Manager, Fintech and Cyber Audit at Safaricom Plc

2026-08-03

Job Overview

  • Date Posted
    2026-08-03
  • Location
  • Expiration date
    2026-10-04
  • Experience
    5+ Years
  • Gender
    Both
  • Qualification
    Bachelor Degree

Job Description

Job Description

Reporting to the Internal Audit Senior Managers based on Flow to Work, the Manager, Fintech and Cyber  Audit is responsible for providing independent, risk-based assurance over the effectiveness of the Group’s technology governance, digital ecosystem, enterprise applications, infrastructure, cloud environments, data management, technology-enabled business processes and IT general controls. The role evaluates whether technology risks are effectively identified, assessed and managed through appropriate governance, risk management and internal control frameworks that support secure, resilient, reliable and efficient business operations.

Responsibilities

Health and Safety

  • Uphold the company code of conduct, policies and procedures, ensuring integrity and accountability in every aspect of your work.
  • All employees have a responsibility to adhere to safety, health, and wellbeing policies, guidelines and procedures in all actions and decisions.

Risk-Based Fintech & Cyber Audit

  • Develop and execute risk-based audit and technical security testing engagements covering technology and cyber risks across the Financial Services ecosystem.
  • Execute technology audit assignments, including VAPT engagements, from planning, scoping and fieldwork through reporting, escalation and remediation validation.
  • Evaluate the adequacy and effectiveness of technology controls supporting critical business processes through control assessment, technical testing, vulnerability validation and other appropriate assurance procedures.
  • Evaluate application controls, system configuration, authentication, authorisation, transaction integrity, processing reliability, data protection and operational resilience using both control-based and technical testing techniques.
  • Assess the effectiveness of controls relating to: Cybersecurity governance, Security Operations Centre (SOC), Identity and Access Management (IAM), Privileged Access Management (PAM), Multi-factor authentication, Endpoint protection, Network security, Cloud security, Vulnerability management, Penetration testing governance, threat intelligence, Security monitoring, Incident response, Cyber resilience, Encryption and key management, Data Loss Prevention (DLP), and Security awareness programmes.
  • Assess Financial Services’ readiness to prevent, detect, respond to and recover from evolving cyber threats and emerging attack vectors, supported where appropriate by technical security testing.
  • Ensure audit engagements comply with the Global Internal Audit Standards (IIA), Internal Audit Methodology and quality assurance requirements.
  • Perform data-driven audits and technology-enabled security testing using analytics, automation, scripts and continuous auditing techniques to identify control weaknesses, vulnerabilities, anomalous activity and emerging risk trends.
  • Deliver clear assurance reports, including reports on VAPT engagements, containing practical, risk-based recommendations that strengthen security, operational resilience and business performance.
  • Support the development of the annual risk assessment and audit planning process.
  • Coach and provide technical guidance to junior auditors where assigned.


Vulnerability Assessment and Penetration Testing

  • Plan and execute risk-based vulnerability assessments and penetration tests, as part of Internal Audit assurance engagements, across Financial Services applications, mobile platforms, APIs, networks, infrastructure and cloud environments, in accordance with approved scope and rules of engagement.
  • Apply automated and manual security-testing techniques to identify vulnerabilities, eliminate false positives, validate exploitability and assess technical, business and customer impact.
  • Assess the security of fintech and payment journeys, including customer-facing services and third-party integrations.
  • Maintain sufficient technical evidence and deliver clear VAPT reports covering confirmed vulnerabilities, affected assets, exploitability, business impact, risk ratings and practical remediation actions.
  • Immediately escalate critical vulnerabilities and perform technical retesting to confirm that agreed remediation actions have effectively addressed identified weaknesses.
  • Review the scope, methodology, execution quality and results of penetration tests performed by external service providers.


Regulatory & Industry Compliance

  • Assess compliance with applicable technology and cyber-related regulations,  standards and industry frameworks including: Data Protection and Privacy legislation, Cybersecurity regulations, Central Bank technology requirements, Payment industry security requirements, Information security policies, Technology governance standards and Internal technology policies.
  • Monitor regulatory developments and assess organisational readiness.
  • Evaluate effectiveness of controls over technology risks associated with: Cloud service providers, Technology vendors, Fintech partners, Managed service providers, Outsourced technology services, API partners and Digital ecosystem participants
  • Assess fraud prevention, detection, monitoring, and response controls.
  • Evaluate governance, contractual controls, security obligations and operational resilience across the extended technology ecosystem.
  • Assess compliance monitoring processes and governance arrangements.
  • Support continuous improvement of Fintech and Cyber control maturity.

