Senior Manager- Cyber Security Assurance job at DFCU Bank
New
Website :
Today
Linkedid Twitter Share on facebook
Senior Manager- Cyber Security Assurance
2026-04-15T17:47:29+00:00
DFCU Bank
https://cdn.greatugandajobs.com/jsjobsdata/data/employer/comp_7435/logo/dfcu%20Bank.jpeg
FULL_TIME
kampala
Kampala
00256
Uganda
Banking
Management, Computer & IT, Protective Services
UGX
MONTH
2026-04-22T17:00:00+00:00
8

Background

Reporting to the Chief Information Security Officer, the role holder will be responsible for ensuring the design, implementation, oversight, testing, and continuous improvement of cybersecurity controls. This role not only provides assurance that security measures, policies, and programs meet regulatory standards—including ISMS, PCI DSS, and Bank of Uganda requirements—but also actively drives the deployment and operationalization of these controls across the Bank.

Responsibilities

  • Develop, implement, and enforce baseline security standards across all systems.
  • Integrate security into the software development lifecycle and product design.
  • Establish secure coding practices and ensure continuous security testing within CI/CD pipelines.
  • Oversee vulnerability assessments, penetration testing, and red team simulations.
  • Ensure timely remediation of identified risks and communicate critical findings to stakeholders.
  • Lead vulnerability identification, prioritization, and recommendation on resolution.
  • Report on key metrics and ensure compliance with risk appetite thresholds.
  • Ensure effective lifecycle management of user identities, including provisioning, access reviews, and deprovisioning.
  • Drive organization-wide awareness programs to strengthen security culture and reduce human risk.
  • Lead third party security assessments and ongoing monitoring of vendors and partners in line with the security baseline standard.
  • Maintain compliance with the ISMS (ISO 27001), PCI DSS, and all relevant regulatory requirements.
  • Manage Bank of Uganda (BOU) quarterly reporting.
  • Exercise oversight of enterprise technology governance, including cybersecurity and IT project governance—through the establishment of policies and standards, ongoing monitoring of compliance across technology initiatives, and management of governance issues to prevent control failures and recurrence.
  • Manage internal and external audits, track findings, and oversee timely remediation to ensure no overdue findings, no failed validations and no repeat findings.
  • Lead and mentor a high-performing cybersecurity team.
  • Foster a culture of accountability, continuous improvement, and innovation.

Qualifications and Experience

  • Bachelor’s Degree in Information Technology, Computer Science, or related field (Master’s preferred).
  • Professional Certifications such as CISSP, CISM, CISA, or ISO 27001 Lead Auditor/Implementer.
  • 5+ years of experience in cybersecurity, with at least 3 years in a leadership role.
  • Strong knowledge of ISO27001 ISMS, PCI DSS, and regulatory compliance requirements.
  • Experience in DevSecOps, vulnerability management, and penetration testing.
  • Strong leadership and people management skills.
  • Excellent understanding of cybersecurity frameworks and risk management.
  • Exceptional communication and executive reporting skills.
  • Ability to balance strategic planning with hands-on technical oversight.
  • Develop, implement, and enforce baseline security standards across all systems.
  • Integrate security into the software development lifecycle and product design.
  • Establish secure coding practices and ensure continuous security testing within CI/CD pipelines.
  • Oversee vulnerability assessments, penetration testing, and red team simulations.
  • Ensure timely remediation of identified risks and communicate critical findings to stakeholders.
  • Lead vulnerability identification, prioritization, and recommendation on resolution.
  • Report on key metrics and ensure compliance with risk appetite thresholds.
  • Ensure effective lifecycle management of user identities, including provisioning, access reviews, and deprovisioning.
  • Drive organization-wide awareness programs to strengthen security culture and reduce human risk.
  • Lead third party security assessments and ongoing monitoring of vendors and partners in line with the security baseline standard.
  • Maintain compliance with the ISMS (ISO 27001), PCI DSS, and all relevant regulatory requirements.
  • Manage Bank of Uganda (BOU) quarterly reporting.
  • Exercise oversight of enterprise technology governance, including cybersecurity and IT project governance—through the establishment of policies and standards, ongoing monitoring of compliance across technology initiatives, and management of governance issues to prevent control failures and recurrence.
  • Manage internal and external audits, track findings, and oversee timely remediation to ensure no overdue findings, no failed validations and no repeat findings.
  • Lead and mentor a high-performing cybersecurity team.
  • Foster a culture of accountability, continuous improvement, and innovation.
  • Strong leadership and people management skills.
  • Excellent understanding of cybersecurity frameworks and risk management.
  • Exceptional communication and executive reporting skills.
  • Ability to balance strategic planning with hands-on technical oversight.
  • Bachelor’s Degree in Information Technology, Computer Science, or related field (Master’s preferred).
  • Professional Certifications such as CISSP, CISM, CISA, or ISO 27001 Lead Auditor/Implementer.
  • Strong knowledge of ISO27001 ISMS, PCI DSS, and regulatory compliance requirements.
  • Experience in DevSecOps, vulnerability management, and penetration testing.
bachelor degree
60
JOB-69dfcf3193635

