Who we are
There is a business owner in Lagos who woke up this morning and still hasn't received a payment she sent last week. She's not waiting because the money isn't there. She's waiting because the infrastructure that moves it was never built with her in mind.
Juicyway exists to fix that. We are building the financial rails that connect African businesses to the world — cross-border payments, FX conversions, and global liquidity — fast, transparent, and built for the people who have been underserved by every system that came before us. Our mission isn't a slide. It's the reason we come to work: every African should be able to participate in the global economy on equal footing.
We're not improving what exists. We're replacing it.
And the infrastructure doing the replacing moves real money, in real time, across multiple countries. Which means the security of what we build is not a compliance checkbox. It is the foundation on which the whole mission stands or falls.
The team you're joining
The Security and Infrastructure team protects Juicyway's technology, people, and products. We are technical in what we build but operational in how we work, and we are committed to supporting every product and every bold bet Juicyway makes. Our tenets are simple: prioritise for impact, prepare the foundations for transformative financial technology, and build a security culture that runs deeper than policy.
Tasks
The problem you'll be solving
Financial infrastructure is one of the most targeted surfaces on the internet. When you are moving money across African borders, navigating multi-cloud environments, multiple jurisdictions, and a threat landscape that does not stand still, the attack surface is wide and the consequences of getting it wrong are not theoretical.
InfraSec protects the foundations of Juicyway's production and experimental environments. That spans everything from bare-metal hardware and workforce devices to Kubernetes clusters and service meshes, from data storage to the access pathways for some of the most sensitive financial data on the continent.
This role exists to lead that function. Not to audit it from a distance. To actively harden it — building the controls, the tooling, and the instincts that make Juicyway's infrastructure genuinely difficult to compromise. You will be the senior security voice in a technical team that takes this seriously, working on infrastructure that processes real financial transactions for thousands of African businesses every day.
What you'll own
- Conduct application security testing (Threat modelling, SCA, SAST, DAST) across web, mobile, and API platforms to identify vulnerabilities such as those in the OWASP Top 10
- Perform vulnerability assessments across internal and external networks, systems, and cloud infrastructure
- Execute penetration tests (black-box, gray-box, and white-box) against cloud environments (AWS, Azure, GCP), including IAM misconfigurations, storage exposure, container security, and serverless architectures
- Simulate real-world attack scenarios, including red team exercises, social engineering, and adversary emulation
- Analyze and validate findings from automated scanning tools to eliminate false positives
- Develop custom scripts, tools, or exploits to test specific attack vectors as needed
- Document findings in detailed technical reports with clear risk ratings, business impact, and remediation recommendations
- Present findings to technical teams and leadership in a clear, actionable manner
- Collaborate with engineering and DevOps teams to support secure coding practices and remediation efforts
- Stay current with emerging threats, attack techniques, CVEs, and cloud security research
- Contribute to the development of internal security testing methodologies, playbooks, and tooling
- Support compliance efforts (e.g., PCI-DSS, SOC 2, ISO 27001) through testing evidence and reporting
Requirements
What we need
- 4+ years of experience in penetration testing, red teaming, or offensive security roles
- Strong understanding of web application security (OWASP Top 10, API security, authentication/authorization flaws)
- Hands-on experience with cloud security testing across AWS, Azure, and/or GCP
- Proficiency with common offensive security tools (e.g., Burp Suite, Metasploit, Nmap, Nessus, Cobalt Strike)
- Scripting/programming skills (Python, Bash, PowerShell, or similar) for tool development and automation
- Solid understanding of networking, operating systems (Linux/Windows), and containerization (Docker/Kubernetes)
- Experience with vulnerability management and reporting tools
- Strong written and verbal communication skills, with the ability to translate technical findings for non-technical audiences
Preferred Qualifications
- Relevant certifications: OSCP, OSCE, OSWE, GPEN, GWAPT, CRTO, or AWS/Azure security certifications
- Experience with Infrastructure as Code (Terraform, CloudFormation) security review
- Familiarity with CI/CD pipeline security and DevSecOps practices
- Experience with cloud-native security tools (e.g., Prowler, ScoutSuite, Pacu)
- Bug bounty experience or CTF participation
- Prior experience in a regulated industry
Benefits
What we offer
- Competitive pay
- Meaningful equity at an early stage
- Real flexibility on hours, location, and how you do your best work
- A technical team that takes security seriously and will actually listen to you