Manager, Technology (IT) Risk (EBKL)

Company Details

Rating: No ratings yet — log in to rate this company
Industry: Banking
Description: Equity Bank Limited (The "Bank”) is incorporated, registered under the Kenyan Companies Act Cap 486 and domiciled in Kenya. The address of the Bank’s registered office is 9th Floor, Equity Centre, P.O. Box 75104 - 00200 Nairobi. The Bank is licensed under the Kenya Banking Act (Chapter 488), and con… Equity Bank Limited (The "Bank”) is incorporated, registered under the Kenyan Companies Act Cap 486 and domiciled in Kenya. The address of the Bank’s registered office is 9th Floor, Equity Centre, P.O. Box 75104 - 00200 Nairobi. The Bank is licensed under the Kenya Banking Act (Chapter 488), and continues to offer retail banking, microfinance and related services. The Bank has subsidiaries in Kenya, Uganda, South Sudan, Rwanda and Tanzania. Its shares are listed on the Nairobi Securities Exchange and Uganda Securities Exchange. Equity Bank was founded as Equity Building Society (EBS) in October 1984 and was originally a provider of mortgage financing for the majority of customers who fell into the low income population. The society’s logo, a modest house with a brown roof, resonates with its target market and their determination to make small but steady gains toward a better life, seeking security and advancement of their dreams. The vast majority of Africans have historically been excluded from access to fin View more View less

Job Details

Job Type: Full Time
Workplace Type: On-site
Qualification: Diploma
Job Experience: Mandatory
Job Location: Nairobi County, Kenya
Closing Date: Undisclosed
Salary: Not specified
Other Pay: Benefits
Job Category: Telecommunications

Job Description

Role Overview

The Manager, Technology Risk leads the bank’s approach to identifying and controlling risks across its technology environment, from core infrastructure and cybersecurity to cloud services and digital banking initiatives. Working with technology, information security, audit, and business teams, this role turns regulatory obligations and risk assessments into practical controls, stronger resilience, and clear reporting for senior decision-makers.

Key Responsibilities

  • Maintain the bank’s technology risk framework, policies, and controls, aligning them with applicable regulatory requirements and standards such as NIST, ISO 27001, COBIT, and Basel.
  • Plan and carry out technology risk assessments, control testing, risk and control self-assessments, and scenario analysis; document findings and agree on mitigation actions with accountable teams.
  • Monitor developing exposures involving cyber threats, vulnerabilities, cloud adoption, artificial intelligence, third-party technology, and digital banking services.
  • Partner with IT and information security teams to review security controls, incident response readiness, data protection practices, and remediation of cybersecurity events.
  • Evaluate critical technology vendors, cloud providers, and outsourced services through due diligence and ongoing risk monitoring.
  • Coordinate technology risk reviews and audits with internal audit and regulators, track findings, and drive corrective actions through to closure.
  • Support disaster recovery and business continuity planning, including response coordination and reporting when significant technology disruptions occur.
  • Prepare risk dashboards, key risk indicators, and management reports for senior leaders and risk governance committees; provide technology risk training to business and IT teams.

Requirements & Qualifications

  • Bachelor’s degree in computer science, information technology, risk management, cybersecurity, or a related discipline; a master’s degree is an advantage.
  • At least 5–7 years of relevant experience in technology risk, IT security, cybersecurity, or IT audit, preferably within banking or financial services.
  • Working knowledge of the Central Bank of Kenya ICT Risk Guidelines, Basel requirements, the NIST Cybersecurity Framework, ISO 27001, GDPR, and the Kenya Data Protection Act.
  • Practical expertise in technology risk assessment, control evaluation, risk mitigation, and ongoing monitoring.
  • Understanding of IT governance and assurance practices, including COBIT and ITIL, and experience supporting audits or regulatory reviews.
  • Ability to assess cyber and data protection risks, coordinate incident response, and contribute to business continuity and disaster recovery efforts.
  • Strong written and verbal communication skills, including the ability to present risk findings and remediation progress to senior stakeholders.
  • Professional qualifications such as CISA, CRISC, CISSP, or ITIL are highly preferred.
873 open positions on Semasocial right now · 11766 open positions in Nairobi County, Kenya · 20 posted in the last 7 days
Contact Information
CV Job Description Matcher See how well your CV matches this job and get tips to improve your chances AI Tool

This tool helps you see how closely your CV matches a job description. It also gives you simple suggestions on what to improve so you have a better chance of getting shortlisted.

Similar Jobs

View Job Oct 09, 2026
View Job Oct 09, 2026
UAE Jobs Dubai, United Arab Emirates
View Job Oct 09, 2026
Startup Lions Turkana County, Kenya
View Job Oct 08, 2026
Beware of Fraudsters!
Never pay anyone for job applications, interview tests, or job interviews. A genuine employer will never ask you for payment under any circumstances.
Disclaimer & TOS: We do not guarantee the authenticity of every single job posting and are not responsible for any fraudulent activity or misrepresentation by third parties. We are not involved in any stage of the interview or recruitment process and do not charge any fees from job seekers. For further details, please read the rest of the Terms of Service.