- The IT Control Manager shall be responsible for ensuring appropriate information technology controls, security measures, and compliance procedures are implemented and maintained to safeguard the organization's IT systems, data, and digital channels. The role supports the organization in managing IT risks, ensuring regulatory compliance, and maintaining the integrity, availability, and confidentiality of information systems.
- Monitor the effectiveness of IT controls across the organization's systems, applications, and infrastructure.
- Ensure compliance with IT policies, standards, and procedures.
- Monitor and enforce adherence to IT governance frameworks and security standards.
- Ensure that all IT assets (computers, servers, network devices, POS terminals, software licenses, etc.) are properly recorded, tagged, and maintained in an up-to-date asset inventory register.
- Conduct periodic verification and reconciliation of physical IT assets with the asset register to detect missing, unauthorized, or unrecorded devices.
- Monitor controls over asset allocation, movement, maintenance, and disposal to ensure proper authorization and prevent loss, misuse, or theft of IT equipment.
- Review and monitor user access rights and privileges across core banking and other systems.
- Ensure timely activation, modification, and deactivation of user accounts.
- Maintain an up-to-date inventory of privilege user accounts and service accounts
- Conduct periodic user access review exercises.
- Identify and report IT-related risks and control weaknesses.
- Maintain an IT risk register and track remediation of identified control gaps.
- Maintain records of IT control issues and follow up on remediation actions.
- Support enterprise risk management initiatives relating to IT and digital channels.
- Monitor system changes, deployments, and configuration updates to ensure adherence to change management procedures.
- Ensure proper backup, recovery, and business continuity controls are implemented.
- Ensure critical systems are properly monitored and reviewed for gaps identification and risk remediation.
- Monitor and ensure that End-of-Day (EOD) processing for core banking and related applications is successfully completed without errors or system interruptions.
- Review EOD reports, system logs, and reconciliation outputs to identify exceptions, failed jobs, or unusual activities and ensure timely resolution.
Development and Change Control
- Ensure software development, testing, and release processes comply with the approved Software Development Life Cycle (SDLC), change management procedures, and security standards to prevent unauthorized changes and system vulnerabilities.
- Monitor enforcement of segregation of duties, proper testing, and management approvals before applications or system updates are deployed into the production environment.
API Security and Integration Controls
- Monitor security controls around Application Programming Interfaces (APIs) used for system integrations, digital banking platforms, and third-party services.
- Ensure appropriate controls exist for API authentication, authorization, encryption, and access monitoring to prevent unauthorized access and data exposure.
- Review and monitor third-party integrations to ensure they comply with the organization's security standards and regulatory requirements.
Cloud and DevOps Control Monitoring
- Ensure appropriate security and governance controls are implemented in cloud infrastructure, DevOps pipelines, and automated deployment processes.
- Monitor access controls, configuration management, and security settings across cloud platforms, containers, and deployment environments.
- Ensure proper approval, logging, and monitoring of automated builds, deployments, and infrastructure changes.
- Assist in monitoring and reporting IT incidents, system failures, and security breaches.
- Escalate issues to management for timely resolution.
Digital Channels and Fintech Platforms
- Monitor controls around mobile banking, POS, API integrations, and payment platforms.
- Ensure appropriate controls exist for third-party integrations and fintech partnerships.
Information Security / Cybersecurity Controls
- Ensure implementation and monitoring of information security controls to protect systems, networks, and data from cyber threats and unauthorized access.
- Monitor compliance with security policies, vulnerability management, and patch management processes to address security weaknesses.
- Support cybersecurity incident monitoring, investigation, and security awareness initiatives to strengthen the organization's security posture.
- Ensure adherence to regulatory guidelines and internal policies relating to IT systems and digital banking platforms.
- Support compliance reviews and regulatory inspections.
- Provide required documentation and support during internal and external IT audits.
- Track and follow up on audit findings and remediation actions.
- Periodic IT control review reports
- User access review reports
- IT risk assessment reports
- Compliance monitoring reports
- Incident investigation reports
- IT control gap remediation tracking
Key Performance Indicators (KPIs)
- Timely completion of user access reviews
- Number of IT control issues identified and resolved
- Compliance with IT policies and regulatory guidelines
- Timely closure of audit findings
- Effective monitoring of system access and activities
Educational Qualification
- B.Sc in Computer Science, Information Technology, Cybersecurity, or related discipline.
- Minimum of 5 - 7 years experience in IT control, IT audit, or IT risk management, preferably in the banking or financial services industry.
Professional Certifications (Added Advantage)
- CISA
- CISM
- CISSP
- ISO 27001 certification
- Relevant cybersecurity certifications
- IT General Controls (ITGC)
- Access Management and Identity Governance
- Database and system security
- Network security
- Risk assessment and control testing
- IT audit and compliance
- Security monitoring tools
- Knowledge of digital banking platforms and payment systems