ICT Security Officer job at UGAFODE Microfinance Limited (MDI)
Posted by: great-volunteer
Posted date: 2026-Aug-13
Location: Head office, Kampala
ICT Security Officer 2026-08-12T17:16:59+00:00 UGAFODE Microfinance Limited (MDI) https://cdn.ugashare.com/jsjobsdata/data/employer/comp_699/logo/ugafode.png https://www.ugashare.com/jobs/ FULL_TIME Head office Kampala 00256 Uganda Financial Services Computer & IT, Science & Engineering, Business Operations 2026-08-25T17:00:00+00:00 8 Background information about the job or company (e.g., role context, company overview) The job holder shall be responsible for enforcing compliance to all aspects of computer security in UGAFODE MDI especially in operationalizing of the Cyber Security Strategy, Policies, Standards, Procedures, Methods, best practices, architecture and systems to protect the bankâs data and ICT systems from Cyber threats while evaluating the MDIâs ICT environment and data processing to ensure compliance to applicable standards & laws and relevance with industry security norms. Responsibilities or duties KEY ACCOUNTABILITIES: - Implement, maintain and monitor UGAFODEâs Cyber Security systems and participation in the design and implementation of up-to-date IT standards, policies, guidelines and appropriate architectural principles to ensure the UGAFODEâs IT Security goals continue to be met
- Manage UGAFODEâs IT Security systems and tools, e.g. firewalls, data protection controls, log analyzers, end-point-security, patching, encryption, vulnerability scanning and pen testing etc. ensuring that they are use optimally, including, monitoring and enforcing security access procedures to UGAFODEâs Information Technology Systems and networks.
- Research, evaluate, design, test, recommend and/or plan technological upgrade improvements and major changes to the IT Security environment, and analyze their impact on the existing environment, while overseeing their proper deployment, configuration, and functioning.
- Providing training on IT Security Awareness trainings to UGAFODEâs personnel as per established IT security training programs to promote good security hygiene.
- Serve as the departmentâs representative to support IT security & operational audits by UGAFODEâs internal assurance functions or third-parties to ensure UGAFODE maintains a strong security posture including ensuring that service-level agreements with outsourced ICT security services providers are enforced.
- Enforce UGAFODEâs ICT Change and Incident management activities and processes ensuring that they are in line with the approved IT Policies.
- Work with ICT staffs to ensure that all Audit, Risk, Vulnerability & compliance findings are appreciated and closed in time.
- Enforce the day-to-day activities of threat and vulnerability management, identify risk tolerances, recommend and support implementation of treatment plans
- Provide guidance during security incidents and investigations, ensuring root-cause analysis is undertaken and input suggested approaches to deal with lessons identified
- Ensure that systems and the information within them comply with the Data-Protection-and-Privacy-Act-2019 of Uganda and other relevant legal and regulatory requirements.
- Work with the IT team to ensure that security is factored into the evaluation, selection, installation and configuration of hardware, applications, Softwareâs and 3rd party connections before being introduced into the ICT environment in compliance with current Security Policies
- Maintain a knowledgebase comprising a technical reference library, security advisories and alerts, information on security trends and practices, and laws and regulations
- Support the Head Information Security in developing and planning of the IT Security sectionâs annual Budgets and work plans and execution of the same.
- And undertake any other assignments related to information systems technology as may be assigned by supervisors from time to time
Qualifications or requirements (e.g., education, skills) KNOWLEDGE, SKILLS AND EXPERIENCE REQUIRED: - Minimum of a Bachelorâs degree in Computer Science, Information Technology or other relevant degree from a recognized University and any certification in Systems, Databases or Networks
- Knowledge of UNIX Operating Systems, Microsoft Server Operating Systems, Virtualization technologies, Intrusion Prevention & Detection systems and advanced enterprise networks (LANs & WANs).
- Have well-developed IT skills and experience in related jobs in IT, such as a network engineer/Administrator, a database administrator, a systems analyst, applications developer, IT auditing, IT risk analyst, etc.
- Must have excellent communication skills and excellent interpersonal skills with the ability to influence teams.
