Head Information Security job at UGAFODE Microfinance Limited (MDI)
New
Today
Linkedid Twitter Share on facebook
Head Information Security
2026-01-09T05:55:45+00:00
UGAFODE Microfinance Limited (MDI)
https://cdn.greatugandajobs.com/jsjobsdata/data/employer/comp_699/logo/ugafode.png
FULL_TIME
 
Kampala, Uganda
Kampala
00256
Uganda
Financial Services
Computer & IT, Management, Business Operations
UGX
 
MONTH
2026-01-12T17:00:00+00:00
 
 
8

About Organisation:

UGAFODE Microfinance Limited (MDI) is a registered financial institution in Uganda and is adherent to the Central Bank’s regulations and guidelines and was founded in 1994 to provide quality microfinance services.

Job Summary:

Responsible for establishing and maintaining the enterprise vision, strategy, and program to ensure information assets and technologies are adequately protected within compliance and risk perspectives of the business.

Key Duties and Responsibilities:

  • Oversees the development, implementation and enforcement of Cyber and technology policy programs at UGAFODE
  • Ensuring that information systems meet the needs of the institution, and the ICT strategy, in particular information system development strategies, comply with the overall business strategies, risk appetite and ICT risk management policies of the institution.
  • Ensures that UGAFODE maintains an up-to date enterprise-wide knowledge base of its users, devices, applications, software licenses and their relationships including but not limited to: Software and hardware asset inventory, Network maps (including boundaries, traffic and data flow) and network utilization & performance data.
  • Designs cybersecurity controls with the consideration of users at all levels of the institution, including internal (management & staff), external users (contractors/consultants, business partners and service providers).
  • Organizing professional cyber related trainings to improve technical proficiency of staff.
  • Ensures that regular and comprehensive cyber risk assessments are conducted within the institution.
  • Ensures adequate processes & tools are in place for monitoring IT systems to detect cyber and technology events and incidents in a timely manner.
  • Conducts reviews associated with exceptions/deviations to the approved cyber and technology policies and procedures and gain senior management approval for risk assessments.
  • Assessment of the confidentiality, integrity and availability of the information systems in the institution
  • Reporting as agreed on the assessment of the effectiveness of the approved cybersecurity program, all material cyber and technology events that affected the institution, e.t.c.
  • Timely detection and action to identify compromises to the IT systems and controls and speedy rectification to avoid financial and operational losses.
  • Ensuring the bank’s cyber security controls and procedures are up to date to prevent breaches of the bank’s systems by internal and external actors.
  • Continuously test disaster recovery and Business Continuity Plans (BCP) arrangements to ensure that the institution can continue to function and meet its regulatory obligations in the event of an unforeseen attack through cyber-crime.
  • Ensure timely update of the incident response mechanism and Business Continuity Plan (BCP) based on the latest cyber threat intelligence gathered.

Qualifications, Skills and Experience:

  • Minimum of Bachelor’s degree in Computer Science, MIS or equivalent, and any IT certification (e.g. CISCO Certified Network Associate (CCNA) etc.
  • At least 6 years’ experience in information security or banking computer systems
  • Extensive knowledge of Information security within Banking environment including related statutory IT compliance regulations, IT and MIS banking policies & procedures, e.t.c.
  • Specialist security certifications such as GSEC (GIAC Security Essentials), CISSP (Certified Information Systems Security Professional) or related field is an added advantage
  • Experience with incident response, risk assessment, and management.
  • Maintain relevant industry, information technology, and process knowledge expertise
  • Ability to maintain confidentiality
  • Experience in leading teams
  • Exceptional planning and organizational skills, and excellent written and oral communication
  • Analytical mind with the ability to quickly get to the root cause of issues
  • An overall understanding of relevant scripting and source code programming languages, such as C#, C++, .NET, Java, Perl, PHP, Python and others that are in use.
  • An up to date working knowledge of IT Security related hardware, software and vendor solutions.

