Cybersecurity and IT Auditor job at Prime Life Insurance Limited
New
Website :
Today
Linkedid Twitter Share on facebook
Cybersecurity and IT Auditor
2026-08-14T03:19:45+00:00
Prime Life Insurance Limited
https://cdn.greatrwandajobs.com/jsjobsdata/data/employer/comp_1653/logo/Prime%20Life%20Insurance%20Limited.png
FULL_TIME
Kigali
Kigali
00000
Rwanda
Insurance
Computer & IT, Business Operations
RWF
MONTH
2026-08-23T17:00:00+00:00
8

BACKGROUND

Prime Life Insurance Limited was established in December 2011 in compliance with regulatory directives requiring the separation of short-term and long-term insurance policies. In May 2012, the company obtained its license from the National Bank of Rwanda to deliver life insurance services.

Fully accredited by the National Bank of Rwanda, Prime Life Insurance Limited offers a comprehensive range of long-term insurance solutions across Rwanda.

As a licensed financial institution entrusted with sensitive customer, financial, and health data, Prime Life Insurance is committed to a strong cybersecurity and IT control environment aligned with the National Cyber Security Authority (NCSA), Law N° 058/2021 on the Protection of Personal Data and Privacy, and applicable National Bank of Rwanda (BNR) requirements. In line with this commitment, Prime Life Insurance is seeking a highly skilled, self-motivated, and experienced professional to join its team as a Cybersecurity and IT Auditor.

POSITION: CYBERSECURITY AND IT AUDITOR (1)

Reporting administratively to the Chief Executive Officer (CEO) and presenting cybersecurity and IT audit reports to the Board of Directors on a quarterly basis, the Cybersecurity and IT Auditor will be tasked with independently assessing and reporting on IT and cybersecurity controls, regulatory compliance, risk advisory, incident response assist, and governance, as outlined in the responsibilities below.

RESPONSIBILITIES:

A. Cybersecurity & IT Audit (35%)

Plan and execute risk-based audits covering network security, access management, data protection, application controls, and cloud/outsourcing arrangements.

Assess the design and operating effectiveness of IT general controls (ITGCs) and IT application controls across core insurance and finance systems.

Conduct periodic vulnerability assessments and organize independent penetration testing, and track remediation to closure.

Evaluate compliance with Law N° 058/2021 on data protection and privacy, NCSA guidelines, and BNR cybersecurity and IT risk requirements.

Prepare evidence-based audit reports with risk ratings and prioritised recommendations for the CEO, and present consolidated cybersecurity and IT audit reports to the Board of Directors on a quarterly basis.

B. Risk Assessment & Advisory (20%)

Keep and update the IT and cyber risk register in line with the enterprise risk management framework.

Advise management on emerging cyber threats, control weaknesses, and industry good practice, without compromising audit independence.

Evaluate new IT projects, system implementations, and vendor/outsourcing agreements to ensure security and compliance requirements are embedded from design stage.

C. Incident Response & Reporting (20%)

Support the cybersecurity incident response process, including root-cause analysis and post-incident audit evaluate.

Help with preparing statutory and regulatory notifications for data breaches, in coordination with the Data Protection Officer, NCSA, and BNR.

Report audit outcomes and control gaps to the CEO, escalating significant matters to the Board of Directors at the quarterly reporting cycle.

D. Governance, Policy & Awareness (15%)

Evaluate and recommend updates to IT security policies and standards (access control, encryption, backup, incident management).

Assist the design and delivery of staff cybersecurity awareness and training programmes.

Track remediation of audit findings and regulatory recommendations to closure.

E. Regulatory Responsibilities (10%)

Support the Data Protection Officer (DPO) function in ensuring compliance with data privacy regulations.

Track changes in Rwanda's cybersecurity, data protection, and financial-sector regulations and assess their impact on the Company's control environment.

Education & Experience Requirements

a) Qualifications:

Bachelor's degree in Information Technology, Computer Science, Information Systems Security, or a related field.

Minimum 3+ years of experience in IT audit, cybersecurity, or information security risk management.

Experience in financial services or insurance sector IT environments is a plus.

Familiarity with Rwanda's regulatory environment (NCSA, BNR) is required;

b) Technical Skills & Competencies:

Cybersecurity: Firewalls, IDS/IPS, endpoint security, penetration testing, VPNs.

IT Audit: IT general and application controls, ITGC testing, control frameworks (COBIT, ISO 27001, NIST).

IT Infrastructure: Windows/Linux server environments, virtualization, cloud, and network fundamentals (TCP/IP, VLANs, firewalls).

Data Protection: Data privacy principles, breach management, and regulatory reporting requirements.

Preferred Certifications: CISA, CISSP, CISM, CEH, ISO/IEC 27001 guide Auditor is a plus.

