{"id":108733,"date":"2026-08-18T04:47:50","date_gmt":"2026-08-18T04:47:50","guid":{"rendered":"https:\/\/jobs.dataaxisnode.com\/kenya\/uncategorized\/senior-officer-information-systems-audit\/"},"modified":"2026-08-18T04:47:50","modified_gmt":"2026-08-18T04:47:50","slug":"senior-officer-information-systems-audit","status":"publish","type":"post","link":"https:\/\/jobs.dataaxisnode.com\/kenya\/jobs\/nairobi\/senior-officer-information-systems-audit\/","title":{"rendered":"Senior Officer \u2013 Information Systems Audit"},"content":{"rendered":"<p><script type=\"application\/ld+json\">{\"@context\": \"https:\/\/schema.org\/\", \"@type\": \"JobPosting\", \"title\": \"Senior Officer \u2013 Information Systems Audit\", \"description\": \"JOB PURPOSE\\nThe job holder will provide an independent, objective assurance on the adequacy and effectiveness of the bank\u2019s IT governance, risk management, compliance, and internal control environment. He\/she will lead and oversee the planning, execution, reporting, and follow-up of complex audit assignments in line with Information Technology Assurance FrameworksITAF and Standards, CBK Prudential Guidelines, and the bank\u2019s policies and internal audit methodology.\\nKEY RESPONSIBILITIES\\nAudit Planning\\nLead comprehensive, risk-based planning for assigned audits by analyzing enterprise risks, regulatory expectations, historical audit results, emerging risks, and strategic priorities.\\nDefine audit objectives, scope, and detailed test procedures that directly address inherent, residual, and emerging risks, ensuring alignment with the annual audit plan.\\nConduct in-depth process understanding through system walkthroughs, Logs analysis, policy reviews, and stakeholder interviews to identify control gaps or vulnerabilities early.\\nDetermine the appropriate audit approach, sampling methodology, nature, timing, and extent of testing using risk-based and data-driven criteria.\\nAudit Execution\\nReview core banking systems, payment platforms and IT infrastructure controls.\\nConduct vulnerability assessments and penetration tests.\\nAssess cybersecurity controls, access management and incident response.\\nEvaluate IT governance, policies, and regulatory compliance.\\nEvaluate vendor management processes, including IT service provider oversight, contract compliance, and SLA performance.\\nReview the Bank\u2019s Business Continuity Management BCM framework, including disaster recovery testing.\\nPerform audits in accordance with Global Internal Audit Standards GIAS and ISACA guidelines.\\nProvide Quality assurance on ICT projects before Go-Live.\\nScript and schedule continuous audit reports by use of CAATs.\\nConduct forensic reviews from time to time where need arises as directed by Head Of Internal Audit.\\nPerform all other related duties as assigned from time to time\\nAudit Reporting, Monitoring & Follow-Up\\nPrepare high-impact, concise, and well-supported audit reports that clearly articulate issues, underlying root causes, associated risks, and practical recommendations.\\nPresent audit findings confidently to departmental heads, senior management, and governance committees where required.\\nTrack and monitor management action plans, validate remediation, and perform follow-up reviews to ensure the effectiveness and sustainability of corrective actions.\\nRisk & Compliance\\nProvide independent and objective assurance on the effectiveness of the bank\u2019s IT risk management, compliance, and governance frameworks.\\nEvaluate the adequacy and operating effectiveness of controls in key risk areas and across risk types Cyber security, Access Controls, Business continuity and System related AML risks.\\nReview and challenge the quality, completeness, and accuracy of risk assessments, KRIs, RCSAs, and mitigation plans developed by business units and second-line functions.\\nTest compliance with relevant laws, regulatory requirements, CBK guidelines, internal policies, and industry best practices.\\nDocument and escalate control weaknesses, non-compliance, unethical conduct, and emerging risks promptly and in accordance with escalation protocols.\\nProvide advisory insight on new regulatory developments and business initiatives while preserving audit independence.\\nMaintain up-to-date professional knowledge on emerging ICT risks.\\nDECISION MAKING AUTHORITY\\nDetermine the audit approach, depth of testing, and sampling strategies for assigned engagements based on risk assessment and professional judgment.\\nEvaluate the adequacy and effectiveness of internal controls and assign issue ratings consistent with the bank\u2019s methodology and regulatory expectations.