Equity Group Holdings PLC is a Pan-African Financial Services Group with operations in six countries, namely Kenya, Rwanda, DRC, Uganda, Tanzania, and South Sudan. We also have the ambition to grow our footprint to a further six countries by 2030. The scope of our business cuts across Banking, Insurance, Technology, and Social Enterprise. Our business model is underpinned by Social, Economic, and Sustainability engines (TriEngine Model) that capacitate value chains sustainably and support communities. Our Purpose is “Transforming lives, giving dignity and expanding opportunities for wealth creation”. Our Vision is “To be the champion of the socio-economic prosperity of the people of Africa”. Our mission is lived through our global values of professionalism, Integrity, Creativity & Innovation, Teamwork, Utility of Purpose, Respect, and Effective Corporate Governance, summarized in the acronym PICTURE. Our Strategic ambitions are articulated in the Africa Recovery and Resilience Plan (ARRP). Currently, the Bank is seeking additional talent to serve as HEAD OF CYBERSECURITY(CISO), whose holder reports to the Managing Director.
HEAD OF CYBERSECURITY (CISO)
Position Title: Head of Cyber Security (CISO) - Rwanda
Position Grade/level: Director
Reports to: Managing Director
Function/Department: Information Security
Subsidiary: Rwanda
Job Summary
The Head of Cyber Security (CISO) is accountable for establishing, implementing, and continuously improving the subsidiary cybersecurity strategy, governance framework, and security operating model. The role protects the confidentiality, integrity, and availability of customer information, banking systems, digital channels, and critical services while enabling the subsidiary’s business and digital growth objectives. The role provides independent cyber risk oversight, leads country cyber defense and resilience, and ensures compliance with Rwanda’s cybersecurity, banking, data protection and privacy requirements. It also translates Group security strategy, policies and standards into effective local controls, with locally owned execution, evidence and regulatory accountability.
KEY RESPONSIBILITIES.
- Develop and maintain a risk-based Rwanda cybersecurity strategy and roadmap aligned to the subsidiary business plan, risk appetite, Group standards and regulatory requirements.
- Provide clear cyber risk reporting to Executive Management, the Board IT Committee and relevant Group governance forums.
- Maintain the subsidiary cybersecurity policy framework, standards, procedures, exceptions and control ownership model.
- Ensure cybersecurity is embedded in technology planning, product design, projects, procurement and change governance.
- Own the country cyber risk profile and ensure risks are identified, assessed, treated, accepted, monitored and escalated through approved governance channels.
- Ensure compliance with applicable National Bank of Rwanda regulations, Rwanda data protection and privacy requirements, National Cyber Security Authority directives and other relevant obligations.
- Coordinate regulatory reviews, internal and external audits, independent security assessments, penetration tests and remediation of findings.
- Maintain reliable evidence of control design, implementation and operating effectiveness.
- Provide leadership and oversight for security monitoring, threat detection, vulnerability management, incident response, digital forensics and cyber threat intelligence.
- Ensure incidents are classified, contained, investigated, recovered and reported within applicable internal and regulatory requirements.
- Maintain and test cyber incident response, crisis management and communication arrangements with Technology, Risk, Legal, Compliance, Business Continuity and Corporate Affairs.
- Ensure lessons from incidents, exercises and threat intelligence are translated into sustainable control improvements.
- Provide leadership and oversight for security monitoring, threat detection, vulnerability management, incident response, digital forensics and cyber threat intelligence.
- Ensure incidents are classified, contained, investigated, recovered and reported within applicable internal and regulatory requirements.
- Maintain and test cyber incident response, crisis management and communication arrangements with Technology, Risk, Legal, Compliance, Business Continuity and Corporate Affairs.
- Ensure lessons from incidents, exercises and threat intelligence are translated into sustainable control improvements.
- Provide leadership and oversight for security monitoring, threat detection, vulnerability management, incident response, digital forensics and cyber threat intelligence.
- Ensure incidents are classified, contained, investigated, recovered and reported within applicable internal and regulatory requirements.
- Maintain and test cyber incident response, crisis management and communication arrangements with Technology, Risk, Legal, Compliance, Business Continuity and Corporate Affairs.
- Ensure lessons from incidents, exercises and threat intelligence are translated into sustainable control improvements.
- Provide leadership and oversight for security monitoring, threat detection, vulnerability management, incident response, digital forensics and cyber threat intelligence.
- Ensure incidents are classified, contained, investigated, recovered and reported within applicable internal and regulatory requirements.
- Maintain and test cyber incident response, crisis management and communication arrangements with Technology, Risk, Legal, Compliance, Business Continuity and Corporate Affairs.
- Ensure lessons from incidents, exercises and threat intelligence are translated into sustainable control improvements.
CORE ACCOUNTABILITIES AND DELIVERABLES
Financial:
- Own and optimize the subsidiary cybersecurity budget, resource plan and investment roadmap, demonstrating value, risk reduction and disciplined cost management.
