Back to jobs
Job in Kenya

Senior Officer – Information Systems Audit

Sidian Bank Nairobi , Kenya Type not specified Posted 2026-08-17
CountyNairobiCityNairobiContractType not specifiedPosted2026-08-17Close dateNot specifiedExperience3 yearsSourceOpened Career Kenya
information systems auditIT auditcybersecurityinternal auditbankingNairobiSidian Banksenior officercompliancerisk-based auditsecurityinternship
Use AI for this job

AI summary

Sidian Bank is hiring a Senior Officer – Information Systems Audit in Nairobi to lead risk-based IT audits covering core banking systems, cybersecurity, IT governance, compliance, and business continuity. The role involves planning and executing complex audit assignments, reporting findings to senior management, and monitoring remediation in line with ITAF, GIAS, CBK guidelines, and ISACA standards.

  • Lead end-to-end IT audit planning, execution, reporting, and follow-up
  • Review core banking systems, payments, cybersecurity, and IT governance
  • Conduct vulnerability assessments, penetration tests, and forensic reviews
  • Present findings to senior management and governance committees
  • Requires Bachelor’s Degree and around 3 years of experience
  • Open to both male and female candidates

AI job guide

Use this guide to check salary signals, requirements, documents, application steps and safety before you apply.

AI salary guide

Not enough public data

Not enough public salary data is available for this exact role. Before applying, prepare to ask about gross pay, benefits, contract length, probation period, transport and any allowances.

Can you qualify for this role?

  • Required3+ years of relevant experienceThe job post includes a minimum experience signal.
  • RequiredEducation or certification mentioned in the postThe captured text mentions education, a diploma, certificate, or licence.
  • PreferredPractical evidence in security, internship, segurancaThe tags and summary point to skills connected with this role.
  • RequiredAvailability to work in NairobiThe vacancy is associated with this location.

Documents to prepare

  • Likely requiredUpdated CV
  • Role specificCover letter or short employer message
  • OptionalProfessional references
  • Role specificAcademic or professional certificates
  • VerifyID or passport only after verifying the employer

Application tips for this job

  • Place your strongest Senior Officer – Information Systems Audit evidence in the first half of your CV.
  • In your cover letter or employer message, connect your experience to Sidian Bank and the role in Nairobi.
  • Add concrete examples related to security, internship, seguranca, ideally with measurable outcomes or clear responsibilities.
  • Follow the instructions from Opened Career Kenya; avoid sending documents to unofficial contacts or copied links.
  • Confirm the deadline, interview location and employer contact before sharing personal documents.
  • Prepare a polite question about pay, benefits and contract terms for later interview stages.

Source and safety check

  • Opened Career Kenya
  • Original source link available
  • Application method is clear
  • Deadline not specified
  • No major risk signal was detected in the captured text.

Never pay for interviews, shortlisting, medical checks, uniforms, or job placement. Confirm every application at the original source before sharing personal documents. Report suspicious listing.

Interview preparation

  • What experience makes you a strong fit for this Senior Officer – Information Systems Audit role in security, internship?
  • How have you handled responsibilities similar to those in this job post?
  • Are you available to work in Nairobi under the listed contract or schedule?
  • Prepare examples with clear responsibilities, tools used and measurable outcomes.
  • Review the source and research Sidian Bank before the interview.

Ask what the first priorities will be in the role and how success will be measured.

Use AI to apply better

After confirming the original source, use Career Assistant to check role fit, tailor your CV and prepare a cover letter or employer message.

Original source description

  • 2026-08-17
  • Nairobi
  • ,
  • Kenya
  • Expiration date
  • 2026-10-16
  • 3 Years
  • Gender
  • Both
  • Qualification
  • Bachelor Degree
  • Job Description

Job Purpose

The job holder will provide an independent, objective assurance on the adequacy and effectiveness of the bank’s IT governance, risk management, compliance, and internal control environment. He/she will lead and oversee the planning, execution, reporting, and follow-up of complex audit assignments in line with Information Technology Assurance Frameworks(ITAF) and Standards, CBK Prudential Guidelines, and the bank’s policies and internal audit methodology.

