IT Risk & Quality Assurance Specialists at CRDB Bank Tanzania

Job Role Insights

  • Date posted

    2026-07-24

  • Closing date

    2026-08-06

  • Hiring location

    Dar es Salaam

  • Career level

    Middle

  • Qualification

    Bachelor Degree

  • Experience

    2 Years

  • Quantity

    2 person

  • Gender

    both

  • Job ID

    139136

Job Description

Reporting Line

SENIOR MANAGER TECHNOLOGY RISK & COMPLIANCE

Location

Tanzania Head Office

Department

DEPARTMENT OF ICT

Number of openings

2

Job Purpose

Responsible for identifying, assessing, monitoring, and reporting ICT risks across systems, applications, projects, and business processes. Maintains the ICT risk register and collaborates with stakeholders to develop, implement, and track risk treatment actions, ensuring timely resolution of identified issues. Evaluates the design and effectiveness of ICT controls and recommends enhancements to strengthen governance, risk management, and compliance practices. Conducts ICT and third-party risk assessments, provides risk advisory support for technology initiatives, and ensures alignment with applicable regulatory, legal, and data privacy requirements. Maintains ICT risk frameworks, policies, procedures, key risk indicators (KRIs), and reporting to support informed decision-making and effective risk oversight.

Principle Responsibilities

  • Conduct ICT risk assessments for systems, applications, projects, and business processes to identify risks, control gaps, and areas requiring mitigation.
  • Lead and coordinate Risk and Control Self-Assessments (RCSAs), ensuring risks, controls, and action plans are appropriately assessed, documented, and reported, with timely escalation of emerging risks and issues.
  • Perform independent assessments of ICT controls to evaluate their design and operating effectiveness, identify control weaknesses, and recommend improvements where necessary.
  • Maintain and update the ICT Risk Register, ensuring identified risks, control deficiencies, mitigation actions, and owners are accurately documented and tracked.
  • Maintain and periodically review ICT frameworks, policies, procedures, standards, guidelines, process documents, and other governance artefacts, ensuring they remain current, effective, and compliant with applicable regulatory and organizational requirements.
  • Collaborate with Risk, Compliance, Internal Audit, and other stakeholders to support effective risk management and assurance activities.
  • Collaborate with risk and control owners to develop, implement, and monitor risk treatment plans, ensuring timely closure of identified issues.
  • Develop, monitor, and report Key Risk Indicators (KRIs), risk events, and risk trends, escalating material issues as appropriate.
  • Coordinate the identification, assessment, reporting, and management of ICT-related risk incidents and control failures.
  • Conduct third-party risk assessments and supplier due diligence to evaluate technology, operational, compliance, and data privacy risks.
  • Monitor compliance with applicable ICT-related regulatory, legal, and data privacy requirements and escalate non-compliance issues.
  • Prepare and present ICT risk reports, dashboards, and management information to support effective risk oversight and informed decision-making.
  • Provide risk advisory support for technology initiatives, projects, system implementations, and significant changes to ICT processes.
  • Promote a culture of ICT risk awareness, accountability, and compliance across ICT functions through awareness initiatives, training programmes, and support for adherence to internal policies, regulatory requirements, and standards.

Qualifications Required

  • Bachelor’s degree in computer science, Computer Information Systems, Management Information Systems or related fields.
  • At least 2 years of experience in ICT risk management, technology governance, operational risk, information security risk, or compliance within banking or another regulated environment.
  • At least one of the related professional certifications (COBIT, ITIL, CGEIT, CRISC, CISA, ISO27001 LA/LI, PCI DSS).
  • Experience conducting technology risk assessments and maintaining enterprise or ICT risk registers.
  • Practical experience engaging technology teams, business owners, vendors, auditors, and risk stakeholders.
  • Technology governance frameworks and recognized practices such as COBIT, ISO 31000, ISO 27001, ITIL, NIST, and PCI DSS
  • Third-party technology risk management and vendor due-diligence practices.
  • Regulatory compliance, data privacy, cyber and technology-related requirements applicable to the banking sector
  • Experience in policy framework design and control mapping, risk register management and GRC tooling, and data visualization for executive reporting dashboards.

CRDB Commitment

CRDB Bank is dedicated to upholding Sustainability and ESG practices and encourage applicants who share this commitment. The Bank also promotes an inclusive workplace, hence applications from women and individual with disabilities are encouraged.

It is important to note that CRDB Bank does not charge any fees for the application or recruitment process, and any requests for payment should be disregarded as they do not represent the bank’s practices.

Only Shortlisted Candidates will be Contacted.

Deadline

2026-08-06

Employment Terms

PERMANENT

Interested in this job?

13 days left to apply

Apply now

Your job search, in your pocket

Get the ZoomTanzania Jobs app - apply on the go, get instant job alerts, and chat with our AI assistant anytime, anywhere.

How to Apply

Apply now