HF

Careers

HF Group
📍 KenyaCDI🗓️ about 1 month ago

Job Description

Kenya
CDI

Your safety comes first — read before you go. Taf4All only lists job offers published by third parties. We are not the employer, we do not conduct these recruitments, and we cannot guarantee what happens once you make contact — you deal directly with the person or company behind the offer, at your own risk.

Housing Finance Company of Kenya, the premier mortgage finance institution in Kenya licensed under the Banking Act, is recruiting for several positions. Below are the details for each role.

Insurance Premium Finance Manager

Job Type: Full Time

Qualification: BA/BSc/HND

Location: Not specified

Job Field: Sales and Business Development

About the Role: The role holder will be responsible for driving IPF business growth through direct business development efforts as well as nurturing strong business relationships with existing and potential customers, key insurance intermediaries and branch business teams to ensure quick business conversion and turnaround time. The role holder will also be responsible for compliance with the laid-out Product procedures to safeguard bank’s exposure and ensure a quality IPF loan book.

Key Accountabilities:

Oversight of end-to-end IPF business transactions and compliance with product lending parameters.

Business development through effective linkages with customers, underwriters, Insurance intermediaries and branch business teams to ensure quick conversion and sustained business growth.

Preliminary evaluation on potential customers under IPF to ensure repayment ability is demonstrated prior to disbursement.

Prompt customer / intermediary issue resolution and relationship management for all insurance stakeholders.

Firstline follow up on IPF loan repayments and eventual refund process from the Insurance Company.

Organizing and training various stakeholders e.g. branches and insurance intermediaries to ensure they source quality business as per set standards.

Ensuring key Insurance Companies and intermediaries are reviewed and onboarded and that they have adequate access to the bank’s IPF application and other critical documentation.

Act as coordinator for gathering market intelligence as pertains to IPF portfolio performance in the industry alongside establishment of innovative ways to counter the stiff competition.

**

**

Bachelor’s degree in a Business-related field.

At least 4 years’ relevant experience in IPF business development role.

Competencies:

Good knowledge of the Insurance Act and other developments in banking and insurance fields in general.

Good knowledge of requisite documentation under IPF transactions.

Good knowledge of CBK’s prudential guidelines as pertains to lending.

**

**

Presentation skills

Business minded.

Articulate.

Tactful.

Quality conscious

Attentive to detail

Ability to effectively manage customer relationships

Manager – IT Security

Job Type: Full Time

Qualification: BA/BSc/HND, Professional Certificate

Experience: 5 years

Location: Nairobi

Job Field: ICT / Computer

About the Role: The Manager – IT Security supports the Head of ICT Security / CISO in strengthening the Group’s information security posture by coordinating IT security governance, cyber risk management, SOC operations oversight, security assurance, audit remediation, regulatory compliance and proactive cyber resilience across the Group. The role ensures that security policies, standards, controls, monitoring processes and assurance activities are embedded into technology operations, digital channels, projects, third-party engagements, and business processes. The role holder provides security support to the substantive Data Protection Officer by ensuring that technical and organisational security controls for personal data are defined, implemented, tested, monitored, and evidenced. This role supports privacy governance through technology control implementation, security assurance, access control, monitoring, incident coordination, third-party reviews, and remediation tracking.

Key Accountabilities:

Data Protection and Privacy Security Support - Support the substantive Data Protection Officer by providing information security input into privacy governance, DPIAs, data classification, access controls, encryption, logging and monitoring, data loss prevention, third-party risk reviews, breach investigation, audit evidence and remediation tracking.

IT Security Governance and Strategy Execution - Support the CISO in implementing the Group information security strategy, governance framework, policies, standards, procedures, operating model and control assurance programme.

Regulatory Compliance and Security Reporting - Coordinate compliance reviews, evidence packs, management attestations, regulatory responses, control self-assessments and reporting to ICT, Risk, Compliance, Audit and management governance forums.

Cyber Risk, Audit and Remediation Management - Coordinate identification, assessment, monitoring, reporting and remediation of ICT and cyber risks across the Group, including audit and regulatory findings to closure.

SOC Operations Oversight and Incident Coordination - Provide management oversight of security monitoring, incident triage, escalation, response coordination, threat intelligence, SOC use cases, alert handling, incident reporting and post-incident remediation.

ICT Resilience, Disaster Recovery and Cyber Recovery Support - Coordinate security input into ICT business continuity, disaster recovery, cyber recovery planning, backup assurance, recovery testing and remediation of resilience gaps.

