All jobs

From the employer's hiring system · Verified employer

Manager, Technology (IT) Risk

Equity Group Holdings PLC

View job & apply

Job at a glance

Employer
Equity Group Holdings PLC
Position
Manager, Technology (IT) Risk
Location
Kenya
Experience
5-7 years in tech risk/cybersecurity/audit
Education
Bachelor’s degree in CS, IT, Risk, or Cybersecurity
Salary
Not stated in the advert
Application deadline
Open until filled (listed until 25 October 2026)
Posted on VacancyKE
8 October 2026

VacancyKE summary

Equity Group Holdings PLC is hiring a Manager, Technology (IT) Risk to oversee the bank’s technology risk management framework. You will manage risks related to IT infrastructure, cybersecurity, and data protection while ensuring regulatory compliance.

What stands out about this opportunity

  • Focus on cybersecurity and data protection oversight
  • Requires knowledge of specific frameworks like NIST and ISO 27001
  • Role involves liaising with auditors and regulators

Key responsibilities

  • Develop and maintain the Technology Risk Management Framework aligned with NIST, ISO 27001, COBIT, and Basel standards.
  • Conduct technology risk assessments, including IT control testing, RCSAs, and scenario analysis.
  • Identify emerging risks in cybersecurity, third-party IT, cloud computing, AI, and digital banking.
  • Assess cyber threats and vulnerabilities alongside Information Security and IT teams.
  • Ensure compliance with GDPR, Kenya Data Protection Act, and other regulatory requirements.
  • Monitor cybersecurity incidents and oversee remediation efforts.
  • Assess risks associated with third-party vendors and conduct due diligence on critical IT providers.
  • Coordinate with internal audit and regulators during technology risk audits.

Who should apply?

This role suits experienced professionals with a background in technology risk or cybersecurity within the banking sector, holding relevant degrees and preferably professional certifications like CISA or CISSP.

Key requirements

  • 5-7 years' tech risk experience
  • Bachelor's in CS/IT/Risk/Cybersecurity
  • Knowledge of CBK/Basel/NIST/ISO
  • Experience in banking/financial services

Nice to have

  • Master’s degree in a relevant field.
  • Professional certifications such as CISA, CRISC, CISSP, or ITIL.

How to apply

  • Apply via the Equity Bank careers portal using job reference 2600016G.

Official source: From the employer's hiring system · equitybank.taleo.net. VacancyKE never charges job seekers.

View job & apply

Original employer advertisement

Published by Equity Group Holdings PLC on equitybank.taleo.net. Shown for reference; the employer’s version is the official one.

The employer’s advert
Equity Group Holdings PLC is a leading financial services provider in Africa, committed to transforming lives and fostering socio-economic prosperity. Guided by its purpose of giving dignity and expanding opportunities for wealth creation, the Group’s vision is to champion socio-economic progress across the continent. Its mission focuses on delivering integrated financial services that empower individuals, businesses, and communities socially and economically. Equity positions itself as an inclusive financial institution, offering solutions that restore dignity and create opportunities, under the tagline “Your Listening, Caring Partner” and motto “Growing Together in Trust.”
The Group’s core values—integrity, customer focus, innovation, and accountability—shape its culture and operations. Equity provides a comprehensive range of services, including retail, SME, and corporate banking, insurance, investment products, and digital solutions such as Equitel and Finserve. With a strong emphasis on financial inclusion and digital transformation, Equity leverages technology and strategic partnerships to serve diverse markets and promote access to financial services across Africa.
Job Purpose:
The Manager, Technology (IT) Risk is responsible for overseeing the bank’s technology risk management framework, ensuring that risks related to IT infrastructure, cybersecurity, data protection, and digital transformation initiatives are effectively managed. This role works closely with IT, cybersecurity, and risk management teams to identify, assess, monitor, and mitigate technology-related risks while ensuring compliance with regulatory requirements and best practices.
Key Responsibilities:
Technology Risk Framework Implementation

• Develop, implement, and maintain the bank’s Technology Risk Management Framework in alignment with regulatory requirements and industry standards (e.g., NIST, ISO 27001, COBIT, Basel).

• Ensure technology risk policies, procedures, and controls are effectively embedded across all business units.

Risk Identification, Assessment & Mitigation

• Conduct technology risk assessments, including IT control testing, risk control self-assessments (RCSA), and scenario analysis.

• Identify emerging risks related to cybersecurity threats, third-party IT risks, cloud computing, AI, and digital banking platforms.

• Implement risk mitigation measures to strengthen IT security and resilience.

Cybersecurity & Data Protection Oversight

• Work closely with the Information Security and IT teams to assess cyber threats, vulnerabilities, and incident response strategies.

• Ensure compliance with data protection laws (e.g., GDPR, Kenya Data Protection Act) and regulatory requirements.

• Monitor cybersecurity incidents and oversee remediation efforts.

Third-Party & Vendor Risk Management

• Assess technology risks associated with third-party vendors, cloud service providers, and IT outsourcing arrangements.

• Conduct due diligence and continuous monitoring of critical IT service providers.

Regulatory Compliance & Audit Coordination

• Ensure adherence to local and international regulatory requirements, including CBK ICT Risk Guidelines, Basel III, and ISO standards.

• Act as the liaison between IT, internal audit, and external regulatory bodies during technology risk audits.

• Address and close audit findings related to IT risk.

Business Continuity & Incident Management

• Support IT Disaster Recovery (DR) and Business Continuity Planning (BCP) initiatives.

• Coordinate technology risk incident response efforts and ensure timely reporting of critical IT disruptions.

Technology Risk Reporting & Governance

• Develop and present technology risk reports, dashboards, and key risk indicators (KRIs) to senior management, the Risk Committee, and Board-level governance forums.

• Track and monitor IT risk remediation plans, ensuring timely resolution of identified risks.

Training & Awareness

• Conduct technology risk awareness training for business units to promote a risk-aware culture.

• Support risk management capacity-building initiatives for IT and business teams.

Education and Qualifications

• Education: Bachelor’s degree in computer science, Information Technology, Risk Management, Cybersecurity, or a related field. A master’s degree is an added advantage.

• Certifications: Professional certifications such as CISA (Certified Information Systems Auditor), CRISC (Certified in Risk and Information Systems Control), CISSP (Certified Information Systems Security Professional), or ITIL (Information Technology Infrastructure Library) are highly preferred.

• Experience: Minimum of 5-7 years of experience in technology risk management, IT security, cybersecurity, or audit in the banking or financial services industry.

• Regulatory Knowledge: Strong understanding of CBK ICT Risk Guidelines, Basel Accords, NIST Cybersecurity Framework, GDPR, Kenya Data Protection Act, and ISO 27001.

Key Skills and Competencies:

• Technology Risk Management – Expertise in IT risk identification, mitigation, and monitoring.

• Cybersecurity & Information Security – Strong understanding of cyber threats, vulnerability management, and data protection regulations.

• IT Governance & Compliance – Knowledge of COBIT, ITIL, and regulatory requirements for technology risk management.

• Incident & Crisis Management – Ability to handle IT incidents, cyber breaches, and business continuity disruptions.

• Audit & Assurance – Experience in conducting IT risk assessments, internal audits, and regulatory compliance reviews.