Legal and Compliance · Not stated
Direct employerManager, Technology (IT) Risk (EBKL)

About this role
This plain-English summary was prepared by work.ke from the original advert. Confirm all details on the source before applying.
Role overview
Equity Bank in Kenya is hiring a Manager for Technology (IT) Risk. This role is suited for experienced professionals in technology risk management, cybersecurity, and IT governance within the banking or financial services sector. The position involves overseeing the bank's technology risk framework and ensuring compliance with relevant regulations.
Read full role
What you will do
- Develop and maintain the bank's Technology Risk Management Framework following regulatory and industry standards.
- Embed technology risk policies and controls across all business units.
- Conduct technology risk assessments and identify emerging IT risks including cybersecurity threats and risks related to cloud computing and AI.
- Collaborate with IT and Information Security teams to assess cyber threats and ensure compliance with data protection laws.
- Assess and monitor risks related to third-party IT vendors and service providers.
- Coordinate with audit and regulatory bodies to ensure compliance and address audit findings.
- Support IT disaster recovery and business continuity planning and manage incident response efforts.
- Prepare and present technology risk reports and track remediation plans.
- Conduct technology risk awareness training and support capacity-building initiatives.
Requirements
- Bachelor's degree in Computer Science, Information Technology, Risk Management, Cybersecurity, or related field; a master's degree is an advantage.
- Professional certifications such as CISA, CRISC, CISSP, or ITIL are highly preferred.
- 5 to 7 years of experience in technology risk management, IT security, cybersecurity, or audit within banking or financial services.
- Strong knowledge of CBK ICT Risk Guidelines, Basel Accords, NIST Cybersecurity Framework, GDPR, Kenya Data Protection Act, and ISO 27001.
- Expertise in IT risk identification, mitigation, and monitoring.
- Understanding of cybersecurity threats, vulnerability management, and data protection regulations.
- Knowledge of IT governance frameworks like COBIT and ITIL.
- Ability to manage IT incidents, cyber breaches, and business continuity disruptions.
- Experience in conducting IT risk assessments, internal audits, and regulatory compliance reviews.
How to apply
Apply through the employer's official contact. The employer has not published a closing date.