Senior Manager, Information Risk
Kenya
KCB Group
- Provide leadership in individual Information Risk / Technology related Risk and advisory assignments for the assigned scope.
- Conduct Technology and Information risk assessments through Information Risk Managers and Analysts to develop the annual Group Information Risk action plan.
- Provide leadership in cyber security risk related reviews and advisory assignments, IT general and IT application control risk reviews on information systems and Technology environment to give assurance on the effectiveness and efficiency of the preventive control and compliance to KCB Group policies, International Standards (ISO 27001, ISO 22301, PCI DSS, NIST 800 series, etc.), and Regulatory requirements and guidelines.
- Provide leadership in emerging risks, threat hunting, Cloud computing & AI/ML by working with business functions in Technology in providing mitigations.
- Providing regular updates to group senior leadership and the board on the latest trends.
- Perform ongoing risk-based project assurance and post implementation reviews on Technology related projects.
- Coordinate Red Team exercises across the group and SWIFT attestation program in timely manner.
- Tracking of outstanding risks in DORCCO, GORCCO, CAB meetings.
- Be a member of CAB representing the Information Risk Department.
- Conduct, follow up and validate closure of PIR & KCSA review issues action plans as per stakeholder engagement agreements and track to completion within agreed timelines.
- Design and monitor implementation of Information risks awareness program across KCB Group
- Responsible for oversight and challenge of Information risks across KCB Group, including Information Security, Technology and Data quality risks.
MINIMUM POSITION REQUIREMENTS
- Academic & Professional
Need
Type[1]
Education Bachelor’s Degree Information Technology, Electrical Engineering, Computer Science, Business RQ Professional Qualifications – Information Risk, Security and BCM Relevant certifications in Information Security and Risk Management knowledge areas such as CRISC, CISM, CISSP, CISA or equivalent. RQ Master’s Degree IT, MBA, Computer Science AA
2. Experience
Total Minimum No of Years’ Experience Required 6 Detail
Minimum
No of Years
Need Type[2]- Experience Information Risk /or IT Security and/or IT Audit
- Vulnerability Assessments Experience
- Red Team Exercises and / or Penetration Testing Experience
- Stakeholder management
- People management
- Banking/Financial Services
- Project Management
[2]Need Types are ESSENTIAL if minimum years are required.
Any experience a staff has in in areas with blanks is an ADDED ADVANTAGE.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Audits Banking CISA CISM CISSP Cloud Compliance Computer Science CRISC ISO 22301 ISO 27001 NIST PCI DSS Pentesting Red team Risk assessment Risk management
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.