IT Risk Officer
2026-10-05T08:43:49+00:00
Yako Bank Uganda
https://cdn.greatugandajobs.com/jsjobsdata/data/employer/comp_7516/logo/yako.png
https://www.yakobank.com/
FULL_TIME
Head Office
Kampala
00256
Uganda
Banking
Computer & IT, Accounting & Finance, Business Operations
2026-10-10T17:00:00+00:00
8
Background
Yako Bank was incorporated in 2010 and began operating as a deposit-taking microfinance institution (Yako Microfinance Uganda Ltd) in September 2015. In 2020, the institution was upgraded and licensed by the Bank of Uganda as a Tier II Credit Institution under the name Yako Bank Uganda Limited, taking over the financial services business of its predecessor microfinance arm. Today, Yako Bank is a fully-fledged credit institution serving a growing clientele through a network of four branches in Kampala and Jinja. The Bank offers a variety of products and services including savings accounts, term deposits, collateralized and non-collateralized loans, and basic mobile banking services to its target markets—SMEs, salaried individuals, micro-entrepreneurs, and smallholder farmers.
Role of the Job
Responsible for identifying, assessing, monitoring and reporting on Information Technology, cybersecurity and information security risks across Yako Bank. The job entails providing independent oversight of the Bank’s ICT environment, testing IT controls, overseeing IT incident, business continuity and third-party risks, and reporting to Risk Manager, while ensuring compliance with the Bank’s Risk Management Framework, Bank of Uganda requirements and applicable laws.
Key Result Areas
- Identify, assess, document and monitor Information Technology (IT), cyber and information security risks across the Bank’s systems, processes, projects and branches, and maintain an up-to-date IT risk register.
- Conduct IT Risk and Control Self-Assessments (RCSAs) and carry out risk assessments of new systems, products, digital channels and major IT changes before they are introduced into the ICT environment.
- Test the design and operating effectiveness of key IT controls, including access management, change management, backups, patching and segregation of duties, and carry out periodic user access reviews on the core banking and other critical systems.
- Monitor the Bank’s cybersecurity posture, including vulnerability assessment and penetration test results, and track remediation of identified weaknesses to closure.
- Ensure that IT and cyber incidents are logged, assessed, escalated and reported in line with the Bank’s Incident Management Policy and regulatory timelines, and lead root-cause analysis of significant incidents.
- Review the Bank’s Business Continuity and Disaster Recovery plans, participate in Disaster Recovery tests, and report on results, gaps and recovery objectives for critical systems.
- Assess and monitor risks arising from IT vendors, cloud and outsourced service providers before onboarding and periodically thereafter, including enforcement of service-level agreements.
- Ensure compliance with Bank of Uganda ICT and cyber risk requirements, the Data Protection and Privacy Act, 2019 of Uganda, the National Payment Systems Act, 2020 and the Bank’s internal IT policies.
- Coordinate responses to IT-related internal audit, external audit and regulatory findings, and work with ICT staff to ensure they are closed in time.
- Preparing and presenting reports on IT Risk to management and stakeholders.
- Supervise, guide and review the work of junior risk staff and interns assigned to IT risk, review IT risk policies and procedures annually, and support IT risk awareness training for staff.
Minimum educational and technical competence requirements
- Bachelor’s degree in Information Technology, Computer Science, Information Systems or other relevant degree from a recognized University.
- Professional certification in IT risk, audit or security, e.g CISA, CISSP, CEH or CCNA are an added advantage.
- Minimum of 3–4 years’ relevant experience in IT risk, IT audit, information security or IT operations, of which at least 1-2 years should be in a bank or financial institution, including supervisory experience.
- Sound knowledge of IT risk and control frameworks and best practices.
- Working knowledge of core banking systems, networks, databases, cloud services, and digital and mobile banking channels.
- Knowledge and understanding of Bank of Uganda ICT and cyber risk requirements, the Data Protection and Privacy Act, 2019 of Uganda, the National Payment Systems Act, 2020 and other relevant legal and regulatory requirements.
- Experience in performing risk, business impact, control and vulnerability assessments, and in defining risk treatment strategies.
- Ability to understand and assess technology systems and applications from both a technical and business function perspective, and to explain technical risks clearly to non-technical audiences.
