Information Systems Auditor

Company Details

Rating: No ratings yet log in to rate this company
Industry: Banking
Description: Caritas Microfinance Bank is a licensed microfinance bank regulated by Central Bank of Kenya. Caritas MFB offers a full range of innovative and customized financial services with a special focus on the unbanked and underbanked. Its headquarters are located in the Nairobi CBD. Caritas MFB was formed … Caritas Microfinance Bank is a licensed microfinance bank regulated by Central Bank of Kenya. Caritas MFB offers a full range of innovative and customized financial services with a special focus on the unbanked and underbanked. Its headquarters are located in the Nairobi CBD. Caritas MFB was formed to provide affordable, innovative and customized financial solutions to micro and small enterprises (MSEs) and to vulnerable groups that are mostly unbanked and underbanked. View more View less

Job Details

Job Type: Full Time
Workplace Type: On-site
Qualification: Diploma
Job Experience: Mandatory
Job Location: Nairobi County, Kenya
Closing Date: Sep 23, 2026
Salary: Not specified
Other Pay: Benefits
Job Category: Telecommunications

Job Description

Role Overview

This position sits at the intersection of technology operations and assurance, taking ownership of the bank's local and wide area networks while independently testing the controls that protect them. Day to day, the holder keeps network, communication and supporting infrastructure services running reliably for business users, and at the same time plans and executes audits that examine how well IT risks are identified, mitigated and reported. The role matters because it is the bank's front line for both uptime and accountability — the person in it ensures technology keeps serving customers and that the controls around that technology stand up to scrutiny from management, regulators and the Audit Committee.

You will work across technical and non-technical audiences, advising business and IT leadership on risk, reviewing digital channels and systems before and after major change, and building the data-driven tooling that makes assurance work faster and sharper.

Key Responsibilities

  • Maintain and support the bank's LAN and WAN environments, including communication links and associated infrastructure, so that business services remain available and perform as required.
  • Advise business and IT management on IT risk management matters, with particular focus on application and infrastructure security.
  • Build, maintain and continuously improve the IT risk assessment framework used across the function.
  • Plan and conduct periodic audits and reviews of systems, applications, IT processes and digital channels, including pre- and post-implementation reviews of new systems and enhancements.
  • Carry out IT security audits covering networks, applications and data centres, confirming that identified vulnerabilities are properly mitigated and coordinating scope with business units and external security specialists.
  • Evaluate and test IT general controls and return practical, value-adding feedback to system and process owners.
  • Schedule and perform reviews of IT management policies and procedures — change management, business continuity and disaster recovery planning, and information security — to confirm the surrounding controls remain adequate.
  • Design and implement analytical tools and techniques that improve the efficiency and effectiveness of audits, including data analysis used in risk assessments.
  • Document every assignment clearly and completely in audit work papers, and produce audit reports with actionable recommendations for Management and the Board Audit Committee.
  • Drive implementation of the Data Protection Act and related organisational policies and standards.
  • Contribute to the annual risk-based audit plan and take on additional duties consistent with the organisation's goals and objectives.

Requirements & Qualifications

  • Bachelor's degree in Information Technology, Computer Science, Information Systems, Cybersecurity, Accounting, Finance or a related discipline.
  • At least 3 years of hands-on experience in IT governance or information systems audit within a reputable organisation, ideally a financial institution.
  • A recognised information systems certification is mandatory — CISA, CISM, CISSP or CIA.
  • Active membership of ISACA is mandatory; ICPAK membership is an added advantage.
  • A relevant additional professional qualification is an added advantage.
  • Strong grasp of internal auditing, internal control, risk management, and finance and accounting practices and methods.
  • Comprehensive understanding of the internal control environment within an IT function.
  • Working knowledge of database management, software development and networking.
  • Familiarity with information security standards, leading practices for securing computer systems, and the applicable laws and regulations governing them.
  • General understanding of operational controls in a banking environment.
  • Outstanding interpersonal and communication skills, with the ability to explain technical issues clearly to both technical and non-technical audiences.
807 open positions on Semasocial right now · 10954 open positions in Nairobi County, Kenya · 40 posted in the last 7 days
Application deadline: Sep 23, 2026 · 2 days left to apply
Contact Information
Sign in to apply for this job.
CV Job Description Matcher See how well your CV matches this job and get tips to improve your chances AI Tool

This tool helps you see how closely your CV matches a job description. It also gives you simple suggestions on what to improve so you have a better chance of getting shortlisted.

Beware of Fraudsters!
Never pay anyone for job applications, interview tests, or job interviews. A genuine employer will never ask you for payment under any circumstances.
Disclaimer & TOS: We do not guarantee the authenticity of every single job posting and are not responsible for any fraudulent activity or misrepresentation by third parties. We are not involved in any stage of the interview or recruitment process and do not charge any fees from job seekers. For further details, please read the rest of the Terms of Service.