INTERNAL AUDITOR – ICT

  • Full Time
  • Nairobi
  • August 28, 2026

About Us

CIC Insurance Group is a leading insurance and financial services organisation with more than five decades of experience helping individuals, families, and organizations achieve financial security.

We have grown into a dynamic Group offering life, general, micro insurance, asset management, and investment solutions, with operations in Kenya, Uganda, South Sudan, and Malawi, and are listed on the Nairobi Securities Exchange.

Our tagline, “We Keep Our Word,” reflects our unwavering commitment to integrity, transparency, and delivering on our promises to our clients, partners, and communities.

CIC Group is passionate about innovation, digital transformation, and inclusive insurance solutions that meet the evolving needs of cooperatives, SMEs, corporates, and individuals. By joining us, you will be part of a team that is shaping the future of financial protection across Africa.

About the Role

Reporting to the Director Internal Audit, the role holder will provide independent and objective assurance and advisory services that strengthen governance, risk management and internal controls across assigned business units. The role supports delivery of the Internal Audit Strategy through risk-based auditing, data-driven assurance, continuous monitoring and practical recommendations that improve business performance and control effectiveness.

Key Responsibilities

  • Execute end-to-end risk-based ICT and technology audits in accordance with the approved Internal Audit Plan, Internal Audit methodology, professional standards, regulatory requirements and the organization’s ICT risk profile.
  • Participate in enterprise and ICT risk assessments and contribute to the development of the annual Internal Audit work plan, with consideration of emerging technology risks, cybersecurity threats and changes in the organization’s technology landscape.
  • Develop audit objectives, scope, risk and control matrices, audit programmes and testing strategies for assigned ICT audit engagements.
  • Conduct ICT audits covering IT governance, cybersecurity, information security, IT general controls, application controls, IT infrastructure, networks, databases, cloud services, system development, change management, access management, IT operations, data management, business continuity and disaster recovery, as applicable.
  • Assess the design and operating effectiveness of IT General Controls (ITGCs), including logical and physical access controls, privileged access, segregation of duties, change management, backup and recovery, incident management and IT operations.
  • Review the adequacy of controls over business applications and core systems, including system configurations, application controls, interfaces, automated controls, system-generated reports and data integrity.
  • Assess the governance, implementation and effectiveness of ICT projects, system implementations, system upgrades and technology transformation initiatives, including project governance, requirements management, testing, implementation and post-implementation controls.
  • Evaluate IT service management and operational controls, including incident management, problem management, service availability, capacity management, service-level agreements and IT support processes.
  • Assess the effectiveness of business continuity and disaster recovery arrangements, including adequacy of recovery strategies, backup arrangements, recovery testing, system resilience and alignment with critical business processes.
  • Review controls over third-party and outsourced technology services, including vendor due diligence, contractual obligations, service-level agreements, information security requirements, performance monitoring, access to organizational data and exit arrangements.
  • Develop data-driven audit tests to identify unauthorized access, unusual user activity, segregation-of-duties conflicts, dormant accounts, duplicate transactions, system overrides, control breaches, anomalies and other indicators of technology or fraud risk.
  • Use appropriate audit, data analytics and visualization tools, including advanced Excel, IDEA, Power BI, SQL and other relevant ICT audit or analytics tools, where applicable.
  • Contribute to the development and implementation of continuous auditing, continuous monitoring and automated control testing to improve audit efficiency, coverage and early identification of emerging technology risks.
  • Discuss audit observations with ICT and business process owners and management, provide practical recommendations and support timely resolution of identified technology and control weaknesses.
  • Follow up on agreed management actions and validate the implementation and effectiveness of corrective measures relating to ICT audit findings.
  • Support the preparation of Audit Committee and Board papers relating to ICT audits, cybersecurity, technology risk, data governance and other key technology control themes.
  • Assess the governance and control environment around emerging technologies, including Artificial Intelligence (AI), automation, cloud computing, digital platforms and other technology-enabled business solutions, where applicable.
  • Contribute to the continuous improvement of Internal Audit methodologies, ICT audit tools, data analytics, automation, continuous monitoring, knowledge resources and quality assurance practices.

Audit Quality, Professional Standards and Independence

  • Perform audit work in accordance with the Internal Audit Charter, approved methodology, policies and applicable professional standards.
  • Ensure audit assignments are completed to required quality standards and within agreed timelines.
  • Maintain complete, accurate and well-organized audit documentation to support review and quality assurance.

Stakeholder Engagement

  • Build effective working relationships with business and functional management while maintaining appropriate audit independence.
  • Communicate audit issues clearly and constructively to process owners and senior management.

Who We’re Looking For

Essential Knowledge/Skills and Experience Required:

  • Bachelor’s degree in a business-related field.
  • CISA
  • CPA/ACCA / CIA/ Computer Assisted Audit Techniques is desirable
  • Insurance Professional Qualification is desirable
  • 3-5 years’ experience. At least 2 years’ experience in the big 4 audit firms or an organization similar in size or larger than CIC Group is an added advantage
  • Knowledge of current technological developments/trends in area of expertise and knowledge of software requirements for audit of systems procedures
  • Basic knowledge of regulations by AKI and IRA
  • Excellent communication skills – written, oral, presentation and report writing
  • Ability to maintain highest levels of integrity and objectivity
  • Flexibility in mobility

Why Join Us?

Joining CIC Insurance Group as an Internal Auditor offers the opportunity to play a pivotal role in strengthening governance, risk management, and internal control effectiveness across a leading regional financial services group. In this role, you will gain broad exposure to diverse business operations, assess key risks, evaluate control environments, and provide insights that drive operational excellence and strategic decision-making. You will work closely with senior management and key stakeholders, contributing to initiatives that enhance compliance, safeguard organizational assets, and promote accountability. If you are intellectually curious, analytical, and passionate about creating value through advisory services, CIC provides an environment where you can grow your expertise while making a measurable impact on the organization’s success.

If you have the aforementioned professional and academic qualifications and you are ready to execute the above mandate, strictly apply clearly indicating the position being applied for.

The application should reach us by close of business on 28th August, 2026. Please note only short-listed candidates will be contacted. If you do not hear from us by 30th September, 2026 consider your application unsuccessful.

 

CIC Group is an equal opportunity employer and does not solicit or require any form of payment for employment opportunities.

N/B: This job advert is open to both internal and external candidates.

Enter your full names
Enter your active email address
Enter your active mobile number
Gender
MM slash DD slash YYYY
Profesional Qualifications(Required)
Qualification
Institution
Status
Year
 
Education (Highest Level Only)(Required)
Certificate
Institution
Status
Year
 
Work Experience(starting with the latest)(Required)
Employer
Position
Start Date
End Date
 
Accepted file types: pdf, Max. file size: 20 MB.
.

Upload your CV/resume or any other relevant file. Max. file size: 5 MB.