Manager, IS Governance GRC And IS Program Delivery at Equity Bank Rwanda

Manager, IS Governance GRC And IS Program Delivery

Equity Bank Rwanda

  • Position(s): 1
  • Deadline: 2026-09-17
  • 35

Equity Bank is one of the region’s leading Banks whose purpose is to transform the lives and livelihoods of the people of Africa socially and economically by availing them modern, inclusive financial services that maximize their opportunities. With a strong footprint in Rwanda, Kenya, Uganda, Tanzania, DRC and South Sudan, Equity Bank is now home to nearly 20 million customers - the largest customer base in Africa. Currently, the Bank is seeking additional talent to serve as the Manager, IS Governance /GRC & IS Program Delivery, whose holder reports to the Head, Information Security.

Manager, IS Governance /GRC & IS Program Delivery

Job Summary

The Bank is seeking a Senior Candidate in Information Security Management to lead the information security governance program for Equity Bank Rwanda by establishing and maintaining the policies, standards, oversight mechanisms, risk reporting and compliance practices required to manage cybersecurity risk. The role ensures that security governance is aligned with business objectives, regulatory obligations, Group requirements, and recognized information security standards.

Key Responsibilities and Accountability.

  • Develop, maintain and coordinate approval of the information security governance framework, policies, standards, procedures and supporting control requirements.
  • Lead the information security strategy and annual program planning process and monitor delivery against approved objectives, risk priorities and budgets.
  • Coordinate cybersecurity risk assessments, control self-assessments, risk treatment plans, exceptions and formal risk acceptance processes.
  • Maintain an accurate information security risk register and ensure material risks are assigned, treated, monitored and escalated through the appropriate governance forums.
  • Define and report meaningful KPIs, KRIs, KCIs, compliance status, program performance and significant security issues to management and Board-level committees.
  • Coordinate compliance with applicable BNR, Rwanda NCSA, data-protection, ISO/IEC 27001, PCI DSS and other contractual or regulatory security obligations.
  • Manage the ISMS governance lifecycle, including scope, objectives, control ownership, Statement of Applicability, internal review, management review and continual improvement.
  • Coordinate internal audit, external audit, regulatory examination and certification activities and track findings and corrective actions to closure.
  • Establish and maintain security governance forums, decision logs, reporting calendars, terms of reference and accountability matrices.

  • Oversee third-party information security governance, including risk classification, security due diligence, contractual control requirements, periodic review and issue escalation.
  • Coordinate policy awareness, role-based security training and governance communications and monitor completion and effectiveness.
  • Review projects, products and changes from a governance and risk perspective and ensure required security assessments and approvals are completed.
  • Monitor the external threat, regulatory and standards landscape and initiate timely updates to policies, controls and risk treatment priorities.
  • Support data governance, information classification, privacy, identity governance, incident governance and business continuity interfaces with relevant control owners.
  • Lead and develop governance personnel and promote clear accountability across security, risk, technology and business functions.
  • Perform any other responsibilities assigned by the line manager. Additional skills required:
  • Strong governance, risk and compliance capability, including policy development, control oversight, risk reporting, audit coordination and executive-level communication.
  • Excellent stakeholder engagement, analytical writing, facilitation and program-management skills, with the ability to translate regulatory and security requirements into practical business controls.

QUALIFICATION, SKILLS AND EXPERIENCE

  • Bachelor’s degree or equivalent qualification in Information Technology, Information Security, Computer Science, Cybersecurity, Risk Management or a similar area of study.
  • Minimum of 3 years’ experience working in information security governance, GRC, cyber risk, compliance, audit coordination or ISMS-related responsibilities.
  • Broad knowledge of information security governance frameworks, cyber risk management, ISMS operations, regulatory compliance, audit management, third-party security governance and control assurance.
  • Experience working within a regulated financial-services environment and applying standards such as ISO/IEC 27001, NIST Cybersecurity Framework, PCI DSS, data-protection requirements and supervisory expectations from regulators.
  • Relevant certifications in IT Governance, Risk Management, Information Security, or Compliance (e.g., CRISC, CISM, CGEIT, COBIT, ISO 27001 Lead Implementer) will be an added advantage.

Key Critical Competencies?

  • Strategic governance leadership with sound risk judgement, independence, integrity and the ability to influence senior stakeholders across technology, risk, compliance and business functions.
  • Clear executive communication, structured documentation, attention to detail, disciplined follow-through and continuous improvement mindset.

Role Complexity:???

  • The role operates across multiple governance, risk, compliance, audit, regulatory, technology and business interfaces and requires balancing strategic oversight with hands-on coordination of security governance deliverables.
  • The position requires interpretation of evolving regulatory, Group, audit and standards requirements and conversion of those requirements into practical policies, controls, accountabilities and management reports.

Budgets/ Financial Input?

  • Contributes to the planning, prioritization and monitoring of information security governance, compliance, certification, awareness, risk assessment and control assurance budgets.
  • Provides input into cost estimates, vendor governance requirements and budget justification for security governance tools, consulting support, training, audits and compliance-related initiatives.

If you meet the above requirements, submit your application by 17th September 2026. Please include an updated Curriculum Vitae, copies of the relevant certificates and testimonials.

All applications should be in soft copy and through the Link Indicated below, and only shortlisted candidates will be contacted:

Link: https://equitybank.taleo.net/careersection/ext_new/jobsearch.ftl

Equity Bank is an equal opportunity employer. We value the diversity of individuals, ideas, perspectives, insights, values, and what they bring to the workplace.

Share this Job: