{"id":103158,"date":"2026-07-22T10:28:54","date_gmt":"2026-07-22T10:28:54","guid":{"rendered":"https:\/\/jobs.dataaxisnode.com\/kenya\/uncategorized\/information-risk-business-resilience-manager\/"},"modified":"2026-07-22T10:28:54","modified_gmt":"2026-07-22T10:28:54","slug":"information-risk-business-resilience-manager","status":"publish","type":"post","link":"https:\/\/jobs.dataaxisnode.com\/kenya\/jobs\/nairobi\/information-risk-business-resilience-manager\/","title":{"rendered":"Information Risk &#038; Business Resilience Manager"},"content":{"rendered":"<p><script type=\"application\/ld+json\">{\"@context\": \"https:\/\/schema.org\/\", \"@type\": \"JobPosting\", \"title\": \"Information Risk & Business Resilience Manager\", \"description\": \"Job Description\\nTo provide independent second-line oversight, advisory, challenge and monitoring across the overlapping risk domains of Information Risk, Data Privacy, Business Resilience, Technology Risk and Cyber Risk. The role will support the Head of Non-Financial Risk by localising Group frameworks and standards, embedding risk appetite, facilitating risk assessments and scenario analysis, coordinating assurance and remediation, and producing integrated risk insights for management and governance committees. The role is not the first-line owner of risk execution; it enables, challenges and monitors business and technology risk owners to ensure risks are identified, assessed, treated, reported and escalated within appetite\\nThis is a strategic second-line risk position for an experienced professional with the ability to translate complex and interconnected risk themes into actionable insights and governance outcomes. The role requires a strong balance of technical credibility, business pragmatism, and stakeholder influence to support growth ambitions while maintaining robust protection of clients, information assets, technology infrastructure, critical services, and regulatory confidence.\\nQualifications\\nType of Qualification:\u00a0First Degree\\nField of Study:\u00a0Information Technology, Computer Science, Information Risk Management, Information Security, Business, Commerce, Law, Finance, Audit or related discipline.\\nProfessional \/ Technical Certifications:\u00a0At least one relevant certification is preferred\\nCertified Information Systems Auditor CISA, Certified Information Security Manager CISM, Certified in Risk and Information Systems Control CRISC, Certified Information Systems Security Professional CISSP, ITIL, ISO 22301, ISO 27001, Certified Data Protection Officer or equivalent\\nExperience Required\\n7-8 years\\nStrong understanding of Non-Financial Risk as a second-line function and clear appreciation that business and technology remain accountable for first-line execution and control remediation.\\nDemonstrable experience in at least three of the following domains: Information Risk, Data Privacy, Business Resilience, Technology Risk, Cyber Risk, Operational Risk, IT Audit, Technology Governance or Business Continuity.\\nAbility to interpret Group standards and regulatory expectations and translate them into practical country implementation actions.\\nStrong governance writing capability: must be able to prepare committee-ready risk commentary, issue escalation notes and executive summaries.\\nStrong analytical capability and attention to detail, including comfort working with dashboards, risk registers, incident data, audit findings and action trackers.\\nAbility to influence senior stakeholders and provide constructive challenge without compromising relationship management.\\nHigh integrity, confidentiality, independence, professional scepticism and sound judgement when handling sensitive incidents, breaches, regulatory matters and risk acceptance decisions.\\nWorking knowledge of risk systems and collaboration tools, including Risk Market Place or equivalent governance, risk and compliance platforms, Microsoft Excel, PowerPoint, Word and Teams.\\nAdditional Information\\nBehavioural Competencies:\\nArticulating Information\\nDeveloping Expertise\\nDocumenting Facts\\nExamining Information\\nFollowing Procedures\\nInteracting with People\\nManaging Tasks\\nTechnical Competencies:\\nEvaluating Risk Management Effectiveness\\nInformation Security\\nInformation Security Management\\nCyber and Technology Risk Oversight\\nAnalytical Skills\\nRisk Response Strategy\", \"datePosted\": \"2026-07-21\", \"hiringOrganization\": {\"@type\": \"Organization\", \"name\": \"Standard Bank Group\"}, \"jobLocation\": {\"@type\": \"Place\", \"address\": {\"@type\": \"PostalAddress\", \"addressLocality\": \"Nairobi\", \"addressCountry\": \"KE\"}}, \"directApply\": true, \"validThrough\": \"2026-08-04T23:59:59\", \"employmentType\": \"FULL_TIME\"}<\/script><\/p>\n<p><strong>Company:<\/strong> Standard Bank Group<\/p>\n<p><strong>Location:<\/strong> Nairobi<\/p>\n<p><strong>Job Type:<\/strong> Full Time<\/p>\n<p><strong>Apply Before:<\/strong> 2026-08-04<\/p>\n<h3>Job Description<\/h3>\n<p>Job Description<br \/>To provide independent second-line oversight, advisory, challenge and monitoring across the overlapping risk domains of Information Risk, Data Privacy, Business Resilience, Technology Risk and Cyber Risk. The role will support the Head of Non-Financial Risk by localising Group frameworks and standards, embedding risk appetite, facilitating risk assessments and scenario analysis, coordinating assurance and remediation, and producing integrated risk insights for management and governance committees. The role is not the first-line owner of risk execution; it enables, challenges and monitors business and technology risk owners to ensure risks are identified, assessed, treated, reported and escalated within appetite<br \/>This is a strategic second-line risk position for an experienced professional with the ability to translate complex and interconnected risk themes into actionable insights and governance outcomes. The role requires a strong balance of technical credibility, business pragmatism, and stakeholder influence to support growth ambitions while maintaining robust protection of clients, information assets, technology infrastructure, critical services, and regulatory confidence.