Information and Cyber Risk Governance, Policies and Framework Specialist at

4 weeks ago


Nairobi, Nairobi Area, Kenya Equity Bank Kenya Full time
Equity Bank Limited (The "Bank") is incorporated, registered under the Kenyan Companies Act Cap 486 and domiciled in Kenya. The address of the Bank's registered office is 9th Floor, Equity Centre, P.O. Box Nairobi.

The Bank is licensed under the Kenya Banking Act (Chapter 488), and continues to offer retail banking, microfinance and related services.

The Bank has subsidiaries in Kenya, Uganda, South Sudan, Rwanda and Tanzania. Its shares are listed on the Nairobi Securities Exchange and Uganda Securities Exchange.
The Role

The Information and Cyber risk governance, policies and framework specialist role is highly technical and challenging with opportunities to be part of a team that will have a meaningful impact.

The incumbent is expected to support all the 6 subsidiaries that Equity has presence and should possess an adequate understanding of governance of both cyber security and information technology and should understand concepts including computer networking, web and native application functionality, operating system functionality, cloud services, corporate network environments and operations.

She/He should be able to quickly learn and keep up with the ever-changing landscape of technology. The candidate should have strong policy making skills, processes and procedures mapping, compliance reviews and technical reporting skills.
Responsibilities

Support the review and update of the Technology, Information and Cyber security (TICS) risk management framework across the group on an annual basis with the changes in the environment.

Review Technology, Information and Cyber security policies, processes and procedures across the group identify potential opportunities for improvement and alignment.

Conduct risk assessments covering strategic arm of IT dealing with projects, 3rd party risks, people, measurement of the risk culture with metrics such as count and closure rates of audit and risk issues.

Conduct risk assessments in areas on IT asset management lifecycle both logical and physical and make appropriate recommendations. Prior experience in assets management software such as CMDB is an added advantage.
Conduct risk assessments incident management and response measures.
Perform compliance reviews against various laws and standards including Data protection, PCI DSS, ISO 27001, SWIFT CSP etc.

Work with first line of defense IT team to get buy in on recommendations and walk with the team to ensure full implementation.

Assist in compiling and reviewing management and board reports to ensure consistency and accuracy of information contained and proper follow through of actions.

Monitor allocated Key Risk Indicators ensuring clear escalation and action on detected breaches.
Maintain the risk registers with updated risk treatment plans and dates to ensure effective control design and operations.

Ensure sufficient coordination across all subsidiaries to ensure that technology, information and cyber risks are sufficiently identified and reported upon.

Track major IT and cyber security incidents both internal and external ensuring that lessons learnt are appropriately documented and implemented.

Assisting in setting out the methodology and templates to be used across the group for TICS risk assessments and reporting.

Work closely with the IT teams to ensure that innovative ideas are implemented through a clear risk and opportunity assessment.

Support the definition of the TICS risk appetite statements.

Review and advice on the risk control self-assessments (RCSAs) performed by 1 LOD teams for the allocated risk subtypes.

Assist in investigations when required to.

Ideal Candidate

Bachelor's degree in computer science, Information and Cyber Security, Technology or equivalent
5 years of relevant in information security or risk management, audit, information assurance preferably in Banking and Financial sector
Must have CISA (Certified Information Systems Auditor) certification
Must have CCSP (Certified Cloud Security Professional) certification
Other ISACA related Certification (e.g., CISM, CRISC or CGEIT) * Added advantage
Consistently able to demonstrate or articulate value proposition
Candidates must have hands on experience in performing risk assessments in diverse technology environments
Good understanding of technology infrastructure, networks, and database management systems.
Good understanding of cloud computing technologies and Microsoft Azure environment.
Expertise in Linux machine recommended Kali and parrot.
Familiar with various operating systems and databases
Ability to both assess priorities and to focus on work in a structured fashion which delivers results
Sound judgement and anticipation
Strong integrity, independence, and resilience
Deliver with minimal supervision.
Avid researcher of best practices and happenings in the global cyber space.
Engage key stakeholders on actions required.
Team player and contributor.