Note:

UGAFODE provides equal opportunity in employment to all people and therefore, women are encouraged to apply

  • Oversees the development, implementation and enforcement of Cyber and technology policy programs at UGAFODE
  • Ensuring that information systems meet the needs of the institution, and the ICT strategy, in particular information system development strategies, comply with the overall business strategies, risk appetite and ICT risk management policies of the institution.
  • Ensures that UGAFODE maintains an up-to date enterprise-wide knowledge base of its users, devices, applications, software licenses and their relationships including but not limited to: Software and hardware asset inventory, Network maps (including boundaries, traffic and data flow) and network utilization & performance data.
  • Designs cybersecurity controls with the consideration of users at all levels of the institution, including internal (management & staff), external users (contractors/consultants, business partners and service providers).
  • Organizing professional cyber related trainings to improve technical proficiency of staff.
  • Ensures that regular and comprehensive cyber risk assessments are conducted within the institution.
  • Ensures adequate processes & tools are in place for monitoring IT systems to detect cyber and technology events and incidents in a timely manner.
  • Conducts reviews associated with exceptions/deviations to the approved cyber and technology policies and procedures and gain senior management approval for risk assessments.
  • Assessment of the confidentiality, integrity and availability of the information systems in the institution
  • Reporting as agreed on the assessment of the effectiveness of the approved cybersecurity program, all material cyber and technology events that affected the institution, e.t.c.
  • Timely detection and action to identify compromises to the IT systems and controls and speedy rectification to avoid financial and operational losses.
  • Ensuring the bank’s cyber security controls and procedures are up to date to prevent breaches of the bank’s systems by internal and external actors.
  • Continuously test disaster recovery and Business Continuity Plans (BCP) arrangements to ensure that the institution can continue to function and meet its regulatory obligations in the event of an unforeseen attack through cyber-crime.
  • Ensure timely update of the incident response mechanism and Business Continuity Plan (BCP) based on the latest cyber threat intelligence gathered.
  • Ability to maintain confidentiality
  • Experience in leading teams
  • Exceptional planning and organizational skills, and excellent written and oral communication
  • Analytical mind with the ability to quickly get to the root cause of issues
  • An overall understanding of relevant scripting and source code programming languages, such as C#, C++, .NET, Java, Perl, PHP, Python and others that are in use.
  • An up to date working knowledge of IT Security related hardware, software and vendor solutions.
  • Minimum of Bachelor’s degree in Computer Science, MIS or equivalent, and any IT certification (e.g. CISCO Certified Network Associate (CCNA) etc.
  • Specialist security certifications such as GSEC (GIAC Security Essentials), CISSP (Certified Information Systems Security Professional) or related field is an added advantage
bachelor degree
72
JOB-69609861cc2ef

Vacancy title:
Head Information Security

[Type: FULL_TIME, Industry: Financial Services, Category: Computer & IT, Management, Business Operations]

Jobs at:
UGAFODE Microfinance Limited (MDI)

Deadline of this Job:
Monday, January 12 2026

Duty Station:
Kampala, Uganda | Kampala

Summary
Date Posted: Friday, January 9 2026, Base Salary: Not Disclosed

Similar Jobs in Uganda
Learn more about UGAFODE Microfinance Limited (MDI)
UGAFODE Microfinance Limited (MDI) jobs in Uganda

JOB DETAILS:

About Organisation:

UGAFODE Microfinance Limited (MDI) is a registered financial institution in Uganda and is adherent to the Central Bank’s regulations and guidelines and was founded in 1994 to provide quality microfinance services.

Job Summary:

Responsible for establishing and maintaining the enterprise vision, strategy, and program to ensure information assets and technologies are adequately protected within compliance and risk perspectives of the business.