\\nRecommend improvements and control enhancements aligned with business realities and regulatory requirements.\\nEscalate material risks, control failures, fraud indicators, or non-compliance without delay.\\nExercise sound judgment in balancing audit rigor, business impact, and operational practicality.\\nACADEMIC BACKGROUND\\nBachelor\u2019s degree in IT, Computer Science, or related field.\\nMinimum of 3 years\u2019 experience in IS audit, risk, forensics and security preferably in banking.\\nWORK EXPERIENCE\\nMinimum of three 3 years\u2019 experience in IS audit, risk, forensics and security preferably in banking\\nProven exposure to ICT banking operations audits and regulatory compliance requirements.\\nExperience in using audit management systems and data analytics tools.\\nSKILLS & COMPETENCIES\\nAdvanced analytical, critical thinking, and problem-solving capabilities.\\nStrong report-writing and communication skills with the ability to articulate complex issues clearly.\\nHigh professional skepticism, attention to detail, and ability to challenge status quo effectively.\\nPROFESSIONAL CERTIFICATION\\nCISA certification mandatory; CISM, CEH, or ISO 27001 Lead Audito\", \"datePosted\": \"2026-08-17\", \"hiringOrganization\": {\"@type\": \"Organization\", \"name\": \"Sidian Bank\"}, \"jobLocation\": {\"@type\": \"Place\", \"address\": {\"@type\": \"PostalAddress\", \"addressLocality\": \"Nairobi\", \"addressCountry\": \"KE\"}}, \"directApply\": true, \"validThrough\": \"2026-08-31T23:59:59\", \"employmentType\": \"FULL_TIME\"}<\/script><\/p>\n<p><strong>Company:<\/strong> Sidian Bank<\/p>\n<p><strong>Location:<\/strong> Nairobi<\/p>\n<p><strong>Job Type:<\/strong> Full Time<\/p>\n<p><strong>Apply Before:<\/strong> 2026-08-31<\/p>\n<h3>Job Description<\/h3>\n<p>JOB PURPOSE<br \/>The job holder will provide an independent, objective assurance on the adequacy and effectiveness of the bank\u2019s IT governance, risk management, compliance, and internal control environment. He\/she will lead and oversee the planning, execution, reporting, and follow-up of complex audit assignments in line with Information Technology Assurance FrameworksITAF and Standards, CBK Prudential Guidelines, and the bank\u2019s policies and internal audit methodology.<br \/>KEY RESPONSIBILITIES<br \/>Audit Planning<br \/>Lead comprehensive, risk-based planning for assigned audits by analyzing enterprise risks, regulatory expectations, historical audit results, emerging risks, and strategic priorities.<br \/>Define audit objectives, scope, and detailed test procedures that directly address inherent, residual, and emerging risks, ensuring alignment with the annual audit plan.<br \/>Conduct in-depth process understanding through system walkthroughs, Logs analysis, policy reviews, and stakeholder interviews to identify control gaps or vulnerabilities early.<br \/>Determine the appropriate audit approach, sampling methodology, nature, timing, and extent of testing using risk-based and data-driven criteria.<br \/>Audit Execution<br \/>Review core banking systems, payment platforms and IT infrastructure controls.<br \/>Conduct vulnerability assessments and penetration tests.<br \/>Assess cybersecurity controls, access management and incident response.<br \/>Evaluate IT governance, policies, and regulatory compliance.<br \/>Evaluate vendor management processes, including IT service provider oversight, contract compliance, and SLA performance.<br \/>Review the Bank\u2019s Business Continuity Management BCM framework, including disaster recovery testing.<br \/>Perform audits in accordance with Global Internal Audit Standards GIAS and ISACA guidelines.<br \/>Provide Quality assurance on ICT projects before Go-Live.<br \/>Script and schedule continuous audit reports by use of CAATs.<br \/>Conduct forensic reviews from time to time where need arises as directed by Head Of Internal Audit.<br \/>Perform all other related duties as assigned from time to time<br \/>Audit Reporting, Monitoring &#038; Follow-Up<br \/>Prepare high-impact, concise, and well-supported audit reports that clearly articulate issues, underlying root causes, associated risks, and practical recommendations.<br \/>Present audit findings confidently to departmental heads, senior management, and governance committees where required.<br \/>Track and monitor management action plans, validate remediation, and perform follow-up reviews to ensure the effectiveness and sustainability of corrective actions.<br \/>Risk &#038; Compliance<br \/>Provide independent and objective assurance on the effectiveness of the bank\u2019s IT risk management, compliance, and governance frameworks.