Identity and Access Governance - Maintain access governance covering privileged access, periodic user access reviews, role-based access control, joiner-mover-leaver controls, access certification, segregation of duties, exceptions, remediation tracking and evidence management.

Security Assurance for Projects, Platforms and Third Parties - Provide security assurance over systems, infrastructure, digital channels, cloud services, APIs, integrations, third parties and technology changes.

Qualifications:

Bachelor's degree in information security, Computer Science, Information Systems, Information Technology, Cybersecurity, Risk Management, or related fields.

Relevant certifications such as CISM, CISSP, CRISC, CISA, ISO 27001 Lead Implementer/Lead Auditor, CompTIA Security+, CBCP or equivalent will be an added advantage.

At least 5 years’ experience in information security, IT governance, cyber risk, security operations, security assurance, or technology risk management.

Understanding of implementation of technical security controls, identity and access management and designing security solutions in a dynamic environment

At least 2 years in a supervisory or managerial role within a highly regulated or digitized environment.

Demonstrable experience in security governance, SOC oversight, audit remediation, regulatory compliance, access governance, third-party assurance, project security assurance, incident coordination, cyber resilience and executive reporting.

Understanding of IT Audit processes, technical security testing (Red Team, Blue Team, Penetration Testing) and Cyber Incident Response including data protection guidelines.

IT Governance and Controls Manager

Job Type: Full Time

Qualification: BA/BSc/HND, Professional Certificate

Experience: 4 - 5 years

Location: Nairobi

Job Field: ICT / Computer

About the Role: The role holder is responsible for the establishment, implementation, and continuous improvement of the Bank’s IT policy framework, internal control environment, regulatory compliance, technology risk management processes, and overall governance framework. The role ensures that technology operations align with business objectives, regulatory requirements, industry best practices, and the organization's risk appetite.

Key Accountabilities:

Develop, implement, and maintain the IT Governance, Risk, and Controls framework to ensure alignment with business objectives and regulatory requirements.

Establish and oversee IT governance structures, policies, standards, and procedures, ensuring organization-wide compliance.

Design, monitor, and continuously improve the IT internal control environment through control assessments and governance reviews.

Ensure compliance with applicable regulatory, legal, and industry requirements, coordinating regulatory engagements and remediation of findings.

Lead technology risk management activities, including risk assessments, maintenance of the Technology Risk Register, monitoring of Key Risk Indicators (KRIs), and reporting to governance forums.

Coordinate internal, external, and regulatory audits, ensuring timely resolution of audit findings and effective stakeholder reporting.

Develop governance dashboards, KPIs, KRIs, compliance scorecards, and management reports for executive leadership and the Board.

Oversee governance of third-party technology risks, outsourcing, business continuity, and disaster recovery to ensure operational resilience.

Drive continuous improvement of IT governance maturity through benchmarking, process automation, and adoption of industry best practices.

Foster a culture of governance, accountability, compliance, and continuous improvement across the Technology function.

Perform any other duties as assigned by the immediate supervisor in support of departmental and organizational objectives.

Qualifications:

Bachelor's degree in information technology, Computer Science, Information Systems, Cybersecurity, or related field.

Preferred certifications include: CISA, CISM, CRISC and CISSP

4 - 5 years in IT governance, technology risk, IT audit, compliance, or information security.

Experience within a regulated industry, preferably banking or financial services.

Experience engaging with regulators, auditors, and executive management.

Systems Administrator

Job Type: Full Time

Qualification: BA/BSc/HND, Professional Certificate

Experience: 2 - 3 years

Location: Nairobi

Job Field: ICT / Computer

About the Role: The role holder is responsible for administering, maintaining, and optimizing the organization's on-premises and cloud-based IT infrastructure to ensure the availability, security, performance, and reliability of business-critical systems and services. The role provides a secure and standardized technology environment that supports business operations, development, testing, and production workloads, while serving as a key link between infrastructure and development teams to deliver sustainable, scalable, and secure technology solutions aligned with organizational objectives.

Key Accountabilities:

Monitor, administer, and maintain on-premises and cloud infrastructure, including virtual machines, databases, storage, virtual machine scale sets, VPN connections, and automated monitoring and alerting systems, to ensure optimal performance and availability.

Manage the day-to-day security of infrastructure by administering Just-in-Time (JIT) access, communication port restrictions, and other infrastructure security controls in accordance with organizational security policies.

Log, manage, and resolve cloud infrastructure incidents and service requests, ensuring timely restoration of services in line with agreed Service Level Agreements (SLAs).

