Nafasi ya kazi :- SSDLC Specialist, Cybersecurity at Inventions Technologies Company Limited September 2026

Inventions_424.png

Job Description

 

Job Description: SSDLC Specialist, Cybersecurity 

  1. Job Purpose

The SSDLC Specialist is a member of the Cybersecurity Department, reporting to the Manager Cyber Strategy and Secure by Design. This role defines, governs and improves the Secure Software Development Life Cycle while applying architecture, solution design and hands-on development expertise to ensure applications and digital services are secure by design, scalable, resilient and maintainable.

  1. Key Responsibilities

2.1 SSDLC Governance and Assurance

  • Define and maintain SSDLC policies, standards, templates, security controls, quality gates and evidence requirements.
  • Embed secure-by-design practices across Agile, DevOps and DevSecOps delivery, from requirements through retirement.
  • Perform lifecycle assurance, identify security exceptions, vulnerabilities and technical debt, and oversee remediation.
  • Maintain traceability and metrics covering security requirements, design decisions, testing, releases, defects and incidents.

2.2 Architecture and Solution Design

  • Translate business, functional, security and non-functional requirements into secure solution architectures and detailed technical designs.
  • Design scalable and resilient applications, APIs, integrations, data models, cloud components, security controls and observability capabilities.
  • Evaluate technologies and patterns; produce architecture diagrams, specifications and decision records.
  • Conduct threat modelling, architecture and design reviews, proofs of concept and technical risk assessments.

2.3 Secure Software Engineering

  • Develop, integrate and refactor production-quality software, prototypes, reference implementations and reusable components.
  • Apply secure coding, version control, peer review, automated testing and software supply-chain controls.
  • Review code, troubleshoot complex defects and vulnerabilities, and guide root-cause analysis and remediation.
  • Improve CI/CD pipelines, security scanning, release controls, performance, production readiness and rollback capability.

2.4 Technical Leadership and Collaboration

  • Partner with product, architecture, engineering, testing, operations, cybersecurity and supplier teams.
  • Coach delivery teams on architecture, design, secure coding, testing and SSDLC requirements.
  • Support technical planning, supplier evaluation, solution acceptance and communities of practice.
  1. Qualifications and Experience
  • Bachelor’s degree in computer science, Software Engineering, Information Technology, or related discipline.
  • At least two (2) years of software engineering experience covering architecture, detailed design, and hands-on development.
  • Experience delivering secure systems through Agile, DevOps and DevSecOps practices.
  • Practical experience with APIs, integrations, data models, cloud platforms, source control, automated testing, CI/CD, containers and observability.
  • Relevant certification in architecture, cloud, secure software development, Agile, DevOps or DevSecOps is advantageous.
  1. Required Skills and Competencies
  • Architecture and design: distributed and cloud-native systems, microservices, APIs, integrations, data modelling, design patterns, performance and resilience.
  • Development: strong proficiency in at least one enterprise programming language and ability to review code across technology stacks.
  • Secure engineering: threat modelling, secure coding, identity and access management, API security, secrets protection, vulnerability management and supply chain security.
  • Tooling and operations: Git, CI/CD, automated testing and scanning, artefact management, containers, monitoring, tracing and release management.
  • Core competencies: systems thinking, analytical problem-solving, technical judgement, clear communication, collaboration, coaching, accountability and attention to quality.
  1. Key Performance Measures
  • Compliance with SSDLC, cybersecurity and architecture quality gates.
  • Reduction in escaped defects, repeat vulnerabilities, security-related incidents and overdue remediation actions.
  • Timeliness and quality of architecture, design and code reviews.
  • Improvement in automated test, security scanning and deployment coverage.
  • Adoption of approved secure patterns, reusable components and engineering standards.

 

How to Apply:
Job type Full-time Job, To submit your application, please follow the link provided below.
CLICK HERE TO APPLY