<br \/>Evaluate the adequacy and operating effectiveness of controls in key risk areas and across risk types Cyber security, Access Controls, Business continuity and System related AML risks.<br \/>Review and challenge the quality, completeness, and accuracy of risk assessments, KRIs, RCSAs, and mitigation plans developed by business units and second-line functions.<br \/>Test compliance with relevant laws, regulatory requirements, CBK guidelines, internal policies, and industry best practices.<br \/>Document and escalate control weaknesses, non-compliance, unethical conduct, and emerging risks promptly and in accordance with escalation protocols.<br \/>Provide advisory insight on new regulatory developments and business initiatives while preserving audit independence.<br \/>Maintain up-to-date professional knowledge on emerging ICT risks.<br \/>DECISION MAKING AUTHORITY<br \/>Determine the audit approach, depth of testing, and sampling strategies for assigned engagements based on risk assessment and professional judgment.<br \/>Evaluate the adequacy and effectiveness of internal controls and assign issue ratings consistent with the bank\u2019s methodology and regulatory expectations.<br \/>Recommend improvements and control enhancements aligned with business realities and regulatory requirements.<br \/>Escalate material risks, control failures, fraud indicators, or non-compliance without delay.<br \/>Exercise sound judgment in balancing audit rigor, business impact, and operational practicality.<br \/>ACADEMIC BACKGROUND<br \/>Bachelor\u2019s degree in IT, Computer Science, or related field.<br \/>Minimum of 3 years\u2019 experience in IS audit, risk, forensics and security preferably in banking.<br \/>WORK EXPERIENCE<br \/>Minimum of three 3 years\u2019 experience in IS audit, risk, forensics and security preferably in banking<br \/>Proven exposure to ICT banking operations audits and regulatory compliance requirements.<br \/>Experience in using audit management systems and data analytics tools.<br \/>SKILLS &#038; COMPETENCIES<br \/>Advanced analytical, critical thinking, and problem-solving capabilities.<br \/>Strong report-writing and communication skills with the ability to articulate complex issues clearly.<br \/>High professional skepticism, attention to detail, and ability to challenge status quo effectively.<br \/>PROFESSIONAL CERTIFICATION<br \/>CISA certification mandatory; CISM, CEH, or ISO 27001 Lead Auditor an advantage.<\/p>\n<h3>How to Apply<\/h3>\n<p>Interested and qualified? Go to Sidian Bank on sidianbank.co.ke to apply<br \/>Build your CV for free. Download in different templates.<\/p>\n<p><a href=\"https:\/\/www.myjobmag.co.ke\/apply-now\/1309320\" target=\"_blank\" rel=\"noopener\" style=\"display:inline-block;padding:10px 20px;background:#2271b1;color:#fff;text-decoration:none;border-radius:4px;\">Apply Now<\/a><\/p>\n<p><small>Source: MyJobMag<\/small><\/p>\n<p><!-- job-expiry: 2026-08-31 --><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Company: Sidian Bank Location: Nairobi Job Type: Full Time Apply Before: 2026-08-31 Job Description JOB PURPOSEThe job holder will provide an independent, objective assurance on the adequacy and effectiveness of the bank\u2019s IT governance, risk management, compliance, and internal control environment. He\/she will lead and oversee the planning, execution, reporting, and follow-up of complex audit [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1408,1409],"tags":[1425,1413,1412,2562],"class_list":["post-108733","post","type-post","status-publish","format-standard","hentry","category-jobs","category-nairobi","tag-full-time","tag-job-listing","tag-myjobmag","tag-sidian-bank"],"_links":{"self":[{"href":"https:\/\/jobs.dataaxisnode.com\/kenya\/wp-json\/wp\/v2\/posts\/108733","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/jobs.dataaxisnode.com\/kenya\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/jobs.dataaxisnode.com\/kenya\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/jobs.dataaxisnode.com\/kenya\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/jobs.dataaxisnode.com\/kenya\/wp-json\/wp\/v2\/comments?post=108733"}],"version-history":[{"count":0,"href":"https:\/\/jobs.dataaxisnode.com\/kenya\/wp-json\/wp\/v2\/posts\/108733\/revisions"}],"wp:attachment":[{"href":"https:\/\/jobs.dataaxisnode.com\/kenya\/wp-json\/wp\/v2\/media?parent=108733"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/jobs.dataaxisnode.com\/kenya\/wp-json\/wp\/v2\/categories?post=108733"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/jobs.dataaxisnode.com\/kenya\/wp-json\/wp\/v2\/tags?post=108733"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}