Kuda is a full-service, app-based digital bank. Our mission is to be the go-to bank not just for those living on the African continent, but also for the African diaspora wherever they might live, anywhere in the world. Kuda is free of ridiculous banking charges and great at helping customers budget, spend smartly, and save more.
We are seeking a proactive and detail-oriented IT Risk Analyst to join our growing Risk Management team. The successful candidate will be responsible for identifying, assessing, monitoring, and mitigating technology-related risks across the organization. This role is critical in ensuring the security, resilience, and compliance of our IT infrastructure, applications, and processes in line with regulatory requirements (like CBN guidelines) and industry best practices (such as ISO 27001, PCI DSS).
Requirements
- Conduct comprehensive IT risk assessments across various domains including infrastructure, applications, data security, cloud environments, third-party vendors, and change management processes. Identify potential threats, vulnerabilities, and their potential impact.
- Evaluate the effectiveness of existing IT controls. Recommend, design, and assist in the implementation of new controls and mitigation strategies to reduce identified risks to acceptable levels.
- Develop and monitor Key Risk Indicators (KRIs) for IT risks. Prepare regular risk reports for management and relevant committees, clearly articulating risk posture, control effectiveness, and remediation progress.
- Support IT compliance activities related to relevant regulations (e.g., CBN guidelines, NDPR) and standards (e.g., ISO 27001, PCI DSS). Assist in internal and external audits.
- Participate in the assessment of IT risks associated with third-party vendors and service providers.
- Contribute to the development, testing, and maintenance of IT BCP and DR plans, ensuring technology resilience.
- Assist in the analysis of IT security incidents to identify root causes and recommend improvements to prevent recurrence.
- Assist in the development, review, and updating of IT risk management policies, standards, and procedures.
- Contribute to promoting IT risk awareness across the organization.
Required Qualifications:
- Bachelor's degree in Information Technology, Computer Science, Information Systems, Cybersecurity, Risk Management, or a related field.
- Minimum of 3-5 years of relevant experience in IT risk management, IT audit, information security, or IT governance, preferably within the financial services or fintech industry.
- Strong understanding of IT risk assessment methodologies and frameworks (e.g., NIST RMF, ISO 27005, COBIT).
- Familiarity with relevant regulatory requirements in Nigeria (CBN guidelines, NDPR).
- Knowledge of industry standards like ISO 27001, PCI DSS.
- Experience with assessing risks in areas such as network security, application security, cloud security (AWS/Azure/GCP), identity and access management, data protection, and vendor management.
- Relevant professional certifications such as CISA (Certified Information Systems Auditor), CRISC (Certified in Risk and Information Systems Control), CISSP (Certified Information Systems Security Professional), or similar are highly desirable.
- Proficiency with risk management tools and Microsoft Office Suite (Excel, Word, PowerPoint).
- Understanding of banking operations and fintech products is a plus.
Method of Application
Signup to view application details.
Signup Now