Assistant Manager, IS Technical Assurance Specialist

Equity Bank Rwanda
jobs 1 position 4 days left
Equity Bank Rwanda Overview

Equity Bank is one of the region’s leading Banks whose purpose is to transform the lives and livelihoods of the people of Africa socially and economically by availing them modern, inclusive financial services that maximize their opportunities. With a strong footprint in Kenya, Uganda, Tanzania, Rwanda; DRC and South Sudan, Equity Bank is now home to nearly 18 million customers - the largest customer base in Africa. Currently the Bank is seeking additional talent to serve in the role outlined below.

Assistant Manager, IS Technical Assurance Specialist

Job Summary

The role holder will be responsible for overseeing the security framework to ensure security controls are in place in the bank, direct the cyber security strategy, identify threat scenarios, quantify risks, and work with stakeholders to ensure effective mitigation controls are in place and ensure compliance with all relevant regulatory requirements. Additionally, he/she will be responsible for overseeing the Bank’s vulnerability posture (vulnerability management), performing Risk Control Assessments, and designing cybersecurity controls.

Key Responsibilities and Accountability

  • Overseeing and implementing the bank’s cybersecurity program and enforcing the cybersecurity policy/framework and ensuring up-to-date information security policies and standards are in place, including the cyber risk management plan.
  • Ensure the Bank maintains a current enterprise -wide knowledge base of its users, devices, applications and their relationships
  • Keep up to date with the latest security and technology developments, research/ evaluate emerging security threats and ways to manage them.
  • Ensuring that Equity maintains a current and comprehensive cyber asset and user register.
  • Risk identification should be forward-looking and include security incident handling.
  • Ensuring that information systems meet the needs of the bank, particularly that information system development strategies comply with the overall business strategies, ERM framework, risk appetite and ICT policies.
  • Design cybersecurity controls with consideration of users at all levels of the organization, including internal (i.e., management and staff) and external users (i.e., contractors/consultants, business partners and service providers).
  • Organizing professional cyber-related training to improve the technical proficiency of staff and user awareness training for improved cyber hygiene
  • Detailed exceptions to the approved cybersecurity policies and procedures.
  • Assessment of the effectiveness of the approved cybersecurity program.
  • All material cybersecurity events that affected the Bank during the period.
  • Reporting to the Board, at least quarterly, on EQUITY’S capability to manage cybersecurity and progress in implementation of the cybersecurity strategy and goals.
  • Ensure timely update of the incident response mechanism and Business Continuity Plan (BCP) based on the latest cyber threat intelligence gathered.
  • Incorporate the utilization of scenario analysis to consider a material cyber-attack, mitigating actions, and identify potential control gaps.
  • Ensure adequate backups of critical IT systems and data in line with predetermined recovery objectives (e.g., real-time backup of changes made to critical data) are carried out to a site that is unlikely to be affected by a disaster event at the main processing site.
  • Ensure the roles and responsibilities of managing cyber risks, including in emergency or crisis decisionmaking, are clearly defined, documented and communicated to relevant staff.
  • Put in place BCP and disaster recovery test plans to ensure that the Bank can continue to function and meet its regulatory obligations in the event of an unforeseen attack through cybercrime.
  • Assess the overall effectiveness of Equity's cybersecurity program.
  • Quarterly reporting on the organization’s cybersecurity posture to senior management
  • Conduct oversight over and provide directions to any third-party service provider contracted to perform operational security functions such as information security monitoring, testing, and threat intelligence.
  • Use of advanced analytic tools to determine emerging threat patterns and vulnerabilities.
  • Drive implementation of capabilities to enable an optimal Information Security control environment; directly responsible for significantly contributing to the overall security posture, stability, and resiliency of the EQUITY environment and security solutions
  • Create and maintain security roadmap requirements by monitoring the control environment; identifying security gaps; evaluating and implementing enhancements.
  • Evaluate and manage outsourced/third-party technologies and hosting environments to ensure they provide adequate protection for the processing, transmission, and storage of EQUITY’s information; validate that security controls are designed properly, perform effectively, and align to Group Information Security
  • Work with the application functions, network teams and IT infrastructure teams to identify and assist with the implementation of Security policy, process, people and technology improvements.
  • Analyze and provide remediation guidance for identified weaknesses or vulnerabilities; validate and verify appropriate remediation
  • Work closely with the various business and Technology teams to identify and select the right security controls to protect EQUITY’s network & IT infrastructure, cloud and IoT solutions;
  • Drive assessments of security risk and audits; work with Technology Assurance, EQUITY Risk, Audit and Group teams to review compliance and audit requirements for Information
  • Security and ensure they are addressed;
  • Report any residual risk or security exposures against the security standards, policies, and noncompliance.
  • Provide actionable recommendations
  • Ensure that benchmarking is conducted with other companies and organizations within and outside the industry
  • Group and manage the actionable outcomes related to security

