Description

Description

Reporting to the Chief- Information & Cyber Security Officer, the role is responsible for developing, implementing, and overseeing security policies, frameworks, and strategies to ensure compliance with regulations, alignment with business objectives, and effective risk management across the organization.

Duty Station: Head Office

KEY ACCOUNTABILITIES:

  • Develop, implement, and maintain security policies, standards, and guidelines.
  • Ensure policies align with `bank goals, industry standards, and regulatory requirements (e.g., ISO 27001, NIST.).
  • Periodically review and update policies to address evolving risks and technologies.
  • Lead department risk assessment process in line with ISO 27001.
  • Test the controls identified within the department RCSA and implement identified gaps.
  • Develop and oversee risk treatment plans to mitigate identified vulnerabilities.
  • Facilitate regular risk assessments and track the resolution of high-priority risks.
  • Ensure the bank complies with legal, regulatory, and contractual obligations related to information security. This includes ensuring quarterly reporting to Bank of Uganda as per the Bank of Uganda Guidelines on Cyber and Technology Risk 2024.
  • Act as a liaison during audits or assessments and ensure audit findings are addressed timely. This involves working with other team members resolve audit issues timely and effectively to avoid repeat issues.
  • Monitor changes in relevant regulations and update governance practices accordingly.
  • Implement and manage security frameworks such as ISO 27001, COBIT, NIST CSF, or others as appropriate.
  • Establish and maintain an Information Security Management System (ISMS) for structured governance.
  • Automation of the information security reporting dashboard and management of update of the same.
  • Provide regular reports to Executive management and the board on the organization’s security posture, risks, and compliance status.
  • Participate in security governance committees, ensuring cross-functional alignment on security goals.
  • Develop and enforce third-party security agreements and ensure they align with organizational risk tolerance.
  • Provide governance support during security incidents by ensuring the incident response process aligns with policies and compliance requirements.
  • Ensure lessons learned from incidents are integrated into governance improvements.
  • Establish and oversee security awareness programs to educate employees and customers on security policies, risks, and best practices.
  • Develop and refine the organization’s long-term information security strategy.
  • Stay informed about emerging threats, technologies, and governance trends to adapt practices proactively.
  • Benchmark the bank’s information security program against industry best practices.

KNOWLEDGE, SKILLS, AND EXPERIENCE REQUIRED:

  • A minimum qualification of a Bachelor’s Degree in Computer Science, Information Technology, or a related numerical Sciences Degree.
  • A Master’s Degree specializing in Digital Security is an added advantage
  • Information Security and /or Information Technology industry certification (CISSP, CISM, CEH, CISSP-ISSMP, CISA, CRISC or GIAC equivalent) is required.
  • At least 6 years’ experience with a minimum of 3 years’ exposure to reviewing and advancing Information Security in a bank/ financial services environment.
  • Experience in assessing and mitigating technology risk (Solid understanding of Risk Management processes).
  • Knowledge of risk management processes (e.g., methods for assessing and mitigating risk).
  • Knowledge of laws, regulations, policies, and ethics as they relate to cybersecurity and privacy.
  • Knowledge of authentication, authorization, and access control methods.
  • Knowledge of the ISO 27001 framework and PCI DSS.
  • Knowledge of applicable business processes and operations of customer organizations.
  • Knowledge of Cyber-Defense and vulnerability assessment tools and their capabilities.
  • Knowledge of cryptography and cryptographic key management concepts.
  • Skill in determining how a security system should work (including its resilience and dependability capabilities) and how changes in conditions, operations, or the environment will affect these outcomes.
  • Skill in discerning the protection needs (i.e., security controls) of information systems and networks.
  • Skill in identifying measures or indicators of system performance and the actions needed to improve or correct performance, relative to the goals of the system.
  • Skill in recognizing and categorizing types of vulnerabilities and associated attacks.
  • Skill in applying security controls.
  • Advanced Business Architectural & IT Security skills.
  • Analytical Thinking & Inductive Reasoning.
  • Planning and Organization.
  • Problem Solving.
  • Strategic Perspective – Establish priorities, challenging goals and measurements consistent with these goals and organizational vision.
  • Critical Judgement and Decision-Making – Define issues and focus on achieving workable solutions to obstacles.
  • Good Communicator – Presents ideas effectively, clearly, and concisely both orally and in writing.
  • Leadership and Interpersonal Skills – Create a culture of continuous development and ownership with self and the team.
  • Inspire Commitment –Actions and behaviors are consistent with words.
  • Self-Development – Pursues positive change in self and organization. Drives own personal development plan.
  • Advanced Business Architectural & IT Security skills.
  • Analytical Thinking & Inductive Reasoning.
  • Planning and Organization.
  • Problem Solving.
  • Strategic Perspective – Establish priorities, challenging goals and measurements consistent with these goals and organizational vision.
  • Critical Judgement and Decision-Making – Define issues and focus on achieving workable solutions to obstacles.
  • Good Communicator – Presents ideas effectively, clearly and concisely both orally and in writing.
  • Leadership and Interpersonal Skills – Create a culture of continuous development and ownership with self and the team
  • Inspire Commitment –Actions and behaviours are consistent with words.
  • Self-Development – Pursues positive change in self and organization.  Drives own personal development plan.

INVITATION

If you believe you meet the requirements as noted above, please use the link below to apply.

careers.dfcugroup.com

Once there, click on “Career Opportunities” to get started. (We recommend using Google Chrome for the best experience.)

Deadline: Friday 7th August 2026

Only short-listed candidates will be contacted.

Location

Join Our Group