- Location
- Capital City Building Branch, Seychelles
- Workplace
- Hybrid
- Type
- Full-time
- Department
- Finance
- Seniority
- Manager
- Closing date
- Today
- Source
- Workday
Description
Empowering Africa’s tomorrow, together…one story at a time.
With over 100 years of rich history and strongly positioned as a local bank with regional and international expertise, a career with our family offers the opportunity to be part of this exciting growth journey, to reset our future and shape our destiny as a proudly African group.
My Career Development Portal: Wherever you are in your career, we are here for you. Design your future. Discover leading-edge guidance, tools and support to unlock your potential. You are Absa. You are possibility.
Job Summary
To provide first-line Information Risk Management oversight across Absa Bank Seychelles by embedding effective governance, risk management, and control practices relating to information security, data privacy, logical access management, and data governance. The role supports business resilience and regulatory compliance by ensuring information risks are proactively managed, monitored, and reported in alignment with Absa Group standards and organisational objectives.Job Description
Information Risk Management Delivery (30%)
- Act as the primary Information Risk Management (IRM) lead for Seychelles, providing subject matter expertise and guidance to business and support functions.
- Implement and embed Information Risk policies, standards, frameworks, and governance requirements across the organisation.
- Maintain oversight of the information risk profile, ensuring key risks, control weaknesses, audit findings, risk events, and remediation actions are effectively identified, managed, escalated, and closed within agreed timelines.
- Drive achievement of Information Risk objectives, including Risk and Control Assessments (RCAs), Control Self-Assessments (CSAs), Key Risk Indicators (KRIs), Risk Events, Risk Appetite metrics, and regulatory requirements.
- Support and coordinate assurance, audit, and compliance reviews, ensuring timely remediation of identified issues.
- Provide risk input into business initiatives, projects, and change programmes to ensure risks are appropriately assessed and mitigated.
- Analyse the effectiveness of information risk processes, controls, reporting, and governance mechanisms, recommending improvements where required.
- Represent Information Risk Management at relevant governance forums, committees, and stakeholder engagements.
Information Security and Logical Access Management (20%)
- Act as the Information Security and Logical Access Management (LAM) subject matter expert for Seychelles.
- Ensure alignment with Group Information Security policies, standards, and control requirements.
- Provide risk and security oversight for projects, systems, applications, and business initiatives to safeguard information assets.
- Ensure appropriate access management controls, including user provisioning, role design, segregation of duties, joiner/mover/leaver processes, access recertification, and deprovisioning controls.
- Monitor information security and access management risks, control deficiencies, and audit findings, ensuring timely remediation and escalation where required.
- Provide specialist advice on information security, cyber risk, and access management matters across the business.
Data Governance, Records Management and End User Computing (20%)
- Implement and monitor governance frameworks for Data Quality, Records Management, Data Classification, and End User Computing (EUC).
- Ensure relevant standards, processes, and reporting requirements are embedded and effectively communicated across the business.
- Monitor compliance with established controls and governance requirements, escalating material issues where necessary.
- Work with business stakeholders to strengthen data quality, information management, and record retention practices.
- Facilitate periodic reporting and oversight activities to support effective governance and regulatory compliance.
Data Privacy and Protection (20%)
- Act as the primary Data Privacy subject matter expert for the business and support compliance with applicable privacy legislation, regulatory requirements, policies, and standards.
- Drive implementation and operationalisation of privacy controls across the organisation.
- Support the management, escalation, investigation, and reporting of privacy incidents and breaches.
- Provide privacy risk advisory support to business areas, projects, third-party engagements, and change initiatives.
- Support conduct privacy oversight, monitoring, assurance activities, and risk assessments to ensure ongoing compliance.
- Collaborate with Compliance, Service Technology, Data Management, and other relevant stakeholders to strengthen privacy and data protection controls.
- Report on privacy risks, incidents, key metrics, and regulatory compliance obligations.
Strategy, Stakeholder Management and Reporting (10%)
- Support the Head of Governance & Control in the development, implementation, and alignment of Information Risk Management strategies and objectives.
- Build and maintain effective relationships with business leaders, risk teams, regulators, auditors, and regional stakeholders.
- Provide strategic advice on emerging information risk, technology, security, privacy, and data management trends.
- Prepare, review, and present management information, risk reports, metrics, and governance updates to relevant stakeholders and committees.
- Ensure timely and accurate completion of all Information Risk reporting and regulatory requirements.
Education
Higher Diplomas: Physical, Mathematical, Computer and Life Sciences (Required)