Tiko Africa Invites Proposals for Remote Penetration Testing Consultancy to Strengthen Digital Platform Security|Deadline 21 Jul 2026

Tiko Africa has issued a Request for Proposals (RFP) seeking a qualified consultancy firm or experienced cybersecurity specialists to conduct a comprehensive penetration testing assessment of the Tiko digital platform. The consultancy presents an excellent opportunity for organizations with expertise in information security, ethical hacking, and vulnerability assessments to support a mission-driven organization improving the lives of young women and adolescent girls across Africa.
The consultancy focuses on evaluating the security of the Tiko platform and identifying vulnerabilities that could affect the confidentiality, integrity, and availability of its digital services. Interested firms and consultants are invited to submit technical and financial proposals by 21 July 2026.
About Tiko Africa
Tiko Africa is a social impact organization that uses technology to encourage positive health and economic outcomes among young people, particularly adolescent girls and young women aged 15–24.
Through its innovative digital platform, Tiko provides users with incentives such as:
- Reward points.
- Discounts on products and services.
- Digital reminders and follow-ups.
- Subsidies for sexual and reproductive health services.
- Opportunities to participate in entrepreneurship initiatives.
The organization currently operates directly or through local partners in:
- Kenya
- Uganda
- Ethiopia
- Burkina Faso
- South Africa
As the platform continues to expand, maintaining strong cybersecurity measures has become essential to protecting user information and ensuring secure digital services.
Scope of the Penetration Testing Consultancy
The selected consultancy will perform a comprehensive security assessment of the Tiko platform using industry-recognized penetration testing methodologies.
The assignment will include testing of:
- Android mobile application.
- Mobile application APIs.
- Web-based configuration interface.
- Web APIs.
- Backend services.
- Databases.
- Server infrastructure.
To minimize operational disruption, all testing will be conducted within staging environments rather than production systems.
The assessment will not include:
- Physical security testing.
- Social engineering attacks.
Testing should combine automated vulnerability scanning with manual penetration testing techniques while following internationally recognized OWASP security standards.
Expected Deliverables
The successful consultancy will provide a detailed set of reports and recommendations that help strengthen the organization’s cybersecurity posture.
Deliverables include:
- Comprehensive vulnerability assessment report.
- Executive summary highlighting key findings.
- Technical report outlining:
- Identified vulnerabilities.
- Risk severity levels.
- Recommended remediation actions.
- Summary of successful and unsuccessful penetration testing methods.
- Post-engagement technical support to clarify findings and recommendations.
- Retesting of remediated critical and high-risk vulnerabilities.
- Final closure report confirming remediation results.
These deliverables will enable Tiko Africa to improve platform security while reducing cybersecurity risks.
Proposal Evaluation Criteria
Submitted proposals will be evaluated using a weighted scoring system totaling 100 points.
Evaluation areas include:
Experience, Skills, and Ability (30 Points)
- Previous experience conducting similar penetration testing engagements.
- Qualifications and expertise of the proposed team.
- Demonstrated ability to meet project requirements.
Technical Approach and Execution Plan (40 Points)
- Quality of the proposed testing methodology.
- Clarity of the implementation approach.
- Understanding of the assignment requirements.
Financial Proposal (15 Points)
- Detailed cost breakdown.
- Value for money.
References (15 Points)
- At least three relevant client references from comparable engagements completed within the past three years.
Organizations with strong cybersecurity credentials and experience securing digital platforms are encouraged to apply.
Proposal Submission Requirements
Interested firms and individual consultants should submit proposals of no more than 15 pages, excluding annexes.
The proposal should include:
- Cover page with organizational information.
- Capacity statement.
- Qualifications regarding the scope of work.
- Proposed technical approach.
- Details of proposed personnel.
- Work plan and implementation timeline.
- Budget presented in Euros with itemized costs.
- At least three relevant references.
Financial proposals should clearly indicate whether quoted prices include applicable taxes and identify any assumptions used in preparing the budget.
Important Dates and Application Process
Prospective bidders may submit clarification questions by 13 July 2026 via email.
Clarification requests should be sent to:
Responses to clarification questions will be shared by 16 July 2026.
Final technical and financial proposals must also be submitted by email to:
The application deadline is 21 July 2026.
Applicants should use the following email subject line:
RFP – Penetration Testing Consultancy 2026
Late or incomplete submissions may not be considered.
Final Thoughts
Tiko Africa’s Request for Proposals offers an outstanding opportunity for cybersecurity firms and penetration testing specialists to contribute to the security of a digital platform serving thousands of young women across Africa. By identifying vulnerabilities and recommending effective remediation measures, the selected consultancy will help strengthen data protection, improve system resilience, and support the organization’s mission of delivering secure digital health and entrepreneurship services.
Qualified organizations with proven expertise in penetration testing, OWASP methodologies, and application security are encouraged to prepare comprehensive proposals and submit them to bidding@tiko.org before 21 July 2026.
Join Our WhatsApp Community
Disclaimer: Remote Job Opportunities (RJO) is not the organization offering this opportunity. For any inquiries, please contact the responsible organization directly. Please do not send your applications to RJO, as we are unable to process them. Due to the high volume of emails we receive daily, we may not be able to respond to all inquiries. Thank you for your understanding.



