IT Risk & Quality Assurance Specialists job at CRDB
New
Website :
2 Days Ago
Linkedid Twitter Share on facebook
IT Risk & Quality Assurance Specialists
2026-07-23T19:39:26+00:00
CRDB
https://cdn.greattanzaniajobs.com/jsjobsdata/data/employer/comp_2278/logo/CRDB%20Bank%20Plc.jpg
FULL_TIME
Tanzania Head Office
Dar es Salaam
00000
Tanzania
Finance
Computer & IT, Business Operations, Management
TZS
MONTH
2026-08-05T17:00:00+00:00
8

Job Purpose

Responsible for identifying, assessing, monitoring, and reporting ICT risks across systems, applications, projects, and business processes. Maintains the ICT risk register and collaborates with stakeholders to develop, implement, and track risk treatment actions, ensuring timely resolution of identified issues. Evaluates the design and effectiveness of ICT controls and recommends enhancements to strengthen governance, risk management, and compliance practices. Conducts ICT and third-party risk assessments, provides risk advisory support for technology initiatives, and ensures alignment with applicable regulatory, legal, and data privacy requirements. Maintains ICT risk frameworks, policies, procedures, key risk indicators (KRIs), and reporting to support informed decision-making and effective risk oversight.

Principle Responsibilities

  • Conduct ICT risk assessments for systems, applications, projects, and business processes to identify risks, control gaps, and areas requiring mitigation.
  • Lead and coordinate Risk and Control Self-Assessments (RCSAs), ensuring risks, controls, and action plans are appropriately assessed, documented, and reported, with timely escalation of emerging risks and issues.
  • Perform independent assessments of ICT controls to evaluate their design and operating effectiveness, identify control weaknesses, and recommend improvements where necessary.
  • Maintain and update the ICT Risk Register, ensuring identified risks, control deficiencies, mitigation actions, and owners are accurately documented and tracked.
  • Maintain and periodically review ICT frameworks, policies, procedures, standards, guidelines, process documents, and other governance artefacts, ensuring they remain current, effective, and compliant with applicable regulatory and organizational requirements.
  • Collaborate with Risk, Compliance, Internal Audit, and other stakeholders to support effective risk management and assurance activities.
  • Collaborate with risk and control owners to develop, implement, and monitor risk treatment plans, ensuring timely closure of identified issues.
  • Develop, monitor, and report Key Risk Indicators (KRIs), risk events, and risk trends, escalating material issues as appropriate.
  • Coordinate the identification, assessment, reporting, and management of ICT-related risk incidents and control failures.
  • Conduct third-party risk assessments and supplier due diligence to evaluate technology, operational, compliance, and data privacy risks.
  • Monitor compliance with applicable ICT-related regulatory, legal, and data privacy requirements and escalate non-compliance issues.
  • Prepare and present ICT risk reports, dashboards, and management information to support effective risk oversight and informed decision-making.
  • Provide risk advisory support for technology initiatives, projects, system implementations, and significant changes to ICT processes.
  • Promote a culture of ICT risk awareness, accountability, and compliance across ICT functions through awareness initiatives, training programmes, and support for adherence to internal policies, regulatory requirements, and standards.

