Skip to main content

IT Internal Auditor

Vision Fund Rwanda

VisionFund Rwanda (VFR) is one of the largest deposit-taking Microfinance Institutions (MFIs) in Rwanda with a mission to provide financial and non-financial services to underprivileged rural communities. VFR is a subsidiary of VisionFund International and began in 1997 as a World Vision microfinance program, and in 2004 became a Central Bank regulated MFI in Rwanda.

We provide microfinance products to empower the clients we serve, primarily vulnerable women with children and youth in rural areas. Our products provide financial services to strengthen Village Savings and Loans Associations (VSLAs) and groups. Our average loan size is US $235. Strategically, we are one of the biggest partners with World Vision Rwanda and Care International in Rwanda.

Our savings products include educational savings accounts for children and we are developing financial products targeting youth. VisionFund Rwanda’s eight branches serve the entire country. Ninety percent of our field officers' work is spent in rural areas meeting potential clients and groups. The introduction of digital solutions allows our loan officers to provide better access to financial services for our most remote clients.

Sector
Finance and investment
Rate this employer
Average: 3.8 (68 votes)

September 1st 2026

JOB ADVERTISEMENT

‘’Make a difference to thousands in the land of a thousand hills’’

VisionFund Rwanda (VFR), is Rwanda’s largest microfinance Institution. VFR is committed to the development of Rwanda through providing affordable financial services (savings and loans) to the less privileged throughout its 4 zones in Rwanda. 

VFR is the institution where you can develop your expertise working with the best people worldwide in a dynamic, team focused high performance environment. If you are looking for interesting but challenging work where you can make a difference in the world, then VFR has the will to make it so.

VisionFund Rwanda (VFR) has zero tolerance to abuse and sexual exploitation of children and adults beneficiaries. We expect all our employees/affiliates to commit to protecting children and adult beneficiaries from harm and abide by our safeguarding policy.

IT Internal Auditor

Reporting to Internal Auditor Manager

Work location: Head Office/Nyarutarama

Job Purpose 

The IT Internal Auditor is responsible for planning and conducting information technology audits and reviews to assess the adequacy and effectiveness of IT governance, risk management, and internal controls. The position evaluates the organization's IT systems, applications, processes, policies, cybersecurity, and information security practices to ensure compliance with applicable laws, regulations, policies, procedures, and industry standards.

The role provides independent and objective assurance and advisory support to management on IT-related risks and controls, identifies control weaknesses, and recommends practical improvements to strengthen the overall control environment.

Main Responsibilities 

  1. Contribute to the development and implementation of the Annual Internal Audit Plan, applying a risk-based approach to identify and prioritize IT audit areas.
  2. Monitor emerging IT risks, technology developments, cybersecurity threats, regulatory requirements, and industry trends that may impact the VFR's risk and control environment.
  3. Plan and execute assigned IT audit engagements in accordance with approved audit programs, agreed timelines, scope, and quality standards.
  4. Assess IT governance, risk management, and internal controls and provide management with practical recommendations for strengthening IT risk management and the control environment.
  5. Conduct and, where assigned, lead IT audits and reviews covering areas including:
  • IT General Controls;
  • Information and Cybersecurity;
  • IT Governance and IT Risk Management;
  • Systems and application reviews;
  • Access and user administration;
  • Backup and disaster recovery/business continuity;
  • IT projects and Project Assurance;
  • IT policies, procedures, standards, and frameworks;
  • Third-party/vendor technology risk.
  1. Utilize data analytics, and technology-enabled audit techniques to improve the efficiency, effectiveness, and coverage of IT audit activities.
  2. Prepare and maintain complete and well-organized audit working papers, documenting the audit process from planning through fieldwork, conclusion, and reporting in accordance with Internal Audit methodology and quality standards.
  3. Perform timely validation and follow-up of management's implementation of agreed audit actions, and provide accurate issue tracking and status reporting.
  4. Monitor and communicate emerging IT risks, recurring control weaknesses, process inefficiencies, and potential solutions to management and the Internal Audit Manager.
  5. Contribute to the continuous improvement of Internal Audit methodologies, quality assurance standards, audit programs, templates, tools, and data analytics techniques, particularly for IT audit assignments.
  6. Maintain awareness of applicable laws, regulations, regulatory guidance, internal policies, and recognized IT and cybersecurity frameworks relevant to the organization's operations.
  7. Collaborate effectively with Internal Audit team and key stakeholders, including IT, Operations, Risk, Compliance, Finance, and other business functions, while maintaining appropriate independence and professional objectivity.
  8. Provide advisory input on IT-related initiatives, systems, projects, and process changes, where requested, without assuming management responsibility or compromising Internal Audit independence.
  9. Support the Internal Audit Manager in preparing audit reports, management updates, committee reporting, and other Internal Audit deliverables related to IT risk and control matters.
  10. Maintain professional competence and continuously develop IT audit, cybersecurity, data analytics, risk management, and regulatory knowledge to remain current with evolving technology and emerging risks.
  11. Perform any other duties related to Internal Audit and IT risk and control assurance as assigned by the Internal Audit Manager.

Education & Core Competencies Required

  • Degree in Computer Science or related discipline.
  • Certified Information System Auditor (CISA) or Pursuing CISA.
  • Additional Certification e.g. CISM, CRISC an added advantage.
  • At least 3 years’ experience in information System Audit.
  • Strong analytic skills. Ability to conduct analysis of Business processes and operations and to think strategically using financial analysis.
  • Excellent communication and negotiation skills.
  • Ability to present financial information effectively to both specialists and non-specialists.
  • Understanding of financial and banking software packages, preferably familiarity with Orbit Rubikon Banking Solution.
  • Knowledge of micro, small and medium enterprise Market segments in Rwanda

Attributes Desired:

  • Understanding of Banking System Enterprises Resources Planners (ERPS) Operating System and Database.
  • Data Analysis skill include ability to use data analysis took to perform test identify trends provide insight interpret and communicate results.
  • Understanding of information Security standard took and best practices.
  • Understand of IT Governance and IT Audit fundamentals.
  • Knowledge of internal auditing internal control risk management and corporate governance.
  • Ability to write reports.
  • Maintain Professional understanding internal Audit International Professional Practice and consistently apply them to improve the audit methodology and deliverable.

How to apply

Should you wish to apply for this position, please go to the following link Search for Jobs

All applicants must apply using our online application system, CVs received via email or standard post will not be considered. If the aforementioned positions speak to you, send your application via above-mentioned Link by or before 11th September2026.

In case you face any challenges in applying, please let us know on: recruitment@vfcrwanda.rw (no applications will be accepted through this email).

Only shortlisted candidates will be contacted.

Click on the APPLY button to send your application documents:
  • Your application will be sent to the employer immediately (Allowed formats: .doc .pdf .txt .docx)
  • A confirmation email will be sent to you few minutes afterwards
  • You can request any documents archived from our website (ex: a job description, a CV, a cover letter...)