Manager, Cyber Security Audit
2026-02-20T16:07:04+00:00
KCB Bank Kenya
https://cdn.greatkenyanjobs.com/jsjobsdata/data/employer/comp_8992/logo/kCB.png
https://ke.kcbgroup.com/
FULL_TIME
Nairobi
Nairobi
00100
Kenya
Finance
Management, Computer & IT, Business Operations
2026-03-06T17:00:00+00:00
8
Kenya Commercial Bank Limited is registered as a non-operating holding company which started operations as a licensed banking institution with effect from January 1, 2016. The holding company oversees KCB Kenya - incorporated with effect from January 1, 2016 - and all KCB's regional units in Uganda, Tanzania, Rwanda, Burundi, Ethiopia and South Sudan. It als...
Responsibilities or duties
- Conduct cyber risk assessment for assigned cyber security audit and advisory assignments.
- Perform independent threat and vulnerability assessment and penetration test audits of the bank’s ICT systems to assess the effectiveness of the cybersecurity control framework and report on cyber risks noted.
- Serve as an objective and independent advisor to business functions by providing assurance that cyber security operations and processes conform to current KCB group policies and procedures, regulatory requirements as well as applicable legislation.
- Conduct walkthroughs, testing of controls, and negotiating potential issues for Technology audits within the cybersecurity and infrastructure portfolio, including scope areas such as identity and access management, asset classification, network security, operating system security, database security, web application security, mobile application security, public cloud (AWS/GCP/Azure) environments, vulnerability management, endpoint protection, etc.
- Identify and evaluate significant cyber security risk exposures and contribute to the improvement of technology risk management and control systems.
- Ensure cyber security audits are performed in accordance with the International Professional Practices Framework (IPPF) and the bank’s internal audit methodology.
- Documents the results of audit work in accordance with internal audit guidelines and the Institute of Internal Auditors (IIA) standards.
- Maintain respectful and effective communications and relationships with key stakeholders pre, during and post audit assignments to ensure alignment of audit objectives to Bank strategy.
- Follow up on the implementation of audit recommendations, identifying and reporting any gaps that may derail implementation of audit recommendations.
- Keep the organisation updated on cyber security industry trends, regulatory changes, and best practices in internal auditing as well as developments in the Banking industry and business environments that would inform the quality of the audit and quality assurance
Qualifications or requirements
ACADEMIC & PROFESSIONAL
Education
- Bachelor’s Degree
- Information Technology, Electrical Engineering, Computer Science RQ
- Professional Qualifications – Information Systems Audit / Security
- CISA/CISM/CISSP AA
- Professional Qualifications – Vulnerability Assessment and Penetration Testing
- OSCP/ CCIE Security / CRTO / CRTP/ CRTE / CRTM /CPTS RQ
- Master’s Degree
- IT, MBA, Computer Science AA
Experience Needed
Total Minimum No of Years’ Experience Required
4 Years
Detail Minimum No of Years Need Type[2]
Cyber Security Reviews, Vulnerability Assessments and Penetration Testing Experience 4 ES
IT Security and/or IT Audit 3 ES
Red Team Exercises 1 AA
Stakeholder management 2 ES
- Conduct cyber risk assessment for assigned cyber security audit and advisory assignments.
- Perform independent threat and vulnerability assessment and penetration test audits of the bank’s ICT systems to assess the effectiveness of the cybersecurity control framework and report on cyber risks noted.
- Serve as an objective and independent advisor to business functions by providing assurance that cyber security operations and processes conform to current KCB group policies and procedures, regulatory requirements as well as applicable legislation.
- Conduct walkthroughs, testing of controls, and negotiating potential issues for Technology audits within the cybersecurity and infrastructure portfolio, including scope areas such as identity and access management, asset classification, network security, operating system security, database security, web application security, mobile application security, public cloud (AWS/GCP/Azure) environments, vulnerability management, endpoint protection, etc.
- Identify and evaluate significant cyber security risk exposures and contribute to the improvement of technology risk management and control systems.
- Ensure cyber security audits are performed in accordance with the Internation Professional Practices Framework (IPPF) and the bank’s internal audit methodology.
- Documents the results of audit work in accordance with internal audit guidelines and the Institute of Internal Auditors (IIA) standards.
- Maintain respectful and effective communications and relationships with key stakeholders pre, during and post audit assignments to ensure alignment of audit objectives to Bank strategy.
