- Experience
- Any
- Salary
- —
- Openings
- 1
- Posted
- 5 hours ago
- Work mode
- In office
- Resume
- Required to apply
Where you'll work
Job description
Role Overview
Reporting to the Internal Audit Senior Managers, the Manager for Fintech and Cyber Audit provides independent, risk-focused assurance regarding the effectiveness of the Group's technology governance, digital platforms, enterprise applications, infrastructure, cloud environments, data management, and IT general controls. The position ensures that technology risks are properly identified and managed via effective governance, risk management, and control frameworks that support secure, reliable, resilient, and efficient business operations.
Responsibilities and Scope
The role evaluates governance, risk management, internal controls, cyber resilience, technical architecture, operational continuity, and regulatory compliance throughout Safaricom’s digital financial ecosystem. The role also supports the protection of critical technology assets while promoting innovation through principles of secure-by-design and controls-by-design.
Key duties include planning and performing independent, risk-based vulnerability assessments and penetration testing across the Group's financial services technology infrastructure. This hands-on work encompasses testing web applications, mobile apps, APIs, networks, cloud platforms, infrastructure, and related technology components to detect weaknesses, verify exploitability, assess business impact, and validate remediation effectiveness.
Aligned with the Group Internal Audit strategy and Safaricom’s goal to become a world-class AI-driven Internal Audit function, the manager provides proactive assurance and advisory services across initiatives involving digital transformation, emerging technologies, cloud migration, enterprise systems, artificial intelligence, automation, and technological innovation. Collaboration with Technology, Digital Engineering, Enterprise Architecture, M-PESA Technology, Data, and Business leaders fosters forward-looking insights that enhance governance, operational efficiency, and secure technology-driven growth.
The manager is accountable for creating and executing risk-based audit plans, monitoring corrective action implementation, and assessing emerging technology risks across the Group. This includes delivering independent assessments on the adequacy of technology governance, system controls, project execution, digital transformation efforts, data governance, and operational resilience while identifying opportunities to improve effectiveness, control quality, and business value.
Compliance and Standards
The role contributes to ensuring adherence to all pertinent regulatory requirements and industry benchmarks such as ISO/IEC 27001, ISO 22301, COBIT, the NIST Cybersecurity Framework, CIS Critical Security Controls, PCI DSS, GSMA security mandates, data privacy laws, and other applicable technology governance standards across Safaricom Group.
Outcomes and Impact
Through high-caliber assurance, insight, and innovative approaches, this manager position aims to bolster stakeholder confidence, improve operational resilience, and support the achievement of the Group’s strategic goals.