentication, authorisation, transaction integrity, processing reliability, data protection and operational resilience using both control-based and technical testing techniques.
  • Assess the effectiveness of controls relating to: Cybersecurity governance, Security Operations Centre (SOC), Identity and Access Management (IAM), Privileged Access Management (PAM), Multi-factor authentication, Endpoint protection, Network security, Cloud security, Vulnerability management, Penetration testing governance, threat intelligence, Security monitoring, Incident response, Cyber resilience, Encryption and key management, Data Loss Prevention (DLP), and Security awareness programmes.
  • Assess Financial Services’ readiness to prevent, detect, respond to and recover from evolving cyber threats and emerging attack vectors, supported where appropriate by technical security testing.
  • Ensure audit engagements comply with the Global Internal Audit Standards (IIA), Internal Audit Methodology and quality assurance requirements.
  • Perform data-driven audits and technology-enabled security testing using analytics, automation, scripts and continuous auditing techniques to identify control weaknesses, vulnerabilities, anomalous activity and emerging risk trends.
  • Deliver clear assurance reports, including reports on VAPT engagements, containing practical, risk-based recommendations that strengthen security, operational resilience and business performance.
  • Support the development of the annual risk assessment and audit planning process.
  • Coach and provide technical guidance to junior auditors where assigned.

Vulnerability Assessment and Penetration Testing

  • Plan and execute risk-based vulnerability assessments and penetration tests, as part of Internal Audit assurance engagements, across Financial Services applications, mobile platforms, APIs, networks, infrastructure and cloud environments, in accordance with approved scope and rules of engagement.
  • Apply automated and manual security-testing techniques to identify vulnerabilities, eliminate false positives, validate exploitability and assess technical, business and customer impact.
  • Assess the security of fintech and payment journeys, including customer-facing services and third-party integrations.
  • Maintain sufficient technical evidence and deliver clear VAPT reports covering confirmed vulnerabilities, affected assets, exploitability, business impact, risk ratings and practical remediation actions.
  • Immediately escalate critical vulnerabilities and perform technical retesting to confirm that agreed remediation actions have effectively addressed identified weaknesses.
  • Review the scope, methodology, execution quality and results of penetration tests performed by external service providers.

Regulatory & Industry Compliance

  • Assess compliance with applicable technology and cyber-related regulations,  standards and industry frameworks including: Data Protection and Privacy legislation, Cybersecurity regulations, Central Bank technology requirements, Payment industry security requirements, Information security policies, Technology governance standards and Internal technology policies.
  • Monitor regulatory developments and assess organisational readiness.
  • Evaluate effectiveness of controls over technology risks associated with: Cloud service providers, Technology vendors, Fintech partners, Managed service providers, Outsourced technology services, API partners and Digital ecosystem participants
  • Assess fraud prevention, detection, monitoring, and response controls.
  • Evaluate governance, contractual controls, security obligations and operational resilience across the extended technology ecosystem.
  • Assess compliance monitoring processes and governance arrangements.
  • Support continuous improvement of Fintech and Cyber control maturity.

Strategic Initiatives & Advisory

  • Conduct controls-by-design and risk-based technical security reviews for Financial Services system implementations, major system changes and new products.
  • Support cloud migration programmes through independent assessment of cloud governance, configuration, identity, network security, data protection and vulnerability exposure.
  • Assess digital transformation initiatives.
  • Reviewing cybersecurity enhancement programmes.
  • Evaluating new technology implementations before production deployment.
  • Utilize data analytics and technology-enabled assurance techniques.
  • Monitor emerging technology and Cyber risks affecting financial services.
  • Support continuous auditing and monitoring initiatives.
  • Validate effectiveness of remediation actions and control improvements.
  • Contribute to development of an AI-enabled continuous assurance model.
  • Use advanced analytics to identify emerging Fintech and Cyber risks.
  • Provide objective advice while maintaining audit independence.

Stakeholder Management & Audit Follow-Up

  • Build strong relationships with Financial Services leadership teams to drive awareness and culture of controls ownership.
  • Provide advisory insights that strengthen Fintech controls and business performance.
  • Track and validate closure of audit findings.
  • Escalate significant Fintech control weaknesses and emerging risks.
  • Promote awareness of Fintech and Cyber control responsibilities.
  • Share industry best practices and emerging risk insights.
  • Communicate complex technology risks clearly to both technical and non-technical stakeholders.