Vacancy title:
Senior Manager- Cyber Security Assurance

[Type: FULL_TIME, Industry: Banking, Category: Management, Computer & IT, Protective Services]

Jobs at:
DFCU Bank

Deadline of this Job:
Wednesday, April 22 2026

Duty Station:
kampala | Kampala

Summary
Date Posted: Wednesday, April 15 2026, Base Salary: Not Disclosed

Similar Jobs in Uganda
Learn more about DFCU Bank
DFCU Bank jobs in Uganda

JOB DETAILS:

Background

Reporting to the Chief Information Security Officer, the role holder will be responsible for ensuring the design, implementation, oversight, testing, and continuous improvement of cybersecurity controls. This role not only provides assurance that security measures, policies, and programs meet regulatory standards—including ISMS, PCI DSS, and Bank of Uganda requirements—but also actively drives the deployment and operationalization of these controls across the Bank.

Responsibilities

  • Develop, implement, and enforce baseline security standards across all systems.
  • Integrate security into the software development lifecycle and product design.
  • Establish secure coding practices and ensure continuous security testing within CI/CD pipelines.
  • Oversee vulnerability assessments, penetration testing, and red team simulations.
  • Ensure timely remediation of identified risks and communicate critical findings to stakeholders.
  • Lead vulnerability identification, prioritization, and recommendation on resolution.
  • Report on key metrics and ensure compliance with risk appetite thresholds.
  • Ensure effective lifecycle management of user identities, including provisioning, access reviews, and deprovisioning.
  • Drive organization-wide awareness programs to strengthen security culture and reduce human risk.
  • Lead third party security assessments and ongoing monitoring of vendors and partners in line with the security baseline standard.
  • Maintain compliance with the ISMS (ISO 27001), PCI DSS, and all relevant regulatory requirements.
  • Manage Bank of Uganda (BOU) quarterly reporting.
  • Exercise oversight of enterprise technology governance, including cybersecurity and IT project governance—through the establishment of policies and standards, ongoing monitoring of compliance across technology initiatives, and management of governance issues to prevent control failures and recurrence.
  • Manage internal and external audits, track findings, and oversee timely remediation to ensure no overdue findings, no failed validations and no repeat findings.
  • Lead and mentor a high-performing cybersecurity team.
  • Foster a culture of accountability, continuous improvement, and innovation.

Qualifications and Experience

  • Bachelor’s Degree in Information Technology, Computer Science, or related field (Master’s preferred).
  • Professional Certifications such as CISSP, CISM, CISA, or ISO 27001 Lead Auditor/Implementer.
  • 5+ years of experience in cybersecurity, with at least 3 years in a leadership role.
  • Strong knowledge of ISO27001 ISMS, PCI DSS, and regulatory compliance requirements.
  • Experience in DevSecOps, vulnerability management, and penetration testing.
  • Strong leadership and people management skills.
  • Excellent understanding of cybersecurity frameworks and risk management.
  • Exceptional communication and executive reporting skills.
  • Ability to balance strategic planning with hands-on technical oversight.

Work Hours: 8

Experience in Months: 60

Level of Education: bachelor degree

Job application procedure

Application Link:Click Here to Apply Now

All Jobs | QUICK ALERT SUBSCRIPTION

Job Info
Job Category: Computer/ IT jobs in Uganda
Job Type: Full-time
Deadline of this Job: Wednesday, April 22 2026
Duty Station: kampala | Kampala
Posted: 15-04-2026
No of Jobs: 1
Start Publishing: 15-04-2026
Stop Publishing (Put date of 2030): 10-10-2076
Apply Now
Notification Board

Join a Focused Community on job search to uncover both advertised and non-advertised jobs that you may not be aware of. A jobs WhatsApp Group Community can ensure that you know the opportunities happening around you and a jobs Facebook Group Community provides an opportunity to discuss with employers who need to fill urgent position. Click the links to join. You can view previously sent Email Alerts here incase you missed them and Subscribe so that you never miss out.

Caution: Never Pay Money in a Recruitment Process.

Some smart scams can trick you into paying for Psychometric Tests.