Customer:
- Protect customer information and maintain trust in digital and physical banking services through effective preventive, detective and recovery controls.
- Process, risk and compliance: : Maintain an effective country cybersecurity governance, risk, compliance, incident management and assurance framework with timely closure of material issues.
KEY DECISIONS MADE BY THE JOB-HOLDER (NOT RECOMMENDATIONS) AND HOW OFTEN
- Country cybersecurity priorities: Set and adjust country cybersecurity priorities and implementation sequencing within approved strategy, risk appetite and budget.
- Cyber risk treatment : Determine treatment and escalation recommendations for material cyber risks; approve operational treatments within delegated authority.
Per Event response:
- Direct containment, investigation, recovery, and escalation for material cybersecurity incidents.
- Security exceptions Approve, reject or escalate security exceptions and compensating controls within delegated authority.
- Determine whether material security conditions have been met before production release or escalate residual risk for formal acceptance.
- Budget and resources
- Set country security resource priorities and allocate approved cybersecurity spend.
- Annual/As required
COMPLEXITY EXPECTED IN THE ROLE
(eg. multiple countries, cross-functional responsibilities, delivering through other third parties, e.g)
- Balances local regulatory independence and accountability with Group policy, shared platforms and regional operating standards.
- Protects a regulated banking environment with interconnected legacy, digital, cloud, third-party and Group-provided services.
- Leads cross-functional outcomes through Technology, Risk, Legal, Compliance, HR, Procurement, Operations and business teams, including areas outside direct authority.
- Manages fast-changing cyber threats, material incidents and regulatory expectations while supporting innovation, customer access and service continuity.
- Delivers outcomes through internal teams, shared Group capabilities, managed security providers and specialist third parties.
CRITICAL RELATIONSHIPS/STAKEHOLDERS/CONTACTS
A: Internal:
- Managing Director / CEO, Executive Management, Board IT Committee and other Board committees as required.
- Group CISO and Group Information Security teams;
- Country CIO / Head of Technology;
- Enterprise Risk, Compliance, Legal, Internal Audit, Business Continuity, Operations and business leaders.
- B: External: Agencies, Suppliers, Public Media/Press, National Bank of Rwanda, National Cyber Security, Authority, Data Protection and Privacy Office, Rwanda Utilities Regulatory Authority and other competent authorities as applicable.
- Cybersecurity service providers, technology vendors, external auditors, law enforcement and relevant industry bodies.
QUALIFICATIONS, EXPERIENCE, SKILLS AND ATTRIBUTES
- Bachelor’s degree in computer science, Information Technology, Cybersecurity, Engineering, Risk Management or a related discipline.
- A postgraduate qualification in Information Security, Risk Management, Business Administration or Technology Management is advantageous.
- At least one relevant professional certification is strongly preferred, such as CISSP, CISM, CRISC, CCISO, ISO/IEC 27001 Lead Implementer or Lead Auditor.
- Additional certifications in cloud security, incident response, privacy, business continuity or technology audit are advantageous.
- Ability to convert business strategy and risk appetite into a practical security strategy, operating model and investment roadmap.
- Strong knowledge of cyber risk management, regulated financial services, control assurance, audit and Rwanda compliance obligations.
- Expertise in SOC operations, threat intelligence, incident response, crisis leadership, vulnerability management, recovery and continuity.
- Understanding of enterprise, cloud, application, network, identity, data and digital-channel security.
- Ability to oversee data security, encryption, retention, cross-border handling and privacy control requirements.
- Ability to present complex cyber risk in clear business language to executive, Board and regulatory audiences.
- Sound judgement, integrity, accountability, talent development and the ability to influence across organizational boundaries.
- Ability to manage budgets, contracts, outsourced services, service levels and third-party risk.
- Minimum 10 years of progressive experience across information security, cybersecurity, technology risk, or IT, including at least 5 years in a senior cybersecurity leadership role.
- Demonstrated experience leading cybersecurity in a regulated financial services or similarly complex environment.
- Practical experience in cybersecurity strategy, governance, risk, regulatory engagement, security operations, incident response, resilience and third-party security.
- Proven experience reporting cyber risk and control performance to executive management and Boardlevel forums.
- Experience leading multidisciplinary teams and coordinating delivery through shared services, outsourced providers and cross-functional stakeholders.
- Demonstrated ability to deliver material security improvements while enabling business change and digital growth.
If you meet the above requirements, submit your application by 30th September 2026. Please include an updated Curriculum Vitae, copies of the relevant certificates and testimonials.
All applications should be in soft copy and submitted through the Link Indicated below, and only shortlisted candidates will be contacted:
Link:https://equitybank.taleo.net/careersection/ext_new/jobsearch.ftl
Equity Bank is an equal opportunity employer. We value the diversity of individuals, ideas, perspectives, insights, values, and what they bring to the workplace.