Skip to content
Nairobi · KenyaFree to read
Technology

Cybersecurity Consultant (GRC)

A Cybersecurity Consultant specializing in Governance, Risk, and Compliance (GRC) helps organizations align security with business objectives by developing policies, managing risk, and ensuring compliance with regulations such as Kenya's Data Protection Act (2019), ISO 27001, and PCI DSS. The role is central to building trust and resilience in digital operations.

Daily responsibilities include conducting risk assessments, auditing security controls, advising C-suite on cyber risk appetite, and implementing compliance frameworks. Consultants also lead incident response planning and vendor risk management. The work is cross-functional, requiring collaboration with legal, IT, and business teams.

In Kenya, GRC consultants are in high demand in banking, telecoms, and government due to tightening data privacy laws and increasing cyber threats. Career progression leads to roles like Chief Information Security Officer (CISO) or GRC Director. As AI-driven regulation evolves, GRC skills become critical for ethical AI governance and automated compliance monitoring.

AI exposure
35 of 100, low exposure
Hiring trend
Growing
Hiring rate
70%
Minimum education
Bachelor

The role

What the work is, what it pays, and what it costs you.

At a glance

Work environment
Office or hybrid/remote, in front of a screen most of the day, with cross functional collaboration across product, design and engineering.
Remote friendly
Yes
Freelance potential
High
Freelance rate
Ksh 350,000
Time to senior
6 years
Adaptation level
High

A day in the role

A GRC consultant in Kenya starts by reviewing regulatory updates (e.g., Data Protection Act), then conducts risk assessments for client organizations. They develop compliance frameworks and policies, and train staff on security governance, ensuring alignment with 2026 standards.

What it pays

Kenyan market, per month
Entry
Ksh 120,000 to Ksh 170,000

The trade offs

In its favour

  • Very high salaries: KES 250,000-600,000+ monthly, especially in banks and large telcos, with premium for certifications like CISA, CISSP.
  • Low AI risk and growing demand as Kenyan companies ramp up compliance with data protection and cyber insurance requirements.
  • High job satisfaction from protecting critical infrastructure (e.g., banking, electricity) and helping firms avoid costly breaches.
  • Clear career ladder from consultant to senior manager or CISO, with opportunities to work for international standards bodies.

Against it

  • Requires deep expertise in frameworks like NIST, ISO 27001, and Kenya's Data Protection Act, which few local training programs cover adequately.
  • Constant pressure to stay ahead of evolving threats and regulations, leading to burnout without proper work-life boundaries.
  • Client-facing role means frequent travel within Nairobi to conduct audits or gap analyses, adding traffic stress and irregular hours.
  • In smaller firms, you may be the only security expert, leading to isolation and lack of mentorship for career growth.

In practice

A cybersecurity consultant specializing in GRC in Kenya usually begins with a bachelor's degree in information security, computer science, or law with IT focus. Key certifications like CISA, CISM, or CISSP are almost mandatory, with many professionals obtaining them after a few years of experience. Entry-level roles include IT auditor, compliance analyst, or junior consultant at firms like EY Kenya, Deloitte, or specialized cybersecurity firms. Many start in internal audit departments of banks or in government agencies like the Communications Authority of Kenya.

Career progression moves from junior GRC consultant to senior consultant, then to manager or director of cybersecurity over 8–12 years. Salaries range from KES 150,000 per month for entry-level to KES 500,000+ for senior consultants at top firms. Specialization options include focusing on data privacy (e.g., Data Protection Act compliance), risk management, or specific industry standards like PCI DSS. Promotions are tied to successful client engagements, regulatory understanding, and earning advanced certifications like CRISC or ISO 27001 Lead Auditor.

The GRC cybersecurity market in Kenya is driven by strict regulations, particularly the Data Protection Act 2019 and CBK guidelines for financial institutions. Key employers include commercial banks (e.g., Equity Bank, KCB), fintech companies, and consulting firms like PwC and EY, with job concentrations in Nairobi’s banking districts. Growth is fueled by digital transformation, increased cyber threats, and regulatory fines for non-compliance. The market is still emerging but expanding rapidly, with demand for experienced GRC professionals outpacing supply.

A mid-level GRC consultant in Nairobi typically starts the day reviewing regulatory updates and client emails. Mornings are spent conducting risk assessments or policy gap analyses for a bank client, often referencing the Data Protection Act. Afternoons involve writing compliance reports, preparing for client presentations, and advising on remediation plans. The day may include a virtual meeting with the Central Bank of Kenya’s cybersecurity team or a site visit to a client’s IT department in Upper Hill.

