Skip to content
Nairobi · KenyaFree to read
Technology

Cybersecurity

Cybersecurity professionals safeguard computer systems, networks, and data from cyber threats, ensuring confidentiality, integrity, and availability. In Kenya, this career is pivotal as the country accelerates digital transformation across finance, government, and e-commerce, with mobile money and cloud adoption expanding the attack surface. Core purpose is to design, implement, and monitor security controls to protect against breaches, ransomware, and insider threats.

Daily responsibilities include vulnerability assessments, penetration testing, incident response, security architecture reviews, and policy enforcement. Analysts use tools like SIEM, firewalls, and endpoint detection systems to detect anomalies, while engineers build secure network segments and conduct forensic investigations. Collaboration with IT teams and compliance officers ensures alignment with regulations like the Data Protection Act (2019).

Career progression ranges from security analyst to penetration tester, security architect, or chief information security officer (CISO) as experience grows. Kenya-specific demand is driven by fintechs, banks, and government agencies; the Serianu Africa Cyber Security Report 2025 notes a 35% rise in cyber incidents. Salaries for entry-level analysts in Nairobi start around KES 150,000–250,000 monthly, with CISOs earning over KES 500,000. Upskilling through certifications like CISSP, CEH, or CompTIA Security+ is crucial.

AI exposure
39 of 100, low exposure
Hiring trend
Growing
Hiring rate
95%
Minimum education
Bachelor

The role

What the work is, what it pays, and what it costs you.

At a glance

Work environment
Office or hybrid/remote, in front of a screen most of the day, with cross functional collaboration across product, design and engineering.
Remote friendly
Yes
Freelance potential
High
Freelance rate
Ksh 200,000
Time to senior
5 years
Adaptation level
High

A day in the role

A cybersecurity professional in Kenya starts the day reviewing threat intelligence feeds and security alerts, then conducts vulnerability assessments on critical infrastructure like mobile banking platforms. Afternoons involve patch management and security awareness training for employees, ending with a shift handover for 24/7 monitoring.

What it pays

Kenyan market, per month
Entry
Ksh 108,000 to Ksh 153,000

The trade offs

In its favour

  • Salaries are above average, with entry-level roles starting at 80,000 KES and experienced staff earning 250,000+.
  • Extremely high demand across all sectors, offering numerous job openings and career paths.
  • Critical national importance - you protect Kenya's digital infrastructure, contributing to national security.
  • Certifications like CEH, CompTIA Security+ are globally recognized, enabling international mobility.
  • Strong community and networking opportunities through groups like ISACA and (ISC)² Kenya chapter.

Against it

  • High stress due to 24/7 incident response; many roles require on-call duty including weekends.
  • Rapidly evolving field demands constant learning, often outside work hours, leading to fatigue.
  • Entry-level positions can be repetitive (e.g., monitoring dashboards) with slow initial growth.
  • Certification costs are high (up to 50,000 KES per exam) with no guarantee of immediate promotion.

In practice

To enter cybersecurity in Kenya, pursue a Bachelor's degree in Computer Science, Information Technology, or Cyber Security from universities like University of Nairobi or Strathmore. Supplement with certifications such as CompTIA Security+, CEH, or CISSP, and attend bootcamps at Moringa School or Akirachix. Entry-level steps include applying for graduate trainee programs at Safaricom, KCB, or government agencies like the National KE-CIRT, or starting as a security intern at a bank or telecom. Common routes also involve participating in bug bounty programs and building a cybersecurity portfolio on platforms like TryHackMe.

A typical progression moves from Junior Security Analyst to SOC Analyst, then Security Engineer, Senior Consultant, and eventually CISO or Head of Security. Salary grows from around KES 80,000 per month for entry-level to over KES 400,000 after 10 years, with specializations in cloud security, penetration testing, or governance commanding higher pay. Within 10 years, a professional might transition from hands-on technical work to strategic roles, often earning CISSP or CISM. Career growth is accelerated by experience in incident response and compliance with Kenya's Data Protection Act.

The Kenyan cybersecurity market is driven by the financial sector (banks like Equity, Co-operative Bank), telecoms (Safaricom, Airtel), and fintechs (M-Pesa, Tala), with high demand for security analysts and engineers. The government, through the ICT Authority and e-Citizen platform, also employs cybersecurity experts, as does the National Computer and Cybercrimes Coordination Committee. Jobs are concentrated in Nairobi, with emerging opportunities in Kisumu and Mombasa due to digital hubs. Market growth is fueled by rising cyber threats, increased mobile money usage, and regulatory enforcement of the Data Protection Act 2019.

