ICT Risk & Compliance specialist CRDB Bank Plc Tanzania
Job Type: Full-Time
Closing Date: 30th October 2023
Location: Dar es Salaam, Tanzania

CRDB Bank PLC is looking for a suitable candidate to fill 2 vacant position of ICT Risk & Compliance specialist existing in the Department of Information & Communication Technology (ICT) at Head Office, Dar es Salaam.

 

Job Purpose:

 

Responsibilities for the Role:

  1. Coordinate regular compliance, risk, maturity and audit reviews executed within the ICT functions, including reporting progress against identified areas of improvement.
  2. Participate in implementation of technological audit and regulator recommendations to ensure compliance to both bank and regulatory requirements.
  3. Ensure all relevant ICT documents like policies, procedure, processes are reviewed regularly according to the policies and maintained.
  4. Ensures compliance with ICT security policies and the alignment of ICT procedures and policies; ensure the adherence of ICT working instructions, systems and software applications to established procedures, policies, standards and best-practices.
  5. Review all Bank’s Information Systems such as workstations and servers to ensure that they are well protected against virus attacks and are updated with latest security patches according to the policy
  6. Training users and promoting information security awareness to enhance the overall compliance with the Bank’s security standards, procedures, policies, checklists, statutory and regulatory requirements.
  7. Advise ICT team of emerging compliance issues and consults and guides the Bank in the establishment of controls to mitigate risks and ensure all employees are educated on the latest regulations and processes.
  8. Facilitate and coordinate user access reviews which will be performed quarterly and System reviews which will be performed semi-annually.
  9. Responding to all governance reports from different committee and Boards such as MARC, ORC and FPC.
  10. Perform monitoring and review the adherences of ISO 27001 and PCI standards
  11. Monitoring the compliance of licenses and vendor contracts and vendor SLA
  12. Provides guidance, evaluation and advocacy on audit findings and recommendations and ensures appropriate mitigation actions are developed and implemented in a timely manner.
  13. Undertake risk control self-assessment prior to any independent audit or assessment, report and raise any issue noted for management attention and recording.
  14. Working closely with the Department of Risk and Compliance, Internal & External auditors to ensure all system related risks and gaps identified are timely addressed.
  15. Tracking of all audit issues raised by internal and external auditors to its closure
  16. Collecting and validating all supporting evidences requested in risk assessment and audit reviews
  17. Reports all KRI (Key Risk Indicator) and RCSA (Risk Control Self-Assessment) in to Risk department on monthly basis.
  18. Performing risk assessment on Quarterly basis
  19. Updating ICT Risk register and track all gaps identify in risk assessment and act as ICT Risk champion.

 

Knowledge, Skills, Qualifications and Experiences Required for the Role.