Equity Bank is one of the region’s leading banks whose purpose is to transform the lives and livelihoods of the people of Africa socially and economically by availing them modern and inclusive financial services that maximize their opportunities. With a strong footprint in Kenya, Uganda, Tanzania, Rwanda, South Sudan and DRC Congo, Equity Bank is now home to over 12 million customers - the largest customer base in Africa. Currently the Bank is seeking additional talent to serve in the role of Manager, Technology Risk.
Job Purpose:
The Manager, Technology Risk is responsible for overseeing the bank’s technology risk management framework, ensuring that risks related to IT infrastructure, cybersecurity, data protection, and digital transformation initiatives are effectively managed. This role works closely with IT, cybersecurity, and risk management teams to identify, assess, monitor, and mitigate technology-related risks while ensuring compliance with regulatory requirements and best practices.
Key Responsibilities
Technology Risk Framework Implementation
Develop, implement, and maintain the bank’s Technology Risk Management Framework in alignment with regulatory requirements and industry standards (e.g., NIST, ISO 27001, COBIT, Basel).
Ensure technology risk policies, procedures, and controls are effectively embedded across all business units.
Risk Identification, Assessment & Mitigation
- Conduct technology risk assessments, including IT control testing, risk control self-assessments (RCSA), and scenario analysis.
- Identify emerging risks related to cybersecurity threats, third-party IT risks, cloud computing, AI, and digital banking platforms.
- Implement risk mitigation measures to strengthen IT security and resilience.
Cybersecurity & Data Protection Oversight
- Work closely with the Information Security and IT teams to assess cyber threats, vulnerabilities, and incident response strategies.
- Ensure compliance with data protection laws (e.g., GDPR, Kenya Data Protection Act) and regulatory requirements.
- Monitor cybersecurity incidents and oversee remediation efforts.
Third-Party & Vendor Risk Management
- Assess technology risks associated with third-party vendors, cloud service providers, and IT outsourcing arrangements.
- Conduct due diligence and continuous monitoring of critical IT service providers.
Regulatory Compliance & Audit Coordination
- Ensure adherence to local and international regulatory requirements, including CBK ICT Risk Guidelines, Basel III, and ISO standards.
- Act as the liaison between IT, internal audit, and external regulatory bodies during technology risk audits.
- Address and close audit findings related to IT risk.
Business Continuity & Incident Management
- Support IT Disaster Recovery (DR) and Business Continuity Planning (BCP) initiatives.
- Coordinate technology risk incident response efforts and ensure timely reporting of critical IT disruptions.
Technology Risk Reporting & Governance
- Develop and present technology risk reports, dashboards, and key risk indicators (KRIs) to senior management, the Risk Committee, and Board-level governance forums.
- Track and monitor IT risk remediation plans, ensuring timely resolution of identified risks.
Training & Awareness
- Conduct technology risk awareness training for business units to promote a risk-aware culture.
- Support risk management capacity-building initiatives for IT and business teams.