Role Overview
The Manager, Fintech and Cyber Audit at Safaricom Kenya is responsible for executing risk-based audits and technical security testing engagements covering technology and cyber risks across the Financial Services ecosystem. The role ensures that technology controls supporting critical business processes are effective, robust, and compliant with regulatory and industry standards.
Responsibilities
Health and Safety
- Uphold the company code of conduct, policies, and procedures, ensuring integrity and accountability in every aspect of your work.
- Adhere to safety, health, and wellbeing policies, guidelines, and procedures in all actions and decisions.
Risk-Based Fintech & Cyber Audit
- Develop and execute risk-based audit and technical security testing engagements covering technology and cyber risks across the Financial Services ecosystem.
- Execute technology audit assignments, including VAPT engagements, from planning, scoping, and fieldwork through reporting, escalation, and remediation validation.
- Evaluate the adequacy and effectiveness of technology controls supporting critical business processes through control assessment, technical testing, vulnerability validation, and other appropriate assurance procedures.
- Evaluate application controls, system configuration, authentication, authorization, transaction integrity, processing reliability, data protection, and operational resilience using both control-based and technical testing techniques.
- Assess the effectiveness of controls relating to: Cybersecurity governance, Security Operations Centre (SOC), Identity and Access Management (IAM), Privileged Access Management (PAM), Multi-factor authentication, Endpoint protection, Network security, Cloud security, Vulnerability management, Penetration testing governance, threat intelligence, Security monitoring, Incident response, Cyber resilience, Encryption and key management, Data Loss Prevention (DLP), and Security awareness programmes.
- Assess Financial Services’ readiness to prevent, detect, respond to, and recover from evolving cyber threats and emerging attack vectors, supported where appropriate by technical security testing.
- Ensure audit engagements comply with the Global Internal Audit Standards (IIA), Internal Audit Methodology, and quality assurance requirements.
- Perform data-driven audits and technology-enabled security testing using analytics, automation, scripts, and continuous auditing techniques to identify control weaknesses, vulnerabilities, anomalous activity, and emerging risk trends.
- Deliver clear assurance reports, including reports on VAPT engagements, containing practical, risk-based recommendations that strengthen security, operational resilience, and business performance.
- Support the development of the annual risk assessment and audit planning process.
- Coach and provide technical guidance to junior auditors where assigned.
Vulnerability Assessment and Penetration Testing (VAPT)
- Plan and execute risk-based vulnerability assessments and penetration tests, as part of Internal Audit assurance engagements, across Financial Services applications, mobile platforms, APIs, networks, infrastructure, and cloud environments, in accordance with approved scope and rules of engagement.
- Apply automated and manual security-testing techniques to identify vulnerabilities, eliminate false positives, validate exploitability, and assess technical, business, and customer impact.
- Assess the security of fintech and payment journeys, including customer-facing services and third-party integrations.
- Maintain sufficient technical evidence and deliver clear VAPT reports covering confirmed vulnerabilities, affected assets, exploitability, business impact, risk ratings, and practical remediation actions.
- Immediately escalate critical vulnerabilities and perform technical retesting to confirm that agreed remediation actions have effectively addressed identified weaknesses.
- Review the scope, methodology, execution quality, and results of penetration tests performed by external service providers.
Regulatory & Industry Compliance
- Assess compliance with applicable technology and cyber-related regulations, standards, and industry frameworks including: Data Protection and Privacy legislation, Cybersecurity regulations, Central Bank technology requirements, Payment industry security requirements, Information security policies, Technology governance standards, and Internal technology policies.
- Monitor regulatory developments and assess organisational readiness.
- Evaluate effectiveness of controls over technology risks associated with: Cloud service providers, Technology vendors, Fintech partners, Managed service providers, Outsourced technology services, API partners, and Digital ecosystem participants.
- Assess fraud prevention, detection, monitoring, and response controls.
- Evaluate governance, contractual controls, security obligations, and operational resilience across the extended technology ecosystem.
- Assess compliance monitoring processes and governance arrangements.
- Support continuous improvement of Fintech and Cyber control maturity.
Strategic Initiatives & Advisory
- Conduct controls-by-design and risk-based technical security reviews for Financial Services system implementations, major system changes, and new products.
- Support cloud migration programmes through independent assessment of cloud governance, configuration, identity, network security, data protection, and vulnerability exposure.
- Assess digital transformation initiatives.
- Review cybersecurity enhancement programmes.
- Evaluate new technology implementations before production deployment.
- Utilize data analytics and technology-enabled assurance techniques.
- Monitor emerging technology and Cyber risks affecting financial services.
- Support continuous auditing and monitoring initiatives.
- Validate effectiveness of remediation actions and control improvements.
- Contribute to development of an AI-enabled continuous assurance model.
- Use advanced analytics to identify emerging Fintech and Cyber risks.
- Provide objective advice while maintaining audit independence.
Stakeholder Management & Audit Follow-Up
- Build strong relationships with Financial Services leadership teams to drive awareness and culture of controls ownership.
- Provide advisory insights that strengthen Fintech controls and business performance.
- Track and validate closure of audit findings.
- Escalate significant Fintech control weaknesses and emerging risks.
- Promote awareness of Fintech and Cyber control responsibilities.
- Share industry best practices and emerging risk insights.
- Communicate complex technology risks clearly to both technical and non-technical stakeholders.
Core Competencies
- Customer Obsession: Deepen team connection to customers; make customer-centric decisions; simplify processes through digitalization.
- Purpose: Create inspiring vision; show ambition and courage; use external environment knowledge for growth.
- Innovation: Fuel innovative ideas; explore successes and failures with curiosity; learn fast from digital adoption.
- Collaboration: Align resources; break down silos; coach others; maintain inclusive environment and integrity.
Qualifications and Experience
- Bachelor’s Degree in Computer Science, Information Systems, Information Technology, Cybersecurity, Engineering, or a related discipline.
- Minimum of six years’ relevant experience in Internal Audit, Technology Risk, IT Audit, Cybersecurity, Information Security, or technical security testing, including demonstrable hands-on experience planning and executing vulnerability assessments and penetration tests.
- Experience auditing and technically testing fintech platforms, digital financial services, payment systems, or other high-value transactional environments, including web and mobile applications, APIs, networks, and cloud environments.
- Strong experience conducting cybersecurity and technology audits.
- Experience assessing cloud environments, application controls, and technology governance.
- Experience using audit analytics, automation, and continuous auditing techniques, including automated and manual security-testing approaches.
- Experience engaging senior leadership and communicating complex technical risks to technical and non-technical stakeholders.
- Experience working in highly regulated financial services, banking, fintech, or telecommunications environments is highly desirable.
- One or more relevant professional certifications: CISA, CISM, CISSP, CEH, OSCP, or a recognized hands-on penetration-testing certification.
- Cloud security certifications covering AWS, Microsoft Azure, or Google Cloud are an added advantage.
- Strong analytical, stakeholder-management, and report-writing skills.