Localisation
Reporting Line DIRECTOR OF ICT Location Tanzania Head Office Department DEPARTMENT OF ICT Number of openings 1 Job Purpose The role involves overseeing the strategic direction, governance, and comprehensive management of the Bank’s Technology Risk Management, IT Controls Assurance, Technology Audit Coordination, Vulnerability & Patch Management, Regulatory Compliance, and Technology Risk Reporting functions. This position is responsible for the proactive identification, assessment, mitigation, monitoring, and reporting of ICT risks in accordance with the Bank’s risk appetite, regulatory obligations, cybersecurity frameworks, and industry best practices. It serves as the primary liaison between ICT, Risk Management, Internal Audit, Compliance, Cybersecurity, Regulators, and External Auditors to uphold robust technology governance, validate control effectiveness, and drive continuous enhancement of the Bank’s technology risk posture. Principle Responsibilities Provide high-level strategic guidance and oversight for all Technology Risk & Compliance initiatives throughout the Bank. Develop and sustain a comprehensive, organization-wide Technology Risk Management framework while instituting and overseeing robust technology risk governance structures, including policies, procedures, standards, and controls.
Spearhead the alignment of Technology Risk and Compliance practices with the Bank’s strategic objectives, regulatory mandates, and established industry benchmarks. Lead the annual planning, budgeting, and performance management processes for the Technology Risk & Compliance function, establish SMART objectives, and assess the performance of direct reports. Responsibilities include directing the identification, evaluation, and continuous monitoring of ICT risks, maintaining the integrity and precision of the Technology Risk Register, and spearheading Risk and Control Self-Assessments (ROSA) across all ICT functions. Monitor technology risk trends, key risk indicators (Kris), incidents, and evolving threats, while overseeing the development, execution, and follow-up of risk mitigation strategies until resolution. Offer independent assessments and validation of the efficacy of technology risk controls, while developing and overseeing the Technology Controls Assurance Program, and conducting thorough evaluations of both the design and operational effectiveness of critical technology controls. Oversee comprehensive control reviews encompassing infrastructure, applications, cloud services, cybersecurity, data protection, and third-party technology services, ensuring prompt remediation of identified control weaknesses and diligent progress tracking toward resolution. Lead comprehensive ICT audits—including internal and external assessments, regulatory examinations, and compliance reviews—while coordinating responses to audit findings, regulatory directives, and management action plans. Additionally, oversee the timely resolution and monitoring of audit and regulatory issues to ensure alignment with established deadlines. As the primary point of
[Click the Apply button below to apply, and Create my CV to build a CV tailored to this offer, professionally]