QUALIFICATION, SKILLS AND EXPERIENCE

  • Bachelor’s Degree in Information Technology, Information Security/Assurance, Engineering or similar area of study
  • Hold at least one relevant industry certification (CISSP, CEH, CISA, CISM, etc.)
  • Experience in vulnerability management and penetration testing in applications, APIs, network device configuration review, network architecture review, etc.
  • In-depth knowledge of security concepts such as cyber-attacks and techniques, threat vectors, risk management, incident management, etc.
  • Experience building and maintaining a high-performance team of analysts.
  • Expertise with industry-standard frameworks (ISO, NIST, PCI).
  • Experience in Big 4 is preferred
  • Minimum 2 years of experience in technical assurance or related field
  • Experience in threat management
  • Knowledge of various operating system flavors including but not limited to Windows, Linux, Unix
  • Knowledge of applications, databases, and middleware to address security threats against the same.
  • Knowledge of a number of the following: Strong Authentication, Endpoint Security, Internet Policy Enforcement, Firewalls, Web Content Filtering, Database Activity Monitoring (DAM), Public Key Infrastructure (PKI), Data Loss Prevention (DLP), Identity and Access Management (IAM).
  • Ability to effectively provide briefings to the business stakeholders regarding ongoing security incidents and threat Levels.
  • Possession of relevant certifications in information security, security testing, vulnerability management, or ethical hacking, such as CompTIA Security+, CEH, ISC2 CC, or equivalent, will be an added advantage

Key Critical Competencies

  • Proficient in preparation of reports, dashboards, and documentation
  • Excellent communication and leadership skills
  • Experience in performing vendor management
  • Ability to handle high-pressure situations with key stakeholders
  • Good Analytical skills, problem-solving, and Interpersonal skills
  • Deep knowledge of the Bank’s infrastructure, networks, and systems

Role Complexity:

Technical assurance, including vulnerability management and management of the security controls environment across at least 13 domains in all the Technology functions and in at least 7 markets of Equity Group.

Budgets/ Financial Input?

  • Assist with management of Security budgets in line with business objectives and facilitate forecasting. Includes yearly CAPEX and OPEX Plans, and tracking spend through the year
  • Manage project initiative budgets in line with business objectives
  • Drive initiatives that will ensure that the “cost of operations” is reduced, in line with a least-cost operating strategy stemming from the business drivers

If you meet the above requirements, submit your application by 17th September 2026. Please include an updated Curriculum Vitae, copies of the relevant certificates and testimonials.

All applications should be in soft copy and through the Link Indicated below, and only shortlisted candidates will be contacted:

Link: https://equitybank.taleo.net/careersection/ext_new/jobsearch.ftl

Equity Bank is an equal opportunity employer. We value the diversity of individuals, ideas, perspectives, insights, values, and what they bring to the workplace.

Share
Apply Now

All Jobs and Opportunities Published on cyizere.com are completely free to apply. A candidate should never pay any fee during the recruitment process. Even if Cyizere, Inc. | Careers team does its best to avoid any scam job or opportunity offer, if you doubt about the eligibility of any offer do not apply and notify us via this email: info@cyizere.com. Remember to never pay any fee to have a job or get any opportunity. If you do so, do it at your own risk.

Leave A Comment

© 2026 Copyright Cyizere. All Rights Reserved | Powered by Maroteck