Manager – IT Security Governance job at DFCU Bank
New
Website :
Today
Linkedid Twitter Share on facebook
Manager – IT Security Governance
2026-08-04T10:55:18+00:00
DFCU Bank
https://cdn.greatugandajobs.com/jsjobsdata/data/employer/comp_7435/logo/dfcu%20Bank.jpeg
FULL_TIME
Head Office
Kampala
00256
Uganda
Banking
Management, Computer & IT, Business Operations
UGX
MONTH
2026-08-07T17:00:00+00:00
8

Background information about the job or company (e.g., role context, company overview)

DFCU BANK

Reporting to the Chief- Information & Cyber Security Officer, the role is responsible for developing, implementing, and overseeing security policies, frameworks, and strategies to ensure compliance with regulations, alignment with business objectives, and effective risk management across the organization.

Responsibilities or duties

  • Develop, implement, and maintain security policies, standards, and guidelines.
  • Ensure policies align with bank goals, industry standards, and regulatory requirements (e.g., ISO 27001, NIST.).
  • Periodically review and update policies to address evolving risks and technologies.
  • Lead department risk assessment process in line with ISO 27001.
  • Test the controls identified within the department RCSA and implement identified gaps.
  • Develop and oversee risk treatment plans to mitigate identified vulnerabilities.
  • Facilitate regular risk assessments and track the resolution of high-priority risks.
  • Ensure the bank complies with legal, regulatory, and contractual obligations related to information security. This includes ensuring quarterly reporting to Bank of Uganda as per the Bank of Uganda Guidelines on Cyber and Technology Risk 2024.
  • Act as a liaison during audits or assessments and ensure audit findings are addressed timely. This involves working with other team members resolve audit issues timely and effectively to avoid repeat issues.
  • Monitor changes in relevant regulations and update governance practices accordingly.
  • Implement and manage security frameworks such as ISO 27001, COBIT, NIST CSF, or others as appropriate.
  • Establish and maintain an Information Security Management System (ISMS) for structured governance.
  • Automation of the information security reporting dashboard and management of update of the same.
  • Provide regular reports to Executive management and the board on the organization’s security posture, risks, and compliance status.
  • Participate in security governance committees, ensuring cross-functional alignment on security goals.
  • Develop and enforce third-party security agreements and ensure they align with organizational risk tolerance.
  • Provide governance support during security incidents by ensuring the incident response process aligns with policies and compliance requirements.
  • Ensure lessons learned from incidents are integrated into governance improvements.
  • Establish and oversee security awareness programs to educate employees and customers on security policies, risks, and best practices.
  • Develop and refine the organization’s long-term information security strategy.
  • Stay informed about emerging threats, technologies, and governance trends to adapt practices proactively.
  • Benchmark the bank’s information security program against industry best practices.

Qualifications or requirements (e.g., education, skills)

  • A minimum qualification of a Bachelor’s Degree in Computer Science, Information Technology, or a related numerical Sciences Degree.
  • A Master’s Degree specializing in Digital Security is an added advantage
  • Information Security and /or Information Technology industry certification (CISSP, CISM, CEH, CISSP-ISSMP, CISA, CRISC or GIAC equivalent) is required.
  • Knowledge of risk management processes (e.g., methods for assessing and mitigating risk).
  • Knowledge of laws, regulations, policies, and ethics as they relate to cybersecurity and privacy.
  • Knowledge of authentication, authorization, and access control methods.
  • Knowledge of the ISO 27001 framework and PCI DSS.
  • Knowledge of applicable business processes and operations of customer organizations.
  • Knowledge of Cyber-Defense and vulnerability assessment tools and their capabilities.
  • Knowledge of cryptography and cryptographic key management concepts.
  • Skill in determining how a security system should work (including its resilience and dependability capabilities) and how changes in conditions, operations, or the environment will affect these outcomes.
  • Skill in discerning the protection needs (i.e., security controls) of information systems and networks.
  • Skill in identifying measures or indicators of system performance and the actions needed to improve or correct performance, relative to the goals of the system.
  • Skill in recognizing and categorizing types of vulnerabilities and associated attacks.
  • Skill in applying security controls.
  • Advanced Business Architectural & IT Security skills.
  • Analytical Thinking & Inductive Reasoning.
  • Planning and Organization.
  • Problem Solving.
  • Strategic Perspective – Establish priorities, challenging goals and measurements consistent with these goals and organizational vision.
  • Critical Judgement and Decision-Making – Define issues and focus on achieving workable solutions to obstacles.
  • Good Communicator – Presents ideas effectively, clearly, and concisely both orally and in writing.
  • Leadership and Interpersonal Skills – Create a culture of continuous development and ownership with self and the team.
  • Inspire Commitment –Actions and behaviors are consistent with words.
  • Self-Development – Pursues positive change in self and organization. Drives own personal development plan.
  • Advanced Business Architectural & IT Security skills.
  • Analytical Thinking & Inductive Reasoning.
  • Planning and Organization.
  • Problem Solving.
  • Strategic Perspective – Establish priorities, challenging goals and measurements consistent with these goals and organizational vision.
  • Critical Judgement and Decision-Making – Define issues and focus on achieving workable solutions to obstacles.
  • Good Communicator – Presents ideas effectively, clearly and concisely both orally and in writing.
  • Leadership and Interpersonal Skills – Create a culture of continuous development and ownership with self and the team
  • Inspire Commitment –Actions and behaviours are consistent with words.
  • Self-Development – Pursues positive change in self and organization. Drives own personal development plan.

