ICT Risk Officer

The Coop LLC
United States
about 1 month ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours

Tech stack

Microsoft Windows Software System Penetration Testing Unix Control Objectives for Information and Related Technology (COBIT) Cyber Security Databases Identity and Access Management Networking Hardware IT Architecture Information Technology Network Server Vulnerability Analysis

Job description

Reporting to Head - ICT Risk and Control, the role holder will provide continuous independent assurance of the Bank’s Information Security as regards confidentiality, integrity and availability of the IT Systems by ensuring that appropriate security controls are in place to protect the Bank’s assets. The role holder will also ensure that ICT related risks are managed in compliance to the Bank’s policies, laws, regulatory guidelines and applicable standards., Specifically, the successful jobholder will be required to:

  • Carry out ICT risk assessments of Co-operative Bank systems and provide recommendation of appropriate and adequate IT security controls to mitigate and minimize ICT Risks.
  • Continuously review and improve the ICT controls in place.
  • Continuously review systems at all levels i.e. servers, applications, database, network devices etc., identify risks and make recommendations on closure of the risks.
  • Provide continuous assurance on ICT Risks on the Bank’s systems.
  • Evaluate ICT controls for all operating systems, applications, database management system interfaces and networks across the Bank to ensure consistency in achieving compliance requirements (regulatory, standards and internal policies).
  • Promote Information Security awareness within the Bank by providing consultation, guidance and conducting relevant awareness programs to ensure an IS compliant culture.
  • Proactively anticipate potential threats and vulnerabilities and provide guidance in coordination with the ICT department on effective responses or control measures to be implemented to mitigate them.
  • Manage ICT Risks registers.
  • Periodically perform vulnerability assessments & penetration tests on Bank systems and technology, identifying vulnerabilities and recommendations on closure of these vulnerabilities.

Requirements

Are you a competent and highly motivated person with a career passion in Information Security? Our ICT Risk and Control Team is looking for a detail oriented, self-driven, collaborative individual with a passion for integrity to fill the role of ICT Risk Officer., * A Bachelor’s degree in Information Technology, Information Security or Computer Science.

  • Relevant IT Security professional qualifications e.g. CISA, CISM, CEH or other relevant security certifications.
  • A minimum of 5 years working experience in a similar role in a highly computerized environment.
  • Experience in implementing Information Security Standards such as ISO 27001, COBIT.
  • Understanding of ICT risk and systems security control processes.
  • Understanding of Information Systems Architecture and operational practices.
  • Appreciation of Audit Methodologies.
  • Experience in Windows Enterprise servers or UNIX systems.
  • Experience of working in the IT function within a banking environment will be an advantage.
  • Knowledge of cybersecurity good practices (Identity and Access Management, Data Protection, Penetration Testing etc.)

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.co-opbank.co.ke

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:03 min

Microsoft integrating native Unix coreutils into Windows environments

Chris Heilmann +2 · LIVE

3:04 min

Database evolution and the funding behind vector databases

Erik Bamberg · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:04 min

Defining timestamps and the international standard format

Denny Biasiolli Denny Biasiolli · Europe 2026 Virtual

2:17 min

Governing enterprise IT as a global automotive CIO

Katrin Lehmann Katrin Lehmann +1 · Coffee With Developers

Videos

See all

Related articles

See all