A mid-level Security Analyst in Nairobi starts the day at 8 AM by reviewing dashboards in Splunk and checking overnight alerts from the SOC. After a morning stand-up meeting, they investigate a phishing incident reported by employees, then run a vulnerability scan on a banking app using Nessus. They document findings for the incident response team and attend a working lunch on new compliance requirements. By 4 PM, they prepare a brief for the CISO and participate in a threat intelligence call before handing over to the night shift.

Exposure

How much of this a machine can already do, and how that was worked out.

Where this rating sits

1,516 rated careers
39
lowmoderatehigh
020406080100

Rated above 44% of the 1,516 careers in the catalogue, which averages 43. Inside technology the mean is 62, across 125 careers.

What the rating is made of

Share of recorded tasks
Machine does it
38%Software can already complete this work end to end.
Machine assists
51%A person still decides, but the drafting is done for them.
Person does it
11%Judgement, relationships and accountability that do not transfer.

Named task by task

Already automated

  • Threat detection
  • Incident response
  • Automated vulnerability scanning
  • Security information and event management

Still human

  • Designing security protocols
  • Responding to security incidents
  • Conducting risk assessments
  • Developing security policies
  • Collaborating with IT teams

Your skills, sorted

38 skills recorded

Holding their value

  • Cloud Computing
  • Social Media Management

The six things it was scored on

0 to 100 each
Digital surfaceraises exposure
100

How much of the work already happens inside software.

People and inventionlowers exposure
60

Work that needs trust, persuasion or an original idea.

Rule bound thinkingraises exposure
50

Decisions that follow a procedure rather than a judgement.

Regulatory stakeslowers exposure
45

Where a named person has to carry the liability.

Routine intensityraises exposure
40

How much of it repeats in the same shape each time.

Physical presencelowers exposure
5

Work that has to happen in a place, with hands.

Task counts

Tasks recorded
9
Automatable now
4
Still human
5
Displacing
Boilerplate code generation (now AI-assisted),Routine testing and refactoring,Basic data cleaning
Augmenting
AI pair-programming (Copilot),Automated code review and test generation,LLM-accelerated research and analysis
Creating
Applied AI/ML engineering,MLOps and AI reliability,AI product and data-product roles

Sources

Behind the rating
  • Frey & Osborne (2013), 'The Future of Employment', Oxford Martin
  • McKinsey Global Institute, 'The Future of Work' (2017/2023)
  • OpenAI/UPenn, 'GPTs are GPTs' (2023), occupational LLM exposure
  • WEF, 'Future of Jobs Report' (2023)

Getting in

The routes into the role and what each one asks for.

What to study

8 courses

How people get in

  • University Degree

    4 yearsHigh cost

    BSc in Information Security or Computer Science from JKUAT or KU

  • Technical Diploma

    2 yearsMedium cost

    Diploma in Cybersecurity from Kenya Institute of Management or similar

  • Certification Path

    6 monthsLow cost

    CompTIA Security+ and then CISSP or CISA; self-study and online labs

Certifications

  • CompTIA Security+

    CompTIAKsh 80,0002 months

  • Certified Ethical Hacker (CEH)

    EC-CouncilKsh 150,0003 months

  • Certified Information Systems Security Professional (CISSP)

    (ISC)²Ksh 350,0006 months

  • Certified Information Security Manager (CISM)

    ISACAKsh 250,0004 months

Tools of the trade

  • Burp Suite

    securityRequiredPaid

  • CrowdStrike Falcon

    securityNice to havePaid

  • Kali Linux

    securityRequiredFree

  • Metasploit

    securityNice to haveFree

  • Microsoft Defender

    securityNice to havePaid

  • Python

    codeNice to haveFree

  • Splunk

    analyticsRequiredPaid

  • Nessus

    securityRequiredPaid

  • Nmap

    securityRequiredFree

  • Wireshark

    securityRequiredFree

Who hires

Interview preparation

3 questions
  • Design a security architecture for a new Kenyan mobile money platform that must comply with CBK cybersecurity guidelines and the Data Protection Act. What controls would you put in place for payment encryption, access management, and incident response?

    TechnicalMid

    Mention end-to-end encryption for transactions, multi-factor authentication, least privilege access, SIEM integration (e.g., Splunk), and an incident response plan aligned with CBK's framework. Highlight testing via penetration testing for common local threats like SIM swap fraud.

