
Find Your Next Role Here
Join the Savannah team
Savannah Informatics - Information Security Analyst
Savannah Informatics -Information Security Analyst.
Nairobi, Kenya - Full Time.
Position: Junior-Mid Level Hire
Gross Salary: KES 80,000-100,000
About Us
Savannah Informatics is a Kenyan e-health software company founded by clinicians and finance specialists to deliver interoperable, connected solutions for healthcare facilities, organizations, and regions.
Our vision is to enable a better healthcare future for Kenya through the pioneering use of information technology and knowledge creation.
We are a company with great ideas and employees. Working across various customer sites, our work epitomizes the future we foresee in the East African health sector: efficiency, higher value, better quality, and outcomes for patients and other consumers of health. Our customers partner with Savannah in delivering challenging projects, thus believing in the capabilities of our employees.
The Savannah team is made up of medical doctors, project managers, and software engineers who have a common aspiration of transforming the region’s health care.
If you share our motivation, vision, and aspirations, check out the careers page of our corporate website.
Job Description
As an Information Security Analyst, you will be responsible for safeguarding Savannah Informatics' digital assets and ensuring the confidentiality, integrity, and availability of information across the organization.
You will play a key role in identifying security threats, developing strategies to mitigate risks, and working closely with cross-functional teams to ensure our systems meet industry standards and regulatory requirements for healthcare information security. If you’re detail-oriented, have a passion for cybersecurity, and are eager to make an impact on the healthcare technology landscape in East Africa, we’d like to hear from you!
Responsibilities
The successful candidate will be responsible for:
Security operations and monitoring
-
Run and tune our monitoring and log aggregation tooling so that security events get picked up and triaged quickly.
-
Document and maintain detection rules and alerts across infrastructure, applications, and identity systems.
-
Investigate security incidents. Contain them, work out the root cause, drive the fixes, and write up what happened so we learn from it.
-
Keep the incident response runbooks current and exercise them, including the breach notification path to the Office of the Data Protection Commissioner.
Vulnerability and threat management
-
Run regular vulnerability assessments across systems, applications and networks, and chase the findings to closure with the teams that own them.
-
Coordinate third-party penetration tests and VAPT engagements, then manage the remediation that follows.
-
Stay on top of patching and dependency risk with platform engineering and the development teams.
Cloud, platform and application security
-
Review and harden our cloud footprint across diverse cloud service providers covering identity and access management, network segmentation, and posture management.
-
Assess container and Kubernetes security, including image scanning, admission control, and runtime configuration.
-
Build automated security checks into the delivery pipeline, covering application and dependency scanning, supply-chain risk, and software bill of materials.
-
Review how we manage secrets, and make sure credentials and keys are handled safely.
-
Support secure identity and access design, covering authentication, authorisation, and regular review of privileged and emergency access.
-
Review the security of our APIs and the interfaces we expose to partners and integrating systems.
Governance, risk and compliance
-
Document and maintain security policies, standards and procedures, and keep the control set current.
-
Prepare for internal and external audits. Assemble the evidence packs, write the control narratives, and answer what auditors and regulators come back with.
-
Own the risk register. Assess risks, recommend mitigations, and track treatment plans to completion.
-
Apply ISO/IEC 27001, HIPAA, Kenya DPA 2019, and GDPR where they are relevant, as supporting context to the Kenyan baseline.
Third-party and partner risk management
-
Run security due diligence on vendors, sub-processors and integration partners.
-
Review data processing and data sharing agreements for security and data protection adequacy, working with the Data Protection Officer and legal counsel.
-
Maintain the register of third parties and the assurance evidence we hold for each one.
Awareness and culture
-
Run security training for staff, covering phishing, credential hygiene, safe handling of patient data, and secure development practices.
-
Advise teams on using AI tooling safely, including how model inputs and outputs are handled, prompt injection risk, and unsanctioned use.
-
Follow how threats and practices are changing, and tell us what we should do about it.
Qualifications
-
Bachelor's degree in Computer Science, Information Technology, or a related field.
-
Exceptional academic track record from both high school and university
-
Proven experience in information security, cybersecurity, or a related field.
-
Knowledge of security standards and frameworks such as ISO 27001.
-
Familiarity with security tools and technologies, including firewalls, intrusion detection/prevention systems (IDPS), encryption protocols, and endpoint protection.
-
Experience with vulnerability management tools and SIEM solutions .
-
Strong understanding of networking protocols, operating systems, and database security principles.
-
Ability to assess risks, identify security vulnerabilities, and recommend mitigation strategies.
-
Excellent problem-solving skills with a strong attention to detail.
-
Ability to work independently and collaboratively with cross-functional teams.
-
Certifications related to the role are a plus but not required.
-
Experience in healthcare or e-Health security is a plus.
Why Join Us?
We embrace an informal but fast-paced work environment that values openness, rapid feedback, and the contributions of every team member, regardless of rank.
At Savannah Informatics, you will have the opportunity to work on challenging technology projects, collaborate with a multidisciplinary team, and contribute to solutions that are transforming healthcare across the region.
Benefits
-
Great mission and company culture
-
Opportunity to work on impactful healthcare technology
-
Learning and growth opportunities
-
Market-competitive salary
-
Health and medical benefits package
To Apply: Please submit your resume via our careers page on our website
Savannah Informatics does not discriminate on the basis of race, age, color, religion, national origin or ancestry, sex, gender, disability, veteran status, genetic information, sexual orientation, gender identity, or expression. Savannah is committed to providing a safe and productive learning and living community. To achieve that goal, we may conduct background investigations for all final candidates being considered for employment. Background checks may include but are not limited to, criminal history, national sex offender search, and motor vehicle history.
We thank all applicants for their interest, however, only those candidates selected for interviews will be contacted.
