Role Overview
This position sits within the internal audit function of a bank, focusing exclusively on technology and information systems. You will independently evaluate whether the bank’s IT environment is properly governed, adequately controlled, and compliant with both internal policy and external regulation. Day to day, you will lead risk-based audits of core banking applications, cybersecurity defences, vendor arrangements, and business continuity plans, then translate your findings into clear reports for senior management and help ensure corrective actions are actually implemented.
Key Responsibilities
- Design risk-based audit plans for each engagement, identifying the key systems, processes, and control points to test based on enterprise risk assessments, regulatory priorities, and past audit outcomes.
- Perform hands-on technical reviews of core banking systems, payment platforms, and IT infrastructure, including access controls, change management, and system interfaces.
- Conduct vulnerability assessments and penetration tests, then assess how identified weaknesses are prioritised and remediated by the bank’s security team.
- Evaluate the effectiveness of IT governance structures, cybersecurity policies, incident response capabilities, and business continuity/disaster recovery arrangements.
- Review the management of third-party IT service providers, including contract compliance, SLA performance, and the quality of vendor oversight.
- Use data analytics and computer-assisted audit techniques (CAATs) to script recurring audit reports, analyse system logs, and identify anomalies or patterns of risk.
- Prepare audit reports that clearly state issues, root causes, risk exposure, and practical recommendations, and present these to department heads and governance committees.
- Track the implementation of management action plans, validate whether corrective actions have resolved the underlying issues, and perform follow-up audits to verify sustainability.
Requirements & Qualifications
- A bachelor’s degree in Information Technology, Computer Science, or a related field.
- At least three years of hands-on experience in information systems audit, technology risk, security, or forensic reviews, preferably within a banking or financial services environment.
- CISA certification is mandatory; CISM, CEH, or ISO 27001 Lead Auditor qualifications are considered strong additions.
- Demonstrated experience auditing ICT operations in a banking context, including familiarity with CBK prudential guidelines and general IT audit frameworks such as ITAF and GIAS.
- Hands-on proficiency with audit management systems, data analytics tools, and the ability to script or automate audit testing routines.
- Strong analytical and problem-solving skills, with the ability to review complex technical environments and identify control gaps quickly.
- Excellent written and verbal communication skills, allowing you to articulate technical audit findings to non-technical stakeholders confidently.
- A high level of professional scepticism, attention to detail, and the courage to challenge the status quo when controls are weak or management is non-responsive.
629 open positions on Semasocial right now
· 9295 open positions in Nairobi County, Kenya
· 48 posted in the last 7 days
Contact Information