IT Risk & Quality Assurance Specialists at CRDB Bank Tanzania
Job Role Insights
-
Date posted
2026-07-24
-
Closing date
2026-08-06
-
Hiring location
Dar es Salaam
-
Career level
Middle
-
Qualification
Bachelor Degree
-
Experience
2 Years
-
Quantity
2 person
-
Gender
both
-
Job ID
139136
Job Description
Reporting Line
SENIOR MANAGER TECHNOLOGY RISK & COMPLIANCE
Location
Tanzania Head Office
Department
DEPARTMENT OF ICT
Number of openings
2
Job Purpose
Responsible for identifying, assessing, monitoring, and reporting ICT risks across systems, applications, projects, and business processes. Maintains the ICT risk register and collaborates with stakeholders to develop, implement, and track risk treatment actions, ensuring timely resolution of identified issues. Evaluates the design and effectiveness of ICT controls and recommends enhancements to strengthen governance, risk management, and compliance practices. Conducts ICT and third-party risk assessments, provides risk advisory support for technology initiatives, and ensures alignment with applicable regulatory, legal, and data privacy requirements. Maintains ICT risk frameworks, policies, procedures, key risk indicators (KRIs), and reporting to support informed decision-making and effective risk oversight.
Principle Responsibilities
- Conduct ICT risk assessments for systems, applications, projects, and business processes to identify risks, control gaps, and areas requiring mitigation.
- Lead and coordinate Risk and Control Self-Assessments (RCSAs), ensuring risks, controls, and action plans are appropriately assessed, documented, and reported, with timely escalation of emerging risks and issues.
- Perform independent assessments of ICT controls to evaluate their design and operating effectiveness, identify control weaknesses, and recommend improvements where necessary.
- Maintain and update the ICT Risk Register, ensuring identified risks, control deficiencies, mitigation actions, and owners are accurately documented and tracked.
- Maintain and periodically review ICT frameworks, policies, procedures, standards, guidelines, process documents, and other governance artefacts, ensuring they remain current, effective, and compliant with applicable regulatory and organizational requirements.
- Collaborate with Risk, Compliance, Internal Audit, and other stakeholders to support effective risk management and assurance activities.
- Collaborate with risk and control owners to develop, implement, and monitor risk treatment plans, ensuring timely closure of identified issues.
- Develop, monitor, and report Key Risk Indicators (KRIs), risk events, and risk trends, escalating material issues as appropriate.
- Coordinate the identification, assessment, reporting, and management of ICT-related risk incidents and control failures.
- Conduct third-party risk assessments and supplier due diligence to evaluate technology, operational, compliance, and data privacy risks.
- Monitor compliance with applicable ICT-related regulatory, legal, and data privacy requirements and escalate non-compliance issues.
- Prepare and present ICT risk reports, dashboards, and management information to support effective risk oversight and informed decision-making.
- Provide risk advisory support for technology initiatives, projects, system implementations, and significant changes to ICT processes.
- Promote a culture of ICT risk awareness, accountability, and compliance across ICT functions through awareness initiatives, training programmes, and support for adherence to internal policies, regulatory requirements, and standards.
Qualifications Required
- Bachelor’s degree in computer science, Computer Information Systems, Management Information Systems or related fields.
- At least 2 years of experience in ICT risk management, technology governance, operational risk, information security risk, or compliance within banking or another regulated environment.
- At least one of the related professional certifications (COBIT, ITIL, CGEIT, CRISC, CISA, ISO27001 LA/LI, PCI DSS).
- Experience conducting technology risk assessments and maintaining enterprise or ICT risk registers.
- Practical experience engaging technology teams, business owners, vendors, auditors, and risk stakeholders.
- Technology governance frameworks and recognized practices such as COBIT, ISO 31000, ISO 27001, ITIL, NIST, and PCI DSS
- Third-party technology risk management and vendor due-diligence practices.
- Regulatory compliance, data privacy, cyber and technology-related requirements applicable to the banking sector
- Experience in policy framework design and control mapping, risk register management and GRC tooling, and data visualization for executive reporting dashboards.
CRDB Commitment
CRDB Bank is dedicated to upholding Sustainability and ESG practices and encourage applicants who share this commitment. The Bank also promotes an inclusive workplace, hence applications from women and individual with disabilities are encouraged.
It is important to note that CRDB Bank does not charge any fees for the application or recruitment process, and any requests for payment should be disregarded as they do not represent the bank’s practices.
Only Shortlisted Candidates will be Contacted.
Deadline
2026-08-06
Employment Terms
PERMANENT
Interested in this job?
13 days left to apply