Strong problem-solving, persuasive skills and an ability to grasp abstract concepts and complex technology situations to challenge the status quo and further develop and build on our TICS Risk Management Framework.

Excellent communication skill, both verbal and written, with the ability to initiate and lead conversations with technology and business leaders and risk colleagues regarding anticipated and emerging issues.



  • Nairobi, Nairobi Area, Kenya United Nations Full time

    The United Nations is an intergovernmental organization to promote international co-operation. A replacement for the ineffective League of Nations, the organization was established on 24 October 1945ResponsibilitiesWithin limits of delegated authority, the Cyber Security Officer will be responsible for the following duties: Design, implement, and monitor...


  • Nairobi, Nairobi Area, Kenya Safaricom Kenya Full time

    Safaricom is the leading provider of converged communication solutions in Kenya. In addition to providing a broad range of first-class products and services for Telephony, Broadband Internet and Financial services, Safaricom seeks to uplift the welfare of Kenyans through value-added services and support for community projects.SUMMARYWe are pleased to...


  • Nairobi, Nairobi Area, Kenya Frank Management Consult Ltd Full time

    Frank Management Consult Ltd is an international management consulting agency. We work with major companies, raising their performance, driving their strategies and enhancing their productivity.SummmaryThe Cyber Security Analyst will be primarily responsible for the design, implementation, management, and operations of security controls and systems to...


  • Nairobi, Nairobi Area, Kenya Kenya Marine and Fisheries Research Institute Full time

    ABOUT THE COMPANYKenya Marine and Fisheries Research Institute is empowered to carry out research in Marine and Freshwater fisheries, Aquatic biology, Aquaculture, Environmental Chemistry, Ecological, Geological and Hydrological studies, as well as Chemical and Physical Oceanography.JOB SUMMARYRequirements for Appointment/Person SpecificationsFor appointment...


  • Nairobi, Nairobi Area, Kenya Save the Children (Kenya) Full time

    ABOUT THE COMPANYSave the Children has been operational in Kenya since the 1950s, providing support to children through developmental and humanitarian relief programmes delivered both directly and through local partners. Current programming focuses on child protection, child rights governance, education, health, HIV/AIDS, livelihoods, nutrition and WASH. In...


  • Nairobi, Nairobi Area, Kenya KCB Bank Kenya Full time

    Kenya Commercial Bank Limited is registered as a non-operating holding company which started operations as a licensed banking institution with effect from January 1, 2016. The holding company oversees KCB Kenya - incorporated with effect from January 1, and all KCB's regional units in Uganda, Tanzania, Rwanda, Burundi, Ethiopia and South SudanKey...


  • Nairobi, Nairobi Area, Kenya KCB Bank Kenya Full time

    Kenya Commercial Bank Limited is registered as a non-operating holding company which started operations as a licensed banking institution with effect from January 1, 2016. The holding company oversees KCB Kenya - incorporated with effect from January 1, and all KCB's regional units in Uganda, Tanzania, Rwanda, Burundi, Ethiopia and South...


  • Nairobi, Nairobi Area, Kenya Education Development Center (EDC) Full time

    JOB SUMMARYQualificationsThe candidate for the position of IT Specialist shall have at a minimum the following qualifications:Education:A Master's-level degree in information technology, business, and information technology (BIT), computer science, information science with IT or related field from an accredited institution.Skills and Experience:A minimum of...


  • Nairobi, Nairobi Area, Kenya Education Development Center Full time

    Education Development Center (EDC) is a global nonprofit that advances lasting solutions to improve education, promote health, and expand economic opportunity. Since 1958, we have been a leader in designing, implementing, and evaluating powerful and innovative programs in more than 80 countries around the worldSummaryThe Information Technology (IT)...


  • Nairobi, Nairobi Area, Kenya Equity Bank Kenya Full time

    Equity Bank Limited (The "Bank") is incorporated, registered under the Kenyan Companies Act Cap 486 and domiciled in Kenya. The address of the Bank's registered office is 9th Floor, Equity Centre, P.O. Box Nairobi.Job Purpose:The Lead, Security technology specialist provides a demonstrated holistic mastery and in-depth understanding of existing and emerging...


