Penetration Tester (Ethical Hacker)
A Penetration Tester, also known as an Ethical Hacker, is a cybersecurity professional who simulates real-world cyberattacks to identify and exploit vulnerabilities in computer systems, networks, and applications before malicious actors can. Their core purpose is to proactively strengthen an organization's security posture by uncovering weaknesses and providing actionable remediation advice. In Kenya, they are critical for financial institutions, telecoms, and government agencies to comply with the Data Protection Act, 2019, and to secure digital services like mobile money platforms (e.g., M-Pesa).
Key responsibilities include conducting authorized penetration tests using tools like Metasploit, Burp Suite, and Nmap, writing detailed reports with risk assessments and recommendations, and collaborating with IT teams to patch vulnerabilities. Daily work involves reconnaissance, scanning, exploitation, and post-exploitation analysis, often requiring continuous learning to stay ahead of emerging threats. They may also manage bug bounty programs and participate in red team exercises.
Career growth in Kenya is strong, with demand driven by rising cyber threats and regulatory compliance. Entry-level salaries range from KES 300,000-600,000 annually, while experienced professionals can earn over KES 3 million. As of 2026, the role is increasingly influenced by AI, with automated tools augmenting manual testing. Long-term prospects are excellent as Kenya's digital economy expands, with opportunities in consulting firms, banks, and tech startups.
- AI exposure
- 78 of 100, high exposure
- Hiring trend
- Growing
- Hiring rate
- 75%
- Minimum education
- Bachelor
The role
What the work is, what it pays, and what it costs you.
At a glance
- Work environment
- Office or hybrid/remote, in front of a screen most of the day, with cross functional collaboration across product, design and engineering.
- Remote friendly
- Yes
- Freelance potential
- High
- Freelance rate
- Ksh 180,000
- Time to senior
- 6 years
- Adaptation level
- Moderate
A day in the role
A Penetration Tester in Kenya starts by scoping a security assessment for a client, then runs vulnerability scans on web applications and networks. They manually exploit vulnerabilities like SQL injection, document findings, and present remediation steps to clients. The day often includes writing reports and staying updated on new threats targeting Kenyan enterprises.
What it pays
Kenyan market, per month- Entry
- Ksh 108,000 to Ksh 153,000
The trade offs
In its favour
- Top-tier salaries up to KES 500,000 monthly, as cybersecurity becomes a priority in banking and government.
- Critical impact: your work directly protects Kenyan digital infrastructure from ransomware and fraud.
- Low AI risk because ethical hacking requires creativity, lateral thinking, and unpredictable attack patterns.
- Constant intellectual challenge with new vulnerabilities and systems to test, keeping the work engaging.
Against it
- Legal grey areas: without proper written authorization, testing activities could be misinterpreted as criminal hacking.
- High burnout rates from intense pressure to find critical flaws and stay ahead of attackers.
- Limited dedicated pentesting roles in Kenya; many work freelance or part-time, with inconsistent income.
- Requires expensive certifications (e.g., CEH, OSCP) costing KES 150,000+ and constant self-study to stay relevant.
In practice
A bachelor's in computer science or IT from the University of Nairobi or JKUAT is common, followed by certifications like CEH or OSCP. Entry-level roles include junior security analyst at Safaricom or KCB via internships. The ICT Authority also runs cybersecurity traineeships for fresh graduates.
Mid-level penetration testers earn KES 150,000–300,000 monthly, advancing to senior roles in 3–5 years with CISSP or OSCP and a focus on mobile security or red teaming. After 10 years, top professionals lead security teams at banks like Equity or consultancies like Deloitte, earning over KES 700,000.
Banking (KCB, Equity), telecom (Safaricom, Airtel), and government (ICT Authority, KRA) dominate demand. Growth is fueled by digital payments adoption and the Data Protection Act 2019 requiring security assessments. Job concentration is highest in Nairobi, with emerging roles in Mombasa's tech corridor.
A mid-level tester begins with a stand-up at a Nairobi tech incubator, then spends the morning reviewing client infrastructure logs. Afternoons involve running automated scans on a banking mobile app and manually testing injection vulnerabilities. The day ends documenting findings and briefing a client on risk priorities.
Exposure
How much of this a machine can already do, and how that was worked out.
Where this rating sits
1,516 rated careersRated above 96% of the 1,516 careers in the catalogue, which averages 43. Inside technology the mean is 62, across 125 careers.