Strategic Initiatives & Advisory

  • Conduct controls-by-design and risk-based technical security reviews for Financial Services system implementations, major system changes and new products.
  • Support cloud migration programmes through independent assessment of cloud governance, configuration, identity, network security, data protection and vulnerability exposure.
  • Assess digital transformation initiatives.
  • Reviewing cybersecurity enhancement programmes.
  • Evaluating new technology implementations before production deployment.
  • Utilize data analytics and technology-enabled assurance techniques.
  • Monitor emerging technology and Cyber risks affecting financial services.
  • Support continuous auditing and monitoring initiatives.
  • Validate effectiveness of remediation actions and control improvements.
  • Contribute to development of an AI-enabled continuous assurance model.
  • Use advanced analytics to identify emerging Fintech and Cyber risks.
  • Provide objective advice while maintaining audit independence.

Stakeholder Management & Audit Follow-Up

  • Build strong relationships with Financial Services leadership teams to drive awareness and culture of controls ownership.
  • Provide advisory insights that strengthen Fintech controls and business performance.
  • Track and validate closure of audit findings.
  • Escalate significant Fintech control weaknesses and emerging risks.
  • Promote awareness of Fintech and Cyber control responsibilities.
  • Share industry best practices and emerging risk insights.
  • Communicate complex technology risks clearly to both technical and non-technical stakeholders.


Core competencies, knowledge and experience:

Customer Obsession

  • Deepen team connection to our customers and communities.
  • Foster authentic relationships with customers and partners that build trust.
  • Explicitly take customer-centric decisions and take personal ownership to achieve results.
  • Simplify processes through digitalization and promote a digital mindset and digital first customer experience.
  • Stay focused on the big priorities, know when to make meaningful trade-offs and demonstrate brilliant execution.

Purpose

  • Create an inspiring vision for your team to drive strategy and performance.
  • Show ambition and courage, empowering others to go beyond the plan.
  • Bold and challenge teams to reimagine how things are done.
  • Prompt new thinking and ideas by asking “what if” questions.
  • Use knowledge of the external environment (customers, partners, competition, external bodies) to identify and act on opportunities for growth at pace.

Innovation

  • Create psychological safety so everyone can have an impact.
  • Fuel innovative ideas from others and test them to enable growth.
  • Explore successes and failures with curiosity and resilience; fearlessly recognizing lessons learned.
  • Share your ongoing learning and personal purpose with others.
  • Learn fast from digital adoption, using learnings to drive simplicity, scale and efficiency.

Collaboration

  • Articulate your team’s role in making our strategy happen, prioritizing and aligning resources with current and future needs.
  • Actively collaborate to break silos and hold your team accountable to do the same.
  • Develop others to make the most of their talents and coach them to take ownership to get things done.
  • Create an inclusive environment ensuring the safety and wellbeing of others.
  • Live our Purpose and demonstrate the highest Standard of integrity.

Qualifications

  • Bachelor’s Degree in Computer Science, Information Systems, Information Technology, Cybersecurity, Engineering or a related discipline.
  • Minimum of six years’ relevant experience in Internal Audit, Technology Risk, IT Audit, Cybersecurity, Information Security or technical security testing, including demonstrable hands-on experience planning and executing vulnerability assessments and penetration tests.
  •  Experience auditing and technically testing fintech platforms, digital financial services, payment systems or other high-value transactional environments, including web and mobile applications, APIs, networks and cloud environments.
  • Strong experience conducting cybersecurity and technology audits.
  • Experience assessing cloud environments, application controls and technology governance.
  • Experience using audit analytics, automation and continuous auditing techniques, including automated and manual security-testing approaches.
  • Experience engaging senior leadership and communicating complex technical risks to technical and non-technical stakeholders.
  • Experience working in highly regulated financial services, banking, fintech or     telecommunications environments is highly desirable.
  • The successful candidate should possess one or more relevant professional certifications, including Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP), Certified Ethical Hacker (CEH), Offensive Security Certified Professional (OSCP) or a recognised hands-on penetration-testing certification.
  • Cloud security certifications covering AWS, Microsoft Azure or Google Cloud are an added advantage.
  •  Strong analytical, stakeholder-management and report-writing skills.