  • Nairobi, Nairobi Area, Kenya Standard Chartered Bank Kenya Full time

    Standard Chartered Kenya, whose official name is Standard Chartered Bank Kenya Limited, but is sometimes referred to as Stanchart Kenya, is a commercial bank in Kenya.Job SummaryThe management and monitoring of all the operational risk Standard Chartered Group and its subsidiaries are exposed to because of the business activities and processes that exist....


  • Nairobi, Nairobi Area, Kenya Standard Chartered Bank Kenya Full time

    Standard Chartered Kenya, whose official name is Standard Chartered Bank Kenya Limited, but is sometimes referred to as Stanchart Kenya, is a commercial bank in Kenya.RESPONSIBILITIESStrategy Support the Country Credit Head (CCH) and Head Policy and Governance in tracking and reporting the target risk appetite boundaries for Consumer, Private and Business...


  • Nairobi, Nairobi Area, Kenya Equity Bank Kenya Full time

    ABOUT THE COMPANYEquity Bank Kenya Limited, is a financial services provider headquartered in Nairobi, Kenya. It is licensed as a commercial bank, by the Central Bank of Kenya, the central bank and national banking regulator.JOB SUMMARYQualifications Knowledge and Experience:A Degree or its equivalent in Information Technology, Network Security, Enterprise...


  • Nairobi, Nairobi Area, Kenya Premier Bank Full time

    At a glance we are a bank that leverages cutting-edge technology to empower customers, Business and revolutionize their banking experiences. With a focus on customer-centricity, we are not just about offering another banking option; it's about delivering a transformative end to end banking experience.Key Responsibilities:Assessing adequacy of controls...


  • Nairobi, Nairobi Area, Kenya SBM Bank Full time

    SBM Bank Kenya is a leading and trusted financial institution with an international footprint, headquartered in Mauritius and positioned to offer an unprecedented banking experience in Kenya to niche Retail, SME and corporate clientsJOB SUMMARY:Identification, assessment, and treatment of Information Technology (IT) risks. Execution of IT Risk processes to...

  • Framework Manager at

    4 weeks ago


    Nairobi, Nairobi Area, Kenya Genesis Analytics Full time

    Our purpose is to unlock value in Africa. We use our analytical capabilities to improve decision-making and, through better decisions, to unlock substantial value for our clients and society. While we are the largest economics-based consulting firm in Africa, we use a large number of techniques and approaches to achieve clarity for decision-makers.SummaryThe...

  • ESG, Risk

    5 days ago


    Nairobi, Nairobi Area, Kenya Centum Full time

    Centum is East Africa's leading investment company listed on the Nairobi Securities Exchange and Uganda Securities Exchange. We are an investment channel providing investors with access to a portfolio of inaccessible, quality, diversified investmentsPosition SummaryCentum Investment Company Plc seeks to recruit an ESG, Risk and Compliance Manager.Reporting...


  • Nairobi, Nairobi Area, Kenya KCB Bank Kenya Full time

    Kenya Commercial Bank Limited is registered as a non-operating holding company which started operations as a licensed banking institution with effect from January 1, 2016. The holding company oversees KCB Kenya - incorporated with effect from January 1, and all KCB's regional units in Uganda, Tanzania, Rwanda, Burundi, Ethiopia and South Sudan.Key...


  • Nairobi, Nairobi Area, Kenya Corporate Staffing Services Full time

    IT jobs. As a market leader, we are dedicated towards creating and achieving excellence and the only way we can do it is through our people. Together, we share a common set of values rooted in integrity, excellence and a strong team ethic. We therefore provide you with a superior foundation for building a professional career – a place for people to learn,...

  • ESG, Risk

    1 week ago


    Nairobi, Nairobi Area, Kenya Centum Investments Co. Ltd. Full time

    ABOUT THE COMPANYCentum is East Africa's leading investment company listed on the Nairobi Securities Exchange and Uganda Securities Exchange. It aims at providing investors with access to a portfolio of inaccessible, quality, diversified investments.JOB SUMMARYCentum Investment Company Plc seeks to recruit an ESG, Risk and Compliance Manager.Minimum...