Experience needed

At least 6 years’ experience with a minimum of 3 years’ exposure to reviewing and advancing Information Security in a bank/ financial services environment.

Experience in assessing and mitigating technology risk (Solid understanding of Risk Management processes).

Any other provided details (e.g., benefits, work environment, team info, or additional notes)

Only short-listed candidates will be contacted.

Please note that all recruitment terms and conditions as stated in the HR Policies and Procedures Manual shall apply.

* Develop, implement, and maintain security policies, standards, and guidelines. * Ensure policies align with bank goals, industry standards, and regulatory requirements (e.g., ISO 27001, NIST.). * Periodically review and update policies to address evolving risks and technologies. * Lead department risk assessment process in line with ISO 27001. * Test the controls identified within the department RCSA and implement identified gaps. * Develop and oversee risk treatment plans to mitigate identified vulnerabilities. * Facilitate regular risk assessments and track the resolution of high-priority risks. * Ensure the bank complies with legal, regulatory, and contractual obligations related to information security. This includes ensuring quarterly reporting to Bank of Uganda as per the Bank of Uganda Guidelines on Cyber and Technology Risk 2024. * Act as a liaison during audits or assessments and ensure audit findings are addressed timely. This involves working with other team members resolve audit issues timely and effectively to avoid repeat issues. * Monitor changes in relevant regulations and update governance practices accordingly. * Implement and manage security frameworks such as ISO 27001, COBIT, NIST CSF, or others as appropriate. * Establish and maintain an Information Security Management System (ISMS) for structured governance. * Automation of the information security reporting dashboard and management of update of the same. * Provide regular reports to Executive management and the board on the organization’s security posture, risks, and compliance status. * Participate in security governance committees, ensuring cross-functional alignment on security goals. * Develop and enforce third-party security agreements and ensure they align with organizational risk tolerance. * Provide governance support during security incidents by ensuring the incident response process aligns with policies and compliance requirements. * Ensure lessons learned from incidents are integrated into governance improvements. * Establish and oversee security awareness programs to educate employees and customers on security policies, risks, and best practices. * Develop and refine the organization’s long-term information security strategy. * Stay informed about emerging threats, technologies, and governance trends to adapt practices proactively. * Benchmark the bank’s information security program against industry best practices.
* Advanced Business Architectural & IT Security skills. * Analytical Thinking & Inductive Reasoning. * Planning and Organization. * Problem Solving. * Strategic Perspective – Establish priorities, challenging goals and measurements consistent with these goals and organizational vision. * Critical Judgement and Decision-Making – Define issues and focus on achieving workable solutions to obstacles. * Good Communicator – Presents ideas effectively, clearly, and concisely both orally and in writing. * Leadership and Interpersonal Skills – Create a culture of continuous development and ownership with self and the team. * Inspire Commitment –Actions and behaviors are consistent with words. * Self-Development – Pursues positive change in self and organization. Drives own personal development plan. * Advanced Business Architectural & IT Security skills. * Analytical Thinking & Inductive Reasoning. * Planning and Organization. * Problem Solving. * Strategic Perspective – Establish priorities, challenging goals and measurements consistent with these goals and organizational vision. * Critical Judgement and Decision-Making – Define issues and focus on achieving workable solutions to obstacles. * Good Communicator – Presents ideas effectively, clearly and concisely both orally and in writing. * Leadership and Interpersonal Skills – Create a culture of continuous development and ownership with self and the team * Inspire Commitment –Actions and behaviours are consistent with words. * Self-Development – Pursues positive change in self and organization. Drives own personal development plan.
* A minimum qualification of a Bachelor’s Degree in Computer Science, Information Technology, or a related numerical Sciences Degree. * A Master’s Degree specializing in Digital Security is an added advantage * Information Security and /or Information Technology industry certification (CISSP, CISM, CEH, CISSP-ISSMP, CISA, CRISC or GIAC equivalent) is required. * Knowledge of risk management processes (e.g., methods for assessing and mitigating risk). * Knowledge of laws, regulations, policies, and ethics as they relate to cybersecurity and privacy. * Knowledge of authentication, authorization, and access control methods. * Knowledge of the ISO 27001 framework and PCI DSS. * Knowledge of applicable business processes and operations of customer organizations. * Knowledge of Cyber-Defense and vulnerability assessment tools and their capabilities. * Knowledge of cryptography and cryptographic key management concepts. * Skill in determining how a security system should work (including its resilience and dependability capabilities) and how changes in conditions, operations, or the environment will affect these outcomes. * Skill in discerning the protection needs (i.e., security controls) of information systems and networks. * Skill in identifying measures or indicators of system performance and the actions needed to improve or correct performance, relative to the goals of the system. * Skill in recognizing and categorizing types of vulnerabilities and associated attacks. * Skill in applying security controls.
bachelor degree
12
JOB-6a71c516b9395

