Cybersecurity Consultant (GRC)
A Cybersecurity Consultant specializing in Governance, Risk, and Compliance (GRC) helps organizations align security with business objectives by developing policies, managing risk, and ensuring compliance with regulations such as Kenya's Data Protection Act (2019), ISO 27001, and PCI DSS. The role is central to building trust and resilience in digital operations.
Daily responsibilities include conducting risk assessments, auditing security controls, advising C-suite on cyber risk appetite, and implementing compliance frameworks. Consultants also lead incident response planning and vendor risk management. The work is cross-functional, requiring collaboration with legal, IT, and business teams.
In Kenya, GRC consultants are in high demand in banking, telecoms, and government due to tightening data privacy laws and increasing cyber threats. Career progression leads to roles like Chief Information Security Officer (CISO) or GRC Director. As AI-driven regulation evolves, GRC skills become critical for ethical AI governance and automated compliance monitoring.
- AI exposure
- 35 of 100, low exposure
- Hiring trend
- Growing
- Hiring rate
- 70%
- Minimum education
- Bachelor
The role
What the work is, what it pays, and what it costs you.
At a glance
- Work environment
- Office or hybrid/remote, in front of a screen most of the day, with cross functional collaboration across product, design and engineering.
- Remote friendly
- Yes
- Freelance potential
- High
- Freelance rate
- Ksh 350,000
- Time to senior
- 6 years
- Adaptation level
- High
A day in the role
A GRC consultant in Kenya starts by reviewing regulatory updates (e.g., Data Protection Act), then conducts risk assessments for client organizations. They develop compliance frameworks and policies, and train staff on security governance, ensuring alignment with 2026 standards.
What it pays
Kenyan market, per month- Entry
- Ksh 120,000 to Ksh 170,000
The trade offs
In its favour
- Very high salaries: KES 250,000-600,000+ monthly, especially in banks and large telcos, with premium for certifications like CISA, CISSP.
- Low AI risk and growing demand as Kenyan companies ramp up compliance with data protection and cyber insurance requirements.
- High job satisfaction from protecting critical infrastructure (e.g., banking, electricity) and helping firms avoid costly breaches.
- Clear career ladder from consultant to senior manager or CISO, with opportunities to work for international standards bodies.
Against it
- Requires deep expertise in frameworks like NIST, ISO 27001, and Kenya's Data Protection Act, which few local training programs cover adequately.
- Constant pressure to stay ahead of evolving threats and regulations, leading to burnout without proper work-life boundaries.
- Client-facing role means frequent travel within Nairobi to conduct audits or gap analyses, adding traffic stress and irregular hours.
- In smaller firms, you may be the only security expert, leading to isolation and lack of mentorship for career growth.
In practice
A cybersecurity consultant specializing in GRC in Kenya usually begins with a bachelor's degree in information security, computer science, or law with IT focus. Key certifications like CISA, CISM, or CISSP are almost mandatory, with many professionals obtaining them after a few years of experience. Entry-level roles include IT auditor, compliance analyst, or junior consultant at firms like EY Kenya, Deloitte, or specialized cybersecurity firms. Many start in internal audit departments of banks or in government agencies like the Communications Authority of Kenya.
Career progression moves from junior GRC consultant to senior consultant, then to manager or director of cybersecurity over 8–12 years. Salaries range from KES 150,000 per month for entry-level to KES 500,000+ for senior consultants at top firms. Specialization options include focusing on data privacy (e.g., Data Protection Act compliance), risk management, or specific industry standards like PCI DSS. Promotions are tied to successful client engagements, regulatory understanding, and earning advanced certifications like CRISC or ISO 27001 Lead Auditor.
The GRC cybersecurity market in Kenya is driven by strict regulations, particularly the Data Protection Act 2019 and CBK guidelines for financial institutions. Key employers include commercial banks (e.g., Equity Bank, KCB), fintech companies, and consulting firms like PwC and EY, with job concentrations in Nairobi’s banking districts. Growth is fueled by digital transformation, increased cyber threats, and regulatory fines for non-compliance. The market is still emerging but expanding rapidly, with demand for experienced GRC professionals outpacing supply.
A mid-level GRC consultant in Nairobi typically starts the day reviewing regulatory updates and client emails. Mornings are spent conducting risk assessments or policy gap analyses for a bank client, often referencing the Data Protection Act. Afternoons involve writing compliance reports, preparing for client presentations, and advising on remediation plans. The day may include a virtual meeting with the Central Bank of Kenya’s cybersecurity team or a site visit to a client’s IT department in Upper Hill.
Exposure
How much of this a machine can already do, and how that was worked out.
Where this rating sits
1,516 rated careersRated above 36% of the 1,516 careers in the catalogue, which averages 43. Inside technology the mean is 62, across 125 careers.
