Posted: By:Hiring Kenya
Job Description
The purpose of the job is monitoring overall information technology risk, maintaining an active view, and reporting on the actual, mitigated and residual risk in the IT systems of Liberty Kenya.
Key Responsibilities
Implement the IT Risk Management Strategy and Framework for the company.
Perform periodic review of IT Policies and procedures to incorporate new changes and system upgrades for better service delivery.
Conduct IT risk assessments for new IT business applications and IT infrastructure projects to verify their safety before use.
Implement information systems controls to mitigate risk.
Facilitate the identification of metrics and key performance indicators (KPIs) to enable the measurement of IT control performance in meeting business objectives.
Assess and recommend tools to automate information systems control and processes.
Keep up to date on emerging cyber security threats and ways to counter the threats for assured protection of the company’s information.
Perform on-going IT risk assessments, testing and monitoring and facilitate remediation of control deficiencies based on observations or findings from compliance monitoring and internal audit in the system.
Ensure all controls are assigned control owners to establish accountability
Conduct periodic training and awareness initiatives on IT risk and compliance matters to ensure that a compliance and risk culture is embedded within the organization.
Develop reports on the IT security status in the company for informing future decisions and assessment of current systems.
Support implementation of the business resilience process and assess adequacy of IT structures to support policy requirements
Drive the development of guidelines and standards to improve IT risk governance and develop dashboards to review indicators of alignment to set requirements
Qualifications
Bachelors’ degree in Information and Technology or any related field Relevant professional qualification – CISA/CRISC/ISACA
Experience
At least 6 years’ experience as information risk specialist/or information technology auditor or similar role.
Experience in financial services is an added advantage
Experience with data analytics software and data visualization tools is an added advantage.
Competencies
In depth understanding of insurance operations and concepts
Knowledge of IT systems
Knowledge of insurance regulatory requirements
Risk assessment techniques
Risk response strategies
Risk management policies
Excellent organizational and stakeholder management skills