Role Overview
The Manager, Technology Risk leads the bank’s approach to identifying and controlling risks across its technology environment, from core infrastructure and cybersecurity to cloud services and digital banking initiatives. Working with technology, information security, audit, and business teams, this role turns regulatory obligations and risk assessments into practical controls, stronger resilience, and clear reporting for senior decision-makers.
Key Responsibilities
- Maintain the bank’s technology risk framework, policies, and controls, aligning them with applicable regulatory requirements and standards such as NIST, ISO 27001, COBIT, and Basel.
- Plan and carry out technology risk assessments, control testing, risk and control self-assessments, and scenario analysis; document findings and agree on mitigation actions with accountable teams.
- Monitor developing exposures involving cyber threats, vulnerabilities, cloud adoption, artificial intelligence, third-party technology, and digital banking services.
- Partner with IT and information security teams to review security controls, incident response readiness, data protection practices, and remediation of cybersecurity events.
- Evaluate critical technology vendors, cloud providers, and outsourced services through due diligence and ongoing risk monitoring.
- Coordinate technology risk reviews and audits with internal audit and regulators, track findings, and drive corrective actions through to closure.
- Support disaster recovery and business continuity planning, including response coordination and reporting when significant technology disruptions occur.
- Prepare risk dashboards, key risk indicators, and management reports for senior leaders and risk governance committees; provide technology risk training to business and IT teams.
Requirements & Qualifications
- Bachelor’s degree in computer science, information technology, risk management, cybersecurity, or a related discipline; a master’s degree is an advantage.
- At least 5–7 years of relevant experience in technology risk, IT security, cybersecurity, or IT audit, preferably within banking or financial services.
- Working knowledge of the Central Bank of Kenya ICT Risk Guidelines, Basel requirements, the NIST Cybersecurity Framework, ISO 27001, GDPR, and the Kenya Data Protection Act.
- Practical expertise in technology risk assessment, control evaluation, risk mitigation, and ongoing monitoring.
- Understanding of IT governance and assurance practices, including COBIT and ITIL, and experience supporting audits or regulatory reviews.
- Ability to assess cyber and data protection risks, coordinate incident response, and contribute to business continuity and disaster recovery efforts.
- Strong written and verbal communication skills, including the ability to present risk findings and remediation progress to senior stakeholders.
- Professional qualifications such as CISA, CRISC, CISSP, or ITIL are highly preferred.
873 open positions on Semasocial right now
· 11766 open positions in Nairobi County, Kenya
· 20 posted in the last 7 days
Contact Information