Qualifications Required

  • Bachelor’s degree in computer science, Computer Information Systems, Management Information Systems or related fields.
  • At least 2 years of experience in ICT risk management, technology governance, operational risk, information security risk, or compliance within banking or another regulated environment.
  • At least one of the related professional certifications (COBIT, ITIL, CGEIT, CRISC, CISA, ISO27001 LA/LI, PCI DSS).
  • Experience conducting technology risk assessments and maintaining enterprise or ICT risk registers.
  • Practical experience engaging technology teams, business owners, vendors, auditors, and risk stakeholders.
  • Technology governance frameworks and recognized practices such as COBIT, ISO 31000, ISO 27001, ITIL, NIST, and PCI DSS
  • Third-party technology risk management and vendor due-diligence practices.
  • Regulatory compliance, data privacy, cyber and technology-related requirements applicable to the banking sector
  • Experience in policy framework design and control mapping, risk register management and GRC tooling, and data visualization for executive reporting dashboards.
  • Conduct ICT risk assessments for systems, applications, projects, and business processes to identify risks, control gaps, and areas requiring mitigation.
  • Lead and coordinate Risk and Control Self-Assessments (RCSAs), ensuring risks, controls, and action plans are appropriately assessed, documented, and reported, with timely escalation of emerging risks and issues.
  • Perform independent assessments of ICT controls to evaluate their design and operating effectiveness, identify control weaknesses, and recommend improvements where necessary.
  • Maintain and update the ICT Risk Register, ensuring identified risks, control deficiencies, mitigation actions, and owners are accurately documented and tracked.
  • Maintain and periodically review ICT frameworks, policies, procedures, standards, guidelines, process documents, and other governance artefacts, ensuring they remain current, effective, and compliant with applicable regulatory and organizational requirements.
  • Collaborate with Risk, Compliance, Internal Audit, and other stakeholders to support effective risk management and assurance activities.
  • Collaborate with risk and control owners to develop, implement, and monitor risk treatment plans, ensuring timely closure of identified issues.
  • Develop, monitor, and report Key Risk Indicators (KRIs), risk events, and risk trends, escalating material issues as appropriate.
  • Coordinate the identification, assessment, reporting, and management of ICT-related risk incidents and control failures.
  • Conduct third-party risk assessments and supplier due diligence to evaluate technology, operational, compliance, and data privacy risks.
  • Monitor compliance with applicable ICT-related regulatory, legal, and data privacy requirements and escalate non-compliance issues.
  • Prepare and present ICT risk reports, dashboards, and management information to support effective risk oversight and informed decision-making.
  • Provide risk advisory support for technology initiatives, projects, system implementations, and significant changes to ICT processes.
  • Promote a culture of ICT risk awareness, accountability, and compliance across ICT functions through awareness initiatives, training programmes, and support for adherence to internal policies, regulatory requirements, and standards.
  • Technology governance frameworks and recognized practices such as COBIT, ISO 31000, ISO 27001, ITIL, NIST, and PCI DSS
  • Third-party technology risk management and vendor due-diligence practices.
  • Regulatory compliance, data privacy, cyber and technology-related requirements applicable to the banking sector
  • Experience in policy framework design and control mapping, risk register management and GRC tooling, and data visualization for executive reporting dashboards.
  • Bachelor’s degree in computer science, Computer Information Systems, Management Information Systems or related fields.
  • At least 2 years of experience in ICT risk management, technology governance, operational risk, information security risk, or compliance within banking or another regulated environment.
  • At least one of the related professional certifications (COBIT, ITIL, CGEIT, CRISC, CISA, ISO27001 LA/LI, PCI DSS).
  • Experience conducting technology risk assessments and maintaining enterprise or ICT risk registers.
  • Practical experience engaging technology teams, business owners, vendors, auditors, and risk stakeholders.
bachelor degree
24
JOB-6a626dee0952b

Vacancy title:
IT Risk & Quality Assurance Specialists

[Type: FULL_TIME, Industry: Finance, Category: Computer & IT, Business Operations, Management]

Jobs at:
CRDB

Deadline of this Job:
Wednesday, August 5 2026

Duty Station:
Tanzania Head Office | Dar es Salaam

Summary
Date Posted: Thursday, July 23 2026, Base Salary: Not Disclosed

Similar Jobs in Tanzania
Learn more about CRDB
CRDB jobs in Tanzania

JOB DETAILS:

Job Purpose

Responsible for identifying, assessing, monitoring, and reporting ICT risks across systems, applications, projects, and business processes. Maintains the ICT risk register and collaborates with stakeholders to develop, implement, and track risk treatment actions, ensuring timely resolution of identified issues. Evaluates the design and effectiveness of ICT controls and recommends enhancements to strengthen governance, risk management, and compliance practices. Conducts ICT and third-party risk assessments, provides risk advisory support for technology initiatives, and ensures alignment with applicable regulatory, legal, and data privacy requirements. Maintains ICT risk frameworks, policies, procedures, key risk indicators (KRIs), and reporting to support informed decision-making and effective risk oversight.

