This job listing has expired and may no longer be relevant!
18 Sep 2023

Manager, Cyber Security Audit at KCB Bank Kenya

Recruit candidates with Ease. 100% recruitment control with Employer Dashboard.
We have the largest Job seeker visits by alexa rankings. Post a Job

Resubmit your Resume Today. Click Here to Start

We have started building our professional LinkedIn page. Follow


Job Description

Kenya Commercial Bank Limited is registered as a non-operating holding company which started operations as a licensed banking institution with effect from January 1, 2016. The holding company oversees KCB Kenya – incorporated with effect from January 1, 2016 – and all KCB’s regional units in Uganda, Tanzania, Rwanda, Burundi, Ethiopia and South Sudan. It also owns KCB Insurance Agency, KCB Capital, KCB Foundation and all associate companies. The holding company was set up to among other things to enhance the Group’s capacity to access unrestricted capital and also enable investment in new ventures outside banking regulations, achieve operational and strategic autonomy for the Group’s operating entities and enhance corporate governance across the Group and oversight in management of subsidiaries.

Key Responsibilities

  • Conduct cyber risk assessment for assigned cyber security audit and advisory assignments.
  • Perform independent threat and vulnerability assessment and penetration test audits of the bank’s ICT systems to assess the effectiveness of the cybersecurity control framework and report on cyber risks noted.
  • Conduct walkthroughs, testing of controls, and negotiating potential issues for Technology audits within the cybersecurity and infrastructure portfolio, including scope areas such as identity and access management, asset classification, network security, operating system security, database security, web application security, mobile application security, public cloud (AWS/GCP/Azure) environments, vulnerability management, endpoint protection, etc.
  • Documents the results of audit work in accordance with internal audit guidelines and the Institute of Internal Auditors (IIA) standards.
  • Share knowledge, skills, and experience with team members.
  • Perform other related duties as assigned.

The Person

For the above position, the successful applicant should meet the following criteria:

  • Bachelor’s Degree in Information Technology, Electrical Engineering, Computer Science, Business, or a Related field from a university recognized by Commission for University Education.
  • Must Possess CISA/CISM/CISSP or a related Information Systems Audit / Security certification.
  • Must Possess LPT/Offensive Security Certified Professional (OSCP)/CCIE Security/CSX Practitioner/ Certified Red Team Expert (CRTE) or a related penetration testing or red team exercise certification.
  • Master’s degree is an added advantage
  • A minimum 4 years’ experience in IT Security and/or IT Audit covering 3 years in Cyber Security Reviews and Vulnerability Assessments and 3 years in Red Team Exercises and/or Penetration Testing Experience.
  • Must possess proficiency in using penetration testing tools e.g., Kali Linux, Nessus, Nipper, Burp suite, Metasploit framework, Wireshark, Acunetix, Netsparker, Mobsf, Frida, BeEF, Objection etc.
  • Must possess proficiency in performing security assessments on operating systems, database management systems, web applications and mobile applications.
  • Must possess proficiency in the use of audit management software e.g., TeamMate.
  • Must possess excellent audit report writing and presentation skills.
  • Must possess excellent customer service skills, strong business analytical skills, superior communication, and inter-personal skills.
  • Must possess effective planning, organizing and problem-solving skills.


Method of Application

Submit your CV and Application on Company Website : Click Here

Closing Date : 29 September. 2023





Subscribe


Apply for this Job