Skip to main content

Cybersecurity and IT Auditor

Prime Life Insurance Limited

Prime Life Insurance Limited is an insurance company, established in 2011 by Rwandan investors, a licensed life insurance company authorized by the National Bank of Rwanda (BNR).

Rate this employer
Average: 4 (42 votes)

JOB VACANCY

Job Title Cybersecurity and IT Auditor (1)
Supervisor Chief Executive Officer (CEO)
Reporting to Administratively to the Chief Executive Officer (CEO); presents cybersecurity and IT audit reports to the Board of Directors on a quarterly basis
Duration Open-ended contract.
Level Officer-II
Publication Date Thursday 13/08/2026
Closing Date Sunday 23/08/2026, 23:59, CAT.

TERMS OF REFERENCE FOR THE RECRUITMENT OF A CYBERSECURITY AND IT AUDITOR

BACKGROUND

Prime Life Insurance Limited was established in December 2011 in compliance with regulatory directives requiring the separation of short-term and long-term insurance policies. In May 2012, the company obtained its license from the National Bank of Rwanda to provide life insurance services.

Fully accredited by the National Bank of Rwanda, Prime Life Insurance Limited offers a comprehensive range of long-term insurance solutions across Rwanda.

As a licensed financial institution entrusted with sensitive customer, financial, and health data, Prime Life Insurance is committed to a strong cybersecurity and IT control environment aligned with the National Cyber Security Authority (NCSA), Law N° 058/2021 on the Protection of Personal Data and Privacy, and applicable National Bank of Rwanda (BNR) requirements. In line with this commitment, Prime Life Insurance is seeking a highly skilled, self-motivated, and experienced professional to join its team as a Cybersecurity and IT Auditor.

2. POSITION: CYBERSECURITY AND IT AUDITOR (1)

Reporting administratively to the Chief Executive Officer (CEO) and presenting cybersecurity and IT audit reports to the Board of Directors on a quarterly basis, the Cybersecurity and IT Auditor will be responsible for independently assessing and reporting on IT and cybersecurity controls, regulatory compliance, risk advisory, incident response support, and governance, as outlined in the responsibilities below.

3. RESPONSIBILITIES:

A. Cybersecurity & IT Audit (35%)

  • Plan and execute risk-based audits covering network security, access management, data protection, application controls, and cloud/outsourcing arrangements.
  • Assess the design and operating effectiveness of IT general controls (ITGCs) and IT application controls across core insurance and finance systems.
  • Conduct periodic vulnerability assessments and coordinate independent penetration testing, and track remediation to closure.
  • Evaluate compliance with Law N° 058/2021 on data protection and privacy, NCSA guidelines, and BNR cybersecurity and IT risk requirements.
  • Prepare evidence-based audit reports with risk ratings and prioritised recommendations for the CEO, and present consolidated cybersecurity and IT audit reports to the Board of Directors on a quarterly basis.

B. Risk Assessment & Advisory (20%)

  • Maintain and update the IT and cyber risk register in line with the enterprise risk management framework.
  • Advise management on emerging cyber threats, control weaknesses, and industry good practice, without compromising audit independence.
  • Review new IT projects, system implementations, and vendor/outsourcing agreements to ensure security and compliance requirements are embedded from design stage.

C. Incident Response & Reporting (20%)

  • Support the cybersecurity incident response process, including root-cause analysis and post-incident audit review.
  • Assist in preparing statutory and regulatory notifications for data breaches, in coordination with the Data Protection Officer, NCSA, and BNR.
  • Report audit outcomes and control gaps to the CEO, escalating significant matters to the Board of Directors at the quarterly reporting cycle.

D. Governance, Policy & Awareness (15%)

  • Review and recommend updates to IT security policies and standards (access control, encryption, backup, incident management).
  • Support the design and delivery of staff cybersecurity awareness and training programmes.
  • Track remediation of audit findings and regulatory recommendations to closure.

E. Regulatory Responsibilities (10%)

  • Support the Data Protection Officer (DPO) function in ensuring compliance with data privacy regulations.
  • Monitor changes in Rwanda's cybersecurity, data protection, and financial-sector regulations and assess their impact on the Company's control environment.

4. Education & Experience Requirements

a) Qualifications:

  • Bachelor's degree in Information Technology, Computer Science, Information Systems Security, or a related field.
  • Minimum 3+ years of experience in IT audit, cybersecurity, or information security risk management.
  • Experience in financial services or insurance sector IT environments is a plus.
  • Familiarity with Rwanda's regulatory environment (NCSA, BNR) is required;

b) Technical Skills & Competencies:

  • Cybersecurity: Firewalls, IDS/IPS, endpoint security, penetration testing, VPNs.
  • IT Audit: IT general and application controls, ITGC testing, control frameworks (COBIT, ISO 27001, NIST).
  • IT Infrastructure: Windows/Linux server environments, virtualization, cloud, and network fundamentals (TCP/IP, VLANs, firewalls).
  • Data Protection: Data privacy principles, breach management, and regulatory reporting requirements.
  • Preferred Certifications: CISA, CISSP, CISM, CEH, ISO/IEC 27001 Lead Auditor is a plus.
  • Experience in compliance and regulatory frameworks (e.g. ISO 27001, NCSA/BNR requirements) is a plus.

5. APPLICATION PROCEDURE:

Qualified and interested Candidates should submit their applications to Prime Life Insurance Ltd mail: hr.it@prime.rw  IN ONE SINGLE PDF FILE and the application must include:

  1. Application letter addressed to CEO
  2. Curriculum Vitae (CV) with proven work Experience
  3. Copy of academic documents and professional certifications
  4. Copy of National Identification

The deadline for submitting applications is Sunday 23/08/202623:59, CAT.

Only selected candidates will be contacted.

Signed by:

HABARUREMA Innocent

Chief Executive Officer
 

Click on the APPLY button to send your application documents:
  • Your application will be sent to the employer immediately (Allowed formats: .doc .pdf .txt .docx)
  • A confirmation email will be sent to you few minutes afterwards
  • You can request any documents archived from our website (ex: a job description, a CV, a cover letter...)