Vacancy title:
Manager – IT Security Governance

[Type: FULL_TIME, Industry: Banking, Category: Management, Computer & IT, Business Operations]

Jobs at:
DFCU Bank

Deadline of this Job:
Friday, August 7 2026

Duty Station:
Head Office | Kampala

Summary
Date Posted: Tuesday, August 4 2026, Base Salary: Not Disclosed

Similar Jobs in Uganda
Learn more about DFCU Bank
DFCU Bank jobs in Uganda

JOB DETAILS:

Background information about the job or company (e.g., role context, company overview)

DFCU BANK

Reporting to the Chief- Information & Cyber Security Officer, the role is responsible for developing, implementing, and overseeing security policies, frameworks, and strategies to ensure compliance with regulations, alignment with business objectives, and effective risk management across the organization.

Responsibilities or duties

  • Develop, implement, and maintain security policies, standards, and guidelines.
  • Ensure policies align with bank goals, industry standards, and regulatory requirements (e.g., ISO 27001, NIST.).
  • Periodically review and update policies to address evolving risks and technologies.
  • Lead department risk assessment process in line with ISO 27001.
  • Test the controls identified within the department RCSA and implement identified gaps.
  • Develop and oversee risk treatment plans to mitigate identified vulnerabilities.
  • Facilitate regular risk assessments and track the resolution of high-priority risks.
  • Ensure the bank complies with legal, regulatory, and contractual obligations related to information security. This includes ensuring quarterly reporting to Bank of Uganda as per the Bank of Uganda Guidelines on Cyber and Technology Risk 2024.
  • Act as a liaison during audits or assessments and ensure audit findings are addressed timely. This involves working with other team members resolve audit issues timely and effectively to avoid repeat issues.
  • Monitor changes in relevant regulations and update governance practices accordingly.
  • Implement and manage security frameworks such as ISO 27001, COBIT, NIST CSF, or others as appropriate.
  • Establish and maintain an Information Security Management System (ISMS) for structured governance.
  • Automation of the information security reporting dashboard and management of update of the same.
  • Provide regular reports to Executive management and the board on the organization’s security posture, risks, and compliance status.
  • Participate in security governance committees, ensuring cross-functional alignment on security goals.
  • Develop and enforce third-party security agreements and ensure they align with organizational risk tolerance.
  • Provide governance support during security incidents by ensuring the incident response process aligns with policies and compliance requirements.
  • Ensure lessons learned from incidents are integrated into governance improvements.
  • Establish and oversee security awareness programs to educate employees and customers on security policies, risks, and best practices.
  • Develop and refine the organization’s long-term information security strategy.
  • Stay informed about emerging threats, technologies, and governance trends to adapt practices proactively.
  • Benchmark the bank’s information security program against industry best practices.

