Point your AI agent at freehire and let it find you a job.

Get the CLI →

Equity Group Holdings

NewBe an early applicant

Manager, Data Protection and IT Risk

Discussion

Job Summary

The Data Protection and IT Risk Manager will be responsible for overseeing the Bank’s data protection strategy, IT risk strategy, and their implementation to ensure compliance with Data Protection Laws in the country and ensure IT risk is managed well. The role will work closely with the leadership of IT Security, Legal, Risk, and Compliance functions.

Key Responsibilities and Accountability

· Inform and advise Equity Bank of its obligations pursuant to the Data Protection Laws.

· Monitor compliance with the Data Protection Laws and with the policies of the data controller or data processor in relation to the protection of personal data, including the assignment of responsibilities, awareness-raising and training of staff involved in personal data processing operations, and the related audits.

· Provide advice where requested as regards the data protection impact assessment and monitor its performance.

· Cooperate with the supervisory authority and to act as its contact point on issues relating to the processing of personal data, including prior consultation with the supervisory authority, and to consult, where appropriate, about any other matter.

· Implementing measures and a privacy governance framework to manage data handling and use in compliance with the privacy laws that Equity Bank has to comply with.

· Working with key internal stakeholders in the review of projects to ensure compliance with local data privacy laws, and where necessary, complete and advise on privacy impact assessments

· Serving as the primary point of contact for queries in the business regarding data Protection and Privacy.

· Reviewing Equity vendor contracts and consents needed to implement projects in partnership with the Bank’s Legal and Information Security functions, and ensuring filing requirements with local regulators are achieved

· Ensure fulfilment of data Subject rights arising from the various touch points the bank has with the customer.

· Developing policies, standards and procedures that align to the requirements set out in the GDPR, Data Protection Act and any localization requirements in countries of operation

· Collaborating with the Information Security function to raise employee awareness of data privacy and security issues, and providing training on the subject matter in the bank.

· Monitoring performance and providing advice on the impact of data protection efforts across the bank.

· Maintaining comprehensive records of all data processing activities conducted by the bank, including the purpose of all processing activities, which must be made public on request.

· Interfacing with Equity Bank customers to inform them about how their data is being used, their rights, and what measures the company has put in place to protect their personal information.

· Collaborating with the Bank’s Information Security and Legal functions to maintain records of all data assets, ensure data classification, and maintain a data security incident management plan to ensure timely remediation of incidents, security breaches, complaints, and claims

· Conduct risk assessment related to data handling and ensure the risk register is in place and updated.

· Serve as the chief point of contact for our Technology Risk Management & Information Security team.

· Provide support for reviewing technology initiatives with reputational risks and red flags identified during defined intake procedures.

· Assist in the definition of the client’s technology risk appetite statements and monitor Key Risk Indicators (KRIs) against our technology risk appetite.

· Prepare the Technology Risk Management & Information Security line of business Technology Risk report and track actions to reduce technology risk.

· Assist with the Technology Risk reporting operations, including scheduling key monthly meetings, monitoring key milestones, escalation of past-due activities, problem triage and management, and archiving key monthly artifacts for audit purposes.

· Develop ongoing technology risk reporting, monitoring key trends and defining metrics to regularly measure control effectiveness for own area.

· Adhere to internal policies and procedures, technology control standards, and applicable regulatory guidelines.

· Contribute to the review of internal processes and activities and assist in identifying potential opportunities for improvement.

· Adhere to, advise, oversee, monitor, and enforce enterprise frameworks and methodologies that relate to technology controls/information security activities.

· Influence behavior to reduce risk and foster a strong technology risk management culture throughout the bank.

Key Critical Competence

1. Behavioural Skills

· Critical thinking and Problem-solving skills with the ability to analyze complex information to identify the key issue/action and drive resolution.

· Excellent organizational skills with attention to detail.

· Excellent interpersonal and communication skills, both oral and written

· Ethical and moral skills

· Have good personal values

2. Technical skills

· Knowledge and understanding of modern risk management standards, frameworks and practices

· Knowledge of national and international regulatory environments and key regulatory regimes

· Understanding of the national financial industry and business environment.

· Risk intelligence(critical thinking, creativity, and curiosity, research, surveys, interviews, brainstorming, and scenario planning, analysis emerging risk, forward looking )

· Risk ethics (risk culture, risk appetite, risk governance, and risk accountability

· Risk communication (communication skills, good listener, team player, positive attitude is a must, report preparation, dashboard, presentation, and communication about identified risk and control to be implemented)

· Risk intelligence(critical thinking, creativity, and curiosity, research, surveys, interviews, brainstorming, and scenario planning, analysis emerging risk, forward looking )

· Risk ethics (risk culture, risk appetite, risk governance, and risk accountability)

· Knowledge and experience of best practice Governance, Risk Management and Compliance frameworks and methodologies

· Excellent analytical, statistical, and math skills with the ability to interpret vast amounts of performance data and be IT literate

· Strong understanding of IT coding, IT information security assessment, and IT risk management

· Interpret the Vulnerability assessment report and penetration Testing report

· Ability to test the incident response plan

· Ability to conduct IT risk assessment and provide recommendations on identified loopholes

· Ability to evaluate the IT environment, assess controls in place, and suggest any improvements

· Ability to assess the adequacy of information security tools

Skills

See also

Management jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available