Skip to content
Nairobi · KenyaFree to read
Technology

Penetration Tester (Ethical Hacker)

A Penetration Tester, also known as an Ethical Hacker, is a cybersecurity professional who simulates real-world cyberattacks to identify and exploit vulnerabilities in computer systems, networks, and applications before malicious actors can. Their core purpose is to proactively strengthen an organization's security posture by uncovering weaknesses and providing actionable remediation advice. In Kenya, they are critical for financial institutions, telecoms, and government agencies to comply with the Data Protection Act, 2019, and to secure digital services like mobile money platforms (e.g., M-Pesa).

Key responsibilities include conducting authorized penetration tests using tools like Metasploit, Burp Suite, and Nmap, writing detailed reports with risk assessments and recommendations, and collaborating with IT teams to patch vulnerabilities. Daily work involves reconnaissance, scanning, exploitation, and post-exploitation analysis, often requiring continuous learning to stay ahead of emerging threats. They may also manage bug bounty programs and participate in red team exercises.

Career growth in Kenya is strong, with demand driven by rising cyber threats and regulatory compliance. Entry-level salaries range from KES 300,000-600,000 annually, while experienced professionals can earn over KES 3 million. As of 2026, the role is increasingly influenced by AI, with automated tools augmenting manual testing. Long-term prospects are excellent as Kenya's digital economy expands, with opportunities in consulting firms, banks, and tech startups.

AI exposure
78 of 100, high exposure
Hiring trend
Growing
Hiring rate
75%
Minimum education
Bachelor

The role

What the work is, what it pays, and what it costs you.

At a glance

Work environment
Office or hybrid/remote, in front of a screen most of the day, with cross functional collaboration across product, design and engineering.
Remote friendly
Yes
Freelance potential
High
Freelance rate
Ksh 180,000
Time to senior
6 years
Adaptation level
Moderate

A day in the role

A Penetration Tester in Kenya starts by scoping a security assessment for a client, then runs vulnerability scans on web applications and networks. They manually exploit vulnerabilities like SQL injection, document findings, and present remediation steps to clients. The day often includes writing reports and staying updated on new threats targeting Kenyan enterprises.

What it pays

Kenyan market, per month
Entry
Ksh 108,000 to Ksh 153,000

The trade offs

In its favour

  • Top-tier salaries up to KES 500,000 monthly, as cybersecurity becomes a priority in banking and government.
  • Critical impact: your work directly protects Kenyan digital infrastructure from ransomware and fraud.
  • Low AI risk because ethical hacking requires creativity, lateral thinking, and unpredictable attack patterns.
  • Constant intellectual challenge with new vulnerabilities and systems to test, keeping the work engaging.

Against it

  • Legal grey areas: without proper written authorization, testing activities could be misinterpreted as criminal hacking.
  • High burnout rates from intense pressure to find critical flaws and stay ahead of attackers.
  • Limited dedicated pentesting roles in Kenya; many work freelance or part-time, with inconsistent income.
  • Requires expensive certifications (e.g., CEH, OSCP) costing KES 150,000+ and constant self-study to stay relevant.

In practice

A bachelor's in computer science or IT from the University of Nairobi or JKUAT is common, followed by certifications like CEH or OSCP. Entry-level roles include junior security analyst at Safaricom or KCB via internships. The ICT Authority also runs cybersecurity traineeships for fresh graduates.

Mid-level penetration testers earn KES 150,000–300,000 monthly, advancing to senior roles in 3–5 years with CISSP or OSCP and a focus on mobile security or red teaming. After 10 years, top professionals lead security teams at banks like Equity or consultancies like Deloitte, earning over KES 700,000.

Banking (KCB, Equity), telecom (Safaricom, Airtel), and government (ICT Authority, KRA) dominate demand. Growth is fueled by digital payments adoption and the Data Protection Act 2019 requiring security assessments. Job concentration is highest in Nairobi, with emerging roles in Mombasa's tech corridor.

A mid-level tester begins with a stand-up at a Nairobi tech incubator, then spends the morning reviewing client infrastructure logs. Afternoons involve running automated scans on a banking mobile app and manually testing injection vulnerabilities. The day ends documenting findings and briefing a client on risk priorities.