Experience in compliance and regulatory frameworks (e.g. ISO 27001, NCSA/BNR requirements) is a plus.

  • Plan and execute risk-based audits covering network security, access management, data protection, application controls, and cloud/outsourcing arrangements.
  • Assess the design and operating effectiveness of IT general controls (ITGCs) and IT application controls across core insurance and finance systems.
  • Conduct periodic vulnerability assessments and organize independent penetration testing, and track remediation to closure.
  • Evaluate compliance with Law N° 058/2021 on data protection and privacy, NCSA guidelines, and BNR cybersecurity and IT risk requirements.
  • Prepare evidence-based audit reports with risk ratings and prioritised recommendations for the CEO, and present consolidated cybersecurity and IT audit reports to the Board of Directors on a quarterly basis.
  • Keep and update the IT and cyber risk register in line with the enterprise risk management framework.
  • Advise management on emerging cyber threats, control weaknesses, and industry good practice, without compromising audit independence.
  • Evaluate new IT projects, system implementations, and vendor/outsourcing agreements to ensure security and compliance requirements are embedded from design stage.
  • Support the cybersecurity incident response process, including root-cause analysis and post-incident audit evaluate.
  • Help with preparing statutory and regulatory notifications for data breaches, in coordination with the Data Protection Officer, NCSA, and BNR.
  • Report audit outcomes and control gaps to the CEO, escalating significant matters to the Board of Directors at the quarterly reporting cycle.
  • Evaluate and recommend updates to IT security policies and standards (access control, encryption, backup, incident management).
  • Assist the design and delivery of staff cybersecurity awareness and training programmes.
  • Track remediation of audit findings and regulatory recommendations to closure.
  • Support the Data Protection Officer (DPO) function in ensuring compliance with data privacy regulations.
  • Track changes in Rwanda's cybersecurity, data protection, and financial-sector regulations and assess their impact on the Company's control environment.
  • Cybersecurity: Firewalls, IDS/IPS, endpoint security, penetration testing, VPNs.
  • IT Audit: IT general and application controls, ITGC testing, control frameworks (COBIT, ISO 27001, NIST).
  • IT Infrastructure: Windows/Linux server environments, virtualization, cloud, and network fundamentals (TCP/IP, VLANs, firewalls).
  • Data Protection: Data privacy principles, breach management, and regulatory reporting requirements.
  • Experience in compliance and regulatory frameworks (e.g. ISO 27001, NCSA/BNR requirements) is a plus.
  • Bachelor's degree in Information Technology, Computer Science, Information Systems Security, or a related field.
  • Minimum 3+ years of experience in IT audit, cybersecurity, or information security risk management.
  • Experience in financial services or insurance sector IT environments is a plus.
  • Familiarity with Rwanda's regulatory environment (NCSA, BNR) is required.
  • Preferred Certifications: CISA, CISSP, CISM, CEH, ISO/IEC 27001 guide Auditor is a plus.
bachelor degree
12
JOB-6a7e8951991c1

Vacancy title:
Cybersecurity and IT Auditor

[Type: FULL_TIME, Industry: Insurance, Category: Computer & IT, Business Operations]

Jobs at:
Prime Life Insurance Limited

Deadline of this Job:
Sunday, August 23 2026

Duty Station:
Kigali | Kigali

Summary
Date Posted: Friday, August 14 2026, Base Salary: Not Disclosed

Similar Jobs in Rwanda
Learn more about Prime Life Insurance Limited
Prime Life Insurance Limited jobs in Rwanda

JOB DETAILS:

BACKGROUND

Prime Life Insurance Limited was established in December 2011 in compliance with regulatory directives requiring the separation of short-term and long-term insurance policies. In May 2012, the company obtained its license from the National Bank of Rwanda to deliver life insurance services.

Fully accredited by the National Bank of Rwanda, Prime Life Insurance Limited offers a comprehensive range of long-term insurance solutions across Rwanda.

As a licensed financial institution entrusted with sensitive customer, financial, and health data, Prime Life Insurance is committed to a strong cybersecurity and IT control environment aligned with the National Cyber Security Authority (NCSA), Law N° 058/2021 on the Protection of Personal Data and Privacy, and applicable National Bank of Rwanda (BNR) requirements. In line with this commitment, Prime Life Insurance is seeking a highly skilled, self-motivated, and experienced professional to join its team as a Cybersecurity and IT Auditor.

POSITION: CYBERSECURITY AND IT AUDITOR (1)

Reporting administratively to the Chief Executive Officer (CEO) and presenting cybersecurity and IT audit reports to the Board of Directors on a quarterly basis, the Cybersecurity and IT Auditor will be tasked with independently assessing and reporting on IT and cybersecurity controls, regulatory compliance, risk advisory, incident response assist, and governance, as outlined in the responsibilities below.

