#IkoKaziKE

Back to jobs

Ict Risk Officer At Co-Operative Bank Of Kenya

Highlands Drinks Limited

Banking / Financial Services full time Nairobi Posted 3 months ago

The Co-operative Bank of Kenya Limited is incorporated in Kenya under the Company Act and is also licensed to do the business of banking under the Banking Act. The Bank was initially registered under the Co-operative Societies Act at the point of founding in 1965. This status was retained up to and until June 27th 2008 when the Banks Special General Meeting resolved to incorporate under the Companies Act with a view to complying with the requirements for listing on the Nairobi Securities Exchange (NSE). The Bank went public and was listed on December 22nd 2008. Shares previously held by the 3,805 Co-operative Societies and unions were ring-fenced under CoopHoldings Co-operative Society Limited which became the strategic investor in the Bank with a 64.56% stake. The Bank runs three subsidiary companies, namely: Kingdom Securities Limited: This is a stockbroking firm with the bank holding a controlling 60% stake. Co-opTrust Investment Services Limited: This is the fund management subsidiary wholly-owned by the bank. Co-op Consultancy & Insurance Agency Limited (CCIA): This is the corporate finance, financial advisory and capacity-building subsidiary wholly-owned by the bank. Our Vision To be the dominant bank in Kenya and the region, riding on the unique Co-operative Model providing innovative financial solutions for distinctive customer experience. Our Mission To offer a wide range of innovative financial solutions leveraging on our heavy investment in multi-channels, national and regional presence and with a focus on excellent customer experience by a highly motivated and talented team. Our Values We are Trustworthy We are Innovative and Agile We Value our Customers/People We Share and Collaborate We have Passion for Excellence We are Bold and courageous. The Role Specifically, the successful jobholder will be required to: Carry out ICT risk assessments of Co-operative Bank systems and provide recommendation of appropriate and adequate IT security controls to mitigate and minimize ICT Risks. Continuously review and improve the ICT controls in place. Continuously review systems at all levels i.e. servers, applications, database, network devices etc., identify risks and make recommendations on closure of the risks. Provide continuous assurance on ICT Risks on the Bank’s systems. Evaluate ICT controls for all operating systems, applications, database management system interfaces and networks across the Bank to ensure consistency in achieving compliance requirements (regulatory, standards and internal policies). Promote Information Security awareness within the Bank by providing consultation, guidance and conducting relevant awareness programs to ensure an IS compliant culture. Proactively anticipate potential threats and vulnerabilities and provide guidance in coordination with the ICT department on effective responses or control measures to be implemented to mitigate them. Manage ICT Risks registers. Periodically perform vulnerability assessments & penetration tests on Bank systems and technology, identifying vulnerabilities and recommendations on closure of these vulnerabilities. Skills, Competencies and Experience The successful candidate will be required to have the following skills and competencies: A Bachelor’s degree in Information Technology, Information Security or Computer Science. Relevant IT Security professional qualifications e.g. CISA, CISM, CEH or other relevant security certifications. A minimum of 5 years working experience in a similar role in a highly computerized environment. Experience in implementing Information Security Standards such as ISO 27001, COBIT. Understanding of ICT risk and systems security control processes. Understanding of Information Systems Architecture and operational practices. Appreciation of Audit Methodologies. Experience in Windows Enterprise servers or UNIX systems. Experience of working in the IT function within a banking environment will be an advantage. Knowledge of cybersecurity good practices (Identity and Access Management, Data Protection, Penetration Testing etc.)