Security Engineer — AfriVote Platform Integrity
Remote — AfricaPosted 34 days ago
KES 170,000 - 260,000
per monthly
account_treeThis role is part of AfriVote — Digital Civic Participation Platform
About the role
AfriVote is civic infrastructure and its security posture must be beyond reproach. Any successful attack — vote manipulation, data breach of citizen identity, service disruption during a consultation — would be a democratic incident with real political consequences. You will own the security of the platform from architecture through to independent audit. Your responsibilities: threat modelling for every component of the platform using STRIDE methodology, with documented threat-to-control mapping; application security review of all code before release, with particular focus on the cryptographic components; penetration testing of the full application stack using OWASP testing methodology; DDoS resilience design and testing, since consultation launch days will attract high traffic and potentially adversarial load; the secure development lifecycle policies that the engineering team will follow; coordination with external security auditors for the independent audit that will be required before any government contract; and incident response planning including tabletop exercises with the core team. You will also lead the bug bounty programme, triaging and validating reports, coordinating fixes, and managing researcher rewards. You will produce a public security white paper that explains AfriVote's security architecture to technically literate scrutinisers — academics, civil society, and journalists. Strong candidates have experience securing voting systems, electoral technology, or other high-stakes public infrastructure. OSCP, CEH, or equivalent certifications are strongly preferred. Experience working with government clients on security compliance is a significant advantage.