Never pay for any notarisation, certificate or assessment as part of any recruitment process. When in doubt, contact us
Housing Finance Company of Kenya was incorporated as the premier mortgage Finance Institution in Kenya licensed under the Banking Act with the CDC and the GoK owning 60% and 40% respectively.
Housing Finance started operations with the main objective of implementing the government’s policy of promoting thrift and home ownership by lending ...
Read more about this company
About the Role
The role holder will be responsible for driving IPF business growth through direct business development efforts as well as nurturing strong business relationships with existing and potential customers, key insurance intermediaries and branch business teams to ensure quick business conversion and turnaround time. The role holder will also be responsible for compliance with the laid-out Product procedures to safeguard bank’s exposure and ensure a quality IPF loan book.
Key Accountabilities
- Oversight of end-to-end IPF business transactions and compliance with product lending parameters.
- Business development through effective linkages with customers, underwriters, Insurance intermediaries and branch business teams to ensure quick conversion and sustained business growth.
- Preliminary evaluation on potential customers under IPF to ensure repayment ability is demonstrated prior to disbursement.
- Prompt customer / intermediary issue resolution and relationship management for all insurance stakeholders.
- Firstline follow up on IPF loan repayments and eventual refund process from the Insurance Company.
- Organizing and training various stakeholders e.g. branches and insurance intermediaries to ensure they source quality business as per set standards.
- Ensuring key Insurance Companies and intermediaries are reviewed and onboarded and that they have adequate access to the bank’s IPF application and other critical documentation.
- Act as coordinator for gathering market intelligence as pertains to IPF portfolio performance in the industry alongside establishment of innovative ways to counter the stiff competition
Qualifications
- Bachelor’s degree in a Business-related field.
- At least 4 years’ relevant experience in IPF business development role.
Competencies
- Good knowledge of the Insurance Act and other developments in banking and insurance fields in general.
- Good knowledge of requisite documentation under IPF transactions.
- Good knowledge of CBK’s prudential guidelines as pertains to lending.
- People skills.
- Presentation skills
- Business minded.
- Articulate.
- Tactful.
- Quality conscious
- Attentive to detail
- Ability to effectively manage customer relationships
go to method of application »
About the Role
The Manager – IT Security supports the Head of ICT Security / CISO in strengthening the Group’s information security posture by coordinating IT security governance, cyber risk management, SOC operations oversight, security assurance, audit remediation, regulatory compliance and proactive cyber resilience across the Group. The role ensures that security policies, standards, controls, monitoring processes and assurance activities are embedded into technology operations, digital channels, projects, third-party engagements, and business processes. The role holder provides security support to the substantive Data Protection Officer by ensuring that technical and organisational security controls for personal data are defined, implemented, tested, monitored, and evidenced. This role supports privacy governance through technology control implementation, security assurance, access control, monitoring, incident coordination, third-party reviews, and remediation tracking.
Key Accountabilities
- Data Protection and Privacy Security Support - Support the substantive Data Protection Officer by providing information security input into privacy governance, DPIAs, data classification, access controls, encryption, logging and monitoring, data loss prevention, third-party risk reviews, breach investigation, audit evidence and remediation tracking.
- IT Security Governance and Strategy Execution - Support the CISO in implementing the Group information security strategy, governance framework, policies, standards, procedures, operating model and control assurance programme.
- Regulatory Compliance and Security Reporting - Coordinate compliance reviews, evidence packs, management attestations, regulatory responses, control self-assessments and reporting to ICT, Risk, Compliance, Audit and management governance forums.
- Cyber Risk, Audit and Remediation Management - Coordinate identification, assessment, monitoring, reporting and remediation of ICT and cyber risks across the Group, including audit and regulatory findings to closure.
- SOC Operations Oversight and Incident Coordination - Provide management oversight of security monitoring, incident triage, escalation, response coordination, threat intelligence, SOC use cases, alert handling, incident reporting and post-incident remediation.
- ICT Resilience, Disaster Recovery and Cyber Recovery Support - Coordinate security input into ICT business continuity, disaster recovery, cyber recovery planning, backup assurance, recovery testing and remediation of resilience gaps.
- Identity and Access Governance - Maintain access governance covering privileged access, periodic user access reviews, role-based access control, joiner-mover-leaver controls, access certification, segregation of duties, exceptions, remediation tracking and evidence management.
