Website CRDB Bank
CRDB Bank
Senior Manager Technology Risk & Compliance – CRDB Bank
Job Title: Senior Manager Technology Risk & Compliance
Organization: CRDB Bank
Department: ICT Department
Reporting Line: Director of ICT
Location: Tanzania Head Office
Number of Openings: 1
Employment Type: Permanent / Full-Time
Application Deadline: 13 August 2026
About CRDB Bank
CRDB Bank is one of Tanzania’s leading financial institutions, committed to digital transformation, strong technology governance, cybersecurity, and responsible banking practices.
Job Purpose
The Senior Manager Technology Risk & Compliance is responsible for providing strategic leadership, governance, and oversight of the Bank’s technology risk management and compliance functions.
The role ensures ICT risks are proactively:
- Identified.
- Assessed.
- Mitigated.
- Monitored.
- Reported.
The position ensures alignment with:
- CRDB Bank’s risk appetite.
- Bank of Tanzania regulatory requirements.
- Cybersecurity frameworks.
- Technology governance standards.
- Industry best practices.
The role serves as the central coordination point between:
- ICT Department.
- Risk Management.
- Internal Audit.
- Compliance.
- Cybersecurity teams.
- Regulators.
- External auditors.
Key Responsibilities
1. Technology Risk Governance and Leadership
- Provide strategic leadership for Technology Risk & Compliance activities across the Bank.
- Develop and maintain an enterprise-wide Technology Risk Management framework.
- Establish and monitor technology risk governance structures, including:
- Policies.
- Procedures.
- Standards.
- Controls.
- Ensure technology risk practices align with:
- Business strategy.
- Regulatory requirements.
- Industry standards.
2. Technology Risk Management and Assessment
- Lead annual planning, budgeting, and performance management for the Technology Risk & Compliance function.
- Set SMART objectives and evaluate performance of direct reports.
- Oversee:
- ICT risk identification.
- Risk assessments.
- Risk monitoring.
- Risk reporting.
- Maintain accuracy of the Technology Risk Register.
- Lead Risk and Control Self-Assessments (RCSA) across ICT functions.
- Monitor:
- Technology risk trends.
- Key Risk Indicators (KRIs).
- Technology incidents.
- Emerging threats.
- Ensure risk mitigation plans are developed, implemented, and closed within agreed timelines.
3. Technology Controls Assurance
- Provide independent challenge and assurance on effectiveness of technology risk controls.
- Establish and manage the Technology Controls Assurance Program.
- Ensure testing of key technology controls for:
- Design effectiveness.
- Operating effectiveness.
- Oversee control reviews covering:
- IT infrastructure.
- Business applications.
- Cloud services.
- Cybersecurity controls.
- Data protection.
- Third-party technology services.
- Track remediation of identified control weaknesses.
4. Audit and Regulatory Coordination
- Lead ICT-related:
- Internal audits.
- External audits.
- Regulatory examinations.
- Compliance reviews.
- Coordinate responses to:
- Audit findings.
- Regulatory observations.
- Management action plans.
- Monitor closure of audit and regulatory issues.
- Act as the primary technology risk liaison with:
- Bank of Tanzania (BOT).
- Internal Audit.
- External Auditors.
- Risk Management.
- Compliance teams.
5. Vulnerability and Patch Management Oversight
- Provide governance oversight for vulnerability assessment and remediation activities.
- Ensure vulnerability management and patching processes operate effectively within agreed SLAs.
- Review:
- Vulnerability management performance.
- KPIs.
- Risks.
- Remediation progress.
- Escalate:
- Critical vulnerabilities.
- Cybersecurity risks.
- Zero-day threats.
to appropriate management levels.
6. Regulatory Compliance and Technology Standards
Ensure compliance with:
- Bank of Tanzania technology regulations.
- Personal Data Protection requirements.
- ISO 27001.
- PCI-DSS.
- COBIT.
- ITIL.
- Internal ICT policies and standards.
Responsibilities include:
- Reviewing and maintaining ICT policies.
- Updating technology frameworks.
- Monitoring compliance requirements.
7. Technology Risk Reporting and Executive Governance
- Drive technology compliance monitoring and reporting.
- Prepare executive dashboards covering:
- Technology risks.
- Control effectiveness.
- Audit status.
- Regulatory compliance.
- Vulnerability management.
- Key Risk Indicators (KRIs).
- Present technology risk updates to:
- ICT Management.
- Risk Committees.
- Executive Management.
- Board Committees.
Required Qualifications
Education
Bachelor’s Degree in:
- Computer Science.
- Information Systems.
- Cybersecurity.
- Information Technology.
- Related ICT fields.
Added Advantage:
Master’s Degree in:
- Technology.
- Risk Management.
- Cybersecurity.
- Business Administration.
- Related fields.
Professional Experience
Minimum requirements:
- 8 years’ experience in:
- ICT Risk Management.
- Technology Governance.
- Cybersecurity.
- IT Audit.
- Compliance.
- Related areas.
- At least 4 years in managerial or leadership roles with responsibility for:
- Leading teams.
- Managing strategic initiatives.
- Driving technology governance programs.
Professional Certifications (Required Advantage)
At least one relevant certification:
- COBIT.
- ITIL.
- CGEIT.
- CRISC.
- CISA.
- ISO 27001 Lead Auditor / Lead Implementer.
- PCI DSS Certification.
Technical Knowledge and Skills
Strong knowledge of:
- Technology risk frameworks.
- Cybersecurity governance.
- Regulatory compliance.
- IT controls.
- Risk registers.
- GRC tools.
- Third-party technology risk management.
- Vendor due diligence.
- Data privacy requirements.
- Banking technology regulations.
Experience with frameworks:
- COBIT.
- ISO 31000.
- ISO 27001.
- ITIL.
- NIST.
- PCI DSS.
Additional skills:
- Policy framework development.
- Control mapping.
- Risk assessment.
- Audit management.
- Executive reporting.
- Data visualization and dashboard development.
- Stakeholder management.
CRDB Bank Commitment
CRDB Bank promotes sustainability, ESG practices, and an inclusive workplace. Applications from women and persons with disabilities are encouraged.
Important: CRDB Bank does not charge any fees during the application or recruitment process. Any request for payment should be ignored.
Only shortlisted candidates will be contacted.
How to Apply
Interested candidates should submit their applications through the official CRDB Bank recruitment platform using the application link provided in the vacancy announcement.
Position: Senior Manager Technology Risk & Compliance
Employment Type: Permanent / Full-Time
Deadline: 13 August 2026
Applicants should carefully review the requirements and ensure they meet the qualifications and experience criteria before applying.
To apply for this job please visit careers.crdbbank.co.tz.
