4G Capital (4th Generation Capital) is Africa's fastest fintech providing ethical credit services to those who require it most. We provide rapidly accessible and affordable unsecured loans with strict affordability criteria to prevent unmanageable debt. Our customers are mainly small businesses and entrepreneurs who use our credit to grow their businesses. As a Senior Cloud Security Engineer, you will own and continuously improve the cloud security posture across our Google Cloud Platform (GCP) organisation. You will design and enforce security models, secure networking, and embed security controls into engineering workflows.
Responsibilities
Own and continuously improve the cloud security posture across our GCP organisation.
Design and enforce least-privilege IAM/RBAC models at organisation level.
Secure VPC networking, firewall policies, private connectivity, and perimeter protections including Cloud Armor.
Strengthen API gateway security (Apigee or equivalent) and service-to-service authentication patterns.
Operationalise Security Command Center and drive structured remediation of high-risk findings.
Embed security controls into CI/CD pipelines, integrating SAST, DAST, dependency, container, and secret scanning.
Define and enforce secure Infrastructure as Code standards using Terraform and policy-as-code guardrails.
Prevent configuration drift and enforce secure deployment patterns across environments.
Support audit readiness, governance initiatives, and regulatory compliance requirements.
Participate in incident response and drive post-incident security improvements.
Qualifications and Experience
Education: BA/BSc/HND in ICT / Computer field.
Experience: 5+ years of experience in Cloud Security, Platform Security, or DevSecOps within production environments.
Technical Skills: Deep, hands-on experience securing multi-project environments on Google Cloud Platform (GCP).
Network Security: Advanced understanding of VPC networking, firewall rules, private connectivity, and Zero Trust architecture.
Security Tools: Experience with cloud security posture management tools (Security Command Center, Cloud Armor) and securing API gateways (Apigee preferred).
Automation: Strong Terraform and Infrastructure as Code experience; strong scripting and automation skills (Bash, Python).
Security Principles: Solid understanding of application security principles (OWASP Top 10, secure coding practices).
Interested and qualified candidates should apply online via the following link: https://www.myjobmag.co.ke/apply-now/1156537. The link directs to the 4G Capital application form on docs.google.com.