Exposure

How much of this a machine can already do, and how that was worked out.

Where this rating sits

1,516 rated careers
35
lowmoderatehigh
020406080100

Rated above 36% of the 1,516 careers in the catalogue, which averages 43. Inside technology the mean is 62, across 125 careers.

What the rating is made of

Share of recorded tasks
Machine does it
38%Software can already complete this work end to end.
Machine assists
51%A person still decides, but the drafting is done for them.
Person does it
11%Judgement, relationships and accountability that do not transfer.

Named task by task

Already automated

  • Automated control testing and log analysis
  • Documentation drafting and template generation
  • Risk scoring based on historical data
  • Compliance monitoring dashboards

Still human

  • Interpreting regulations for specific business contexts
  • Advising executives on risk appetite
  • Conducting stakeholder interviews for risk assessments
  • Developing tailored security policies
  • Managing third-party security reviews
  • Incident communication with regulators

Your skills, sorted

40 skills recorded

Worth more with the tools

  • Programming & Coding
  • Machine Learning
  • Computer Programming
  • Data Analysis

Holding their value

  • DevOps
  • Cloud Computing
  • Data Structures
  • Algorithms
  • Computer Networks
  • Network Security
  • Advanced Cryptography
  • Cybersecurity Leadership

The six things it was scored on

0 to 100 each
Digital surfaceraises exposure
100

How much of the work already happens inside software.

People and inventionlowers exposure
60

Work that needs trust, persuasion or an original idea.

Rule bound thinkingraises exposure
50

Decisions that follow a procedure rather than a judgement.

Regulatory stakeslowers exposure
45

Where a named person has to carry the liability.

Routine intensityraises exposure
40

How much of it repeats in the same shape each time.

Physical presencelowers exposure
5

Work that has to happen in a place, with hands.

Task counts

Tasks recorded
10
Automatable now
4
Still human
6
Displacing
Boilerplate code generation (now AI-assisted),Routine testing and refactoring,Basic data cleaning
Augmenting
AI pair-programming (Copilot),Automated code review and test generation,LLM-accelerated research and analysis
Creating
Applied AI/ML engineering,MLOps and AI reliability,AI product and data-product roles

Sources

Behind the rating
  • Frey & Osborne (2013), 'The Future of Employment', Oxford Martin
  • McKinsey Global Institute, 'The Future of Work' (2017/2023)
  • OpenAI/UPenn, 'GPTs are GPTs' (2023), occupational LLM exposure
  • WEF, 'Future of Jobs Report' (2023)

Getting in

The routes into the role and what each one asks for.

What to study

8 courses

How people get in

  • University Degree

    4 yearsHigh cost

    BSc in Cybersecurity, IT, or Computer Science from UoN, Strathmore, or KCA

  • Professional Certification

    6 monthsHigh cost

    CISA, CISSP, or CISM certification via ISACA or (ISC)²

  • GRC Bootcamp

    3 monthsMedium cost

    Specialized GRC training from Cybersafe Africa or Enovate Labs

  • Self-taught + Experience

    24 monthsLow cost

    Online courses (Coursera, TryHackMe) followed by entry-level IT audit or compliance roles

Certifications

  • Certified in Risk and Information Systems Control (CRISC)

    ISACAKsh 90,0006 months

  • Certified Information Security Manager (CISM)

    ISACAKsh 95,0006 months

  • ISO/IEC 27001 Lead Implementer

    PECBKsh 120,0005 months

  • Certified Information Systems Auditor (CISA)

    ISACAKsh 85,0006 months

Tools of the trade

  • OpenVAS

    securityBonusFree

  • Microsoft Excel

    spreadsheetRequiredPaid

  • OneTrust

    securityNice to havePaid

  • RSA Archer

    securityNice to havePaid

  • Google Sheets

    spreadsheetNice to haveFree

  • Splunk

    securityNice to havePaid

  • Nessus

    securityRequiredPaid

  • Qualys

    securityNice to havePaid

Who hires

Interview preparation

3 questions
  • How would you conduct a risk assessment for a Kenyan bank that wants to comply with the Data Protection Act 2019 and CBK guidelines?

    TechnicalMid

    Reference frameworks like ISO 27001, NIST CSF, and walk through identifying assets, threats, vulnerabilities, and controls for a financial institution.

  • Describe how you would convince a skeptical C-suite to invest in a comprehensive GRC program rather than just buying security tools.

