National Bank of Kenya logo

Application Security Manager

National Bank of Kenya

On-site
Rwanda
Full-time
Manager
5+ yrs
Salary not listedPosted 1w ago

Real job — pulled straight from National Bank of Kenya’s careers page · Verified August 2, 2026 · No reposts.

Job description

National Bank of Kenya is hiring a Application Security Manager — a full-time, based in Rwanda role. Apply directly on National Bank of Kenya's careers page below.

Technology Department,Rwanda.Application Security Manager

Location: Rwanda

KEY RESPONSIBILITIES

  • Lead and manage the Application Security team, ensuring effective delivery of security objectives and initiatives. 

  • Oversee and conduct periodic user access recertification across all bank applications, with focus on MCAs, to enforce least privilege and access governance. 

  • Direct and conduct the execution of Vulnerability Assessments and Penetration Testing (VAPT) for all applications. 

  • Provide security assurance for technology projects, ensuring compliance with security requirements prior to CAB approval. 

  • Define and enforce application security standards, policies, and secure SDLC practices. 

  • Identify, assess, and mitigate application-level risks and vulnerabilities. 

  • Provide ongoing security assurance and reporting on the Bank’s application landscape. 

  • Secure Integration Management: Oversee and ensure secure integration of internal systems such as microservices, API and other third-party services by enforcing security controls, conducting risk assessments, and minimizing potential attack vectors across all interfaces

  • Advise stakeholders on regulatory and industry frameworks (e.g., OWASP Top 10, NIST, ISO 27001/ISMS, PCI DSS and GDPR). 

 

DAILY RESPONSIBILITIES: 

  1. Making regular reports to line manager to issue identified or raised by internal audit, risk and regulatory pertaining to application security unit to line supervisors with clear strategic plan to address them 

    1. Coordinated and Conduct user access reviews and recertification activities

    2. Leading the discovery of vulnerabilities and risks in application, software systems and databases and cloud infrastructure with ongoing vulnerability scans, penetration testing and identifying OWASP top 10 threats targeting both bank internal applications and internet facing environments such as digital channels and others on regular basis through intel monitoring and ensuring software applications are updated.

    3. Review and track application security findings, remediation status, and risk exposure 

    4. Follow up and enforce the correction of Identified risks via RCSA (Risk Control Self-Assessment)

Support business owners and project team to ensure information security requirements are captured and embedded in the overall project life cycle, ranging from internal information policies and standards, compliance with regulatory and relevant laws.

MINIMUM POSITION QUALIFICATION REQUIREMENTS

 

Academic & Professional

 

Particulars

Detail

Specific Field or Qualification

Need Type[1]

Education 

Bachelor’s Degree

BSc. Information Technology / Computer Science / Telecommunications / Engineering (Electrical, Electronic) or related field

RQ

Professional Qualifications

Security certification such as: OSWE (Offensive Security Web Expert), OSCP (Offensive Security Certified Professional

CISM, ISMS lead Implementer or Lead Audit, 

GIAC Certifications, CEH

At least one RQ

 

Master’s Degree

MBA/MSc

AA

 

Experience

 

 

Total Minimum No of Years’ Experience Required

 

 

5

 

 

Detail

Minimum No of Years

Need Type[1]

Experience in Application Security 

5

ES

Communication and Network 

Security

3

ES

Experience in large busy technology environment 

3

ES

Experience in System, Network, or Database Security

3

ES

Security Program Management 

and Operations

3

ES

Identity and Access Management

5

ES

Software Development, Security 

Assessment and Testing

5

ES

Information Security Incident Management

3

ES


 

 

JOB PURPOSE The Application Security Manager is responsible for leading the Bank’s application security function, and a team of Application security lead, Analyst and engineers ensuring that all business applications, particularly Mission Critical Applications (MCAs) are secure, compliant, and aligned with regulatory and industry standards. The role provides oversight across application security assessments, Secure-Software Development Lifecycle (Secure-SDLC), or Dev-SecOps Identity Lifecyle management, access governance, and secure project delivery, while driving continuous improvement in security posture of the Bank and its customer information. Secondly the Role will give oversight support and guidance to the team of Cybersecurity lead and Cybersecurity Analyst and engineers.

Get Application Security Manager jobs like this

New roles from thousands of companies land hourly, straight from their careers pages. Get the freshest matches by email so you never miss one.

Email me new jobs
Accenture logo

Cybersecurity Manager

$80k–$294kChicago, IL
✓ From careers page· 1h ago
UV Cyber logo

Senior Security Engineer

National Harbor, MD
✓ From careers page· 2h ago
PwC logo

PwC

New

Senior Software Developer

Warszawa
✓ From careers page· 3h ago
JLL logo

JLL

New

BMS & OT Systems Engineer

London, GBR
✓ From careers page· 3h ago

Frequently asked questions

What skills are required for Application Security Manager at National Bank of Kenya?

The required skills for Application Security Manager at National Bank of Kenya include: NIST, ISO 27001, PCI DSS, GDPR, IAM, CISM.

What is the seniority level for Application Security Manager at National Bank of Kenya?

Application Security Manager at National Bank of Kenya is a Manager level position.

How do I apply for Application Security Manager at National Bank of Kenya?

You can view the full description and apply for Application Security Manager at National Bank of Kenya on EchoJobs: https://echojobs.io/job/national-bank-of-kenya-technology-department-rwanda-application-security-manager-38ond.