M-Pesa Africa stands at the forefront of digital transformation and financial inclusion in the continent. As the digital economy rapidly evolves, M-Pesa continues to set the pace in mobile money innovation. With over 42 million customers across Africa, our mission is clear—to connect people to opportunity, information, and each other in the safest, most reliable manner possible. Central to that mission is ensuring digital trust. This is why M-Pesa Africa is investing heavily in building a world-class Cyber Security team to support our growth and secure our future.
We are currently expanding our Cyber Security talent pipeline and are seeking passionate, skilled, and innovative professionals who are ready to shape the future of secure financial technology. This is an evergreen recruitment process, meaning applications are accepted and reviewed on a rolling basis. Shortlisted candidates will be considered for current or upcoming openings and may be retained for future opportunities.
If you are experienced in cloud security, cyber defense, security architecture, compliance, or prevention, and eager to work in a purpose-driven environment, then we want to hear from you.
Open Positions in the Cyber Security Talent Pipeline
1. Specialist – Cloud Security
As a Cloud Security Specialist, you will be responsible for the end-to-end security of our cloud infrastructure across AWS, Azure, and Huawei Cloud. Your mission will be to ensure the confidentiality, integrity, and availability of M-Pesa’s cloud-based systems and services. This is a highly technical role focused on designing, deploying, and managing security architectures while ensuring ongoing compliance with industry standards.
Key Responsibilities:
- Execute Security and Privacy by Design Assurance (SPDA) processes for all cloud services.
- Architect secure multi-cloud environments that meet both internal standards and external regulations.
- Conduct comprehensive vulnerability assessments and penetration testing.
- Implement and manage IAM (Identity and Access Management), including multi-factor authentication and privilege access.
- Partner with DevOps to embed DevSecOps principles and tools into CI/CD pipelines.
- Develop and update cloud security policies and standards based on evolving threats.
- Stay up to date on the latest trends and developments in cloud security.
2. Specialist – Cyber Security Governance, Risk & Compliance (GRC)
This role is central to ensuring that all cyber risks at M-Pesa Africa are effectively managed within an established framework. You will also ensure that the business is fully aligned with both internal cybersecurity standards and external legal and regulatory obligations.
Key Responsibilities:
- Drive compliance with Vodafone Cyber Security Baseline standards and applicable laws.
- Update, manage, and disseminate internal cybersecurity policies across the organization.
- Lead and support the execution of enterprise-wide risk assessments.
- Coordinate and support internal and external audits, including implementation of audit remediation plans.
- Engage with cross-functional teams and stakeholders to ensure awareness and adherence to GRC frameworks.
3. Specialist – Cyber Security Architecture & Assurance
The Architecture & Assurance Specialist ensures all technology initiatives at M-Pesa Africa incorporate robust cybersecurity measures from the very beginning. This role will lead security reviews, conduct detailed assessments, and perform security testing to validate resilience against both internal and external threats.
Key Responsibilities:
- Manage the Security and Privacy by Design Assurance (SPDA) process to embed security throughout the software development lifecycle.
- Execute penetration testing on infrastructure, APIs, mobile apps, and backend systems.
- Simulate and evaluate potential attack scenarios to preemptively identify weaknesses.
- Support technology teams to adopt secure design principles and mitigate discovered vulnerabilities.
- Review system architectures to ensure they align with security best practices and compliance requirements.
4. Specialist – Cyber Security Defense
As a Specialist in Cyber Security Defense, you will take a proactive stance in identifying threats and responding to incidents. You will be instrumental in detecting malicious activity, coordinating incident response, and implementing measures to reduce potential exposure to security events.
Key Responsibilities:
- Develop and implement monitoring controls to detect cybersecurity threats in real time.
- Lead the coordination of security incident response, including root cause analysis and remediation planning.
- Optimize M-Pesa’s cybersecurity baselines and collaborate with the Vodacom/Vodafone Group Cyber Defense teams.
- Support periodic technology audits and ensure the timely resolution of audit findings.
- Maintain and manage security solutions including endpoint detection and response (EDR), forensic tools, and SIEM systems.
5. Specialist – Cyber Security Prevent
This role is crucial for minimizing risks before they materialize. You will focus on hardening systems, improving controls, and leading efforts to continuously improve M-Pesa Africa’s security posture across business operations and technologies.
Key Responsibilities:
- Manage and optimize cyber security baselines (CSB) across M-Pesa operations.
- Coordinate and support Privileged Access Management (PAM) to safeguard sensitive credentials and environments.
- Operate and maintain security solutions such as antivirus platforms, firewalls, Web Application Firewalls (WAFs), IDS/IPS, and logging platforms.
- Troubleshoot and resolve security operations issues and implement enhancements.
- Drive the adoption of security policies, conduct training, and lead incident prevention programs.
- Ensure that all audit findings are closed with sustainable solutions that enhance overall security.
What We’re Looking For
We are looking for cybersecurity professionals who:
- Possess deep hands-on experience in one or more cybersecurity domains.
- Thrive in fast-paced environments and bring proactive, team-oriented energy to their work.
- Demonstrate a passion for security and a commitment to continuous professional development.
- Hold industry-recognized certifications relevant to their specialization (please include all cybersecurity and cloud certifications in your CV).
Examples of valuable certifications include (but are not limited to):
- CISSP, CISM, CISA, CEH
- AWS Security Specialty, Azure Security Engineer
- CCNA Security, CCNP Security, CCIE Security
- Security+, OSCP, or other role-relevant qualifications
Our Recruitment Process
- This is an evergreen application. We continuously review submissions and engage with candidates based on current and future openings.
- If your profile matches our needs, we will reach out to schedule interviews tailored to specific roles.
- If not selected immediately, your profile will remain in our database for future consideration.
About M-Pesa Africa
M-Pesa Africa is a regional powerhouse in mobile money innovation, transforming how people live and transact in the digital age. Since the launch of M-PESA in 2007, our journey has been one of relentless innovation, connecting millions with safe and reliable financial services.
We are part of the Safaricom family, one of the largest and most impactful telecommunications companies in Africa. Headquartered in Nairobi, Kenya, Safaricom has played a critical role in advancing economic empowerment and digital connectivity across East Africa.
As of March 2021, our operations supported over 1 million jobs and contributed over KES 362 Billion (USD 3.2 Billion) to the regional economy. With revenues nearing KES 298 Billion (USD 2.5 Billion) in 2022, we continue to invest in the people, platforms, and policies that foster secure and inclusive growth.
Our Cyber Security team is a cornerstone of that investment—tasked with ensuring that millions of transactions, data exchanges, and communications occur within a secure ecosystem.
Job Information Summary
- Job Category: Cyber Security
- Posting Date: 22 July 2025
- Application Deadline: 30 September 2025
- Job Identification Number: 764
- Location: PO BOX 46350, Nairobi, Kenya
- Job Schedule: Full-time
- Degree Requirement: Bachelor’s Degree (in Computer Science, IT, or related fields)
Why Join M-Pesa Africa?
By joining the M-Pesa Cyber Security team, you will:
- Be part of a mission that impacts millions of lives across Africa.
- Work with cutting-edge technologies in a dynamic and collaborative environment.
- Have the opportunity to contribute to one of Africa’s most iconic digital platforms.
- Access continuous learning opportunities and career development.
- Engage in meaningful work that ensures digital trust and enhances financial inclusion.
Next Steps
If you’re ready to help shape the future of secure mobile finance in Africa, we encourage you to take the next step in your cybersecurity career.