Kazi Connect
Jobs in Kenya
Back to jobs
Job in Kenya

Information Risk & Business Resilience Manager Job Standard Bank

Corporate Staffing client Kenya Full Time Posted 2026-07-23
Apply at source
CountyNairobi
CityNot specified
DeadlineNot specified
SourceCorporate Staffing Kenya
SalaryOpen
information risk managerbusiness resilience managerStandard BankNairobiKenyafull-timemanagementIT riskcyber riskbankingsecurityRisk Manager

AI summary

Standard Bank is hiring an Information Risk & Business Resilience Manager to provide independent second-line oversight across information risk, data privacy, business resilience, technology risk, and cyber risk. The role requires 7-8 years experience and relevant certifications like CISA, CISM, CRISC, or CISSP. Based in Nairobi, Kenya, this is a full-time management position.

  • Strategic second-line risk position at Standard Bank
  • Requires certifications such as CISA, CISM, CRISC, CISSP, or equivalent
  • Based in Nairobi, Kenya
  • Full-time, management level role

Description

Home » Jobs In Kenya » Banking Jobs In Kenya » Information Risk & Business Resilience Manager Job Standard Bank Job Title: Information Risk & Business Resilience Manager Date Posted: 21/07/2026 Job Type: Full Time Job Level: Management Employer: Standard Bank Industry: IT Salary: Open Location: Nairobi Country: Kenya Deadline: 31/07/2026 Summary: IT Jobs, Standard Bank Jobs. Looking for an IT job in Kenya? Standard Bank is hiring an Information Risk & Business Resilience Manager skilled in information security risk, business continuity, crisis management, and operational resilience. Job Description To provide independent second-line oversight, advisory, challenge and monitoring across the overlapping risk domains of Information Risk, Data Privacy, Business Resilience, Technology Risk and Cyber Risk. The role will support the Head of Non-Financial Risk by localising Group frameworks and standards, embedding risk appetite, facilitating risk assessments and scenario analysis, coordinating assurance and remediation, and producing integrated risk insights for management and governance committees. The role is not the first-line owner of risk execution; it enables, challenges and monitors business and technology risk owners to ensure risks are identified, assessed, treated, reported and escalated within appetite This is a strategic second-line risk position for an experienced professional with the ability to translate complex and interconnected risk themes into actionable insights and governance outcomes. The role requires a strong balance of technical credibility, business pragmatism, and stakeholder influence to support growth ambitions while maintaining robust protection of clients, information assets, technology infrastructure, critical services, and regulatory confidence. Qualifications Type of Qualification: First Degree Field of Study: Information Technology, Computer Science, Information Risk Management, Information Security, Business, Commerce, Law, Finance, Audit or related discipline. Professional / Technical Certifications: At least one relevant certification is preferred Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM), Certified in Risk and Information Systems Control (CRISC), Certified Information Systems Security Professional (CISSP), ITIL, ISO 22301, ISO 27001, Certified Data Protection Officer or equivalent Experience Required 7-8 years Strong understanding of Non-Financial Risk as a second-line function and clear appreciation that business and technology remain accountable for first-line execution and control remediation. Demonstrable experience in at least three of the following domains: Information Risk, Data Privacy, Business Resilience, Technology Risk, Cyber Risk, Operational Risk, IT Audit, Technology Governance or Business Continuity. Ability to interpret Group standards and regulatory expectations and translate them into practical country implementation actions. Strong governance writing capability: must be able to prepare committee-ready risk commentary, issue escalation notes and executive summaries. Strong analytical capability and attention to detail, including comfort working with dashboards, risk registers, incident data, audit findings and action trackers. Ability to influence senior stakeholders and provide constructive challenge without compromising relationship management. High integrity, confidentiality, independence, professional scepticism and sound judgement when handling sensitive incidents, breaches, regulatory matters and risk acceptance decisions. Working knowledge of risk systems and collaboration tools, including Risk Market Place or equivalent governance, risk and compliance platforms, Microsoft Excel, PowerPoint, Word and Teams. Additional Information Behavioural Competencies: Articulating Information Developing Expertise Documenting Facts Examining Information Following Procedures Interacting with People Managing Tasks Technical Competencies: Evaluating Risk Management Effectiveness Information Security Information Security Management Cyber and Technology Risk Oversight Analytical Skills Risk Response Strategy How to Apply Click here to apply 🎯 Applying for This Job? Don’t Send a Generic CV. Don’t send the same CV to every job/employer. Have our recruitment team customize your CV to match the requirements of this specific job and improve your chances of getting an interview. Customise My CV For This Job . ⭐ 5-Star Reviews . Job Seeker Testimonials: Professionals Who Got Jobs Through Corporate Staffing Since 2011, Kenyan professionals have trusted Corporate Staffing Services to help them secure employment with leading employers in Kenya and beyond. Read testimonials from candidates who have experienced our recruitment process firsthand and successfully gotten hired through our recruitment services. You Could Be Our Next Success Story . Read How They Got Jobs Through Corporate Staffing GET A JOB FASTER! Applying for a Specif

Never pay to apply. Always confirm the original source and watch for payment requests, sensitive document requests, or unrealistic promises.