RESPONSIBILITIES:

A. Cybersecurity & IT Audit (35%)

Plan and execute risk-based audits covering network security, access management, data protection, application controls, and cloud/outsourcing arrangements.

Assess the design and operating effectiveness of IT general controls (ITGCs) and IT application controls across core insurance and finance systems.

Conduct periodic vulnerability assessments and organize independent penetration testing, and track remediation to closure.

Evaluate compliance with Law N° 058/2021 on data protection and privacy, NCSA guidelines, and BNR cybersecurity and IT risk requirements.

Prepare evidence-based audit reports with risk ratings and prioritised recommendations for the CEO, and present consolidated cybersecurity and IT audit reports to the Board of Directors on a quarterly basis.

B. Risk Assessment & Advisory (20%)

Keep and update the IT and cyber risk register in line with the enterprise risk management framework.

Advise management on emerging cyber threats, control weaknesses, and industry good practice, without compromising audit independence.

Evaluate new IT projects, system implementations, and vendor/outsourcing agreements to ensure security and compliance requirements are embedded from design stage.

C. Incident Response & Reporting (20%)

Support the cybersecurity incident response process, including root-cause analysis and post-incident audit evaluate.

Help with preparing statutory and regulatory notifications for data breaches, in coordination with the Data Protection Officer, NCSA, and BNR.

Report audit outcomes and control gaps to the CEO, escalating significant matters to the Board of Directors at the quarterly reporting cycle.

D. Governance, Policy & Awareness (15%)

Evaluate and recommend updates to IT security policies and standards (access control, encryption, backup, incident management).

Assist the design and delivery of staff cybersecurity awareness and training programmes.

Track remediation of audit findings and regulatory recommendations to closure.

E. Regulatory Responsibilities (10%)

Support the Data Protection Officer (DPO) function in ensuring compliance with data privacy regulations.

Track changes in Rwanda's cybersecurity, data protection, and financial-sector regulations and assess their impact on the Company's control environment.

Education & Experience Requirements

a) Qualifications:

Bachelor's degree in Information Technology, Computer Science, Information Systems Security, or a related field.

Minimum 3+ years of experience in IT audit, cybersecurity, or information security risk management.

Experience in financial services or insurance sector IT environments is a plus.

Familiarity with Rwanda's regulatory environment (NCSA, BNR) is required;

b) Technical Skills & Competencies:

Cybersecurity: Firewalls, IDS/IPS, endpoint security, penetration testing, VPNs.

IT Audit: IT general and application controls, ITGC testing, control frameworks (COBIT, ISO 27001, NIST).

IT Infrastructure: Windows/Linux server environments, virtualization, cloud, and network fundamentals (TCP/IP, VLANs, firewalls).

Data Protection: Data privacy principles, breach management, and regulatory reporting requirements.

Preferred Certifications: CISA, CISSP, CISM, CEH, ISO/IEC 27001 guide Auditor is a plus.

Experience in compliance and regulatory frameworks (e.g. ISO 27001, NCSA/BNR requirements) is a plus.

Work Hours: 8

Experience in Months: 12

Level of Education: bachelor degree

Job application procedure
Interested in applying for this job? Click here to submit your application now.

Qualified and interested Candidates should submit their applications to Prime Life Insurance Ltd IN ONE SINGLE PDF FILE and the application must include:

  • Application letter addressed to CEO
  • Curriculum Vitae (CV) with proven work Experience
  • Copy of academic documents and professional certifications
  • Copy of National Identification

The deadline for submitting applications is Sunday 23/08/2026, 23:59, CAT.

Only selected candidates will be contacted.

Signed by:

HABARUREMA Innocent

Chief Executive Officer

All Jobs | QUICK ALERT SUBSCRIPTION

Job Info
Job Category: Computer/ IT jobs in Rwanda
Job Type: Full-time
Deadline of this Job: Sunday, August 23 2026
Duty Station: Kigali | Kigali
Posted: 14-08-2026
No of Jobs: 1
Start Publishing: 14-08-2026
Stop Publishing (Put date of 2030): 10-10-2076
Apply Now
Notification Board

Join a Focused Community on job search to uncover both advertised and non-advertised jobs that you may not be aware of. A jobs WhatsApp Group Community can ensure that you know the opportunities happening around you and a jobs Facebook Group Community provides an opportunity to discuss with employers who need to fill urgent position. Click the links to join. You can view previously sent Email Alerts here incase you missed them and Subscribe so that you never miss out.

Caution: Never Pay Money in a Recruitment Process.

Some smart scams can trick you into paying for Psychometric Tests.