Role Overview
This position sits at the intersection of technology operations and assurance, taking ownership of the bank's local and wide area networks while independently testing the controls that protect them. Day to day, the holder keeps network, communication and supporting infrastructure services running reliably for business users, and at the same time plans and executes audits that examine how well IT risks are identified, mitigated and reported. The role matters because it is the bank's front line for both uptime and accountability — the person in it ensures technology keeps serving customers and that the controls around that technology stand up to scrutiny from management, regulators and the Audit Committee.
You will work across technical and non-technical audiences, advising business and IT leadership on risk, reviewing digital channels and systems before and after major change, and building the data-driven tooling that makes assurance work faster and sharper.
Key Responsibilities
- Maintain and support the bank's LAN and WAN environments, including communication links and associated infrastructure, so that business services remain available and perform as required.
- Advise business and IT management on IT risk management matters, with particular focus on application and infrastructure security.
- Build, maintain and continuously improve the IT risk assessment framework used across the function.
- Plan and conduct periodic audits and reviews of systems, applications, IT processes and digital channels, including pre- and post-implementation reviews of new systems and enhancements.
- Carry out IT security audits covering networks, applications and data centres, confirming that identified vulnerabilities are properly mitigated and coordinating scope with business units and external security specialists.
- Evaluate and test IT general controls and return practical, value-adding feedback to system and process owners.
- Schedule and perform reviews of IT management policies and procedures — change management, business continuity and disaster recovery planning, and information security — to confirm the surrounding controls remain adequate.
- Design and implement analytical tools and techniques that improve the efficiency and effectiveness of audits, including data analysis used in risk assessments.
- Document every assignment clearly and completely in audit work papers, and produce audit reports with actionable recommendations for Management and the Board Audit Committee.
- Drive implementation of the Data Protection Act and related organisational policies and standards.
- Contribute to the annual risk-based audit plan and take on additional duties consistent with the organisation's goals and objectives.
Requirements & Qualifications
- Bachelor's degree in Information Technology, Computer Science, Information Systems, Cybersecurity, Accounting, Finance or a related discipline.
- At least 3 years of hands-on experience in IT governance or information systems audit within a reputable organisation, ideally a financial institution.
- A recognised information systems certification is mandatory — CISA, CISM, CISSP or CIA.
- Active membership of ISACA is mandatory; ICPAK membership is an added advantage.
- A relevant additional professional qualification is an added advantage.
- Strong grasp of internal auditing, internal control, risk management, and finance and accounting practices and methods.
- Comprehensive understanding of the internal control environment within an IT function.
- Working knowledge of database management, software development and networking.
- Familiarity with information security standards, leading practices for securing computer systems, and the applicable laws and regulations governing them.
- General understanding of operational controls in a banking environment.
- Outstanding interpersonal and communication skills, with the ability to explain technical issues clearly to both technical and non-technical audiences.
807 open positions on Semasocial right now
· 10954 open positions in Nairobi County, Kenya
· 40 posted in the last 7 days
Application deadline: Sep 23, 2026 · 2 days left to apply
Contact Information
Sign in to apply for this job.