NCBA Tanzania

Internal Audit Assistant Manager-ICT

NCBA Tanzania
Dar Es Salaam Full-time Negotiable Information Technology Apply before Aug 24, 2026

Job Description

This is a mid-to-senior ICT audit position within NCBA Bank, focused on providing independent assurance over the bank’s technology environment. The role combines IT auditing, cybersecurity, ICT risk management, technology controls, regulatory compliance, data analytics, and advisory work.

The person in this role would assess whether NCBA’s systems, applications, infrastructure, information security controls, and IT processes are properly designed and operating effectively. They would also report significant technology risks to senior management and the Board Audit Committee and follow up until identified issues are properly resolved.

Key Responsibilities

  • Develop annual ICT audit plans and define audit scope in line with the bank’s ICT strategy.

  • Provide guidance to business and ICT management on technology risk management, application security, and infrastructure security.

  • Conduct audits and reviews of IT systems, applications, infrastructure, and technology processes.

  • Perform pre-implementation and post-implementation reviews of new systems and system enhancements.

  • Conduct IT security audits covering areas such as networks, operating systems, databases, and data centres.

  • Assess whether security vulnerabilities have been properly identified, managed, and mitigated.

  • Coordinate ICT audit reviews with business units, external security specialists, external auditors, and regulatory assessors where necessary.

  • Evaluate information technology general controls and test compliance with established controls.

  • Review change management, business continuity, disaster recovery, information security, and ICT management policies and procedures.

  • Develop and implement data-analysis tools to improve the efficiency and effectiveness of internal audits.

  • Use audit analytics to provide business insights and support continuous auditing.

  • Track identified ICT audit issues and independently validate whether management has adequately resolved them.

  • Continuously monitor the bank's ICT environment and identify significant emerging technology risks.

  • Independently assess ICT risks and determine areas requiring additional investment or increased audit attention.

  • Evaluate the effect of ICT risks on the bank's overall risk profile and audit universe.

  • Coordinate external auditors, regulators, and assessors during technology-related reviews.

  • Monitor the whistleblowing process in accordance with the bank's policy.

  • Support the review and improvement of Internal Audit policies, procedures, and methodologies.

  • Conduct special investigations and assignments as directed by the Head of Internal Audit.

  • Perform advisory and consulting reviews designed to improve processes and create business value.

  • Maintain strong relationships with management, Internal Audit, Group Internal Audit, the Board Audit Committee, regulators, external auditors, and other stakeholders.

  • Discuss audit findings with responsible teams, confirm factual accuracy, and agree on appropriate corrective actions.

  • Prepare timely ICT audit reports and follow up on remediation of audit findings.

  • Maintain continuous professional development and complete required learning and development activities.

  • Promote positive change and contribute to improving the bank's ICT control environment.

Qualifications and Requirements

  • Bachelor's degree, preferably in:

    • Computer Science

    • Accounting

    • Finance

    • A related technology or business discipline

  • Master's degree in Finance, Accounting, Computer Science, ICT Risk Management/Governance, Business Administration, or a related field is an added advantage.

  • Professional qualification such as:

    • CISA

    • CPA

    • CIA

    • CISSP

    • An equivalent professional certification

  • At least 4 years of managerial experience in ICT auditing or ICT risk/control assurance.

  • Experience in the financial services industry or a reputable audit firm is preferred.

  • Knowledge of emerging banking products and services.

  • Understanding of multiple technology areas, including:

    • Software development

    • Windows environments

    • Database management

    • Networking

    • SAP

    • T24

  • Understanding of information-security standards and best practices for securing computer systems.

  • Knowledge of applicable ICT laws, regulations, and regulatory requirements.

  • Practical understanding of the financial-sector regulatory environment.

  • Demonstrated high performance and professional integrity.

What the Employer Is Really Looking For

The strongest candidate is not simply an IT professional. This role requires someone who can audit technology from a risk and governance perspective.

In particular, the candidate should be able to:

  1. Identify ICT risks — understand how weaknesses in systems, applications, networks, cybersecurity, or IT processes could affect the bank.

  2. Test controls — determine whether technology controls actually work rather than simply checking whether policies exist.

  3. Understand banking technology — familiarity with systems such as T24 and SAP is valuable.

  4. Understand cybersecurity — particularly infrastructure security, vulnerabilities, access controls, and information-security practices.

  5. Communicate with senior management — convert technical findings into clear business risks and actionable recommendations.

  6. Lead audit assignments — plan, execute, document, report, and follow up ICT audits.

  7. Use data analytics — develop or use analytical tools to identify trends, anomalies, and control weaknesses.

  8. Work independently — provide objective assurance rather than simply accepting management's assessment of risks.

  9. Understand regulations — ensure technology controls meet banking and regulatory expectations.

  10. Influence remediation — work with management to ensure identified weaknesses are actually corrected.

Who Can Apply

This opportunity is primarily suited to experienced professionals with backgrounds in ICT audit, IT risk, cybersecurity assurance, technology controls, internal audit, or financial-services technology risk.

Candidates with general IT experience but without meaningful audit, risk, controls, or assurance experience may find it difficult to demonstrate a strong fit.

A particularly competitive profile would combine ICT/technology expertise + internal auditing + banking/financial-services experience + CISA/CIA/CISSP/CPA certification.

Overall Assessment

This is a senior ICT assurance role rather than a conventional IT support or software-development position. The emphasis is on independently assessing whether the bank's technology environment is secure, controlled, compliant, and capable of supporting business objectives.

The most important areas to highlight on a CV would be ICT audits, IT general controls, cybersecurity audits, application and infrastructure audits, technology risk assessments, data analytics, regulatory compliance, audit reporting, issue remediation, and stakeholder management.

NCBA Tanzania

NCBA Tanzania

Financial Services • Dar es Salam

Company Size 500+
Founded N/A

About the Company

NCBA Bank is a leading financial institution in East Africa, committed to providing innovative financial solutions that help our clients achieve their financial goals. With a rich history spanning over 60 years, we have built a reputation for excellence in service delivery, a strong brand, and a customer-centric approach. We offer a wide range of financial products and services to both retail and corporate clients, including personal banking, business banking, investment banking, and wealth management. Our team of experienced professionals is dedicated to providing personalized financial advice and solutions that are tailored to meet the unique needs of each of our clients. At NCBA Bank, we believe in the power of collaboration and have established strategic partnerships with leading companies in various industries to provide our clients with access to innovative products and services that complement our offerings. We are also committed to promoting financial inclusion and have implemented various initiatives to support individuals and businesses in underserved communities. Our mission is to empower our clients to achieve their financial aspirations through innovative solutions and exceptional service. We are proud of our track record of success, and we look forward to continuing to serve our clients and communities with integrity, professionalism, and excellence.

View profile