This job listing has expired and may no longer be relevant!
5 Oct 2023

Head of Technology Risk Management at Equity Bank Kenya

Recruit candidates with Ease. 100% recruitment control with Employer Dashboard.
We have the largest Job seeker visits by alexa rankings. Post a Job

Resubmit your Resume Today. Click Here to Start

We have started building our professional LinkedIn page. Follow


Job Description

Equity Bank Limited (The “Bank”) is incorporated, registered under the Kenyan Companies Act Cap 486 and domiciled in Kenya. The address of the Bank’s registered office is 9th Floor, Equity Centre, P.O. Box 75104 – 00200 Nairobi. The Bank is licensed under the Kenya Banking Act (Chapter 488), and continues to offer retail banking, microfinance and related services. The Bank has subsidiaries in Kenya, Uganda, South Sudan, Rwanda and Tanzania. Its shares are listed on the Nairobi Securities Exchange and Uganda Securities Exchange. Equity Bank was founded as Equity Building Society (EBS) in October 1984 and was originally a provider of mortgage financing for the majority of customers who fell into the low income population.

The Role

This Head of Technology Risk Management role is a 2nd line of defense role which encompasses creation/improvement/execution of Information and Technology risk governance across the Group, including partnership with 1st line front line business and risk units, in alignment with the Enterprise Risk Framework. The role will be providing Risk Management leadership across the Group’s Information and Technology risks. The candidate is expected to possess a deep understanding of information technology and should understand concepts including computer networking, web and native application functionality, operating system functionality, cloud services, corporate network environments and operations.

Responsibilities

  • Perform external/internal/cloud/wireless network assessments, web and mobile application testing, source code reviews, network security and IT architecture reviews.
  • Provide both subject matter expertise and project management experience to serve as the “point person” for external IT risk assessments engagements and where required, supervise the scoping of prospective engagements by external vendors, participating in engagements from kickoff to completion.
  • Interface with the relevant internal and external teams to clarify and provide support to address concerns, issues, or escalations; track and drive to closure any issues that impact the service and its value to the bank’s customers
  • Develop comprehensive and accurate reports and presentations for both technical and executive audiences
  • Oversee and manage implementation improvements to the group’s business processes, methodologies, tools, and client communication methods
  • Provide expert experience building information, cybersecurity and it risk programs to include hands-on implementation and/or assessment of relevant controls
  • Make use of formal project management skills in planning, tracking, and reporting on project progress
  • Perform IT General Controls Testing and IT Application Controls Testing
  • Identify key risks and evaluate effectiveness of controls in mitigating risks and meeting IT objectives.
  • Identify potential process improvement opportunities.
  • Support the review and update of the Information, Cybersecurity, and IT risk management framework on an annual basis with the changes in the environment.
  • Review technology policies, processes and procedures identify potential opportunities for improvement and alignment.
  • Working across the technology department to analyze and better understand their risk profile.
  • Review IT initiatives from technology risk perspectives and provide advisory and recommendation.
  • Supervise the IT disaster recovery measures deployed across the group.
  • Support the review and update of IT risk and control methodology used in conducting risk assessments.
  • Proactively managing risks so that there are no major incidents, breaches, or examples of non-compliance.
  • Support the definition of the technology risk appetite statements
  • Review and advice on the risk control self-assessments (RCSAs) performed by 1 LOD teams for the allocated risk subtypes.
  • Monitor Key Risk Indicators (KRIs) and report on deviation from defined technology risk appetite.
  • Assist with the Technology Risk reporting operations, including scheduling key monthly meetings, monitoring key milestones, escalation of past due activities, problem triage and management.
  • Increase awareness and enhance risk culture across the organization and provide day to day risk and control advise as trusted 2nd line subject matter expert.

Processes

  • Provide assurance that the first line implements controls to comply with applicable laws and regulations and escalate significant policy and regulatory non-compliance matters and developments to the Group CISRO;
  • Support the global thematic reviews and assurance testing process, stress tests, regulatory submissions, and Internal audit reviews;
  • Establish and maintain strong relationships with identified stakeholders and understand their strategic goals to ensure IT alignment
  • Assist with the articulation of the value of IT controls and their bottom-line impact;
  • Represent EGHL in internal and external meetings where required;

Risk Management

  • Highlight gaps or control weaknesses against security controls and standards, raising concerns to the CISRO and relevant forums;
  • Provide recommendations and feedback based on IT Risk assessments and assurance experience within EGHL and the subsidiaries;
  • Provide input into Group wide ICS assessments, reporting, and strategies

People and Talent

  • Lead through example and help to create the appropriate culture and values.
  • Work in collaboration with risk and control partners.
  • Work collaboratively with the wider CISRO Team
  • Effective staff management to achieve operational objectives
  • Agility to manage and balance own time among multiple tasks, and lead junior staff when required
  • Uphold and reinforce the independence of the second line ICS Risk function.
  • Take personal responsibility for embedding the highest standards of ethics, including regulatory and business conduct, across EGHL. This includes understanding and ensuring compliance with, in letter and spirit, all applicable laws, regulations, guidelines and the Group Code of Conduct.
  • Effectively and collaboratively identify, escalate, mitigate, and resolve risk, conduct and compliance matters.

Key Stakeholders

  • Group Chief Risk Officer and other senior Risk management teams,
  • Group CISRO, Head of IT and Cyber risk governance, Group Directors, Group CISO and other senior management
  • 1LOD risk management and cloud governance heads and teams
  • Group Internal Audit and other Business stakeholders

Ideal Candidate

  • Bachelor’s degree in Computer Science, Information and Cyber Security, Technology or equivalent
  • Minimum of 7 years of relevant in information security or risk management, preferably in Banking and Financial sector, with 5 years hands-on experience in risk, control, and assurance assessments / testing.
  • Minimum of at least a CISSP, CISA, CISM or CRISC certification
  • CoBiT or Risk IT Frameworks (Added advantage)
  • Experience with the establishment of IT risk management frameworks
  • Consistently able to demonstrate or articulate value proposition
  • Prior positive interaction with C-level executives or senior executive personnel
  • Technical report writing and documentation of risk management activities
  • Presentation of technical details to both a technical and executive audiences
  • Support the review and update of the technology risk management framework on an annual basis with the changes in the environment.
  • Must have hands on experience in performing risk assessments in diverse technology environments
  • Good understanding of technology infrastructure, networks, and database management systems.
  • Good understanding of cloud computing technologies and Microsoft Azure environment.
  • Familiar with various operating systems and databases
  • Ability to both assess priorities and to focus on work in a structured fashion which delivers results
  • Sound judgement and anticipation
  • Strong integrity, independence, and resilience
  • Deliver with minimal supervision.
  • Avid researcher of best practices and happenings in the global cyber space.
  • Engage key stakeholders on actions required.
  • Team player and contributor.
  • Strong problem-solving, persuasive skills and an ability to grasp abstract concepts and complex technology situations to challenge the status quo and further develop and build on our IT Risk Management Framework.
  • Excellent communication skill, both verbal and written, with the ability to initiate and lead conversations with technology and business leaders and risk colleagues regarding anticipated and emerging issues.


Method of Application

Submit your CV and Application on Company Website : Click Here

Closing Date : 19 October. 2023





Subscribe


Apply for this Job