DevSecOps Engineer
Integrates security into DevOps pipelines — ensuring code is scanned, tested and deployed securely. In Kenya — with growing DevOps adoption and increasing cyber threats — DevSecOps engineers bridge development, operations and security.
- AI exposure
- 57 of 100, moderate exposure
- Hiring trend
- Rising
- Hiring rate
- 30%
The role
What the work is, what it pays, and what it costs you.
At a glance
- Remote friendly
- Yes
- Freelance potential
- High
- Time to senior
- 8 years
A day in the role
Integrates SAST scanning into a GitHub Actions CI/CD pipeline. Scans Docker images for vulnerabilities using Trivy. Manages secrets in CI/CD using HashiCorp Vault. Reviews Terraform code for security issues using tfsec. Configures Kubernetes security policies. Trains developers on secure coding practices. Responds to a security alert in production. Reviews and remediates vulnerabilities found in a scan.
What it pays
Kenyan market, per month- Entry
- KES 55,000-110,000
- Mid
- KES 130,000-300,000
- Senior
- KES 350,000-800,000
Exposure
How much of this a machine can already do, and how that was worked out.
Where this rating sits
1,516 rated careersRated above 78% of the 1,516 careers in the catalogue, which averages 43. Inside technology the mean is 62, across 125 careers.
Named task by task
Already automated
- AI-powered code security analysis and vulnerability detection
- Automated security policy compliance checking in pipelines
- AI-assisted threat modelling and risk assessment
- Generating security reports and remediation recommendations
Still human
- Integrating security into CI/CD pipelines — adding SAST, DAST, SCA scanning to Jenkins, GitHub Actions, GitLab CI
- Managing security scanning tools — SAST (SonarQube, Checkmarx, Semgrep), DAST (OWASP ZAP, Burp Suite), SCA (Snyk, Dependabot)
- Managing container security — scanning Docker images for vulnerabilities (Trivy, Clair), Kubernetes security policies
- Managing infrastructure security — Terraform security (tfsec), CloudFormation security, IaC scanning
- Implementing secrets management — managing secrets in CI/CD (HashiCorp Vault, AWS Secrets Manager, Azure Key Vault)
- Managing security monitoring — runtime security monitoring, intrusion detection in production environments
- Collaborating with development teams — security training, secure coding practices, security champion programmes
- Managing incident response — security incident detection, response, forensics in DevOps environments
Task counts
- Displacing
- AI code scanning and vulnerability detection improve — but pipeline design, security architecture and incident response remain human.
- Augmenting
- AI security scanning significantly improves vulnerability detection.
Sources
Behind the rating- Kenya DevOps adoption
- Kenya cybersecurity landscape
- Fintech security requirements in Kenya
Getting in
The routes into the role and what each one asks for.
What to study
8 courses- Certificate in Fashion Design and Textile TechnologyKsh 37,320a year
- Certificate in Desktop PublisherKsh 50,000a year
- Certificate in Mobile Applications and TechnologyKsh 56,420a year
- Certificate in Data Science and Artificial IntelligenceKsh 57,050a year
- Diploma in Photogrammetry and Remote SensingKsh 66,270a year
- Artisan in ICTKsh 67,189a year
- Certificate in Artificial Intelligence & CybersecurityKsh 67,189a year
- Certificate in Big DataKsh 67,189a year
How people get in
BSc CS/Software Engineering + DevOps + security experience
6-8 yearsVery high cost
BSc Computer Science or Software Engineering plus DevOps experience plus security engineering experience — combining into DevSecOps
Who hires
- Safaricom
- Banks (KCB, Equity)
- Fintechs (Flutterwave, Cellulant)
- Tech Companies (Andela, Jumia)
Common misconceptions
DevSecOps is just adding security tools to DevOps
DevSecOps is a cultural and technical approach that integrates security thinking throughout the development lifecycle — from design to deployment to runtime. It requires understanding development, operations and security.
What happens next
How the role changes from here, and where it leads.
Growth outlook
- Net demand change
- +20%
- Over
- 2026-2028
- Drivers
- DevOps adoption growth,Cybersecurity threats increasing,Regulatory security requirements,Fintech security demands
- Headwinds
- AI automating security scanning,Cultural adoption challenges,Rare skill combination limiting supply
What to learn
- AI-powered code security analysis
- Cloud-native security (Kubernetes, service mesh)
- Zero Trust architecture implementation
- Supply chain security (SBOM, dependency management)
Kenyan market notes
DevSecOps is an emerging high-demand role in Kenya's tech sector. Key context: as Kenyan companies adopt DevOps practices (CI/CD, containers, cloud), integrating security into the development pipeline is becoming critical — especially for fintechs (handling financial data — security is paramount), banks (CBK security requirements), and tech companies (building secure applications). Key DevSecOps practices: shift-left security (scanning code early in development), continuous security testing (automated scanning in CI/CD), infrastructure security (scanning IaC, container images), and runtime security monitoring. Key tools: SAST (SonarQube, Semgrep, Checkmarx — code scanning), DAST (OWASP ZAP, Burp Suite — application scanning), SCA (Snyk, Dependabot — dependency scanning), container security (Trivy, Clair — image scanning), IaC security (tfsec, Checkov — Terraform scanning), secrets management (Vault, AWS Secrets Manager). Key challenges: requires both DevOps and security expertise (rare combination), cultural change (developers need to care about security), and tool integration complexity. Salary: entry KES 55,000-110,000 (junior DevSecOps engineer), mid KES 130,000-300,000 (DevSecOps engineer), senior KES 350,000-800,000+ (senior DevSecOps or security architect). This is one of the highest-paying tech roles due to the rare combination of skills.
Further reading
This role is rated 57 out of 100 today. Save it and the app keeps that number, then tells you by how much it has moved when the record is next reviewed.