Job Title: ICT Risk Officer
Role Overview: The ICT Risk Officer will be responsible for identifying, assessing, and mitigating information and communication technology risks across the bank. This role ensures that robust controls are in place to protect systems, data, and compliance requirements.
Key Responsibilities
- Carry out ICT risk assessments of Co-operative Bank systems and provide recommendations for appropriate and adequate IT security controls to mitigate and minimize ICT risks.
- Continuously review and improve the ICT controls in place.
- Continuously review systems at all levels – servers, applications, databases, network devices, etc. – identify risks and make recommendations for closure of those risks.
- Provide continuous assurance on ICT risks across the bank’s systems.
- Evaluate ICT controls for all operating systems, applications, database management system interfaces, and networks to ensure consistency in meeting compliance requirements (regulatory, standards, and internal policies).
- Promote information security awareness within the bank by providing consultation, guidance, and conducting relevant awareness programs to foster an IS-compliant culture.
- Proactively anticipate potential threats and vulnerabilities and provide guidance, in coordination with the ICT department, on effective responses or control measures to mitigate them.
- Manage the ICT risk registers.
- Periodically perform vulnerability assessments and penetration tests on bank systems and technology, identify vulnerabilities, and recommend corrective actions.
Qualifications, Skills and Experience
Education and Professional Qualifications
- A Bachelor’s degree in Information Technology, Information Security, or Computer Science.
- Relevant IT security professional qualifications (e.g., CISA, CISM, CEH or other relevant security certifications).
Experience
- A minimum of 5 years of working experience in a similar role within a highly computerized environment.
- Experience in implementing information security standards such as ISO 27001 and COBIT.
- Experience with Windows Enterprise servers or UNIX systems.
- Experience working in the IT function within a banking environment is an advantage.
Skills and Competencies
- Understanding of ICT risk and systems security control processes.
- Understanding of information systems architecture and operational practices.
- Appreciation of audit methodologies.
- Knowledge of cybersecurity good practices (Identity and Access Management, Data Protection, Penetration Testing, etc.).
514 open positions on Semasocial right now
· 8338 open positions in Nairobi County, Kenya
· 28 posted in the last 7 days
Contact Information