Skip to content
Nairobi · KenyaFree to read
Technology

Cybersecurity Analyst

A cybersecurity analyst safeguards an organization's digital assets by identifying vulnerabilities, monitoring networks for threats, and responding to incidents. In Kenya, this role is critical due to the rapid digitization of financial services, government systems, and e-commerce, coupled with the Data Protection Act 2019. The core purpose is to ensure data confidentiality, integrity, and availability, while complying with local regulations.

Daily responsibilities include conducting vulnerability assessments, analyzing security logs, managing firewalls and intrusion detection systems, and leading incident response. Analysts also perform risk assessments, develop security policies, and train employees on best practices. The work is fast-paced, requiring constant vigilance and collaboration with IT and compliance teams.

Career growth is strong, with paths to senior analyst, security architect, or CISO. In Kenya, demand is surging across banking, telecoms, and government, with salaries ranging from KES 3M to 7M for experienced professionals. The rise of AI-driven threats and remote work amplifies the need for skilled analysts, making this a resilient and rewarding career in 2026.

AI exposure
36 of 100, low exposure
Hiring trend
Growing
Hiring rate
90%
Minimum education
Bachelor

The role

What the work is, what it pays, and what it costs you.

At a glance

Work environment
Office or hybrid/remote, in front of a screen most of the day, with cross functional collaboration across product, design and engineering.
Remote friendly
Yes
Freelance potential
Medium
Freelance rate
Ksh 180,000
Time to senior
4 years
Adaptation level
High

A day in the role

A cybersecurity analyst in Kenya responds to intrusion alerts from a financial institution's network. They conduct forensic analysis on a phishing attempt and update firewall rules. In the afternoon, they run vulnerability scans and prepare a security awareness training for staff.

What it pays

Kenyan market, per month
Entry
Ksh 108,000 to Ksh 153,000

The trade offs

In its favour

  • Salaries for mid-level analysts range from 180k to 450k KES per month, with significant premium for certifications like CISSP.
  • Demand is booming as Kenyan banks, telcos, and government agencies invest heavily in security, ensuring job stability.
  • The role directly protects organizations and individuals from cybercrime, giving a strong sense of purpose and impact.
  • You gain deep expertise in networking, forensics, and compliance, which are highly valued globally.

Against it

  • The job is high-stress with constant alert fatigue, incident response pressure, and the need to be on-call for breaches.
  • Certifications are expensive (e.g., CEH, CISSP cost 100k+ KES) and often not fully covered by employers.
  • Cyber threats evolve rapidly, requiring continuous learning that can feel overwhelming and never-ending.
  • Many positions are based in Nairobi, forcing a long commute or relocation, while remote options are rarer than in software engineering.

In practice

Start with a Bachelor's in Computer Science or Cybersecurity from institutions like Strathmore University or the Technical University of Kenya. Earn certifications like CompTIA Security+ or Certified Ethical Hacker (CEH) – often from online platforms or local training centers. Entry-level roles include security analyst or SOC analyst at a Nairobi-based firm. Internships at companies like Safaricom or the Communications Authority of Kenya are common stepping stones.

Junior analysts earn 100K-150K KES monthly, advancing to senior analyst in 3-4 years at 250K-400K KES. Specializations in penetration testing, incident response, or compliance (e.g., ISO 27001) can lead to roles like security architect or CISO. Mid-career, you might lead a SOC team at a bank or telecom, earning 500K+ KES. By year 10, you could be a consultant for regional firms or head of information security at a major corporation.

Kenya's cybersecurity market is growing rapidly, driven by digital banking, mobile money, and government digitization. Key employers include banks (Equity, KCB), telecoms (Safaricom), and e-commerce firms (Jumia). The government's National Cybersecurity Centre and the Communications Authority provide roles. Nairobi is the hub, but demand is rising in Mombasa and Kisumu. Growth is fueled by cyber threats like ransomware and fraud, and regulations like the Data Protection Act 2019.

Your day at a Nairobi bank's SOC starts at 7 AM, monitoring SIEM alerts for suspicious activity. You analyze a phishing email targeting employees and initiate a takedown. After a 10 AM briefing with the incident response team, you run vulnerability scans on the mobile app. Lunch at the canteen, then you write a report on a recent breach attempt. By 5 PM, you're reviewing firewall logs and planning a security awareness workshop for staff.

Exposure

How much of this a machine can already do, and how that was worked out.

