Sign in to save jobs
Create a free account or sign in to bookmark jobs and find them later.
ICT Security Officer

ICT Security Officer

Full-time Expires In -3 weeks Kampala Duty Station - Kampala, Uganda Bachelor's Degree 3 years experience IT Banking Security
VIP Access

Job Details

UGAFODE Microfinance Limited (MDI) is seeking an ICT Security Officer (Ref: HR/STAFF/VAC – 11/08/2026) on a Full Time basis. The job holder is responsible for enforcing compliance to all aspects of computer security, operationalizing the Cyber Security Strategy, Policies, Standards and Procedures, and protecting the bank’s data and ICT systems from cyber threats while ensuring compliance with the Data-Protection-and-Privacy-Act-2019 of Uganda and other regulatory requirements. The role evaluates the MDI’s ICT environment and supports IT security and operational audits. Location: Kampala, Uganda.

Key Duties and Responsibilities

  • Implement, maintain and monitor UGAFODE’s Cyber Security systems and participate in design and implementation of up-to-date IT standards, policies, guidelines and appropriate architectural principles
  • Manage UGAFODE’s IT Security systems and tools, e.g. firewalls, data protection controls, log analyzers, end-point-security, patching, encryption, vulnerability scanning and pen testing, including monitoring and enforcing security access procedures to Information Technology Systems and networks
  • Research, evaluate, design, test, recommend and plan technological upgrades and major changes to the IT Security environment, and analyze their impact on the existing environment, overseeing deployment and configuration
  • Provide IT Security Awareness training to personnel as per established programs to promote good security hygiene
  • Serve as department’s representative to support IT security and operational audits by internal assurance functions or third-parties and ensure service-level agreements with outsourced ICT security providers are enforced
  • Enforce ICT Change and Incident management activities and processes in line with approved IT Policies
  • Work with ICT staff to ensure all Audit, Risk, Vulnerability and compliance findings are appreciated and closed in time
  • Enforce day-to-day activities of threat and vulnerability management, identify risk tolerances, recommend and support implementation of treatment plans
  • Provide guidance during security incidents and investigations, ensuring root-cause analysis is undertaken and lessons identified are addressed
  • Ensure systems and information comply with the Data-Protection-and-Privacy-Act-2019 of Uganda and other relevant legal and regulatory requirements
  • Work with the IT team to ensure security is factored into evaluation, selection, installation and configuration of hardware, applications, software and third party connections before introduction into the ICT environment
  • Maintain a knowledgebase comprising technical reference library, security advisories and alerts, information on security trends and practices, and laws and regulations
  • Support the Head Information Security in developing and planning annual Budgets and work plans and execution of the same
  • Undertake any other assignments related to information systems technology as may be assigned by supervisors

Qualifications, Skills and Requirements

  • Bachelor’s degree in Computer Science, Information Technology or other relevant degree from a recognized University and any certification in Systems, Databases or Networks
  • Minimum 3 years’ experience in an organization of at least the same nature preferably Financial institution, Government institution, Telecom institution or consulting firm
  • Experience in performing risk, business impact, control and vulnerability assessments, and in defining treatment strategies
  • Knowledge of UNIX Operating Systems, Microsoft Server Operating Systems, Virtualization technologies, Intrusion Prevention and Detection systems and advanced enterprise networks (LANs and WANs)
  • Well-developed IT skills and experience in related jobs such as network engineer/Administrator, database administrator, systems analyst, applications developer, IT auditing, IT risk analyst, etc.
  • Professional IT Security Certifications / Trainings e.g. CISSP, CEH, CCSP, MSCE, CISA, CISM, etc. and Network certifications e.g. CCNA, CCNP are an added advantage
  • Excellent communication and interpersonal skills with ability to influence teams
  • Knowledge and understanding of the Data-Protection-and-Privacy-Act-2019 of Uganda and other relevant regulatory requirements
  • Knowledge and experience in developing and documenting security architecture and plans
  • Understanding of information security principles and best practices (e.g., ISO27001/2, COBIT, NIST, PCI and ISF Standards of Good Practice for Information Security)
  • Excellent analytical and problem-solving abilities to analyse security requirements and relate them to appropriate security controls