Job Title: Manager – IT Security Governance
Organisation: Dfcu Bank
Duty Station: Kampala, Uganda
About Organisation:
dfcu Bank is part of dfcu Group, a Ugandan financial services firm. The Group comprises dfcu Bank and dfcu Investment Management. dfcu Bank offers a wide range of products and services in personal banking, business banking, and corporate banking.
Job Summary: Reporting to the Chief- Information & Cyber Security Officer, the role is responsible for developing, implementing, and overseeing security policies, frameworks, and strategies to ensure compliance with regulations, alignment with business objectives, and effective risk management across the organization.
Key Duties and Responsibilities:
- Develop, implement, and maintain security policies, standards, and guidelines.
- Ensure policies align with `bank goals, industry standards, and regulatory requirements (e.g., ISO 27001, NIST.).
- Periodically review and update policies to address evolving risks and technologies.
- Lead department risk assessment process in line with ISO 27001.
- Test the controls identified within the department RCSA and implement identified gaps.
- Develop and oversee risk treatment plans to mitigate identified vulnerabilities.
- Facilitate regular risk assessments and track the resolution of high-priority risks.
- Ensure the bank complies with legal, regulatory, and contractual obligations related to information security.
- This includes ensuring quarterly reporting to Bank of Uganda as per the Bank of Uganda Guidelines on Cyber and Technology Risk 2024.
- Act as a liaison during audits or assessments and ensure audit findings are addressed timely.
- This involves working with other team members resolve audit issues timely and effectively to avoid repeat issues.
- Monitor changes in relevant regulations and update governance practices accordingly.
- Implement and manage security frameworks such as ISO 27001, COBIT, NIST CSF, or others as appropriate.
- Establish and maintain an Information Security Management System (ISMS) for structured governance.
- Automation of the information security reporting dashboard and management of update of the same.
- Provide regular reports to Executive management and the board on the organization’s security posture, risks, and compliance status.
- Participate in security governance committees, ensuring cross-functional alignment on security goals.
- Develop and enforce third-party security agreements and ensure they align with organizational risk tolerance.
- Provide governance support during security incidents by ensuring the incident response process aligns with policies and compliance requirements.
- Ensure lessons learned from incidents are integrated into governance improvements.
- Establish and oversee security awareness programs to educate employees and customers on security policies, risks, and best practices.
- Develop and refine the organization’s long-term information security strategy.
- Stay informed about emerging threats, technologies, and governance trends to adapt practices proactively.
- Benchmark the bank’s information security program against industry best practices.
Qualifications, Skills and Experience:
- A minimum qualification of a Bachelor’s Degree in Computer Science, Information Technology, or a related numerical Sciences Degree.
- A Master’s Degree specializing in Digital Security is an added advantage
- Information Security and /or Information Technology industry certification (CISSP, CISM, CEH, CISSP-ISSMP, CISA, CRISC or GIAC equivalent) is required.
- At least 6 years’ experience with a minimum of 3 years’ exposure to reviewing and advancing Information Security in a bank/ financial services environment.
- Experience in assessing and mitigating technology risk (Solid understanding of Risk Management processes).
- Knowledge of risk management processes (e.g., methods for assessing and mitigating risk).
- Knowledge of laws, regulations, policies, and ethics as they relate to cybersecurity and privacy.
- Knowledge of authentication, authorization, and access control methods.
- Knowledge of the ISO 27001 framework and PCI DSS.
- Knowledge of applicable business processes and operations of customer organizations.
- Knowledge of Cyber-Defense and vulnerability assessment tools and their capabilities.
- Knowledge of cryptography and cryptographic key management concepts.
- Skill in determining how a security system should work (including its resilience and dependability capabilities) and how changes in conditions, operations, or the environment will affect these outcomes.
- Skill in discerning the protection needs (i.e., security controls) of information systems and networks.
- Skill in identifying measures or indicators of system performance and the actions needed to improve or correct performance, relative to the goals of the system.
- Skill in recognizing and categorizing types of vulnerabilities and associated attacks.
- Skill in applying security controls.
- Advanced Business Architectural & IT Security skills.
- Analytical Thinking & Inductive Reasoning.
- Planning and Organization.
- Problem Solving.
- Strategic Perspective – Establish priorities, challenging goals and measurements consistent with these goals and organizational vision.
- Critical Judgement and Decision-Making – Define issues and focus on achieving workable solutions to obstacles.
- Good Communicator – Presents ideas effectively, clearly, and concisely both orally and in writing.
- Leadership and Interpersonal Skills – Create a culture of continuous development and ownership with self and the team.
- Inspire Commitment –Actions and behaviors are consistent with words.
- Self-Development – Pursues positive change in self and organization. Drives own personal development plan.
- Advanced Business Architectural & IT Security skills.
- Analytical Thinking & Inductive Reasoning.
- Planning and Organization.
- Problem Solving.
- Strategic Perspective – Establish priorities, challenging goals and measurements consistent with these goals and organizational vision.
- Critical Judgement and Decision-Making – Define issues and focus on achieving workable solutions to obstacles.
- Good Communicator – Presents ideas effectively, clearly and concisely both orally and in writing.
- Leadership and Interpersonal Skills – Create a culture of continuous development and ownership with self and the team
- Inspire Commitment –Actions and behaviours are consistent with words.
- Self-Development – Pursues positive change in self and organization. Drives own personal development plan.
How to Apply:
All suitably qualified and Interested applicants should apply online at the link below.
Opens the employer’s application pageApply Now →
Deadline: 7th August 2026
NB: Only shortlisted candidates will be contacted.
For more of the latest jobs, please visit https://www.theugandanjobline.com or find us on our facebook page https://www.facebook.com/UgandanJobline
Level of Education: bachelor degree
Work Hours: 8
Experience in Months: 72