Where this rating sits

1,516 rated careers
36
lowmoderatehigh
020406080100

Rated above 38% of the 1,516 careers in the catalogue, which averages 43. Inside technology the mean is 62, across 125 careers.

What the rating is made of

Share of recorded tasks
Machine does it
38%Software can already complete this work end to end.
Machine assists
51%A person still decides, but the drafting is done for them.
Person does it
11%Judgement, relationships and accountability that do not transfer.

Named task by task

Already automated

  • Log analysis and correlation
  • Automated threat intelligence gathering
  • Patch management scheduling
  • Phishing detection and filtering
  • Behavioral analytics for insider threats

Still human

  • Developing security strategy and policies
  • Investigating sophisticated cyber incidents
  • Conducting security awareness training
  • Performing vendor risk assessments
  • Designing security architecture
  • Communicating risks to management

Your skills, sorted

38 skills recorded

Worth more with the tools

  • Programming & Coding
  • Machine Learning
  • Data Analysis
  • Power Systems Analysis
  • Digital Logic Design

Holding their value

  • Cybersecurity
  • DevOps
  • Cloud Computing
  • Computer Networks
  • Video Production
  • Social Media Management
  • Circuit Theory
  • Electromagnetic Fields and Waves

The six things it was scored on

0 to 100 each
Digital surfaceraises exposure
100

How much of the work already happens inside software.

People and inventionlowers exposure
60

Work that needs trust, persuasion or an original idea.

Rule bound thinkingraises exposure
50

Decisions that follow a procedure rather than a judgement.

Regulatory stakeslowers exposure
45

Where a named person has to carry the liability.

Routine intensityraises exposure
40

How much of it repeats in the same shape each time.

Physical presencelowers exposure
5

Work that has to happen in a place, with hands.

Task counts

Tasks recorded
11
Automatable now
5
Still human
6
Displacing
Boilerplate code generation (now AI-assisted),Routine testing and refactoring,Basic data cleaning
Augmenting
AI pair-programming (Copilot),Automated code review and test generation,LLM-accelerated research and analysis
Creating
Applied AI/ML engineering,MLOps and AI reliability,AI product and data-product roles

Sources

Behind the rating
  • Frey & Osborne (2013), 'The Future of Employment', Oxford Martin
  • McKinsey Global Institute, 'The Future of Work' (2017/2023)
  • OpenAI/UPenn, 'GPTs are GPTs' (2023), occupational LLM exposure
  • WEF, 'Future of Jobs Report' (2023)

Getting in

The routes into the role and what each one asks for.

What to study

8 courses

How people get in

  • University Degree

    4 yearsHigh cost

    BSc in Computer Science, IT, or Cybersecurity from UoN or Strathmore

  • Bootcamp

    3-6 monthsMedium cost

    Cybersecurity bootcamp with focus on SOC analysis (e.g., CyberShield Kenya)

  • Self-taught with Labs

    6 monthsLow cost

    Online resources (Cybrary, TryHackMe) to build practical skills in threat detection

Certifications

  • CompTIA CySA+

    CompTIAKsh 90,0002 months

  • EC-Council Certified Incident Handler (ECIH)

    EC-CouncilKsh 120,0003 months

  • GIAC Certified Incident Handler (GCIH)

    GIACKsh 200,0004 months

  • Cisco Certified CyberOps Associate

    CiscoKsh 100,0003 months

Tools of the trade

  • Kali Linux

    codeRequiredFree

  • Metasploit

    securityNice to haveFree

  • Microsoft Defender

    securityRequiredPaid

  • Nmap

    securityRequiredFree

  • Wireshark

    securityRequiredFree

  • Splunk

    analyticsRequiredPaid

  • Burp Suite

    securityNice to havePaid

Who hires

Interview preparation

3 questions
  • You detect a brute-force attack on a company's web portal that uses M-Pesa as a payment method. What immediate steps do you take to mitigate the threat and preserve evidence?

    TechnicalEntry

    Immediate actions: block attacking IPs via firewall, enforce account lockout policies, check server logs for signs of compromise, and alert the incident response team. For preservation, copy logs to secure storage and document timestamps. Mention use of IDS/IPS and SIEM with local threat intelligence feeds.

  • Describe a time you had to explain a security vulnerability to a non-technical colleague, such as a customer service agent, at a Kenyan telecom. How did you ensure they understood the risk without causing panic?

    BehavioralEntry

    Use analogies (e.g., leaving front door open), focus on concrete steps the agent can take (e.g., not sharing passwords), and reassure that security team is handling it. Tailor to local context: relate to M-Pesa PIN safety.

