IT Risk Manager – Risk

Company Details

Rating: No ratings yet — log in to rate this company
Industry: Banking
Description: Equity Bank Limited (The "Bank”) is incorporated, registered under the Kenyan Companies Act Cap 486 and domiciled in Kenya. The address of the Bank’s registered office is 9th Floor, Equity Centre, P.O. Box 75104 - 00200 Nairobi. The Bank is licensed under the Kenya Banking Act (Chapter 488), and con… Equity Bank Limited (The "Bank”) is incorporated, registered under the Kenyan Companies Act Cap 486 and domiciled in Kenya. The address of the Bank’s registered office is 9th Floor, Equity Centre, P.O. Box 75104 - 00200 Nairobi. The Bank is licensed under the Kenya Banking Act (Chapter 488), and continues to offer retail banking, microfinance and related services. The Bank has subsidiaries in Kenya, Uganda, South Sudan, Rwanda and Tanzania. Its shares are listed on the Nairobi Securities Exchange and Uganda Securities Exchange. Equity Bank was founded as Equity Building Society (EBS) in October 1984 and was originally a provider of mortgage financing for the majority of customers who fell into the low income population. The society’s logo, a modest house with a brown roof, resonates with its target market and their determination to make small but steady gains toward a better life, seeking security and advancement of their dreams. The vast majority of Africans have historically been excluded from access to fin View more View less

Job Details

Job Type: Full Time
Workplace Type: On-site
Qualification: Diploma
Job Experience: Mandatory
Job Location: Nairobi County, Kenya
Closing Date: Undisclosed
Salary: Not specified
Other Pay: Benefits
Job Category: Telecommunications

Job Description

Role Overview

This position sits alongside the Head of Risk and Compliance and takes day-to-day ownership of how Finserve protects the resilience of its data and technology estate. The IT Manager translates the Technology Information Cybersecurity (TICS) framework from a document into working controls, measurable reporting and everyday behaviour across the business. Success in the role means the organisation can demonstrate to its Board, its stakeholders and its regulators that its TICS commitments are being met, and that its residual cyber risk exposure is understood and actively managed rather than assumed.

Key Responsibilities

  • Lead the data analytics approach for IT and cybersecurity risk reporting across the subsidiary, turning control and incident data into dashboards, trend analysis and clear narratives for governance forums.
  • Define and embed risk data standards in line with BCBS 239 expectations, covering accuracy, completeness, timeliness and adaptability of the data used in risk reporting.
  • Monitor the operationalisation of IT governance policies, standards and procedures, tracking where adoption is lagging and escalating gaps before they become findings.
  • Maintain visibility of IT skills coverage and headcount against the work the function is required to deliver, flagging capability or capacity risks to leadership.
  • Coordinate the remediation of audit issues end to end, from agreeing actions and owners through to evidence of closure.
  • Design and run awareness and training initiatives that build a durable cybersecurity culture rather than a one-off compliance exercise.
  • Assess TICS risk on new systems and products before they go live, ensuring security and control requirements are built in at design stage.
  • Support the Head of Risk and Compliance in preparing regular TICS risk reporting for the Board and in responding to internal and external stakeholder and regulator enquiries.

Requirements & Qualifications

  • Bachelor's degree in information technology, computer science, information systems, risk management or a related discipline.
  • Working awareness of Technology Information Cybersecurity (TICS) risk assessment and how it is applied in practice.
  • Demonstrated experience adhering to, and operating within, technology and information security policies and frameworks, rather than treating them as reference documents.
  • Ability to design and deliver employee awareness and training programmes on TICS policies and frameworks.
  • Several years of experience in IT risk, cybersecurity governance, IT audit or a closely related control function, ideally in a regulated environment.
  • Familiarity with risk data aggregation and reporting principles such as BCBS 239, and with how data governance is implemented day to day.
  • Track record of remediation work — owning audit or assurance findings through to verified closure.
  • Strong stakeholder skills, with the confidence to challenge technology teams, work with internal audit and compliance, and present risk positions clearly to senior leadership.
853 open positions on Semasocial right now · 11456 open positions in Nairobi County, Kenya · 30 posted in the last 7 days
Contact Information
CV Job Description Matcher See how well your CV matches this job and get tips to improve your chances AI Tool

This tool helps you see how closely your CV matches a job description. It also gives you simple suggestions on what to improve so you have a better chance of getting shortlisted.

Similar Jobs

Beware of Fraudsters!
Never pay anyone for job applications, interview tests, or job interviews. A genuine employer will never ask you for payment under any circumstances.
Disclaimer & TOS: We do not guarantee the authenticity of every single job posting and are not responsible for any fraudulent activity or misrepresentation by third parties. We are not involved in any stage of the interview or recruitment process and do not charge any fees from job seekers. For further details, please read the rest of the Terms of Service.