Exposure

How much of this a machine can already do, and how that was worked out.

Where this rating sits

1,516 rated careers
78
lowmoderatehigh
020406080100

Rated above 96% of the 1,516 careers in the catalogue, which averages 43. Inside technology the mean is 62, across 125 careers.

What the rating is made of

Share of recorded tasks
Machine does it
34%Software can already complete this work end to end.
Machine assists
34%A person still decides, but the drafting is done for them.
Person does it
32%Judgement, relationships and accountability that do not transfer.

Named task by task

Already automated

  • Automated vulnerability scanning
  • Basic password cracking
  • Pattern recognition in code
  • Reporting template generation

Still human

  • Designing complex attack chains
  • Social engineering simulations
  • Custom exploit development
  • Interpreting business context of vulnerabilities
  • Writing convincing phishing emails

Your skills, sorted

40 skills recorded

Worth more with the tools

  • Programming & Coding
  • Machine Learning
  • Computer Programming
  • Data Analysis

Holding their value

  • DevOps
  • Cloud Computing
  • Data Structures
  • Algorithms
  • Computer Networks
  • Network Security
  • Advanced Cryptography
  • Cybersecurity Leadership

The six things it was scored on

0 to 100 each
People and inventionlowers exposure
55

Work that needs trust, persuasion or an original idea.

Digital surfaceraises exposure
50

How much of the work already happens inside software.

Routine intensityraises exposure
45

How much of it repeats in the same shape each time.

Rule bound thinkingraises exposure
45

Decisions that follow a procedure rather than a judgement.

Regulatory stakeslowers exposure
40

Where a named person has to carry the liability.

Physical presencelowers exposure
35

Work that has to happen in a place, with hands.

Task counts

Tasks recorded
9
Automatable now
4
Still human
5
Displacing
Routine, rule-based sub-tasks
Augmenting
AI copilots for drafting, analysis and search
Creating
New AI-adjacent specialist roles

Sources

Behind the rating
  • Frey & Osborne (2013), 'The Future of Employment', Oxford Martin
  • McKinsey Global Institute, 'The Future of Work' (2017/2023)
  • OpenAI/UPenn, 'GPTs are GPTs' (2023), occupational LLM exposure
  • WEF, 'Future of Jobs Report' (2023)

Getting in

The routes into the role and what each one asks for.

What to study

8 courses

How people get in

  • University Degree

    4 yearsHigh cost

    BSc in Cybersecurity or Computer Science from KU or Strathmore

  • Cybersecurity Bootcamp

    6 monthsMedium cost

    Intensive program at CyberShujaa or similar

  • Self-taught with Labs

    12 monthsLow cost

    Online labs like TryHackMe, Hack The Box, and earning CEH certification

Certifications

  • Offensive Security Certified Professional (OSCP)

    Offensive SecurityKsh 194,8706 months

  • Certified Ethical Hacker (CEH)

    EC-CouncilKsh 155,8703 months

  • CompTIA Security+

    CompTIAKsh 26,0002 months

Tools of the trade

  • Burp Suite

    securityRequiredPaid

  • Hydra

    securityNice to haveFree

  • John the Ripper

    securityNice to haveFree

  • Kali Linux

    securityRequiredFree

  • Metasploit

    securityRequiredFree

  • Nmap

    securityRequiredFree

  • SQLMap

    securityRequiredFree

  • Wireshark

    securityRequiredFree

  • Nessus

    securityRequiredPaid

  • Python

    codeRequiredFree

Who hires

Interview preparation

3 questions
  • Walk me through your methodology for conducting a penetration test on a web application that handles mobile money transactions, focusing on OWASP Top 10 vulnerabilities relevant to financial services in Kenya.

    TechnicalMid

    Cover reconnaissance, scanning, exploitation of SQLi, XSS, IDOR, and session management flaws. Emphasize safe testing to avoid disrupting live transactions.

  • Tell me about a time you discovered a critical vulnerability but the development team was resistant to fixing it immediately. How did you persuade them?

