#IkoKaziKE

Back to jobs

Manager, Technology (It) Risk (Ebkl) At Equity Bank Kenya

Baron Capital Limited

Banking / Financial Services full time Nairobi Posted 3 days ago

Equity Bank Limited (The "Bank”) is incorporated, registered under the Kenyan Companies Act Cap 486 and domiciled in Kenya. The address of the Bank’s registered office is 9th Floor, Equity Centre, P.O. Box 75104 - 00200 Nairobi. The Bank is licensed under the Kenya Banking Act (Chapter 488), and continues to offer retail banking, microfinance and related services. The Bank has subsidiaries in Kenya, Uganda, South Sudan, Rwanda and Tanzania. Its shares are listed on the Nairobi Securities Exchange and Uganda Securities Exchange. Equity Bank was founded as Equity Building Society (EBS) in October 1984 and was originally a provider of mortgage financing for the majority of customers who fell into the low income population. The society’s logo, a modest house with a brown roof, resonates with its target market and their determination to make small but steady gains toward a better life, seeking security and advancement of their dreams. The vast majority of Africans have historically been excluded from access to financial resources. Having been declared technically insolvent in 1993, Equity’s transformation into a rapidly growing microfinance and then a commercial bank is widely considered to be an inspirational success story. Currently, Equity Bank has more than 9 million customers making it the largest bank in terms of customer base in Africa and having nearly half of bank accounts in Kenya. The company’s vision is "to be the champion of the socio-economic prosperity of the people of Africa”. Equity Bank retains a passionate commitment to empowering its clients to transform their lives and livelihoods. Through a business model that is anchored in access, convenience and flexibility, the Bank has evolved to become an all-inclusive financial services provider with a growing pan-African footprint. Equity Bank’s business model and its visionary leadership has continued to earn local, regional and global accolades and recognition. The model is also studied in some of the leading business schools in the world, as other developing countries in Africa and Asia seek to learn from Equity’s low margin, high-volume model. Equity Bank in 2010 established the Equity Group Foundation. This innovation and creative vehicle has fully transformed the concept of philanthropy and corporate social responsibility. While Equity Group Foundation champions the socio-economic transformation of the people of Africa and seeks partnerships along six cluster thematic areas, Equity Bank provides the infrastructure of delivery, hence reducing the operational costs for the Foundation and increasing the rate of return on any social investment. The six social thematic areas of focus are: education and leadership development; financial literacy and access; entrepreneurship; agriculture; health; innovations and environment. Make an enquiry todayJob Purpose: The Manager, Technology (IT) Risk is responsible for overseeing the bank’s technology risk management framework, ensuring that risks related to IT infrastructure, cybersecurity, data protection, and digital transformation initiatives are effectively managed. This role works closely with IT, cybersecurity, and risk management teams to identify, assess, monitor, and mitigate technology-related risks while ensuring compliance with regulatory requirements and best practices. Key Responsibilities:  Technology Risk Framework Implementation Develop, implement, and maintain the bank’s Technology Risk Management Framework in alignment with regulatory requirements and industry standards (e.g., NIST, ISO 27001, COBIT, Basel). Ensure technology risk policies, procedures, and controls are effectively embedded across all business units. Risk Identification, Assessment & Mitigation Conduct technology risk assessments, including IT control testing, risk control self-assessments (RCSA), and scenario analysis. Identify emerging risks related to cybersecurity threats, third-party IT risks, cloud computing, AI, and digital banking platforms. Implement risk mitigation measures to strengthen IT security and resilience. Cybersecurity & Data Protection Oversight Work closely with the Information Security and IT teams to assess cyber threats, vulnerabilities, and incident response strategies. Ensure compliance with data protection laws (e.g., GDPR, Kenya Data Protection Act) and regulatory requirements. Monitor cybersecurity incidents and oversee remediation efforts. Third-Party & Vendor Risk Management Assess technology risks associated with third-party vendors, cloud service providers, and IT outsourcing arrangements. Conduct due diligence and continuous monitoring of critical IT service providers. Regulatory Compliance & Audit Coordination Ensure adherence to local and international regulatory requirements, including CBK ICT Risk Guidelines, Basel III, and ISO standards. Act as the liaison between IT, internal audit, and external regulatory bodies during technology risk audits. Address and close audit findings related to IT risk. Business Continuity & Incident Management Support IT Disaster Recovery (DR) and Business Continuity Planning (BCP) initiatives. Coordinate technology risk incident response efforts and ensure timely reporting of critical IT disruptions. Technology Risk Reporting & Governance Develop and present technology risk reports, dashboards, and key risk indicators (KRIs) to senior management, the Risk Committee, and Board-level governance forums. Track and monitor IT risk remediation plans, ensuring timely resolution of identified risks. Training & Awareness Conduct technology risk awareness training for business units to promote a risk-aware culture. Support risk management capacity-building initiatives for IT and business teams. Qualifications Education and Qualifications Education: Bachelor’s degree in computer science, Information Technology, Risk Management, Cybersecurity, or a related field. A master’s degree is an added advantage. Certifications: Professional certifications such as CISA (Certified Information Systems Auditor), CRISC (Certified in Risk and Information Systems Control), CISSP (Certified Information Systems Security Professional), or ITIL (Information Technology Infrastructure Library) are highly preferred. Experience: Minimum of 5-7 years of experience in technology risk management, IT security, cybersecurity, or audit in the banking or financial services industry. Regulatory Knowledge: Strong understanding of CBK ICT Risk Guidelines, Basel Accords, NIST Cybersecurity Framework, GDPR, Kenya Data Protection Act, and ISO 27001. Key Skills and Competencies:  Technology Risk Management – Expertise in IT risk identification, mitigation, and monitoring. Cybersecurity & Information Security – Strong understanding of cyber threats, vulnerability management, and data protection regulations. IT Governance & Compliance – Knowledge of COBIT, ITIL, and regulatory requirements for technology risk management. Incident & Crisis Management – Ability to handle IT incidents, cyber breaches, and business continuity disruptions. Audit & Assurance – Experience in conducting IT risk assessments, internal audits, and regulatory compliance reviews.