What the rating is made of
Share of recorded tasks- Machine does it
- 38%Software can already complete this work end to end.
- Machine assists
- 51%A person still decides, but the drafting is done for them.
- Person does it
- 11%Judgement, relationships and accountability that do not transfer.
Named task by task
Already automated
- Automated control testing and log analysis
- Documentation drafting and template generation
- Risk scoring based on historical data
- Compliance monitoring dashboards
Still human
- Interpreting regulations for specific business contexts
- Advising executives on risk appetite
- Conducting stakeholder interviews for risk assessments
- Developing tailored security policies
- Managing third-party security reviews
- Incident communication with regulators
Your skills, sorted
40 skills recordedWorth more with the tools
- Programming & Coding
- Machine Learning
- Computer Programming
- Data Analysis
Holding their value
- DevOps
- Cloud Computing
- Data Structures
- Algorithms
- Computer Networks
- Network Security
- Advanced Cryptography
- Cybersecurity Leadership
The six things it was scored on
0 to 100 each- Digital surfaceraises exposure
- 100
- People and inventionlowers exposure
- 60
- Rule bound thinkingraises exposure
- 50
- Regulatory stakeslowers exposure
- 45
- Routine intensityraises exposure
- 40
- Physical presencelowers exposure
- 5
How much of the work already happens inside software.
Work that needs trust, persuasion or an original idea.
Decisions that follow a procedure rather than a judgement.
Where a named person has to carry the liability.
How much of it repeats in the same shape each time.
Work that has to happen in a place, with hands.
Task counts
- Tasks recorded
- 10
- Automatable now
- 4
- Still human
- 6
- Displacing
- Boilerplate code generation (now AI-assisted),Routine testing and refactoring,Basic data cleaning
- Augmenting
- AI pair-programming (Copilot),Automated code review and test generation,LLM-accelerated research and analysis
- Creating
- Applied AI/ML engineering,MLOps and AI reliability,AI product and data-product roles
Sources
Behind the rating- Frey & Osborne (2013), 'The Future of Employment', Oxford Martin
- McKinsey Global Institute, 'The Future of Work' (2017/2023)
- OpenAI/UPenn, 'GPTs are GPTs' (2023), occupational LLM exposure
- WEF, 'Future of Jobs Report' (2023)
Getting in
The routes into the role and what each one asks for.
What to study
8 courses- Certificate in Fashion Design and Textile TechnologyKsh 37,320a year
- Certificate in Desktop PublisherKsh 50,000a year
- Certificate in Mobile Applications and TechnologyKsh 56,420a year
- Certificate in Data Science and Artificial IntelligenceKsh 57,050a year
- Diploma in Photogrammetry and Remote SensingKsh 66,270a year
- Artisan in ICTKsh 67,189a year
- Certificate in Artificial Intelligence & CybersecurityKsh 67,189a year
- Certificate in Big DataKsh 67,189a year
How people get in
University Degree
4 yearsHigh cost
BSc in Cybersecurity, IT, or Computer Science from UoN, Strathmore, or KCA
Professional Certification
6 monthsHigh cost
CISA, CISSP, or CISM certification via ISACA or (ISC)²
GRC Bootcamp
3 monthsMedium cost
Specialized GRC training from Cybersafe Africa or Enovate Labs
Self-taught + Experience
24 monthsLow cost
Online courses (Coursera, TryHackMe) followed by entry-level IT audit or compliance roles
Certifications
Certified in Risk and Information Systems Control (CRISC)
ISACAKsh 90,0006 months
Certified Information Security Manager (CISM)
ISACAKsh 95,0006 months
ISO/IEC 27001 Lead Implementer
PECBKsh 120,0005 months
Certified Information Systems Auditor (CISA)
ISACAKsh 85,0006 months
Tools of the trade
OpenVAS
securityBonusFree
Microsoft Excel
spreadsheetRequiredPaid
OneTrust
securityNice to havePaid
RSA Archer
securityNice to havePaid
Google Sheets
spreadsheetNice to haveFree
Splunk
securityNice to havePaid
Nessus
securityRequiredPaid
Qualys
securityNice to havePaid
Who hires
Interview preparation
3 questionsHow would you conduct a risk assessment for a Kenyan bank that wants to comply with the Data Protection Act 2019 and CBK guidelines?
TechnicalMid
Reference frameworks like ISO 27001, NIST CSF, and walk through identifying assets, threats, vulnerabilities, and controls for a financial institution.
Describe how you would convince a skeptical C-suite to invest in a comprehensive GRC program rather than just buying security tools.
BehavioralMid
Emphasize business language, cost of non-compliance, and alignment with organizational goals.