- Security Assurance for Projects, Platforms and Third Parties - Provide security assurance over systems, infrastructure, digital channels, cloud services, APIs, integrations, third parties and technology changes.
Qualifications
- Bachelor's degree in information security, Computer Science, Information Systems, Information Technology, Cybersecurity, Risk Management, or related fields.
- Relevant certifications such as CISM, CISSP, CRISC, CISA, ISO 27001 Lead Implementer/Lead Auditor, CompTIA Security+, CBCP or equivalent will be an added advantage.
- At least 5 years’ experience in information security, IT governance, cyber risk, security operations, security assurance, or technology risk management.
- Understanding of implementation of technical security controls, identity and access management and designing security solutions in a dynamic environment
- At least 2 years in a supervisory or managerial role within a highly regulated or digitized environment.
- Demonstrable experience in security governance, SOC oversight, audit remediation, regulatory compliance, access governance, third-party assurance, project security assurance, incident coordination, cyber resilience and executive reporting.
- Understanding of IT Audit processes, technical security testing (Red Team, Blue Team, Penetration Testing) and Cyber Incident Response including data protection guidelines.
go to method of application »
About the Role
The role holder is responsible for the establishment, implementation, and continuous improvement of the Bank’s IT policy framework, internal control environment, regulatory compliance, technology risk management processes, and overall governance framework. The role ensures that technology operations align with business objectives, regulatory requirements, industry best practices, and the organization's risk appetite.
Key Accountabilities
- Develop, implement, and maintain the IT Governance, Risk, and Controls framework to ensure alignment with business objectives and regulatory requirements.
- Establish and oversee IT governance structures, policies, standards, and procedures, ensuring organization-wide compliance.
- Design, monitor, and continuously improve the IT internal control environment through control assessments and governance reviews.
- Ensure compliance with applicable regulatory, legal, and industry requirements, coordinating regulatory engagements and remediation of findings.
- Lead technology risk management activities, including risk assessments, maintenance of the Technology Risk Register, monitoring of Key Risk Indicators (KRIs), and reporting to governance forums.
- Coordinate internal, external, and regulatory audits, ensuring timely resolution of audit findings and effective stakeholder reporting.
- Develop governance dashboards, KPIs, KRIs, compliance scorecards, and management reports for executive leadership and the Board.
- Oversee governance of third-party technology risks, outsourcing, business continuity, and disaster recovery to ensure operational resilience.
- Drive continuous improvement of IT governance maturity through benchmarking, process automation, and adoption of industry best practices.
- Foster a culture of governance, accountability, compliance, and continuous improvement across the Technology function.
- Perform any other duties as assigned by the immediate supervisor in support of departmental and organizational objectives.
Qualifications
- Bachelor's degree in information technology, Computer Science, Information Systems, Cybersecurity, or related field.
- Preferred certifications include: CISA, CISM, CRISC and CISSP
- 4 - 5 years in IT governance, technology risk, IT audit, compliance, or information security.
- Experience within a regulated industry, preferably banking or financial services.
- Experience engaging with regulators, auditors, and executive management.
go to method of application »
About the Role
The role holder is responsible for administering, maintaining, and optimizing the organization's on-premises and cloud-based IT infrastructure to ensure the availability, security, performance, and reliability of business-critical systems and services. The role provides a secure and standardized technology environment that supports business operations, development, testing, and production workloads, while serving as a key link between infrastructure and development teams to deliver sustainable, scalable, and secure technology solutions aligned with organizational objectives.
Key Accountabilities
- Monitor, administer, and maintain on-premises and cloud infrastructure, including virtual machines, databases, storage, virtual machine scale sets, VPN connections, and automated monitoring and alerting systems, to ensure optimal performance and availability.
- Manage the day-to-day security of infrastructure by administering Just-in-Time (JIT) access, communication port restrictions, and other infrastructure security controls in accordance with organizational security policies.
- Log, manage, and resolve cloud infrastructure incidents and service requests, ensuring timely restoration of services in line with agreed Service Level Agreements (SLAs). • Monitor backup operations and perform data restoration activities for cloud and on-premises servers to ensure data integrity, availability, and business continuity.
- Configure, administer, and maintain Microsoft Azure networking components, including Virtual Networks (VNets), Local Network Gateways, VPN Gateways, VPN connections, and related network services.
- Manage Azure Virtual Machine Scale Sets, including image creation, upgrades, deployments, and lifecycle management.
- Plan, coordinate, and implement infrastructure-related changes, upgrades, and deployments in compliance with the Bank's Change Management procedures.