    BehavioralMid

    Emphasize business language, cost of non-compliance, and alignment with organizational goals.

  • A ransomware attack encrypts critical files in a client's organization. The CEO insists on paying the ransom. What do you do?

    SituationalMid

    Explain legal and ethical implications, advise against payment, and outline incident response steps (isolation, backups, law enforcement).

Common misconceptions

  • Cybersecurity is only for technical hackers

    GRC focuses on policy, risk management, and compliance—less technical, but requires understanding of legal and business context.

  • Certifications guarantee a job

    Employers value experience and practical knowledge; certifications complement but don't replace hands-on work.

  • Salaries are low for GRC specialists

    Senior GRC consultants at top firms earn KES 300,000-500,000/month; freelancers can charge KES 5,000-10,000/hour.

What happens next

How the role changes from here, and where it leads.

How the role changes

2024-2030

4 tasks can already be automated today; expect substantial reshaping by 2030. Success means moving up the value chain — from executing tasks to directing AI and applying judgement.

  1. 2024already here

    AI tools begin displacing routine tasks; practitioners adopt copilots.

  2. 2026already here

    Significant automation of standard sub-tasks; roles consolidate.

  3. 2028projected

    Hybrid human+AI roles dominate; pure-routine work largely automated.

  4. 2030projected

    The cybersecurity consultant (grc) role is reshaped around oversight, judgement and AI-fluency.

The near term

Expect significant workflow change by 2028 — up to 34% of routine tasks reshaped, with entry-level roles most affected.

  • ~34% of current routine tasks automated or heavily augmented by 2028
  • Junior/entry work consolidates; the mid-level bar rises
  • Fluency with GitHub Copilot becomes a hiring baseline
  • Pay premium widens for AI-directing practitioners
  • New 'human + AI' hybrid roles emerge in high fields
What to do
with 4 tasks already automatable, the priority is to stop competing with AI on routine work and start directing it. Master GitHub Copilot and Cursor, deepen Prompt engineering and LLM application development, build a portfolio that shows human + AI fluency. Practitioners who direct AI will out-earn those who don't.

Where pay is heading

2024 to 2030
20242030
Entry145kMid290kSenior580k
flat145k+8%314k+19%690k

Monthly pay in Kenyan shillings, rounded to the nearest thousand. These are projections, not observations.

Growth outlook

Net demand change
30
Over
2024-2030
Drivers
AI adoption across every sector,Kenya's Silicon Savannah and fintech boom
Headwinds
Commoditisation of junior coding

Supply and demand

Demand
70
Supply pressure
25
Balance
Balanced

What to learn

  • Prompt engineering
  • LLM application development
  • MLOps
  • AI ethics & safety

Tools worth knowing

  • GitHub Copilot

    Priority: Essential

    AI pair-programming and code completion

  • Cursor

    Priority: Essential

    AI-first code editor for refactoring and feature building

  • Claude / ChatGPT

    Priority: Essential

    Design discussion, debugging, documentation

  • v0 by Vercel

    Priority: Recommended

    Rapid UI generation from prompts

  • Postman AI

    Priority: Recommended

    API testing and generation

Where people move next

5 recorded moves

Line length under each name is the distance of the move: shorter means more of what you already do carries over. Marked lines are steps up rather than sideways.

  • Data Science

    Challenging30% skill overlap

    Transitioning from GRC to data science requires building strong programming and statistical skills, leveraging analytical thinking but minimal technical overlap.

  • Software Engineering

    Challenging20% skill overlap

    Moving from GRC to software engineering involves learning full-stack development and programming, with only basic secure coding overlap.

  • Cloud Computing

    Moderate50% skill overlap

    Leveraging cloud governance and compliance knowledge, this transition requires building hands-on cloud platform skills.

  • Artificial Intelligence Research Scientist

    Very challenging10% skill overlap

    Transitioning to AI research requires advanced degrees and deep quantitative expertise, with negligible skill overlap from GRC.

  • Cloud Solutions Architect

    Moderate55% skill overlapLateral

    With strong understanding of cloud compliance and risk, you can shift to cloud architecture by deepening technical cloud design skills.

Related careers

Kenyan market notes

Demand surged due to Data Protection Act enforcement and fintech growth. Roles available in banks, telecoms, and consulting firms, mostly Nairobi-based.

Further reading

Keep this

This role is rated 35 out of 100 today. Save it and the app keeps that number, then tells you by how much it has moved when the record is next reviewed.