KEY

Responsibilities

  • Audit Planning
  • Lead comprehensive, risk-based planning for assigned audits by analyzing enterprise risks, regulatory expectations, historical audit results, emerging risks, and strategic priorities.
  • Define audit objectives, scope, and detailed test procedures that directly address inherent, residual, and emerging risks, ensuring alignment with the annual audit plan.
  • Conduct in-depth process understanding through system walkthroughs, Logs analysis, policy reviews, and stakeholder interviews to identify control gaps or vulnerabilities early.
  • Determine the appropriate audit approach, sampling methodology, nature, timing, and extent of testing using risk-based and data-driven criteria.
  • Audit Execution
  • Review core banking systems, payment platforms and IT infrastructure controls.
  • Conduct vulnerability assessments and penetration tests.
  • Assess cybersecurity controls, access management and incident response.
  • Evaluate IT governance, policies, and regulatory compliance.
  • Evaluate vendor management processes, including IT service provider oversight, contract compliance, and SLA performance.
  • Review the Bank’s Business Continuity Management (BCM) framework, including disaster recovery testing.
  • Perform audits in accordance with Global Internal Audit Standards (GIAS) and ISACA guidelines.
  • Provide Quality assurance on ICT projects before Go-Live.
  • Script and schedule continuous audit reports by use of CAATs.
  • Conduct forensic reviews from time to time where need arises as directed by Head Of Internal Audit.
  • Perform all other related duties as assigned from time to time
  • Audit Reporting, Monitoring & Follow-Up
  • Prepare high-impact, concise, and well-supported audit reports that clearly articulate issues, underlying root causes, associated risks, and practical recommendations.
  • Present audit findings confidently to departmental heads, senior management, and governance committees where required.
  • Track and monitor management action plans, validate remediation, and perform follow-up reviews to ensure the effectiveness and sustainability of corrective actions.
  • Risk & Compliance
  • Provide independent and objective assurance on the effectiveness of the bank’s IT risk management, compliance, and governance frameworks.
  • Evaluate the adequacy and operating effectiveness of controls in key risk areas and across risk types (Cyber security, Access Controls, Business continuity and System related AML risks).
  • Review and challenge the quality, completeness, and accuracy of risk assessments, KRIs, RCSAs, and mitigation plans developed by business units and second-line functions.
  • Test compliance with relevant laws, regulatory requirements, CBK guidelines, internal policies, and industry best practices.
  • Document and escalate control weaknesses, non-compliance, unethical conduct, and emerging risks promptly and in accordance with escalation protocols.
  • Provide advisory insight on new regulatory developments and business initiatives while preserving audit independence.
  • Maintain up-to-date professional knowledge on emerging ICT risks.
  • DECISION MAKING AUTHORITY
  • Determine the audit approach, depth of testing, and sampling strategies for assigned engagements based on risk assessment and professional judgment.
  • Evaluate the adequacy and effectiveness of internal controls and assign issue ratings consistent with the bank’s methodology and regulatory expectations.
  • Recommend improvements and control enhancements aligned with business realities and regulatory requirements.
  • Escalate material risks, control failures, fraud indicators, or non-compliance without delay.
  • Exercise sound judgment in balancing audit rigor, business impact, and operational practicality.
  • ACADEMIC BACKGROUND
  • Bachelor’s degree in IT, Computer Science, or related field.
  • Minimum of 3 years’

Experience

  • in IS audit, risk, forensics and security preferably in banking.
  • WORK
  • Minimum of three (3) years’
  • in IS audit, risk, forensics and security preferably in banking
  • Proven exposure to ICT banking operations audits and regulatory compliance requirements.
  • in using audit management systems and data analytics tools.
  • SKILLS & COMPETENCIES
  • Advanced analytical, critical thinking, and problem-solving capabilities.
  • Strong report-writing and communication skills with the ability to articulate complex issues clearly.
  • High professional skepticism, attention to detail, and ability to challenge status quo effectively.
  • PROFESSIONAL CERTIFICATION
  • CISA certification (mandatory); CISM, CEH, or ISO 27001 Lead Auditor an advantage.
Source and provenanceSource: Opened Career Kenya. Last checked: 2026-08-24.Kazi Connect is a job discovery service, not the employer. Always confirm the vacancy at the original source.Summaries may be AI-assisted. Report inaccurate content.
Never pay to apply. Always confirm the original source and watch for payment requests, sensitive document requests, or unrealistic promises.