What the rating is made of
Share of recorded tasks- Machine does it
- 34%Software can already complete this work end to end.
- Machine assists
- 34%A person still decides, but the drafting is done for them.
- Person does it
- 32%Judgement, relationships and accountability that do not transfer.
Named task by task
Already automated
- Automated vulnerability scanning
- Basic password cracking
- Pattern recognition in code
- Reporting template generation
Still human
- Designing complex attack chains
- Social engineering simulations
- Custom exploit development
- Interpreting business context of vulnerabilities
- Writing convincing phishing emails
Your skills, sorted
40 skills recordedWorth more with the tools
- Programming & Coding
- Machine Learning
- Computer Programming
- Data Analysis
Holding their value
- DevOps
- Cloud Computing
- Data Structures
- Algorithms
- Computer Networks
- Network Security
- Advanced Cryptography
- Cybersecurity Leadership
The six things it was scored on
0 to 100 each- People and inventionlowers exposure
- 55
- Digital surfaceraises exposure
- 50
- Routine intensityraises exposure
- 45
- Rule bound thinkingraises exposure
- 45
- Regulatory stakeslowers exposure
- 40
- Physical presencelowers exposure
- 35
Work that needs trust, persuasion or an original idea.
How much of the work already happens inside software.
How much of it repeats in the same shape each time.
Decisions that follow a procedure rather than a judgement.
Where a named person has to carry the liability.
Work that has to happen in a place, with hands.
Task counts
- Tasks recorded
- 9
- Automatable now
- 4
- Still human
- 5
- Displacing
- Routine, rule-based sub-tasks
- Augmenting
- AI copilots for drafting, analysis and search
- Creating
- New AI-adjacent specialist roles
Sources
Behind the rating- Frey & Osborne (2013), 'The Future of Employment', Oxford Martin
- McKinsey Global Institute, 'The Future of Work' (2017/2023)
- OpenAI/UPenn, 'GPTs are GPTs' (2023), occupational LLM exposure
- WEF, 'Future of Jobs Report' (2023)
Getting in
The routes into the role and what each one asks for.
What to study
8 courses- Certificate in Fashion Design and Textile TechnologyKsh 37,320a year
- Certificate in Desktop PublisherKsh 50,000a year
- Certificate in Mobile Applications and TechnologyKsh 56,420a year
- Certificate in Data Science and Artificial IntelligenceKsh 57,050a year
- Diploma in Photogrammetry and Remote SensingKsh 66,270a year
- Artisan in ICTKsh 67,189a year
- Certificate in Artificial Intelligence & CybersecurityKsh 67,189a year
- Certificate in Big DataKsh 67,189a year
How people get in
University Degree
4 yearsHigh cost
BSc in Cybersecurity or Computer Science from KU or Strathmore
Cybersecurity Bootcamp
6 monthsMedium cost
Intensive program at CyberShujaa or similar
Self-taught with Labs
12 monthsLow cost
Online labs like TryHackMe, Hack The Box, and earning CEH certification
Certifications
Offensive Security Certified Professional (OSCP)
Offensive SecurityKsh 194,8706 months
Certified Ethical Hacker (CEH)
EC-CouncilKsh 155,8703 months
CompTIA Security+
CompTIAKsh 26,0002 months
Tools of the trade
Burp Suite
securityRequiredPaid
Hydra
securityNice to haveFree
John the Ripper
securityNice to haveFree
Kali Linux
securityRequiredFree
Metasploit
securityRequiredFree
Nmap
securityRequiredFree
SQLMap
securityRequiredFree
Wireshark
securityRequiredFree
Nessus
securityRequiredPaid
Python
codeRequiredFree
Who hires
Interview preparation
3 questionsWalk me through your methodology for conducting a penetration test on a web application that handles mobile money transactions, focusing on OWASP Top 10 vulnerabilities relevant to financial services in Kenya.
TechnicalMid
Cover reconnaissance, scanning, exploitation of SQLi, XSS, IDOR, and session management flaws. Emphasize safe testing to avoid disrupting live transactions.
Tell me about a time you discovered a critical vulnerability but the development team was resistant to fixing it immediately. How did you persuade them?
BehavioralMid
Discuss risk communication, presenting business impact (e.g., potential loss of customer trust, regulatory fines under Kenya's Data Protection Act), and offering a phased remediation plan.