  • During a routine log review, you notice unusual outbound traffic from a finance department computer at 2 AM. It's suspicious but not definitely malicious. What do you do?

    SituationalEntry

    Escalate to senior analyst, isolate the machine from the network, capture full memory and network activity, and interview the user later. Emphasize not jumping to conclusions but erring on side of caution. Reference playbooks and communication protocols.

Common misconceptions

  • You need years of experience to become an analyst

    Junior SOC roles are available for fresh graduates with certification and internship.

  • Analysts just sit and watch screens

    They actively hunt threats, create rules, and collaborate with incident response teams.

What happens next

How the role changes from here, and where it leads.

How the role changes

2024-2030

5 tasks can already be automated today; expect substantial reshaping by 2030. Success means moving up the value chain — from executing tasks to directing AI and applying judgement.

  1. 2024already here

    AI tools begin displacing routine tasks; practitioners adopt copilots.

  2. 2026already here

    Significant automation of standard sub-tasks; roles consolidate.

  3. 2028projected

    Hybrid human+AI roles dominate; pure-routine work largely automated.

  4. 2030projected

    The cybersecurity analyst role is reshaped around oversight, judgement and AI-fluency.

The near term

This role will be substantially reshaped by 2028: ~34% of routine tasks automated or augmented, ~14% displacement risk.

  • ~34% of current routine tasks automated or heavily augmented by 2028
  • Junior/entry work consolidates; the mid-level bar rises
  • Fluency with GitHub Copilot becomes a hiring baseline
  • Pay premium widens for AI-directing practitioners
  • New 'human + AI' hybrid roles emerge in high fields
What to do
In this role, move up the value chain now — 5 of your routine tasks can already be automated, so treat junior-routine work as transitional. Master GitHub Copilot and Cursor, deepen Prompt engineering and LLM application development, build a portfolio that shows human + AI fluency. Practitioners who direct AI will out-earn those who don't.

Where pay is heading

2024 to 2030
20242030
Entry131kMid290kSenior610k
flat131k+8%314k+19%726k

Monthly pay in Kenyan shillings, rounded to the nearest thousand. These are projections, not observations.

Growth outlook

Net demand change
30
Over
2024-2030
Drivers
AI adoption across every sector,Kenya's Silicon Savannah and fintech boom
Headwinds
Commoditisation of junior coding

Supply and demand

Demand
90
Supply pressure
30
Balance
High demand

What to learn

  • Prompt engineering
  • LLM application development
  • MLOps
  • AI ethics & safety

Tools worth knowing

  • GitHub Copilot

    Priority: Essential

    AI pair-programming and code completion

  • Cursor

    Priority: Essential

    AI-first code editor for refactoring and feature building

  • Claude / ChatGPT

    Priority: Essential

    Design discussion, debugging, documentation

  • v0 by Vercel

    Priority: Recommended

    Rapid UI generation from prompts

  • Postman AI

    Priority: Recommended

    API testing and generation

Where people move next

5 recorded moves

Line length under each name is the distance of the move: shorter means more of what you already do carries over. Marked lines are steps up rather than sideways.

  • Data Science

    Challenging45% skill overlap

    Transition from cybersecurity analyst to data science involves building skills in statistics, machine learning, and data visualization, leveraging existing analytical and problem-solving abilities.

  • Software Engineering

    Challenging35% skill overlap

    Moving to software engineering requires deepening programming skills, learning software design patterns, and version control, with cybersecurity's coding background providing a foundation.

  • Cloud Computing

    Moderate55% skill overlap

    Leveraging cybersecurity's cloud security knowledge, transitioning to cloud computing involves learning cloud services and DevOps, often through certifications and hands-on labs.

  • Artificial Intelligence Research Scientist

    Very challenging30% skill overlapPromotion

    This path requires advanced education in AI/ML, strong mathematical foundations, and research experience; cybersecurity's data analysis skills are beneficial but need significant augmentation.

  • Cloud Solutions Architect

    Moderate60% skill overlapPromotion

    Cybersecurity's understanding of security threats and compliance aids transition to solutions architect, focusing on designing scalable, secure cloud infrastructures.

Related careers

Kenyan market notes

Entry-level SOC analyst roles are growing with outsourced security operation centers in Nairobi. Certifications like Security+ and hands-on experience with SIEM tools (e.g., Splunk) are key.

Further reading

Keep this

This role is rated 36 out of 100 today. Save it and the app keeps that number, then tells you by how much it has moved when the record is next reviewed.