- Proficiency in Advanced Microsoft Excel (Pivot Tables, Dashboards, Data Analysis); experience with GRC or security monitoring tools is an added advantage.
- Excellent analytical, problem-solving and report-writing skills, with excellent verbal and written communication and interpersonal skills.
- High integrity and demonstrated ability to handle confidential information with discretion.
Additional Details
Position carries an attractive salary and benefits package.
- Identify, assess, document and monitor Information Technology (IT), cyber and information security risks across the Bank’s systems, processes, projects and branches, and maintain an up-to-date IT risk register.
- Conduct IT Risk and Control Self-Assessments (RCSAs) and carry out risk assessments of new systems, products, digital channels and major IT changes before they are introduced into the ICT environment.
- Test the design and operating effectiveness of key IT controls, including access management, change management, backups, patching and segregation of duties, and carry out periodic user access reviews on the core banking and other critical systems.
- Monitor the Bank’s cybersecurity posture, including vulnerability assessment and penetration test results, and track remediation of identified weaknesses to closure.
- Ensure that IT and cyber incidents are logged, assessed, escalated and reported in line with the Bank’s Incident Management Policy and regulatory timelines, and lead root-cause analysis of significant incidents.
- Review the Bank’s Business Continuity and Disaster Recovery plans, participate in Disaster Recovery tests, and report on results, gaps and recovery objectives for critical systems.
- Assess and monitor risks arising from IT vendors, cloud and outsourced service providers before onboarding and periodically thereafter, including enforcement of service-level agreements.
- Ensure compliance with Bank of Uganda ICT and cyber risk requirements, the Data Protection and Privacy Act, 2019 of Uganda, the National Payment Systems Act, 2020 and the Bank’s internal IT policies.
- Coordinate responses to IT-related internal audit, external audit and regulatory findings, and work with ICT staff to ensure they are closed in time.
- Preparing and presenting reports on IT Risk to management and stakeholders.
- Supervise, guide and review the work of junior risk staff and interns assigned to IT risk, review IT risk policies and procedures annually, and support IT risk awareness training for staff.
- Sound knowledge of IT risk and control frameworks and best practices.
- Working knowledge of core banking systems, networks, databases, cloud services, and digital and mobile banking channels.
- Knowledge and understanding of Bank of Uganda ICT and cyber risk requirements, the Data Protection and Privacy Act, 2019 of Uganda, the National Payment Systems Act, 2020 and other relevant legal and regulatory requirements.
- Experience in performing risk, business impact, control and vulnerability assessments, and in defining risk treatment strategies.
- Ability to understand and assess technology systems and applications from both a technical and business function perspective, and to explain technical risks clearly to non-technical audiences.
- Proficiency in Advanced Microsoft Excel (Pivot Tables, Dashboards, Data Analysis); experience with GRC or security monitoring tools is an added advantage.
- Excellent analytical, problem-solving and report-writing skills, with excellent verbal and written communication and interpersonal skills.
- High integrity and demonstrated ability to handle confidential information with discretion.
- Bachelor’s degree in Information Technology, Computer Science, Information Systems or other relevant degree from a recognized University.
- Professional certification in IT risk, audit or security, e.g CISA, CISSP, CEH or CCNA are an added advantage.
JOB-6ac36345aeea0
Vacancy title:
IT Risk Officer
[Type: FULL_TIME, Industry: Banking, Category: Computer & IT, Accounting & Finance, Business Operations]
Jobs at:
Yako Bank Uganda
Deadline of this Job:
Saturday, October 10 2026
Duty Station:
Head Office | Kampala
Summary
Date Posted: Monday, October 5 2026, Base Salary: Not Disclosed
Similar Jobs in Uganda
Learn more about Yako Bank Uganda
Yako Bank Uganda jobs in Uganda
JOB DETAILS:
Background
Yako Bank was incorporated in 2010 and began operating as a deposit-taking microfinance institution (Yako Microfinance Uganda Ltd) in September 2015. In 2020, the institution was upgraded and licensed by the Bank of Uganda as a Tier II Credit Institution under the name Yako Bank Uganda Limited, taking over the financial services business of its predecessor microfinance arm. Today, Yako Bank is a fully-fledged credit institution serving a growing clientele through a network of four branches in Kampala and Jinja. The Bank offers a variety of products and services including savings accounts, term deposits, collateralized and non-collateralized loans, and basic mobile banking services to its target markets—SMEs, salaried individuals, micro-entrepreneurs, and smallholder farmers.