During a routine penetration test on a Kenyan government portal, you find a backdoor that appears to be left by a previous tester or insider. What do you do?
SituationalMid
Prioritize responsible disclosure, escalate to management, preserve evidence, and recommend immediate incident response. Be mindful of legal implications under Kenya's Computer Misuse and Cybercrimes Act.
Common misconceptions
You need to be a criminal to be a hacker
Ethical hacking is a legitimate, legal career focused on improving security through authorized testing.
Penetration testing is a one-time activity
Continuous testing is needed as systems evolve; many firms hire testers on retainer.
What happens next
How the role changes from here, and where it leads.
How the role changes
2024-2030Expect steady augmentation rather than wholesale replacement. 5 higher-value tasks remain human-led for years to come. Practitioners who embrace AI tools will out-earn those who don't.
- 2024already here
AI copilots augment daily work; productivity gains for adopters.
- 2027projected
Augmentation deepens; some routine sub-tasks automated.
- 2030projected
Practitioners who pair domain expertise with AI tools pull ahead.
The near term
Steady AI augmentation through 2028 — ~69% of practitioners will use AI copilots, ~31% of routine sub-tasks automated.
- AI copilots become standard (~69% adoption by 2028)
- ~31% of repetitive sub-tasks automated
- Role shifts toward review, judgement, and orchestration
- Digital fluency becomes a differentiator
- ChatGPT / Claude adoption reshapes daily workflows
- What to do
- Here, adopt the AI copilots for your field this year like ChatGPT / Claude and Microsoft Copilot, and reposition around what AI can't do — Digital fluency, Data literacy, and complex problem-solving. Net effect is productivity, not job loss, for those who adapt.
Where pay is heading
2024 to 2030Monthly pay in Kenyan shillings, rounded to the nearest thousand. These are projections, not observations.
Growth outlook
- Net demand change
- 5
- Over
- 2024-2030
- Drivers
- Digital transformation across sectors
- Headwinds
- Automation of routine work
Supply and demand
- Demand
- 75
- Supply pressure
- 23
- Balance
- High demand
What to learn
- Digital fluency
- Data literacy
- AI tooling basics
Tools worth knowing
ChatGPT / Claude
Priority: Essential
Drafting, research and analysis
Microsoft Copilot
Priority: Recommended
Office productivity and writing
Power BI / Excel Copilot
Priority: Recommended
Data analysis and reporting
Where people move next
5 recorded movesLine length under each name is the distance of the move: shorter means more of what you already do carries over. Marked lines are steps up rather than sideways.
- Data Science
Moderate35% skill overlapLateral
Strong analytical skills from penetration testing transfer to data science, but require learning statistics and machine learning. Bridge with dedicated data science courses.
- Software Engineering
Moderate55% skill overlapLateral
Penetration testers already have strong programming skills, especially in Python and scripting, making the transition to software engineering feasible with additional focus on development practices.
- Cloud Computing
Moderate40% skill overlapLateral
Network security expertise is valuable for cloud roles, but requires learning cloud platforms and services. Certifications can bridge the gap.
- Artificial Intelligence Research Scientist
Very challenging20% skill overlapPromotion
Transition to AI research scientist requires advanced degrees and deep expertise in machine learning, with little direct overlap from penetration testing. Long-term commitment to study is essential.
- Cloud Solutions Architect
Challenging30% skill overlapPromotion
Security architecture knowledge helps, but cloud architect roles require broad cloud platform expertise and design skills. Certifications and hands-on experience are key.
Related careers
Kenyan market notes
Penetration testers are in high demand in Kenyan banks, telecoms, and government due to rising cyber threats. Certifications like CEH and OSCP are highly valued. Freelancers often work on bug bounty programs.
Further reading
- Offensive Security OSCP
- PortSwigger Web Security Academy
- PentesterLab
- Hack The Box
- r/netsec Reddit
- Bugcrowd University
- Cybersecurity Ventures: 2026 Cybersecurity Talent Crunch Report
- Kenya National Bureau of Statistics: Digital Economy Report 2025
- World Economic Forum: Global Cybersecurity Outlook 2026
- ILO: Skills for a Digital Future - Cybersecurity in East Africa (2025)
- McKinsey & Company: The Future of Cybersecurity in Africa (2026)
This role is rated 78 out of 100 today. Save it and the app keeps that number, then tells you by how much it has moved when the record is next reviewed.