Monitor backup operations and perform data restoration activities for cloud and on-premises servers to ensure data integrity, availability, and business continuity.

Configure, administer, and maintain Microsoft Azure networking components, including Virtual Networks (VNets), Local Network Gateways, VPN Gateways, VPN connections, and related network services.

Manage Azure Virtual Machine Scale Sets, including image creation, upgrades, deployments, and lifecycle management.

Plan, coordinate, and implement infrastructure-related changes, upgrades, and deployments in compliance with the Bank's Change Management procedures.

Administer Azure subscriptions, Azure Active Directory (Microsoft Entra ID), and role-based access control (RBAC), ensuring appropriate user access and security governance.

Monitor and optimize Azure resource utilization, cloud costs, and billing, providing recommendations to improve cost efficiency.

Perform capacity planning for on-premises, private cloud, and public cloud infrastructure to support current and future business requirements.

Prepare and submit periodic infrastructure reports to management on system performance, resource utilization, cloud consumption, costs, billing, and other operational metrics.

Act as the primary liaison between internal stakeholders and Level 2/Level 3 infrastructure support teams and technology vendors to facilitate timely issue resolution.

Develop, maintain, and continuously update infrastructure documentation, including operational procedures, system configurations, standards, and technical processes.

Configure, administer, troubleshoot, and support Microsoft Windows Server environments (2012, 2016, 2019, and later versions), including Active Directory, DNS, DHCP, IIS, FTP, Failover Clustering, and other core infrastructure services.

Continuously monitor server health, performance, and availability, proactively identifying and resolving issues to ensure optimal system performance.

Monitor and support hybrid email infrastructure to ensure service availability, reliability, and compliance with established SLAs.

Maintain accurate documentation of server infrastructure, configurations, installed services, and assigned roles to support operational continuity and audit requirements.

Manage the patching and update lifecycle for Windows Server and enterprise Windows environments to maintain security, compliance, and system stability.

Perform any other duties as assigned by the immediate supervisor in support of departmental and organizational objectives.

Qualifications:

Degree holder in Information Technology from a recognized University.

Experience with Azure, Amazon Web Services, Google Cloud Platform.

Certifications in various system administration courses such as MCSE, Azure administration and architecture, ITIL Foundation, Linux, Solaris, Windows server etc.

2-3 years working experience in infrastructure administration with bias in cloud.

Experience with automation, Git and continuous delivery.

Practice in designing and implementing business continuity / disaster recovery and high availability plans.

Good troubleshooting aptitude.

Security Testing & Assurance Engineer

Job Type: Full Time

Qualification: BA/BSc/HND, Professional Certificate

Experience: 3 - 5 years

Location: Nairobi

Job Field: ICT / Computer

About the Role: The Security Testing & Assurance Engineer is responsible for independently assessing the effectiveness of the organization’s cybersecurity controls, validating remediation activities, and ensuring continuous compliance with security baselines, regulatory standards, and internal policies. The role conducts technical assurance reviews, verifies CBK-required controls, supports secure system development lifecycle processes, and prepares assurance dashboards and reports for senior management and regulators. This position holder works closely with IT Security Operations, Engineering, and Risk teams while maintaining functional independence to ensure unbiased assurance outcomes.

Key Accountabilities:

Security Assurance Reviews and Technical Assessments - Conduct proactive internal and externally facing service based security assurance reviews across systems, infrastructure, networks and applications; perform technical assessments, configuration checks, access reviews and security control validations; identify weaknesses, document findings and recommend remediation actions; validate that systems meet internal information security policy requirements and baseline standards; research and develop automated testing and validation tools to enhance security testing and reporting across the Group; and support Group projects with security testing and assurance reviews to ensure new services are fit for purpose and aligned to documented policy and security best practice.

Vulnerability and Audit Findings Validation - Validate closure of vulnerabilities identified through internal scans, penetration tests, red-team exercises and external assessments; track timely remediation of findings from Internal Audit, External Audit, regulators and risk assessments; and conduct independent technical validation to confirm remediation is effective and sustainable.

Configuration Compliance and Baseline Enforcement - Perform configuration compliance checks against security baselines, hardening standards and regulatory requirements; monitor and report on compliance posture; and work with IT teams to remediate non-compliant configurations.

Secure Development Lifecycle Support - Support secure coding practices, code reviews, security testing in CI/CD pipelines, and provide security requirements for new projects.

Assurance Reporting and Dashboarding - Prepare assurance dashboards, reports and metrics for senior management, risk committees and regulators; track assurance activities and remediation progress.