A ransomware attack encrypts critical files in a client's organization. The CEO insists on paying the ransom. What do you do?
SituationalMid
Explain legal and ethical implications, advise against payment, and outline incident response steps (isolation, backups, law enforcement).
Common misconceptions
Cybersecurity is only for technical hackers
GRC focuses on policy, risk management, and compliance—less technical, but requires understanding of legal and business context.
Certifications guarantee a job
Employers value experience and practical knowledge; certifications complement but don't replace hands-on work.
Salaries are low for GRC specialists
Senior GRC consultants at top firms earn KES 300,000-500,000/month; freelancers can charge KES 5,000-10,000/hour.
What happens next
How the role changes from here, and where it leads.
How the role changes
2024-20304 tasks can already be automated today; expect substantial reshaping by 2030. Success means moving up the value chain — from executing tasks to directing AI and applying judgement.
- 2024already here
AI tools begin displacing routine tasks; practitioners adopt copilots.
- 2026already here
Significant automation of standard sub-tasks; roles consolidate.
- 2028projected
Hybrid human+AI roles dominate; pure-routine work largely automated.
- 2030projected
The cybersecurity consultant (grc) role is reshaped around oversight, judgement and AI-fluency.
The near term
Expect significant workflow change by 2028 — up to 34% of routine tasks reshaped, with entry-level roles most affected.
- ~34% of current routine tasks automated or heavily augmented by 2028
- Junior/entry work consolidates; the mid-level bar rises
- Fluency with GitHub Copilot becomes a hiring baseline
- Pay premium widens for AI-directing practitioners
- New 'human + AI' hybrid roles emerge in high fields
- What to do
- with 4 tasks already automatable, the priority is to stop competing with AI on routine work and start directing it. Master GitHub Copilot and Cursor, deepen Prompt engineering and LLM application development, build a portfolio that shows human + AI fluency. Practitioners who direct AI will out-earn those who don't.
Where pay is heading
2024 to 2030Monthly pay in Kenyan shillings, rounded to the nearest thousand. These are projections, not observations.
Growth outlook
- Net demand change
- 30
- Over
- 2024-2030
- Drivers
- AI adoption across every sector,Kenya's Silicon Savannah and fintech boom
- Headwinds
- Commoditisation of junior coding
Supply and demand
- Demand
- 70
- Supply pressure
- 25
- Balance
- Balanced
What to learn
- Prompt engineering
- LLM application development
- MLOps
- AI ethics & safety
Tools worth knowing
GitHub Copilot
Priority: Essential
AI pair-programming and code completion
Cursor
Priority: Essential
AI-first code editor for refactoring and feature building
Claude / ChatGPT
Priority: Essential
Design discussion, debugging, documentation
v0 by Vercel
Priority: Recommended
Rapid UI generation from prompts
Postman AI
Priority: Recommended
API testing and generation
Where people move next
5 recorded movesLine length under each name is the distance of the move: shorter means more of what you already do carries over. Marked lines are steps up rather than sideways.
- Data Science
Challenging30% skill overlap
Transitioning from GRC to data science requires building strong programming and statistical skills, leveraging analytical thinking but minimal technical overlap.
- Software Engineering
Challenging20% skill overlap
Moving from GRC to software engineering involves learning full-stack development and programming, with only basic secure coding overlap.
- Cloud Computing
Moderate50% skill overlap
Leveraging cloud governance and compliance knowledge, this transition requires building hands-on cloud platform skills.
- Artificial Intelligence Research Scientist
Very challenging10% skill overlap
Transitioning to AI research requires advanced degrees and deep quantitative expertise, with negligible skill overlap from GRC.
- Cloud Solutions Architect
Moderate55% skill overlapLateral
With strong understanding of cloud compliance and risk, you can shift to cloud architecture by deepening technical cloud design skills.
Related careers
Kenyan market notes
Demand surged due to Data Protection Act enforcement and fintech growth. Roles available in banks, telecoms, and consulting firms, mostly Nairobi-based.
Further reading
- ISACA CISA Certification
- ISACA CISM Certification
- ISO 27001 Lead Auditor (PECB)
- National Institute of Standards and Technology (NIST) Cybersecurity Framework
- Coursera: Governance, Risk, and Compliance
- LinkedIn Learning: GRC Foundations
- Kenya Data Protection Act 2019: Compliance Trends and Challenges
- World Economic Forum Global Cybersecurity Outlook 2025
- ISACA State of Cybersecurity 2024: Kenya Market Insights
- McKinsey & Company The Future of Cybersecurity in Africa
- Kenya National Bureau of Statistics: ICT Sector Report 2025
This role is rated 35 out of 100 today. Save it and the app keeps that number, then tells you by how much it has moved when the record is next reviewed.