Principle Responsibilities

  • Conduct ICT risk assessments for systems, applications, projects, and business processes to identify risks, control gaps, and areas requiring mitigation.
  • Lead and coordinate Risk and Control Self-Assessments (RCSAs), ensuring risks, controls, and action plans are appropriately assessed, documented, and reported, with timely escalation of emerging risks and issues.
  • Perform independent assessments of ICT controls to evaluate their design and operating effectiveness, identify control weaknesses, and recommend improvements where necessary.
  • Maintain and update the ICT Risk Register, ensuring identified risks, control deficiencies, mitigation actions, and owners are accurately documented and tracked.
  • Maintain and periodically review ICT frameworks, policies, procedures, standards, guidelines, process documents, and other governance artefacts, ensuring they remain current, effective, and compliant with applicable regulatory and organizational requirements.
  • Collaborate with Risk, Compliance, Internal Audit, and other stakeholders to support effective risk management and assurance activities.
  • Collaborate with risk and control owners to develop, implement, and monitor risk treatment plans, ensuring timely closure of identified issues.
  • Develop, monitor, and report Key Risk Indicators (KRIs), risk events, and risk trends, escalating material issues as appropriate.
  • Coordinate the identification, assessment, reporting, and management of ICT-related risk incidents and control failures.
  • Conduct third-party risk assessments and supplier due diligence to evaluate technology, operational, compliance, and data privacy risks.
  • Monitor compliance with applicable ICT-related regulatory, legal, and data privacy requirements and escalate non-compliance issues.
  • Prepare and present ICT risk reports, dashboards, and management information to support effective risk oversight and informed decision-making.
  • Provide risk advisory support for technology initiatives, projects, system implementations, and significant changes to ICT processes.
  • Promote a culture of ICT risk awareness, accountability, and compliance across ICT functions through awareness initiatives, training programmes, and support for adherence to internal policies, regulatory requirements, and standards.

Qualifications Required

  • Bachelor’s degree in computer science, Computer Information Systems, Management Information Systems or related fields.
  • At least 2 years of experience in ICT risk management, technology governance, operational risk, information security risk, or compliance within banking or another regulated environment.
  • At least one of the related professional certifications (COBIT, ITIL, CGEIT, CRISC, CISA, ISO27001 LA/LI, PCI DSS).
  • Experience conducting technology risk assessments and maintaining enterprise or ICT risk registers.
  • Practical experience engaging technology teams, business owners, vendors, auditors, and risk stakeholders.
  • Technology governance frameworks and recognized practices such as COBIT, ISO 31000, ISO 27001, ITIL, NIST, and PCI DSS
  • Third-party technology risk management and vendor due-diligence practices.
  • Regulatory compliance, data privacy, cyber and technology-related requirements applicable to the banking sector
  • Experience in policy framework design and control mapping, risk register management and GRC tooling, and data visualization for executive reporting dashboards.

Work Hours: 8

Experience in Months: 24

Level of Education: bachelor degree

Job application procedure

Application Link:Click Here to Apply Now

All Jobs | QUICK ALERT SUBSCRIPTION

Job Info
Job Category: Computer/ IT jobs in Tanzania
Job Type: Full-time
Deadline of this Job: Wednesday, August 5 2026
Duty Station: Tanzania Head Office | Dar es Salaam
Posted: 23-07-2026
No of Jobs: 1
Start Publishing: 23-07-2026
Stop Publishing (Put date of 2030): 10-10-2076
Apply Now
Notification Board

Join a Focused Community on job search to uncover both advertised and non-advertised jobs that you may not be aware of. A jobs WhatsApp Group Community can ensure that you know the opportunities happening around you and a jobs Facebook Group Community provides an opportunity to discuss with employers who need to fill urgent position. Click the links to join. You can view previously sent Email Alerts here incase you missed them and Subscribe so that you never miss out.

Caution: Never Pay Money in a Recruitment Process.

Some smart scams can trick you into paying for Psychometric Tests.