- Administer Azure subscriptions, Azure Active Directory (Microsoft Entra ID), and role-based access control (RBAC), ensuring appropriate user access and security governance.
- Monitor and optimize Azure resource utilization, cloud costs, and billing, providing recommendations to improve cost efficiency.
- Perform capacity planning for on-premises, private cloud, and public cloud infrastructure to support current and future business requirements.
- Prepare and submit periodic infrastructure reports to management on system performance, resource utilization, cloud consumption, costs, billing, and other operational metrics.
- Act as the primary liaison between internal stakeholders and Level 2/Level 3 infrastructure support teams and technology vendors to facilitate timely issue resolution.
- Develop, maintain, and continuously update infrastructure documentation, including operational procedures, system configurations, standards, and technical processes.
- Configure, administer, troubleshoot, and support Microsoft Windows Server environments (2012, 2016, 2019, and later versions), including Active Directory, DNS, DHCP, IIS, FTP, Failover Clustering, and other core infrastructure services.
- Continuously monitor server health, performance, and availability, proactively identifying and resolving issues to ensure optimal system performance.
- Monitor and support hybrid email infrastructure to ensure service availability, reliability, and compliance with established SLAs.
- Maintain accurate documentation of server infrastructure, configurations, installed services, and assigned roles to support operational continuity and audit requirements.
- Manage the patching and update lifecycle for Windows Server and enterprise Windows environments to maintain security, compliance, and system stability.
- Perform any other duties as assigned by the immediate supervisor in support of departmental and organizational objectives.
Qualifications
- Degree holder in Information Technology from a recognized University.
- Experience with Azure, Amazon Web Services, Google Cloud Platform.
- Certifications in various system administration courses such as MCSE, Azure administration and architecture, ITIL Foundation, Linux, Solaris, Windows server etc.
- 2-3 years working experience in infrastructure administration with bias in cloud.
- Experience with automation, Git and continuous delivery.
- Practice in designing and implementing business continuity / disaster recovery and high availability plans.
- Good troubleshooting aptitude.
go to method of application »
About the Role
The Security Testing & Assurance Engineer is responsible for independently assessing the effectiveness of the organization’s cybersecurity controls, validating remediation activities, and ensuring continuous compliance with security baselines, regulatory standards, and internal policies. The role conducts technical assurance reviews, verifies CBK-required controls, supports secure system development lifecycle processes, and prepares assurance dashboards and reports for senior management and regulators. This position holder works closely with IT Security Operations, Engineering, and Risk teams while maintaining functional independence to ensure unbiased assurance outcomes.
Key Accountabilities
- Security Assurance Reviews and Technical Assessments - Conduct proactive internal and externally facing service based security assurance reviews across systems, infrastructure, networks and applications; perform technical assessments, configuration checks, access reviews and security control validations; identify weaknesses, document findings and recommend remediation actions; validate that systems meet internal information security policy requirements and baseline standards; research and develop automated testing and validation tools to enhance security testing and reporting across the Group; and support Group projects with security testing and assurance reviews to ensure new services are fit for purpose and aligned to documented policy and security best practice.
- Vulnerability and Audit Findings Validation - Validate closure of vulnerabilities identified through internal scans, penetration tests, red-team exercises and external assessments; track timely remediation of findings from Internal Audit, External Audit, regulators and risk assessments; and conduct independent technical validation to confirm remediation is effective and sustainable.
- Configuration Compliance and Baseline Checks - Perform configuration compliance assessments against security baseline standards, including CIS Benchmarks, internal hardening guides, operating system, database and network security configurations; maintain the configuration compliance repository; ensure periodic reassessment cycles; escalate deviations and follow up on remediation.
- Secure SDLC and Change Assurance - Support secure SDLC assurance for new systems, upgrades and major changes; review solution designs, security requirements, data flow diagrams and architecture documents for alignment with security standards; validate security testing results, including SAST, DAST and penetration testing, before go-live; participate in go-live readiness reviews and provide security assurance sign-off recommendations.
- Independent Verification of CBK Cybersecurity Controls - Independently verify compliance with CBK Cybersecurity Guidelines, Risk Management Guidelines and other applicable regulatory requirements; track and report deviations, control gaps and improvement areas; and provide assurance evidence for regulatory inspections and supervisory reviews.