Core competencies, knowledge and experience

Customer Obsession

  • Deepen team connection to our customers and communities.
  • Foster authentic relationships with customers and partners that build trust.
  • Explicitly take customer-centric decisions and take personal ownership to achieve results.
  • Simplify processes through digitalization and promote a digital mindset and digital first customer experience.
  • Stay focused on the big priorities, know when to make meaningful trade-offs and demonstrate brilliant execution.

Purpose

  • Create an inspiring vision for your team to drive strategy and performance.
  • Show ambition and courage, empowering others to go beyond the plan.
  • Bold and challenge teams to reimagine how things are done.
  • Prompt new thinking and ideas by asking “what if” questions.
  • Use knowledge of the external environment (customers, partners, competition, external bodies) to identify and act on opportunities for growth at pace.

Innovation

  • Create psychological safety so everyone can have an impact.
  • Fuel innovative ideas from others and test them to enable growth.
  • Explore successes and failures with curiosity and resilience; fearlessly recognizing lessons learned.
  • Share your ongoing learning and personal purpose with others.
  • Learn fast from digital adoption, using learnings to drive simplicity, scale and efficiency.

Collaboration

  • Articulate your team’s role in making our strategy happen, prioritizing and aligning resources with current and future needs.
  • Actively collaborate to break silos and hold your team accountable to do the same.
  • Develop others to make the most of their talents and coach them to take ownership to get things done.
  • Create an inclusive environment ensuring the safety and wellbeing of others.
  • Live our Purpose and demonstrate the highest Standard of integrity.

Qualifications

  • Bachelor’s Degree in Computer Science, Information Systems, Information Technology, Cybersecurity, Engineering or a related discipline.
  • Minimum of six years’ relevant experience in Internal Audit, Technology Risk, IT Audit, Cybersecurity, Information Security or technical security testing, including demonstrable hands-on experience planning and executing vulnerability assessments and penetration tests.
  • Experience auditing and technically testing fintech platforms, digital financial services, payment systems or other high-value transactional environments, including web and mobile applications, APIs, networks and cloud environments.
  • Strong experience conducting cybersecurity and technology audits.
  • Experience assessing cloud environments, application controls and technology governance.
  • Experience using audit analytics, automation and continuous auditing techniques, including automated and manual security-testing approaches.
  • Experience engaging senior leadership and communicating complex technical risks to technical and non-technical stakeholders.
  • Experience working in highly regulated financial services, banking, fintech or     telecommunications environments is highly desirable.
  • The successful candidate should possess one or more relevant professional certifications, including Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP), Certified Ethical Hacker (CEH), Offensive Security Certified Professional (OSCP) or a recognised hands-on penetration-testing certification.
  • Cloud security certifications covering AWS, Microsoft Azure or Google Cloud are an added advantage.
  •  Strong analytical, stakeholder-management and report-writing skills.

How to Apply

Click here to apply

Similar jobs

HN
Project Manager – Cards Job HFCB, Nairobi, Kenya
HFCB, Nairobi, Kenya
Kenya Full-time On-site

About the Role The Project Manager will be responsible for for planning, coordination, implementation and governance of the card issuing and payment system projects that support...

Salary not listed
View details
FN
Ethics Committee Members Job FKF Nairobi, Kenya
FKF Nairobi, Kenya
Kenya Full-time On-site

Job Description The Ethics Committee is one of FKF’s three judicial bodies, established under Article 64 of the FKF Constitution, with its specific functions governed by Article...

Salary not listed
View details
Job alerts
Subscribe to matching jobs by country, role, and category.

Create local job alerts

Get matching jobs for your chosen country, role, and category.

Your browser will ask once for permission. Your filters are stored securely on our own notification server.

Prefer app notifications?

Prime Jobs Global is free on Android and iPhone.

Prime Jobs Global

Get job alerts on your phone

Find jobs, save useful listings, and receive new-job notifications in the free Prime Jobs Global app.

Free for Android, iPhone, and iPad.