Qualifications or requirements (e.g., education, skills)

  • A minimum qualification of a Bachelor’s Degree in Computer Science, Information Technology, or a related numerical Sciences Degree.
  • A Master’s Degree specializing in Digital Security is an added advantage
  • Information Security and /or Information Technology industry certification (CISSP, CISM, CEH, CISSP-ISSMP, CISA, CRISC or GIAC equivalent) is required.
  • Knowledge of risk management processes (e.g., methods for assessing and mitigating risk).
  • Knowledge of laws, regulations, policies, and ethics as they relate to cybersecurity and privacy.
  • Knowledge of authentication, authorization, and access control methods.
  • Knowledge of the ISO 27001 framework and PCI DSS.
  • Knowledge of applicable business processes and operations of customer organizations.
  • Knowledge of Cyber-Defense and vulnerability assessment tools and their capabilities.
  • Knowledge of cryptography and cryptographic key management concepts.
  • Skill in determining how a security system should work (including its resilience and dependability capabilities) and how changes in conditions, operations, or the environment will affect these outcomes.
  • Skill in discerning the protection needs (i.e., security controls) of information systems and networks.
  • Skill in identifying measures or indicators of system performance and the actions needed to improve or correct performance, relative to the goals of the system.
  • Skill in recognizing and categorizing types of vulnerabilities and associated attacks.
  • Skill in applying security controls.
  • Advanced Business Architectural & IT Security skills.
  • Analytical Thinking & Inductive Reasoning.
  • Planning and Organization.
  • Problem Solving.
  • Strategic Perspective – Establish priorities, challenging goals and measurements consistent with these goals and organizational vision.
  • Critical Judgement and Decision-Making – Define issues and focus on achieving workable solutions to obstacles.
  • Good Communicator – Presents ideas effectively, clearly, and concisely both orally and in writing.
  • Leadership and Interpersonal Skills – Create a culture of continuous development and ownership with self and the team.
  • Inspire Commitment –Actions and behaviors are consistent with words.
  • Self-Development – Pursues positive change in self and organization. Drives own personal development plan.
  • Advanced Business Architectural & IT Security skills.
  • Analytical Thinking & Inductive Reasoning.
  • Planning and Organization.
  • Problem Solving.
  • Strategic Perspective – Establish priorities, challenging goals and measurements consistent with these goals and organizational vision.
  • Critical Judgement and Decision-Making – Define issues and focus on achieving workable solutions to obstacles.
  • Good Communicator – Presents ideas effectively, clearly and concisely both orally and in writing.
  • Leadership and Interpersonal Skills – Create a culture of continuous development and ownership with self and the team
  • Inspire Commitment –Actions and behaviours are consistent with words.
  • Self-Development – Pursues positive change in self and organization. Drives own personal development plan.

Experience needed

At least 6 years’ experience with a minimum of 3 years’ exposure to reviewing and advancing Information Security in a bank/ financial services environment.

Experience in assessing and mitigating technology risk (Solid understanding of Risk Management processes).

Any other provided details (e.g., benefits, work environment, team info, or additional notes)

Only short-listed candidates will be contacted.

Please note that all recruitment terms and conditions as stated in the HR Policies and Procedures Manual shall apply.

Work Hours: 8

Experience in Months: 12

Level of Education: bachelor degree

Job application procedure

Once there, click on “Career Opportunities” to get started. (We recommend using Google Chrome for the best experience.)

Deadline: Friday 7th August 2026

Only short-listed candidates will be contacted.

Please note that all recruitment terms and conditions as stated in the HR Policies and Procedures Manual shall apply.

Application Link:Click Here to Apply Now

All Jobs | QUICK ALERT SUBSCRIPTION

Job Info
Job Category: Management jobs in Uganda
Job Type: Full-time
Deadline of this Job: Friday, August 7 2026
Duty Station: Head Office | Kampala
Posted: 04-08-2026
No of Jobs: 1
Start Publishing: 04-08-2026
Stop Publishing (Put date of 2030): 10-10-2076
Apply Now
Notification Board

Join a Focused Community on job search to uncover both advertised and non-advertised jobs that you may not be aware of. A jobs WhatsApp Group Community can ensure that you know the opportunities happening around you and a jobs Facebook Group Community provides an opportunity to discuss with employers who need to fill urgent position. Click the links to join. You can view previously sent Email Alerts here incase you missed them and Subscribe so that you never miss out.

Caution: Never Pay Money in a Recruitment Process.

Some smart scams can trick you into paying for Psychometric Tests.