- Assurance Reporting and Scorecards - Prepare security assurance scorecards, dashboards and management reports showing compliance status, exceptions, risk trends and remediation progress; develop structured reporting for regulators, internal committees, audit teams and senior leadership; and maintain accurate and complete assurance documentation and evidence repositories.
Qualifications
- Bachelor’s degree in information technology, Computer Science, Cybersecurity, Information Systems or related field.
- Professional certifications preferred: CEH, Security+, OSCP as an advantage, ISO 27001 or similar.
- Technical certifications in cloud or infrastructure security are an added advantage
- Minimum 3–5 years’ experience in IT security, assurance or audit.
- Experience conducting vulnerability assessments, technical reviews, or security compliance checks is essential.
- Knowledge of IT infrastructure, web, database, networking technologies from a security assurance view
- Understanding of techniques of cyber-attack and defense
- Experience in a regulated industry, including banking, telecom, fintech or government, is an advantage.
- Understanding software development tools, technologies, CI/CD, containerization, and agile methodology in relation to cyber security is an advantage
- Familiarity with CBK Cybersecurity Guidelines, Data Protection Act, PCI-DSS and ISO 27001 control requirements.
go to method of application »
About the Role
The Quality Assurance Engineer is responsible for ensuring the quality, reliability, and performance of software applications, systems, and digital products through effective test planning, execution, defect management, and quality assurance governance. The role collaborates with business users, development teams, project managers, and external vendors to ensure solutions meet business requirements, regulatory standards, and customer expectations before deployment.
Key Accountabilities
- Develop test strategies, test plans, test scenarios, and test cases for projects and change requests.
- Execute functional, integration, regression, performance, and mobile application testing.
- Maintain and prioritize testing backlogs for projects and enhancement requests.
- Coordinate and facilitate User Acceptance Testing (UAT).
- Track, report, and verify defects through to closure.
- Monitor testing progress and provide regular status reports to stakeholders.
- Develop and maintain QA dashboards and test metrics.
- Ensure adherence to QA standards, governance frameworks, and regulatory requirements.
- Identify testing risks and recommend mitigation strategies.
- Support Agile and DevSecOps delivery practices to ensure quality throughout the software development lifecycle.
Qualifications
- Bachelor’s degree in information technology, Computer Science, Software Engineering, or a related field.
- ISTQB/ASTQB Certification or equivalent testing certification are an advantage.
- Additional certifications in Agile, Scrum, or automation testing are an advantage.
- Minimum 3 years' experience in software testing and quality assurance.
- Experience with Agile testing methodologies.
- Experience using test management and defect tracking tools.
- Experience in mobile application testing and performance testing.
- Experience coordinating User Acceptance Testing (UAT).
- Core banking system testing experience is an added advantage.
go to method of application »
About the Role
The Solution Architect is responsible for designing, governing and assuring delivery of business technology solutions that support the Bank’s strategic objectives. The role provides end-to-end architecture leadership across application design, systems integration and digital transformation initiatives with strong focus on Service-Oriented Architecture (SOA).
Key Accountabilities
Solution Architecture & Application Design
- Define end-to-end solution architectures for banking applications and digital platforms.
- Translate business requirements into scalable technical solution designs and architecture blueprints.
- Ensure solutions meet security, scalability, resilience and performance requirements.
- Review and approve application architecture designs and technical specifications.
Integration Architecture & SOA
- Design and govern enterprise integration solutions using SOA principles.
- Develop reusable services and integration frameworks.
- Define service contracts, messaging standards and integration patterns.
- Design API-led architectures and enterprise service integrations.
- Lead migration from point-to-point integrations to SOA and API-driven architectures.
Architecture Governance
- Participate in Architecture Review Boards.
- Ensure compliance with enterprise architecture standards.
- Maintain architecture artefacts and repositories.
Security & Compliance
- Ensure designs comply with banking regulations and security standards.
- Embed security-by-design principles into all solutions.
Stakeholder Management
- Work with business, project, development and vendor teams.
- Provide technical leadership across project lifecycles.
Technology Innovation
- Evaluate emerging technologies including microservices, cloud, AI and open banking.
Qualifications
- Bachelor’s degree in computer science, Information Technology, Software Engineering or related field.
- TOGAF, Azure/AWS Architect, ITIL or related certification preferred.
- 4–8 years in enterprise application development, integration or architecture. 3+ years in solution architecture within banking or financial services.
Method of Application
Use the link(s) below to apply on company website.
Build your CV for free. Download in different templates.