  • Tell me about a time you led a security awareness training in a Kenyan organization where many employees were resistant or unaware of phishing risks. How did you make the session effective?

    BehavioralMid

    Use real examples of Kenyan phishing campaigns (e.g., fake M-Pesa messages), gamification, and emphasize personal impact (e.g., mobile money theft). Tailor language to local context and involve senior management buy-in.

  • A ransomware attack encrypts critical customer data at a Kenyan e-commerce company. The CIO wants to pay the ransom to restore operations quickly, but you know the data might not be recovered. How do you respond?

    SituationalMid

    Advise against payment, citing no guarantee of decryption and emboldening attackers. Proceed with incident response: isolate systems, activate backups, inform relevant authorities (National KE-CIRT/CC), and communicate transparently with customers. Emphasize legal and ethical considerations.

Common misconceptions

  • Only large companies need cybersecurity

    SMEs are increasingly targeted and seek consultants for cost-effective security.

  • You must be a hacker

    Many roles are in governance, risk, and compliance, which require policy skills.

What happens next

How the role changes from here, and where it leads.

How the role changes

2024-2030

4 tasks can already be automated today; expect substantial reshaping by 2030. Success means moving up the value chain — from executing tasks to directing AI and applying judgement.

  1. 2024already here

    AI tools begin displacing routine tasks; practitioners adopt copilots.

  2. 2026already here

    Significant automation of standard sub-tasks; roles consolidate.

  3. 2028projected

    Hybrid human+AI roles dominate; pure-routine work largely automated.

  4. 2030projected

    The cybersecurity role is reshaped around oversight, judgement and AI-fluency.

The near term

This role will be substantially reshaped by 2028: ~34% of routine tasks automated or augmented, ~14% displacement risk.

  • ~34% of current routine tasks automated or heavily augmented by 2028
  • Junior/entry work consolidates; the mid-level bar rises
  • Fluency with GitHub Copilot becomes a hiring baseline
  • Pay premium widens for AI-directing practitioners
  • New 'human + AI' hybrid roles emerge in high fields
What to do
For this role, with 4 tasks already automatable, the priority is to stop competing with AI on routine work and start directing it. Master GitHub Copilot and Cursor, deepen Prompt engineering and LLM application development, build a portfolio that shows human + AI fluency. Practitioners who direct AI will out-earn those who don't.

Where pay is heading

2024 to 2030
20242030
Entry131kMid265kSenior534k
flat131k+8%287k+19%636k

Monthly pay in Kenyan shillings, rounded to the nearest thousand. These are projections, not observations.

Growth outlook

Net demand change
30
Over
2024-2030
Drivers
AI adoption across every sector,Kenya's Silicon Savannah and fintech boom
Headwinds
Commoditisation of junior coding

Supply and demand

Demand
95
Supply pressure
100
Balance
Saturated

What to learn

  • Prompt engineering
  • LLM application development
  • MLOps
  • AI ethics & safety

Tools worth knowing

  • GitHub Copilot

    Priority: Essential

    AI pair-programming and code completion

  • Cursor

    Priority: Essential

    AI-first code editor for refactoring and feature building

  • Claude / ChatGPT

    Priority: Essential

    Design discussion, debugging, documentation

  • v0 by Vercel

    Priority: Recommended

    Rapid UI generation from prompts

  • Postman AI

    Priority: Recommended

    API testing and generation

Where people move next

3 recorded moves
Software Engineering70%moderateData Science50%challengingElectrical Engineering20%very-challenging

Line length under each name is the distance of the move: shorter means more of what you already do carries over. Marked lines are steps up rather than sideways.

  • Software Engineering

    Moderate70% skill overlap

    Transition from Cybersecurity to Software Engineering leverages secure coding and network skills, but requires learning full-stack development and modern frameworks.

  • Data Science

    Challenging50% skill overlap

    Cybersecurity professionals can move into Data Science by building on security analytics experience, but need strong statistics, machine learning, and data engineering skills.

  • Electrical Engineering

    Very challenging20% skill overlap

    Transitioning to Electrical Engineering requires deep study of circuits, electronics, and embedded systems, with only minor overlap in hardware security and cryptography.

Related careers

Kenyan market notes

Cybersecurity is a priority in Kenya's digital economy, with regulations like the Data Protection Act 2019 driving compliance roles. Nairobi hosts the majority of jobs, but remote opportunities are growing.

Further reading

Keep this

This role is rated 39 out of 100 today. Save it and the app keeps that number, then tells you by how much it has moved when the record is next reviewed.