- Follow up on the implementation of audit recommendations, identifying and reporting any gaps that may derail implementation of audit recommendations.
- Keep the organisation updated on cyber security industry trends, regulatory changes, and best practices in internal auditing as well as developments in the Banking industry and business environments that would inform the quality of the audit and quality assurance
- Cyber Security Reviews
- Vulnerability Assessments
- Penetration Testing
- IT Security
- IT Audit
- Red Team Exercises
- Stakeholder management
- Bachelor’s Degree in Information Technology, Electrical Engineering, or Computer Science
- Professional Qualifications – Information Systems Audit / Security (CISA/CISM/CISSP)
- Professional Qualifications – Vulnerability Assessment and Penetration Testing (OSCP/ CCIE Security / CRTO / CRTP/ CRTE / CRTM /CPTS)
- Master’s Degree in IT, MBA, or Computer Science
JOB-699886a8cab2d
Vacancy title:
Manager, Cyber Security Audit
[Type: FULL_TIME, Industry: Finance, Category: Management, Computer & IT, Business Operations]
Jobs at:
KCB Bank Kenya
Deadline of this Job:
Friday, March 6 2026
Duty Station:
Nairobi | Nairobi
Summary
Date Posted: Friday, February 20 2026, Base Salary: Not Disclosed
Similar Jobs in Kenya
Learn more about KCB Bank Kenya
KCB Bank Kenya jobs in Kenya
JOB DETAILS:
Kenya Commercial Bank Limited is registered as a non-operating holding company which started operations as a licensed banking institution with effect from January 1, 2016. The holding company oversees KCB Kenya - incorporated with effect from January 1, 2016 - and all KCB's regional units in Uganda, Tanzania, Rwanda, Burundi, Ethiopia and South Sudan. It als...
Responsibilities or duties
- Conduct cyber risk assessment for assigned cyber security audit and advisory assignments.
- Perform independent threat and vulnerability assessment and penetration test audits of the bank’s ICT systems to assess the effectiveness of the cybersecurity control framework and report on cyber risks noted.
- Serve as an objective and independent advisor to business functions by providing assurance that cyber security operations and processes conform to current KCB group policies and procedures, regulatory requirements as well as applicable legislation.
- Conduct walkthroughs, testing of controls, and negotiating potential issues for Technology audits within the cybersecurity and infrastructure portfolio, including scope areas such as identity and access management, asset classification, network security, operating system security, database security, web application security, mobile application security, public cloud (AWS/GCP/Azure) environments, vulnerability management, endpoint protection, etc.
- Identify and evaluate significant cyber security risk exposures and contribute to the improvement of technology risk management and control systems.
- Ensure cyber security audits are performed in accordance with the International Professional Practices Framework (IPPF) and the bank’s internal audit methodology.
- Documents the results of audit work in accordance with internal audit guidelines and the Institute of Internal Auditors (IIA) standards.
- Maintain respectful and effective communications and relationships with key stakeholders pre, during and post audit assignments to ensure alignment of audit objectives to Bank strategy.
- Follow up on the implementation of audit recommendations, identifying and reporting any gaps that may derail implementation of audit recommendations.
- Keep the organisation updated on cyber security industry trends, regulatory changes, and best practices in internal auditing as well as developments in the Banking industry and business environments that would inform the quality of the audit and quality assurance
Qualifications or requirements
ACADEMIC & PROFESSIONAL
Education
- Bachelor’s Degree
- Information Technology, Electrical Engineering, Computer Science RQ
- Professional Qualifications – Information Systems Audit / Security
- CISA/CISM/CISSP AA
- Professional Qualifications – Vulnerability Assessment and Penetration Testing
- OSCP/ CCIE Security / CRTO / CRTP/ CRTE / CRTM /CPTS RQ
- Master’s Degree
- IT, MBA, Computer Science AA
Experience Needed
Total Minimum No of Years’ Experience Required
4 Years
Detail Minimum No of Years Need Type[2]
Cyber Security Reviews, Vulnerability Assessments and Penetration Testing Experience 4 ES
IT Security and/or IT Audit 3 ES
Red Team Exercises 1 AA
Stakeholder management 2 ES
Work Hours: 8
Experience in Months: 48
Level of Education: postgraduate degree
Job application procedure
Never pay for any notarisation, certificate or assessment as part of any recruitment process. When in doubt, contact us
Click Here to Apply Now
All Jobs | QUICK ALERT SUBSCRIPTION