Website CRDB Bank PLC
CRDB Bank PLC
IT Risk & Quality Assurance Specialist (2 Positions)
Organization: CRDB Bank PLC
Department: Information and Communication Technology (ICT)
Location: Tanzania Head Office
Reporting Line: Senior Manager – Technology Risk & Compliance
Employment Type: Permanent
Job Type: Full-time
Number of Openings: 2
Application Deadline: 6 August 2026
Job Purpose
CRDB Bank is seeking IT Risk & Quality Assurance Specialists responsible for identifying, assessing, monitoring, and reporting ICT risks across systems, applications, projects, and business processes.
The role will support technology governance, risk management, and compliance by evaluating ICT controls, maintaining risk frameworks, conducting assessments, and ensuring alignment with regulatory, legal, cybersecurity, and data privacy requirements.
The successful candidates will maintain ICT risk registers, monitor risk treatment plans, provide technology risk advisory support, and strengthen the bank’s ICT risk management practices.
Key Responsibilities
- Conduct ICT risk assessments for:
- Systems
- Applications
- Projects
- Business processes
to identify risks, control gaps, and mitigation requirements.
- Lead and coordinate Risk and Control Self-Assessments (RCSAs), ensuring risks, controls, and action plans are properly assessed, documented, monitored, and reported.
- Perform independent assessments of ICT controls to evaluate:
- Control design effectiveness
- Operating effectiveness
- Control weaknesses
- Improvement opportunities
- Maintain and regularly update the ICT Risk Register, ensuring accurate documentation of:
- Identified risks
- Control deficiencies
- Mitigation actions
- Risk owners
- Review and maintain ICT governance documents, including:
- Policies
- Procedures
- Standards
- Guidelines
- Process documentation
- Ensure ICT governance frameworks remain effective and compliant with regulatory and organizational requirements.
- Collaborate with:
- Risk Management teams
- Compliance teams
- Internal Audit
- ICT stakeholders
to support assurance and risk management activities.
- Work with risk and control owners to develop, implement, and monitor risk treatment plans.
- Develop, monitor, and report:
- Key Risk Indicators (KRIs)
- Technology risk trends
- Risk events
- Coordinate identification, assessment, and management of ICT-related incidents and control failures.
- Conduct third-party technology risk assessments and supplier due diligence covering:
- Technology risks
- Operational risks
- Compliance risks
- Data privacy risks
- Monitor compliance with ICT-related:
- Regulatory requirements
- Legal obligations
- Data privacy standards
- Prepare and present ICT risk reports, dashboards, and management information for decision-making.
- Provide risk advisory support for:
- Technology projects
- System implementations
- ICT process changes
- Promote ICT risk awareness, accountability, and compliance through:
- Training programs
- Awareness initiatives
- Policy adherence support
Required Qualifications and Experience
Academic Qualifications
- Bachelor’s degree in:
- Computer Science
- Computer Information Systems
- Management Information Systems
- Or related fields
Professional Experience
- Minimum 2 years of experience in:
- ICT Risk Management
- Technology Governance
- Operational Risk
- Information Security Risk
- ICT Compliance
Experience should preferably be within:
- Banking sector
- Financial institutions
- Other regulated environments
Professional Certifications
Candidates should possess at least one relevant certification, including:
- COBIT
- ITIL
- CGEIT
- CRISC
- CISA
- ISO 27001 Lead Auditor (LA)
- ISO 27001 Lead Implementer (LI)
- PCI DSS Certification
Technical Knowledge and Skills
Candidates should have experience and knowledge in:
- ICT risk assessments and enterprise risk registers.
- Technology governance frameworks, including:
- COBIT
- ISO 31000
- ISO 27001
- ITIL
- NIST
- PCI DSS
- Third-party technology risk management and vendor due diligence.
- Banking regulatory compliance requirements.
- Cybersecurity and data privacy requirements.
- Policy framework development and control mapping.
- Risk register management.
- Governance, Risk, and Compliance (GRC) tools.
- Data visualization and executive risk reporting dashboards.
CRDB Bank Commitment
CRDB Bank promotes sustainability, Environmental, Social, and Governance (ESG) practices and encourages applications from candidates who share these values.
The bank supports an inclusive workplace and encourages applications from:
- Women
- Individuals with disabilities
Important Notice:
CRDB Bank does not charge any fees during the application or recruitment process. Applicants should ignore any requests for payment claiming to represent the bank.
Only shortlisted candidates will be contacted.
How to Apply
Interested candidates should submit their applications through the official CRDB Bank recruitment portal.
To apply for this job please visit careers.crdbbank.co.tz.
