Senior Manager, Information Risk
Key Responsibilities
- Provide leadership in individual Information Risk / Technology related Risk and advisory assignments for the assigned scope.
- Conduct Technology and Information risk assessments through Information Risk Managers and Analysts to develop the annual Group Information Risk action plan.
- Provide leadership in cyber security risk related reviews and advisory assignments, IT general and IT application control risk reviews on information systems and Technology environment to give assurance on the effectiveness and efficiency of the preventive control and compliance to KCB Group policies, International Standards (ISO 27001, ISO 22301, PCI DSS, NIST 800 series, etc.), and Regulatory requirements and guidelines.
- Provide leadership in emerging risks, threat hunting, Cloud computing & AI/ML by working with business functions in Technology in providing mitigations.
- Providing regular updates to group senior leadership and the board on the latest trends.
- Perform ongoing risk-based project assurance and post implementation reviews on Technology related projects.
- Coordinate Red Team exercises across the group and SWIFT attestation program in timely manner.
- Tracking of outstanding risks in DORCCO, GORCCO, CAB meetings.
- Be a member of CAB representing the Information Risk Department.
- Conduct, follow up and validate closure of PIR & KCSA review issues action plans as per stakeholder engagement agreements and track to completion within agreed timelines.
- Design and monitor implementation of Information risks awareness program across KCB Group
- Responsible for oversight and challenge of Information risks across KCB Group, including Information Security, Technology and Data quality risks.
The Person
For the above position, the successful applicant should have the following:
- Bachelor’s degree in information technology, Electrical Engineering, Computer Science, or Business (Required)
- Master’s Degree in IT, MBA, or Computer Science (Advantageous)
- Professional Qualifications: Information Risk, Security, and Business Continuity Management (BCM) certifications
- Relevant certifications in Information Security and Risk Management such as CRISC, CISM, CISSP, CISA, or equivalent (Required)
- Minimum of 6 years of total professional experience
Essential Experience to have:
- At least 6 years’ experience in Information Risk, IT Security, or IT Audit
- 5 years’ experience in Vulnerability Assessments
- 5 years’ experience with Red Team Exercises and/or Penetration Testing
- 5 years’ experience in Stakeholder Management
- 5 years’ experience in Project Management
Desired Experience to have:
- 2 years’ experience in People Management Desired
- 6 years’ experience in the Banking sector Desired
The above position is a demanding role for which the Bank will provide a competitive remuneration package to the successful candidate. If you believe you can clearly demonstrate your abilities to meet the criteria given above, please log in to our Recruitment portal and submit your application with a detailed CV.
To be considered your application must be received by Friday 7th February 2025
Qualified candidates with disability are encouraged to apply.
Only short-listed candidates will be contacted.