Localisation
Reporting Line DIRECTOR OF ICT Location Tanzania Head Office Department DEPARTMENT OF ICT Number of openings 1 Job Purpose The position entails establishing strategic direction, ensuring robust governance, and maintaining rigorous oversight across the Bank’s Technology Risk Management, IT Controls Assurance, Technology Audit Coordination, Vulnerability & Patch Management, Regulatory Compliance, and Technology Risk Reporting functions. The position is responsible for proactively identifying, evaluating, addressing, tracking, and escalating ICT risks to align with the Bank’s risk appetite, regulatory obligations, cybersecurity frameworks, and industry standards. Serving as the key liaison among ICT, Risk Management, Internal Audit, Compliance, Cybersecurity, Regulatory bodies, and External Auditors, the role ensures robust technology governance, verifies control effectiveness, and drives ongoing enhancements to the Bank’s technology risk framework. Principle Responsibilities Provide strategic direction and leadership for all Technology Risk & Compliance initiatives throughout the Bank. To construct and sustain an organization-wide Technology Risk Management framework, along with defining and overseeing technology risk governance structures, policies, procedures, standards, and controls, is a key responsibility. This role involves establishing robust governance mechanisms and ensuring alignment with enterprise objectives, while continuously refining and enforcing risk management protocols across the organization. Ensure alignment of Technology Risk and Compliance practices with the Bank’s strategic objectives, regulatory obligations, and established industry benchmarks. Lead the annual planning, budgeting, and performance management processes for the Technology Risk & Compliance function, establishing SMART objectives and conducting evaluations for direct reports. You will be responsible for identifying, assessing, monitoring, and reporting ICT risks while maintaining the accuracy and upkeep of the Technology Risk Register, in addition to leading Risk and Control Self-Assessments (ROSA) across all ICT functions. Monitor and assess evolving technology-related risk trends, key risk indicators (Kris), incidents, and emerging threats, while ensuring comprehensive risk mitigation strategies are formulated, executed, and diligently tracked to completion. Deliver autonomous evaluations and validation of the efficacy of technology risk controls, develop and oversee the Technology Controls Assurance Program, and verify the design and operational effectiveness of critical technology controls.
- Responsible for conducting control reviews across infrastructure, applications, cloud services, cybersecurity, data protection, and third-party technology services, while ensuring remediation efforts for identified control weaknesses are implemented and progress is tracked to closure. Lead the coordination and execution of ICT-related internal audits, external audits, regulatory examinations, and compliance reviews, ensuring timely and effective responses to audit observations, regulatory findings, and management action plans while overseeing the resolution and closure of audit and regulatory issues within established deadlines. Act as the principal point of
[Click the Apply button below to apply, and Create my CV to build a CV tailored to this offer, professionally]