IT Governance and Controls Manager
Reports to: Head of IT
HFCB Group Plc is an integrated financial solutions provider that is registered as a non–operating holding company (under the Banking Act Cap.488) and regulated by the Central Bank of Kenya (CBK) and the Capital Markets Authority (CMA). The Group is a public limited company with interests in Banking, Property and Insurance, and is listed at the Nairobi Securities Exchange. For more information on our banking, property and insurance solutions, please visit www.hfcb.co.ke The Group has 4 main entities: HFCB Limited – Full-Service Banking, HFCB Properties Limited – Property/Real Estate Solutions, HFCB Bancassurance Intermediary – Insurance Solutions & HFCB Foundation Limited – ESG/Sustainability.
On the back of a strong growth trajectory and in a bid to power the business, HFCB Limited is looking to recruit a dynamic and results-oriented IT Governance and Controls Manager.
About the Role
The role holder is responsible for the establishment, implementation, and continuous improvement of the Bank’s IT policy framework, internal control environment, regulatory compliance, technology risk management processes, and overall governance framework. The role ensures that technology operations align with business objectives, regulatory requirements, industry best practices, and the organization's risk appetite.
Key Accountabilities
- Develop, implement, and maintain the IT Governance, Risk, and Controls framework to ensure alignment with business objectives and regulatory requirements.
- Establish and oversee IT governance structures, policies, standards, and procedures, ensuring organization-wide compliance.
- Design, monitor, and continuously improve the IT internal control environment through control assessments and governance reviews.
- Ensure compliance with applicable regulatory, legal, and industry requirements, coordinating regulatory engagements and remediation of findings.
- Lead technology risk management activities, including risk assessments, maintenance of the Technology Risk Register, monitoring of Key Risk Indicators (KRIs), and reporting to governance forums.
- Coordinate internal, external, and regulatory audits, ensuring timely resolution of audit findings and effective stakeholder reporting.
- Develop governance dashboards, KPIs, KRIs, compliance scorecards, and management reports for executive leadership and the Board.
- Oversee governance of third-party technology risks, outsourcing, business continuity, and disaster recovery to ensure operational resilience.
- Drive continuous improvement of IT governance maturity through benchmarking, process automation, and adoption of industry best practices.
- Foster a culture of governance, accountability, compliance, and continuous improvement across the Technology function.
- Perform any other duties as assigned by the immediate supervisor in support of departmental and organizational objectives.
Qualifications
- Bachelor's degree in information technology, Computer Science, Information Systems, Cybersecurity, or related field.
- Preferred certifications include: CISA, CISM, CRISC and CISSP
- 4 - 5 years in IT governance, technology risk, IT audit, compliance, or information security.
- Experience within a regulated industry, preferably banking or financial services.
- Experience engaging with regulators, auditors, and executive management.
Competencies
- Excellent problem-solving and analytical skills.
- Strong communication and interpersonal abilities.
- Stakeholder Management
- Adaptability and Innovation.
- Team Player.
- Attention to detail and risk awareness.
- Communicates complex technical issues clearly to both technical and non-technical audiences.
- Influencing skills.
- Negotiation.
- Objectivity
- Integrity and Accountability.