Role Overview
This position sits alongside the Head of Risk and Compliance and takes day-to-day ownership of how Finserve protects the resilience of its data and technology estate. The IT Manager translates the Technology Information Cybersecurity (TICS) framework from a document into working controls, measurable reporting and everyday behaviour across the business. Success in the role means the organisation can demonstrate to its Board, its stakeholders and its regulators that its TICS commitments are being met, and that its residual cyber risk exposure is understood and actively managed rather than assumed.
Key Responsibilities
- Lead the data analytics approach for IT and cybersecurity risk reporting across the subsidiary, turning control and incident data into dashboards, trend analysis and clear narratives for governance forums.
- Define and embed risk data standards in line with BCBS 239 expectations, covering accuracy, completeness, timeliness and adaptability of the data used in risk reporting.
- Monitor the operationalisation of IT governance policies, standards and procedures, tracking where adoption is lagging and escalating gaps before they become findings.
- Maintain visibility of IT skills coverage and headcount against the work the function is required to deliver, flagging capability or capacity risks to leadership.
- Coordinate the remediation of audit issues end to end, from agreeing actions and owners through to evidence of closure.
- Design and run awareness and training initiatives that build a durable cybersecurity culture rather than a one-off compliance exercise.
- Assess TICS risk on new systems and products before they go live, ensuring security and control requirements are built in at design stage.
- Support the Head of Risk and Compliance in preparing regular TICS risk reporting for the Board and in responding to internal and external stakeholder and regulator enquiries.
Requirements & Qualifications
- Bachelor's degree in information technology, computer science, information systems, risk management or a related discipline.
- Working awareness of Technology Information Cybersecurity (TICS) risk assessment and how it is applied in practice.
- Demonstrated experience adhering to, and operating within, technology and information security policies and frameworks, rather than treating them as reference documents.
- Ability to design and deliver employee awareness and training programmes on TICS policies and frameworks.
- Several years of experience in IT risk, cybersecurity governance, IT audit or a closely related control function, ideally in a regulated environment.
- Familiarity with risk data aggregation and reporting principles such as BCBS 239, and with how data governance is implemented day to day.
- Track record of remediation work — owning audit or assurance findings through to verified closure.
- Strong stakeholder skills, with the confidence to challenge technology teams, work with internal audit and compliance, and present risk positions clearly to senior leadership.
853 open positions on Semasocial right now
· 11456 open positions in Nairobi County, Kenya
· 30 posted in the last 7 days
Contact Information