KC

Technology Department,Rwanda.Application Security Manager

Full-time Rwanda, RW
Posted 1 hour, 10 minutes ago 4 views 0 applications

Job Description

KEY RESPONSIBILITIES

  • Lead and manage the Application Security team, ensuring effective delivery of security objectives and initiatives.
  • Oversee and conduct periodic user access recertification across all bank applications, with focus on MCAs, to enforce least privilege and access governance.
  • Direct and conduct the execution of Vulnerability Assessments and Penetration Testing (VAPT) for all applications.
  • Provide security assurance for technology projects, ensuring compliance with security requirements prior to CAB approval.
  • Define and enforce application security standards, policies, and secure SDLC practices.
  • Identify, assess, and mitigate application-level risks and vulnerabilities.
  • Provide ongoing security assurance and reporting on the Bank’s application landscape.
  • Secure Integration Management: Oversee and ensure secure integration of internal systems such as microservices, API and other third‑party services by enforcing security controls, conducting risk assessments, and minimizing potential attack vectors across all interfaces
  • Advise stakeholders on regulatory and industry frameworks (e.g., OWASP Top 10, NIST, ISO 27001/ISMS, PCI DSS and GDPR).

DAILY RESPONSIBILITIES:

  1. Making regular reports to line manager to issue identified or raised by internal audit, risk and regulatory pertaining to application security unit to line supervisors with clear strategic plan to address them
    1. Coordinated and Conduct user access reviews and recertification activities
    2. Leading the discovery of vulnerabilities and risks in application, software systems and databases and cloud infrastructure with ongoing vulnerability scans, penetration testing and identifying OWASP top 10 threats targeting both bank internal applications and internet facing environments such as digital channels and others on regular basis through intel monitoring and ensuring software applications are updated.
    3. Review and track application security findings, remediation status, and risk exposure
    4. Follow up and enforce the correction of Identified risks via RCSA (Risk Control Self-Assessment)

Support business owners and project team to ensure information security requirements are captured and embedded in the overall project life cycle, ranging from internal information policies and standards, compliance with regulatory and relevant laws.

MINIMUM POSITION QUALIFICATION REQUIREMENTS

Academic & Professional

Particulars Detail Specific Field or Qualification Need Type
Education Bachelor’s Degree BSc. Information Technology / Computer Science / Telecommunications / Engineering (Electrical, Electronic) or related field RQ
Professional Qualifications Security certification such as: OSWE (Offensive Security Web Expert), OSCP (Offensive Security Certified Professional), CISM, ISMS lead Implementer or Lead Audit, GIAC Certifications, CEH At least one RQ
Master’s Degree MBA/MSc AA

Experience

Total Minimum No of Years’ Experience Required 5
Detail Minimum No of Years Need Type
Experience in Application Security 5 ES
Apply Now ↗

How well do you match?

Get an instant AI match score for this role — free, takes 3 minutes.

Tailor your CV for this role

The concierge rewrites your whole CV and writes a matching cover letter for this job — opens right here, nothing to paste.

Tailor My CV to This Job ✍️

Free cover letter for this job

Upload your CV and get a tailored cover letter in seconds — free, no account needed.

Generate a Cover Letter 📝
MJC
ECHO
Your MJC Assistant

I'm ECHO, your MJC career assistant. I can help you find jobs, explore career tools, and connect with opportunities across Africa.

How was your experience with ECHO?