Key Duties and Responsibilities:

  • Oversees the development, implementation and enforcement of Cyber and technology policy programs at UGAFODE
  • Ensuring that information systems meet the needs of the institution, and the ICT strategy, in particular information system development strategies, comply with the overall business strategies, risk appetite and ICT risk management policies of the institution.
  • Ensures that UGAFODE maintains an up-to date enterprise-wide knowledge base of its users, devices, applications, software licenses and their relationships including but not limited to: Software and hardware asset inventory, Network maps (including boundaries, traffic and data flow) and network utilization & performance data.
  • Designs cybersecurity controls with the consideration of users at all levels of the institution, including internal (management & staff), external users (contractors/consultants, business partners and service providers).
  • Organizing professional cyber related trainings to improve technical proficiency of staff.
  • Ensures that regular and comprehensive cyber risk assessments are conducted within the institution.
  • Ensures adequate processes & tools are in place for monitoring IT systems to detect cyber and technology events and incidents in a timely manner.
  • Conducts reviews associated with exceptions/deviations to the approved cyber and technology policies and procedures and gain senior management approval for risk assessments.
  • Assessment of the confidentiality, integrity and availability of the information systems in the institution
  • Reporting as agreed on the assessment of the effectiveness of the approved cybersecurity program, all material cyber and technology events that affected the institution, e.t.c.
  • Timely detection and action to identify compromises to the IT systems and controls and speedy rectification to avoid financial and operational losses.
  • Ensuring the bank’s cyber security controls and procedures are up to date to prevent breaches of the bank’s systems by internal and external actors.
  • Continuously test disaster recovery and Business Continuity Plans (BCP) arrangements to ensure that the institution can continue to function and meet its regulatory obligations in the event of an unforeseen attack through cyber-crime.
  • Ensure timely update of the incident response mechanism and Business Continuity Plan (BCP) based on the latest cyber threat intelligence gathered.

Qualifications, Skills and Experience:

  • Minimum of Bachelor’s degree in Computer Science, MIS or equivalent, and any IT certification (e.g. CISCO Certified Network Associate (CCNA) etc.
  • At least 6 years’ experience in information security or banking computer systems
  • Extensive knowledge of Information security within Banking environment including related statutory IT compliance regulations, IT and MIS banking policies & procedures, e.t.c.
  • Specialist security certifications such as GSEC (GIAC Security Essentials), CISSP (Certified Information Systems Security Professional) or related field is an added advantage
  • Experience with incident response, risk assessment, and management.
  • Maintain relevant industry, information technology, and process knowledge expertise
  • Ability to maintain confidentiality
  • Experience in leading teams
  • Exceptional planning and organizational skills, and excellent written and oral communication
  • Analytical mind with the ability to quickly get to the root cause of issues
  • An overall understanding of relevant scripting and source code programming languages, such as C#, C++, .NET, Java, Perl, PHP, Python and others that are in use.
  • An up to date working knowledge of IT Security related hardware, software and vendor solutions.

Note:

UGAFODE provides equal opportunity in employment to all people and therefore, women are encouraged to apply

 

Work Hours: 8

Experience in Months: 72

Level of Education: bachelor degree

Job application procedure
Interested in applying for this job? Click here to submit your application now.

If you believe you meet the requirements as stated above, submit an application letter together with an up-to-date CV . Save the Documents as Your Full Name & indicate the job title you are applying for in the Subject Line. Your applications should be addressed to the Head of Human Resources and the closing date for receiving all applications is 12th January 2026.

 

All Jobs | QUICK ALERT SUBSCRIPTION

Job Info
Job Category: Computer/ IT jobs in Uganda
Job Type: Full-time
Deadline of this Job: Monday, January 12 2026
Duty Station: Kampala, Uganda | Kampala
Posted: 09-01-2026
No of Jobs: 1
Start Publishing: 09-01-2026
Stop Publishing (Put date of 2030): 10-10-2076
Apply Now
Notification Board

Join a Focused Community on job search to uncover both advertised and non-advertised jobs that you may not be aware of. A jobs WhatsApp Group Community can ensure that you know the opportunities happening around you and a jobs Facebook Group Community provides an opportunity to discuss with employers who need to fill urgent position. Click the links to join. You can view previously sent Email Alerts here incase you missed them and Subscribe so that you never miss out.

Caution: Never Pay Money in a Recruitment Process.

Some smart scams can trick you into paying for Psychometric Tests.