Continuous Improvement - Research emerging threats, vulnerabilities and assurance methodologies; recommend improvements to security controls and assurance processes.

Qualifications:

Bachelor's degree in Computer Science, Information Security, Cybersecurity, Information Technology, or related field.

Professional certifications such as CEH, OSCP, GPEN, GWAPT, CISSP, CISA, CRISC, or equivalent are preferred.

3-5 years of experience in security testing, vulnerability management, security assurance, or related roles.

Hands-on experience with security testing tools (e.g., Burp Suite, Nessus, Metasploit, Nmap, etc.).

Knowledge of security frameworks (NIST, ISO 27001, PCI DSS, etc.) and regulatory requirements (CBK guidelines).

Experience in cloud security testing (Azure, AWS, GCP) is an advantage.

Strong analytical, problem-solving, and communication skills.

Quality Assurance Engineer

Job Type: Full Time

Qualification: BA/BSc/HND, Professional Certificate

Experience: 3 - 5 years

Location: Nairobi

Job Field: ICT / Computer

About the Role: The Quality Assurance Engineer is responsible for ensuring the quality and reliability of software applications through comprehensive testing strategies, test planning, test execution, and defect management. The role works closely with development teams, business analysts, and project stakeholders to ensure that deliverables meet business requirements and quality standards.

Key Accountabilities:

Develop and maintain test plans, test cases, and test scripts for functional, regression, integration, performance, and user acceptance testing.

Execute manual and automated tests to identify defects, ensure software quality, and validate that applications meet specified requirements.

Collaborate with development teams to understand application architecture, design, and implementation to create effective test strategies.

Report, track, and manage defects using defect tracking tools, and work with development teams to ensure timely resolution.

Participate in requirements review, design review, and code review sessions to provide quality input early in the development lifecycle.

Perform root cause analysis of defects and recommend process improvements to prevent recurrence.

Develop and maintain test automation frameworks and scripts to improve testing efficiency and coverage.

Prepare and present test status reports, metrics, and quality dashboards to project stakeholders and management.

Ensure compliance with software development lifecycle (SDLC) and quality assurance best practices.

Mentor junior QA team members and contribute to continuous improvement of QA processes.

Qualifications:

Bachelor's degree in Computer Science, Information Technology, Software Engineering, or related field.

Professional certifications such as ISTQB, CSTE, or equivalent are preferred.

3-5 years of experience in software quality assurance, testing, or related roles.

Hands-on experience with test automation tools (e.g., Selenium, Appium, JUnit, TestNG, etc.).

Experience with API testing tools (e.g., Postman, SoapUI, RestAssured).

Knowledge of performance testing tools (e.g., JMeter, LoadRunner) is an advantage.

Familiarity with Agile/Scrum methodologies.

Strong analytical, problem-solving, and communication skills.

Solution Architect – Applications & Integration - Technology

Job Type: Full Time

Qualification: BA/BSc/HND, Professional Certificate

Experience: 5 - 7 years

Location: Nairobi

Job Field: ICT / Computer

About the Role: The Solution Architect – Applications & Integration is responsible for designing, architecting, and overseeing the implementation of application solutions and integration strategies that align with the organization's business goals and technology roadmap. The role ensures that applications are scalable, secure, resilient, and cost-effective, while enabling seamless integration across systems, platforms, and channels.

Key Accountabilities:

Define and maintain the application architecture vision, principles, standards, and roadmap in alignment with enterprise architecture.

Design end-to-end solution architectures for new applications, major enhancements, and integration projects, ensuring alignment with business requirements and non-functional requirements.

Evaluate and select appropriate technologies, platforms, and frameworks for application development and integration.

Lead the design of integration solutions, including APIs, microservices, event-driven architectures, and middleware, to enable seamless data flow and process orchestration.

Collaborate with business stakeholders, project managers, developers, and infrastructure teams to ensure solutions are feasible, scalable, and aligned with organizational goals.

Conduct architecture reviews, provide technical guidance, and ensure adherence to architectural standards and best practices.

Identify and mitigate technical risks, performance bottlenecks, and security vulnerabilities in application and integration designs.

Develop and maintain architecture documentation, including solution architecture documents, design patterns, and reference architectures.

Stay current with emerging technologies, industry trends, and best practices in application architecture and integration.

Mentor development teams and promote a culture of technical excellence and continuous improvement.

Qualifications:

Bachelor's degree in Computer Science, Information Technology, Software Engineering, or related field.

