KEY RESPONSIBILITIES:
Technology Resilience & Recovery.
- Mandate the Group-wide Technology BCM and Operational Resilience strategy, ensuring alignment with ISO 22301, global best practices, evolving regional regulatory mandates (e.g., CBK Prudential Guidelines) while integrating modern Cloud-Native resilience patterns, Automated DR Failover Orchestration, and Infrastructure as Code (IaC) for automated recovery.
- Partner with Group Cybersecurity to design and test specialized "Cyber Recovery Playbooks" (e.g., Ransomware recovery, immutable backups) to defend against and rapidly recover from destructive cyber-attacks.
DR Failover Simulations Orchestration & Testing.
- Direct and orchestrate multi-jurisdictional Disaster Recovery (DR) and Cyber Resilience failover simulations for the Group’s Core Banking and Tier-1 applications, rigorously validating strict Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO).
- Develop technology-related crisis management frameworks and facilitate IT DRP simulation exercises (Tabletop drills) for the Group Technology teams.
High-Availability (HA) & BIA.
- Challenge Enterprise Architects and system owners on High Availability and redundancy designs; exercise authority to mandate the elimination of Single Points of Failure (SPOFs) across physical data centers and decentralized Multi-Cloud/Containerized architectures.
- Lead Business Impact Analyses (BIA) and IT Threat/Vulnerability assessments to proactively align technology recovery strategies with business demands.
Third-Party Cloud Resilience & Supply Chain Governance.
- Execute resilience audits and risk assessments of critical third-party technology vendors, SaaS/PaaS Cloud Service Providers (CSPs), and FinTech partners to prevent supply chain disruptions and mitigate systemic concentration risks.
Executive Reporting & Remediation Enforcement
- Design high-impact Operational Resilience dashboards and present strategic BCM risk profiles and compliance postures to the Group Risk Management Committee and the Board.
- Mandate and strictly track the closure of critical vulnerabilities, architectural gaps, and lessons learned identified during DR simulation exercises to their logical conclusion.
MINIMUM POSITION QUALIFICATION REQUIREMENTS
- 1. Academic & Professional
AA
2. Experience
Total Minimum No of Years’ Experience Required 5 Detail Minimum No of Years Need Type2 Experience in IT operations, architecture, or assurance functions within the Financial Services industry. 5 RQ Deep, practical knowledge of current business continuity planning techniques, disaster recovery, and performing complex risk and business impact analyses (BIA). 4 RQ Demonstrated exposure to IT resilience practices, including Cloud-native recovery orchestration, Infrastructure as Code (IaC), Automated DR Failover Orchestration, and governing SaaS/PaaS resilience. 3 ES Strong understanding of Core IT applications and experience in governing Third-Party/Vendor technology resilience. 3 ES Proven track record of managing cross-functional technical teams during high-pressure crisis events or large-scale DR simulations. 4 ESSkills Required
- Bachelor's degree in Computer Science, Information Systems, Information Security or related IT field
- Master's degree in business or IT
- Business Continuity / Resilience certification (CBCP, AMBCI, MBCI, or ISO 22301 Lead Implementer/Auditor)
- Technology governance/security certification (CISA, CISM, CISSP, CRISC, or ITIL v4)
- Minimum 5 years' experience in IT operations, architecture, or assurance within Financial Services
- Deep practical knowledge of business continuity planning, disaster recovery, and complex BIA (minimum 4 years)
- Practical experience with cloud-native recovery orchestration, Infrastructure as Code (IaC), and Automated DR Failover Orchestration (minimum 3 years)
- Experience governing third-party/SaaS/PaaS cloud resilience and conducting vendor resilience audits (minimum 3 years)
- Proven track record managing cross-functional technical teams during crisis events or large-scale DR simulations (minimum 4 years)
What We Do
KCB Group, is the largest financial services organization in East Africa in terms of asset size. The Group's headquarters are located in Nairobi, Kenya, with subsidiaries in Kenya, Rwanda, Southern Sudan, Tanzania, Uganda and Burundi. In 2015, KCB Group opened a representative office in Ethiopia, expanding the growth of the organization. The Bank is over 124 years old having started in Mombasa in 1896. KCB Group has over 354 branches, 26,394 Agents/POS Merchants and 1,103 ATMs. The bank also offers Mobile Banking though the KCB App, Internet Banking and Diaspora Banking Services platform that can be accessed 24/7 basis. The Bank services over 26.8 million customers across the region. KCB Group is the largest financial services organization in East Africa, with an estimated asset base of approximately Ksh. 1.02 trillion as at the of end H1 2021.









