Senior Officer – Information Systems Audit at Sidian Bank in Nairobi, Kenya

    Sidian Bank logo

    Senior Officer – Information Systems Audit

    Sidian BankNairobi, Kenya

    Posted

    6 days ago

    Apply by

    31 Aug

    Full Time
    On Site
    Senior
    Banking, Insurance & Financial Services
    IT & Software

    Build your CV in minutes! Tailored for the Kenyan job market.

    Build My CV

    Job Description

    The job holder will provide independent, objective assurance on the adequacy and effectiveness of the bank's IT governance, risk management, compliance, and internal control environment. He/she will lead and oversee the planning, execution, reporting, and follow-up of complex audit assignments in line with Information Technology Assurance Frameworks (ITAF) and Standards, CBK Prudential Guidelines, and the bank's policies and internal audit methodology.

    Key Responsibilities

    • Lead comprehensive, risk-based planning for assigned audits by analyzing enterprise risks, regulatory expectations, historical audit results, emerging risks, and strategic priorities.
    • Define audit objectives, scope, and detailed test procedures that directly address inherent, residual, and emerging risks, ensuring alignment with the annual audit plan.
    • Conduct in-depth process understanding through system walkthroughs, Logs analysis, policy reviews, and stakeholder interviews to identify control gaps or vulnerabilities early.
    • Determine the appropriate audit approach, sampling methodology, nature, timing, and extent of testing using risk-based and data-driven criteria.
    • Review core banking systems, payment platforms and IT infrastructure controls.
    • Conduct vulnerability assessments and penetration tests.
    • Assess cybersecurity controls, access management and incident response.
    • Evaluate IT governance, policies, and regulatory compliance.
    • Evaluate vendor management processes, including IT service provider oversight, contract compliance, and SLA performance.
    • Review the Bank's Business Continuity Management (BCM) framework, including disaster recovery testing.
    • Perform audits in accordance with Global Internal Audit Standards (GIAS) and ISACA guidelines.
    • Provide Quality assurance on ICT projects before Go-Live.
    • Script and schedule continuous audit reports by use of CAATs.
    • Conduct forensic reviews from time to time where need arises as directed by Head Of Internal Audit.
    • Perform all other related duties as assigned from time to time.
    • Prepare high-impact, concise, and well-supported audit reports that clearly articulate issues, underlying root causes, associated risks, and practical recommendations.
    • Present audit findings confidently to departmental heads, senior management, and governance committees where required.
    • Track and monitor management action plans, validate remediation, and perform follow-up reviews to ensure the effectiveness and sustainability of corrective actions.
    • Provide independent and objective assurance on the effectiveness of the bank's IT risk management, compliance, and governance frameworks.
    • Evaluate the adequacy and operating effectiveness of controls in key risk areas and across risk types (Cyber security, Access Controls, Business continuity and System related AML risks).
    • Review and challenge the quality, completeness, and accuracy of risk assessments, KRIs, RCSAs, and mitigation plans developed by business units and second-line functions.
    • Test compliance with relevant laws, regulatory requirements, CBK guidelines, internal policies, and industry best practices.
    • Document and escalate control weaknesses, non-compliance, unethical conduct, and emerging risks promptly and in accordance with escalation protocols.
    • Provide advisory insight on new regulatory developments and business initiatives while preserving audit independence.
    • Maintain up-to-date professional knowledge on emerging ICT risks.
    • Determine the audit approach, depth of testing, and

    Required Qualifications

    • Advanced analytical, critical thinking, and problem-solving capabilities.
    • Strong report-writing and communication skills with the ability to articulate complex issues clearly.
    • High professional skepticism, attention to detail, and ability to challenge status quo effectively.
    • CISA certification mandatory; CISM, CEH, or ISO 27001 Lead Auditor an advantage.

    Job Details

    Job Function

    IT & Software

    Minimum Experience

    3 years

    Education Level

    Bachelor’s Degree

    Area of Study

    Information Technology

    Field of Study

    Information Systems Audit

    Languages

    English

    Additional Information

    How to Apply: Interested and qualified? Go to Sidian Bank on sidianbank.co.ke to apply.

    Show Your IT Audit Chops Beyond the CISA

    This role sits at the intersection of banking risk and technology, so hiring managers will probe how you've handled real audit engagements, not just your certification. Bring evidence of how you've tested IT controls, used CAATs, and communicated findings to senior stakeholders.

    1. Lead with your audit methodology: In your CV and interview, walk through your approach to planning, fieldwork, and reporting. Mention how you've aligned with ITAF, GIAS, or ISACA guidelines in past roles. Concrete examples of audit plans you've executed carry weight.

    2. Prove your technical depth: Be ready to discuss specific tools and techniques you've used for vulnerability assessments, penetration testing, or log analysis. If you've worked with core banking systems or payment platforms, highlight that. Show you can speak both tech and business.

    3. Show how you've handled regulatory audits: This bank answers to CBK, so any experience with regulatory audits or compliance testing is gold. Describe how you've ensured adherence to prudential guidelines and what you did when you found gaps.

    4. Demonstrate your communication skills: Audit reports are only useful if they're clear. Bring samples of reports you've written that turned complex findings into actionable recommendations. Practice explaining a technical issue to a non-technical audience.

    5. Prepare for scenario questions: Expect questions like 'How would you audit a new payment platform?' or 'What's your process for a forensic review?' Think through your answer step-by-step, showing your risk-based thinking and attention to detail.

    6. Highlight your continuous learning: The tech risk landscape shifts fast. Mention any recent courses, webinars, or certifications you're pursuing beyond CISA. Show you're proactive about staying current.

    7. Understand the bank's context: Research Sidian Bank's products, recent news, and any public IT initiatives. Tailor your answers to show you understand their specific risks and challenges. This signals genuine interest.

    8. Ask sharp questions: When it's your turn, ask about the team's current audit plan, the tools they use, or how they measure audit impact. This shows you're already thinking like a senior auditor.

    CareerSasa Safety Alert: Never pay employers or agencies for interviews, training, or job placement. Does a job request payment? Report it immediately using the "Flag" button. While CareerSasa vets job postings thoroughly, always verify opportunities independently.
    Share this job:

    Boost Your Application Success

    1. 1

      Expert CV help that gets you noticed. Build Your CV

    2. 2

      A personalized cover letter for this role. Write Cover Letter

    3. 3

      Attract recruiters with a stronger profile. Boost LinkedIn

    Tags

    CISA
    IT audit
    cybersecurity
    risk management
    banking