<br \/>Qualifications<br \/>Type of Qualification:\u00a0First Degree<br \/>Field of Study:\u00a0Information Technology, Computer Science, Information Risk Management, Information Security, Business, Commerce, Law, Finance, Audit or related discipline.<br \/>Professional \/ Technical Certifications:\u00a0At least one relevant certification is preferred<br \/>Certified Information Systems Auditor CISA, Certified Information Security Manager CISM, Certified in Risk and Information Systems Control CRISC, Certified Information Systems Security Professional CISSP, ITIL, ISO 22301, ISO 27001, Certified Data Protection Officer or equivalent<br \/>Experience Required<br \/>7-8 years<br \/>Strong understanding of Non-Financial Risk as a second-line function and clear appreciation that business and technology remain accountable for first-line execution and control remediation.<br \/>Demonstrable experience in at least three of the following domains: Information Risk, Data Privacy, Business Resilience, Technology Risk, Cyber Risk, Operational Risk, IT Audit, Technology Governance or Business Continuity.<br \/>Ability to interpret Group standards and regulatory expectations and translate them into practical country implementation actions.<br \/>Strong governance writing capability: must be able to prepare committee-ready risk commentary, issue escalation notes and executive summaries.<br \/>Strong analytical capability and attention to detail, including comfort working with dashboards, risk registers, incident data, audit findings and action trackers.<br \/>Ability to influence senior stakeholders and provide constructive challenge without compromising relationship management.<br \/>High integrity, confidentiality, independence, professional scepticism and sound judgement when handling sensitive incidents, breaches, regulatory matters and risk acceptance decisions.<br \/>Working knowledge of risk systems and collaboration tools, including Risk Market Place or equivalent governance, risk and compliance platforms, Microsoft Excel, PowerPoint, Word and Teams.<br \/>Additional Information<br \/>Behavioural Competencies:<br \/>Articulating Information<br \/>Developing Expertise<br \/>Documenting Facts<br \/>Examining Information<br \/>Following Procedures<br \/>Interacting with People<br \/>Managing Tasks<br \/>Technical Competencies:<br \/>Evaluating Risk Management Effectiveness<br \/>Information Security<br \/>Information Security Management<br \/>Cyber and Technology Risk Oversight<br \/>Analytical Skills<br \/>Risk Response Strategy<\/p>\n<h3>How to Apply<\/h3>\n<p>Interested and qualified? Go to Standard Bank Group on www.standardbank.com to apply<br \/>Build your CV for free. Download in different templates.<\/p>\n<p><a href=\"https:\/\/www.myjobmag.co.ke\/apply-now\/1284889\" target=\"_blank\" rel=\"noopener\" style=\"display:inline-block;padding:10px 20px;background:#2271b1;color:#fff;text-decoration:none;border-radius:4px;\">Apply Now<\/a><\/p>\n<p><small>Source: MyJobMag<\/small><\/p>\n<p><!-- job-expiry: 2026-08-04 --><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Company: Standard Bank Group Location: Nairobi Job Type: Full Time Apply Before: 2026-08-04 Job Description Job DescriptionTo provide independent second-line oversight, advisory, challenge and monitoring across the overlapping risk domains of Information Risk, Data Privacy, Business Resilience, Technology Risk and Cyber Risk. The role will support the Head of Non-Financial Risk by localising Group frameworks [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1408,1409],"tags":[1425,1413,1412,1534],"class_list":["post-103158","post","type-post","status-publish","format-standard","hentry","category-jobs","category-nairobi","tag-full-time","tag-job-listing","tag-myjobmag","tag-standard-bank-group"],"_links":{"self":[{"href":"https:\/\/jobs.dataaxisnode.com\/kenya\/wp-json\/wp\/v2\/posts\/103158","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/jobs.dataaxisnode.com\/kenya\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/jobs.dataaxisnode.com\/kenya\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/jobs.dataaxisnode.com\/kenya\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/jobs.dataaxisnode.com\/kenya\/wp-json\/wp\/v2\/comments?post=103158"}],"version-history":[{"count":0,"href":"https:\/\/jobs.dataaxisnode.com\/kenya\/wp-json\/wp\/v2\/posts\/103158\/revisions"}],"wp:attachment":[{"href":"https:\/\/jobs.dataaxisnode.com\/kenya\/wp-json\/wp\/v2\/media?parent=103158"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/jobs.dataaxisnode.com\/kenya\/wp-json\/wp\/v2\/categories?post=103158"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/jobs.dataaxisnode.com\/kenya\/wp-json\/wp\/v2\/tags?post=103158"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}