    BehavioralMid

    Discuss risk communication, presenting business impact (e.g., potential loss of customer trust, regulatory fines under Kenya's Data Protection Act), and offering a phased remediation plan.

  • During a routine penetration test on a Kenyan government portal, you find a backdoor that appears to be left by a previous tester or insider. What do you do?

    SituationalMid

    Prioritize responsible disclosure, escalate to management, preserve evidence, and recommend immediate incident response. Be mindful of legal implications under Kenya's Computer Misuse and Cybercrimes Act.

Common misconceptions

  • You need to be a criminal to be a hacker

    Ethical hacking is a legitimate, legal career focused on improving security through authorized testing.

  • Penetration testing is a one-time activity

    Continuous testing is needed as systems evolve; many firms hire testers on retainer.

What happens next

How the role changes from here, and where it leads.

How the role changes

2024-2030

Expect steady augmentation rather than wholesale replacement. 5 higher-value tasks remain human-led for years to come. Practitioners who embrace AI tools will out-earn those who don't.

  1. 2024already here

    AI copilots augment daily work; productivity gains for adopters.

  2. 2027projected

    Augmentation deepens; some routine sub-tasks automated.

  3. 2030projected

    Practitioners who pair domain expertise with AI tools pull ahead.

The near term

Steady AI augmentation through 2028 — ~69% of practitioners will use AI copilots, ~31% of routine sub-tasks automated.

  • AI copilots become standard (~69% adoption by 2028)
  • ~31% of repetitive sub-tasks automated
  • Role shifts toward review, judgement, and orchestration
  • Digital fluency becomes a differentiator
  • ChatGPT / Claude adoption reshapes daily workflows
What to do
Here, adopt the AI copilots for your field this year like ChatGPT / Claude and Microsoft Copilot, and reposition around what AI can't do — Digital fluency, Data literacy, and complex problem-solving. Net effect is productivity, not job loss, for those who adapt.

Where pay is heading

2024 to 2030
20242030
Entry131kMid265kSenior534k
-7%122k-2%260k+5%561k

Monthly pay in Kenyan shillings, rounded to the nearest thousand. These are projections, not observations.

Growth outlook

Net demand change
5
Over
2024-2030
Drivers
Digital transformation across sectors
Headwinds
Automation of routine work

Supply and demand

Demand
75
Supply pressure
23
Balance
High demand

What to learn

  • Digital fluency
  • Data literacy
  • AI tooling basics

Tools worth knowing

  • ChatGPT / Claude

    Priority: Essential

    Drafting, research and analysis

  • Microsoft Copilot

    Priority: Recommended

    Office productivity and writing

  • Power BI / Excel Copilot

    Priority: Recommended

    Data analysis and reporting

Where people move next

5 recorded moves

Line length under each name is the distance of the move: shorter means more of what you already do carries over. Marked lines are steps up rather than sideways.

  • Data Science

    Moderate35% skill overlapLateral

    Strong analytical skills from penetration testing transfer to data science, but require learning statistics and machine learning. Bridge with dedicated data science courses.

  • Software Engineering

    Moderate55% skill overlapLateral

    Penetration testers already have strong programming skills, especially in Python and scripting, making the transition to software engineering feasible with additional focus on development practices.

  • Cloud Computing

    Moderate40% skill overlapLateral

    Network security expertise is valuable for cloud roles, but requires learning cloud platforms and services. Certifications can bridge the gap.

  • Artificial Intelligence Research Scientist

    Very challenging20% skill overlapPromotion

    Transition to AI research scientist requires advanced degrees and deep expertise in machine learning, with little direct overlap from penetration testing. Long-term commitment to study is essential.

  • Cloud Solutions Architect

    Challenging30% skill overlapPromotion

    Security architecture knowledge helps, but cloud architect roles require broad cloud platform expertise and design skills. Certifications and hands-on experience are key.

Related careers

Kenyan market notes

Penetration testers are in high demand in Kenyan banks, telecoms, and government due to rising cyber threats. Certifications like CEH and OSCP are highly valued. Freelancers often work on bug bounty programs.

Further reading

Keep this

This role is rated 78 out of 100 today. Save it and the app keeps that number, then tells you by how much it has moved when the record is next reviewed.