Professional certifications such as TOGAF, AWS Certified Solutions Architect, Microsoft Certified: Azure Solutions Architect, or equivalent are preferred.

5-7 years of experience in software development, application architecture, or integration architecture.

Strong experience with integration technologies (REST, SOAP, ESB, message queues, API gateways).

Experience with cloud platforms (Azure, AWS, GCP) and cloud-native architectures.

Knowledge of enterprise integration patterns, microservices architecture, and containerization (Docker, Kubernetes).

Experience in the banking or financial services industry is an advantage.

Excellent communication, presentation, and stakeholder management skills.

Method of Application:

Never pay for any notarisation, certificate or assessment as part of any recruitment process. When in doubt,

[Click the Apply button below to apply, and Create my CV to build a CV tailored to this offer, professionally]

Ready to apply?

Does my CV fit this offer? Free diagnosis

Get seen by recruiters

Publish your CV on the Candidates page — the place recruiters browse directly to find profiles like yours.

See the Candidates page

You are recruiting?

Find candidates on TAF4ALL

🚀 Boost your application

Stand out with a professional CV and a personalized cover letter generated by AI in 3 minutes.

🇨🇦

Canadian employers are also recruiting in Africa

Real offers from Canadian employers who are explicitly looking for candidates outside Canada. No agency, no fees — you apply yourself.

Expert Application Advice

When tailoring your CV for HF Group, don’t just list your duties—show how you met a challenge like les compétences demandées dans l'annonce. Use bullet points with numbers or results. This proves you’re ready for the role and stand out to recruiters.

Positioning — Your cover letter must answer one question: why YOU for THIS specific role right NOW? Avoid generic templates — one sentence on what you specifically bring beats three generic paragraphs.

Targeted application — Align your CV to this offer's exact keywords and back every claimed skill with a concrete example. A cover letter showing you understand the specific challenges of this role consistently makes the difference.

🎯 Make your application ATS-ready

ATS (Applicant Tracking Systems) are the software recruiters use to automatically filter CVs before any human reads them. Our CV builder is specifically designed to pass these filters — and it takes under 3 minutes.

Create my ATS CV →
Career advice powered by Taf4All

Your safety comes first — read before you go

Taf4All only lists job offers published by third parties. We are not the employer, we do not conduct these recruitments, and we cannot guarantee what happens once you make contact — you deal directly with the person or company behind the offer, at your own risk.

  • Never pay any amount of money — for a file, a training, a uniform, or an interview. A real employer never asks the candidate to pay.
  • Never send a photo of your ID card, passport, or banking details before you have physically verified the employer exists.
  • Always meet in a public place, during the day — never an isolated address, a private home, or a location you cannot verify in advance.
  • Tell a relative or friend exactly where you are going, with whom, and at what time — and share your live location if possible.
  • Search the company name online before going: a real business has a trace (website, reviews, other employees, an official address).
  • A salary that is far above the market rate for the position and the city is a red flag — be extra cautious.

You might also be interested in

NA

Careers

NOUVEAU

Le National Treasury, institution clé du Kenya, recrute pour plusieurs postes de direction au sein de sa filiale d investissement (NIF). Ces opportunités sont à pourvoir à Nairobi. Contexte : Le National Treasury tire son mandat de la Constitution de 2010, de la loi sur la gestion publique de 2012 et de l ordonnance ex

CDIabout 7 hours ago
KP

Careers

NOUVEAU
KPMG·Kenya

KPMG is a professional service company and one of the Big Four auditors, along with Deloitte, EY and PwC. Seated in Amsterdam, the Netherlands, KPMG employs 174,000 people and has three lines of services: audit, tax, and advisory. We are currently looking for a Credit Risk Advisory professional to take up a leadership

CDDabout 7 hours ago
CR

Careers

NOUVEAU

Crowne Plaza Nairobi Airport Hotel recrute pour deux postes clés : Electricien et Kitchen Steward. Rejoignez un établissement de référence, situé à seulement 3 minutes du terminal de l aéroport, idéal pour les voyageurs d affaires, les équipages aériens et les vacanciers. Electricien Poste à temps plein, qualification

CDIabout 7 hours ago
SU

Careers

NOUVEAU

Summit Recruitment & Search, established in 2009, is a leading recruitment firm addressing the recruitment, mass recruitment, executive search, outsourcing and training needs of companies based in Kenya or wanting to enter the Kenyan, East African, South African and African market. We have a proven track record in our

Freelanceabout 7 hours ago