Sign in to save jobs
Create a free account or sign in to bookmark jobs and find them later.
ICT Security Officer

ICT Security Officer

Full-time Expires In -3 weeks Kampala Duty Station - Head Office, Kampala Bachelor's Degree 3 years experience ICT IT
VIP Access

Job Details

The ICT Security Officer is responsible for enforcing compliance to all aspects of computer security in UGAFODE MDI, especially operationalizing the Cyber Security Strategy, Policies, Standards, Procedures, Methods, best practices, architecture and systems to protect the bank's data and ICT systems from cyber threats while evaluating the MDI's ICT environment and data processing to ensure compliance to applicable standards, laws and industry security norms.

Duty Station: Head Office, Kampala Employment Type: Full time Work Hours: 8

Key Duties and Responsibilities

  • Implement, maintain and monitor UGAFODE's Cyber Security systems and participate in the design and implementation of up-to-date IT standards, policies, guidelines and appropriate architectural principles
  • Manage UGAFODE's IT Security systems and tools (firewalls, data protection controls, log analyzers, end-point-security, patching, encryption, vulnerability scanning and pen testing etc.) and monitor and enforce security access procedures to IT Systems and networks
  • Research, evaluate, design, test, recommend and plan technological upgrade improvements and major changes to the IT Security environment and oversee their proper deployment, configuration, and functioning
  • Provide IT Security Awareness training to personnel as per established training programs to promote good security hygiene
  • Serve as departmental representative to support IT security and operational audits by internal assurance functions or third-parties and enforce SLAs with outsourced ICT security service providers
  • Enforce ICT Change and Incident management activities and processes in line with approved IT Policies
  • Work with ICT staff to ensure all Audit, Risk, Vulnerability and compliance findings are appreciated and closed in time
  • Enforce day-to-day activities of threat and vulnerability management, identify risk tolerances, recommend and support implementation of treatment plans
  • Provide guidance during security incidents and investigations, ensuring root-cause analysis and suggesting approaches to deal with lessons identified
  • Ensure systems and information comply with the Data-Protection-and-Privacy-Act-2019 of Uganda and other relevant legal and regulatory requirements
  • Work with the IT team to ensure security is factored into evaluation, selection, installation and configuration of hardware, applications, software and third-party connections
  • Maintain a knowledgebase comprising technical reference library, security advisories and alerts, information on security trends, practices, laws and regulations
  • Support the Head Information Security in developing and planning the IT Security section's annual budgets and work plans and execution thereof
  • Undertake any other assignments related to information systems technology as assigned

Qualifications, Skills and Requirements

  • Minimum of a Bachelor's degree in Computer Science, Information Technology or other relevant degree from a recognized University and any certification in Systems, Databases or Networks
  • Minimum of 3 years' experience in an organization of at least the same nature preferably a financial institution, government institution, telecom institution or consulting firm
  • Experience in performing risk, business impact, control and vulnerability assessments, and in defining treatment strategies
  • Knowledge of UNIX Operating Systems, Microsoft Server Operating Systems, Virtualization technologies, Intrusion Prevention and Detection systems and advanced enterprise networks (LANs and WANs)
  • Well-developed IT skills and experience in related IT jobs such as network engineer/administrator, database administrator, systems analyst, applications developer, IT auditing, IT risk analyst, etc.
  • Professional IT Security Certifications/Trainings e.g. CISSP, CEH, CCSP, MSCE, CISA, CISM, and Network certifications e.g. CCNA, CCNP are an added advantage
  • Excellent communication and interpersonal skills with ability to influence teams
  • Knowledge and understanding of the Data-Protection-and-Privacy-Act-2019 of Uganda and other relevant regulatory requirements
  • Knowledge of and experience in developing and documenting security architecture and plans
  • Understanding of information security principles and best practices (e.g., ISO27001/2, COBIT, NIST, PCI and ISF Standards of Good Practice)
  • Excellent analytical and problem-solving abilities