Role of the Job
Responsible for identifying, assessing, monitoring and reporting on Information Technology, cybersecurity and information security risks across Yako Bank. The job entails providing independent oversight of the Bank’s ICT environment, testing IT controls, overseeing IT incident, business continuity and third-party risks, and reporting to Risk Manager, while ensuring compliance with the Bank’s Risk Management Framework, Bank of Uganda requirements and applicable laws.
Key Result Areas
- Identify, assess, document and monitor Information Technology (IT), cyber and information security risks across the Bank’s systems, processes, projects and branches, and maintain an up-to-date IT risk register.
- Conduct IT Risk and Control Self-Assessments (RCSAs) and carry out risk assessments of new systems, products, digital channels and major IT changes before they are introduced into the ICT environment.
- Test the design and operating effectiveness of key IT controls, including access management, change management, backups, patching and segregation of duties, and carry out periodic user access reviews on the core banking and other critical systems.
- Monitor the Bank’s cybersecurity posture, including vulnerability assessment and penetration test results, and track remediation of identified weaknesses to closure.
- Ensure that IT and cyber incidents are logged, assessed, escalated and reported in line with the Bank’s Incident Management Policy and regulatory timelines, and lead root-cause analysis of significant incidents.
- Review the Bank’s Business Continuity and Disaster Recovery plans, participate in Disaster Recovery tests, and report on results, gaps and recovery objectives for critical systems.
- Assess and monitor risks arising from IT vendors, cloud and outsourced service providers before onboarding and periodically thereafter, including enforcement of service-level agreements.
- Ensure compliance with Bank of Uganda ICT and cyber risk requirements, the Data Protection and Privacy Act, 2019 of Uganda, the National Payment Systems Act, 2020 and the Bank’s internal IT policies.
- Coordinate responses to IT-related internal audit, external audit and regulatory findings, and work with ICT staff to ensure they are closed in time.
- Preparing and presenting reports on IT Risk to management and stakeholders.
- Supervise, guide and review the work of junior risk staff and interns assigned to IT risk, review IT risk policies and procedures annually, and support IT risk awareness training for staff.
Minimum educational and technical competence requirements
- Bachelor’s degree in Information Technology, Computer Science, Information Systems or other relevant degree from a recognized University.
- Professional certification in IT risk, audit or security, e.g CISA, CISSP, CEH or CCNA are an added advantage.
- Minimum of 3–4 years’ relevant experience in IT risk, IT audit, information security or IT operations, of which at least 1-2 years should be in a bank or financial institution, including supervisory experience.
- Sound knowledge of IT risk and control frameworks and best practices.
- Working knowledge of core banking systems, networks, databases, cloud services, and digital and mobile banking channels.
- Knowledge and understanding of Bank of Uganda ICT and cyber risk requirements, the Data Protection and Privacy Act, 2019 of Uganda, the National Payment Systems Act, 2020 and other relevant legal and regulatory requirements.
- Experience in performing risk, business impact, control and vulnerability assessments, and in defining risk treatment strategies.
- Ability to understand and assess technology systems and applications from both a technical and business function perspective, and to explain technical risks clearly to non-technical audiences.
- Proficiency in Advanced Microsoft Excel (Pivot Tables, Dashboards, Data Analysis); experience with GRC or security monitoring tools is an added advantage.
- Excellent analytical, problem-solving and report-writing skills, with excellent verbal and written communication and interpersonal skills.
- High integrity and demonstrated ability to handle confidential information with discretion.
Additional Details
Position carries an attractive salary and benefits package.
Work Hours: 8
Experience in Months: 12
Level of Education: bachelor degree
Job application procedure
Interested in applying for this job? Click here to submit your application now.
Suitably qualified candidates should address their application to Head, Human Resource, Yako Bank. as well as photocopies of academic testimonials, and a CV. The CV should include telephone contacts and mail addresses of three referees, one of who should be the most recent employer. Closing date for submission of the applications is 10th October, 2026. Only shortlisted candidates will be contacted. Please note that in line with the Bank procedures, no job offers are made online.
All Jobs | QUICK ALERT SUBSCRIPTION