- Knowledge and understanding of the Data-Protection-and-Privacy-Act-2019 of Uganda and other relevant regulatory requirements.
- Knowledge of and experience in developing and documenting security architecture and plans,
- Understanding of information security principles and best practices (e.g., ISO27001/2, COBIT, NIST, PCI and ISF Standards of Good Practice for Information Security).
- Excellent analytical and problem-solving abilities to analyse security requirements and relate them to appropriate security controls
Experience needed Minimum of 3 yearsâ experience in an organization of at least the same nature preferably a, Financial institution, Government institution, Telecom institution or a consulting firm Experience in performing risk, business impact, control and vulnerability assessments, and in defining treatment strategies Any other provided details (e.g., benefits, work environment, team info, or additional notes) Professional IT Security Certifications / Trainings e.g. CISSP, CEH, CCSP, MSCE, CISA, CISM, etc. and Network certifications e.g. CCNA, CCNP are an added advantage Note: Ladies are encouraged to apply * Implement, maintain and monitor UGAFODEâs Cyber Security systems and participation in the design and implementation of up-to-date IT standards, policies, guidelines and appropriate architectural principles to ensure the UGAFODEâs IT Security goals continue to be met * Manage UGAFODEâs IT Security systems and tools, e.g. firewalls, data protection controls, log analyzers, end-point-security, patching, encryption, vulnerability scanning and pen testing etc. ensuring that they are use optimally, including, monitoring and enforcing security access procedures to UGAFODEâs Information Technology Systems and networks. * Research, evaluate, design, test, recommend and/or plan technological upgrade improvements and major changes to the IT Security environment, and analyze their impact on the existing environment, while overseeing their proper deployment, configuration, and functioning. * Providing training on IT Security Awareness trainings to UGAFODEâs personnel as per established IT security training programs to promote good security hygiene. * Serve as the departmentâs representative to support IT security & operational audits by UGAFODEâs internal assurance functions or third-parties to ensure UGAFODE maintains a strong security posture including ensuring that service-level agreements with outsourced ICT security services providers are enforced. * Enforce UGAFODEâs ICT Change and Incident management activities and processes ensuring that they are in line with the approved IT Policies. * Work with ICT staffs to ensure that all Audit, Risk, Vulnerability & compliance findings are appreciated and closed in time. * Enforce the day-to-day activities of threat and vulnerability management, identify risk tolerances, recommend and support implementation of treatment plans * Provide guidance during security incidents and investigations, ensuring root-cause analysis is undertaken and input suggested approaches to deal with lessons identified * Ensure that systems and the information within them comply with the Data-Protection-and-Privacy-Act-2019 of Uganda and other relevant legal and regulatory requirements. * Work with the IT team to ensure that security is factored into the evaluation, selection, installation and configuration of hardware, applications, Softwareâs and 3rd party connections before being introduced into the ICT environment in compliance with current Security Policies * Maintain a knowledgebase comprising a technical reference library, security advisories and alerts, information on security trends and practices, and laws and regulations * Support the Head Information Security in developing and planning of the IT Security sectionâs annual Budgets and work plans and execution of the same. * And undertake any other assignments related to information systems technology as may be assigned by supervisors from time to time * Knowledge of UNIX Operating Systems, Microsoft Server Operating Systems, Virtualization technologies, Intrusion Prevention & Detection systems and advanced enterprise networks (LANs & WANs). * Well-developed IT skills and experience in related jobs in IT, such as a network engineer/Administrator, a database administrator, a systems analyst, applications developer, IT auditing, IT risk analyst, etc. * Excellent communication skills * Excellent interpersonal skills with the ability to influence teams. * Knowledge and understanding of the Data-Protection-and-Privacy-Act-2019 of Uganda and other relevant regulatory requirements. * Knowledge of and experience in developing and documenting security architecture and plans, * Understanding of information security principles and best practices (e.g., ISO27001/2, COBIT, NIST, PCI and ISF Standards of Good Practice for Information Security). * Excellent analytical and problem-solving abilities to analyse security requirements and relate them to appropriate security controls * Minimum of a Bachelorâs degree in Computer Science, Information Technology or other relevant degree from a recognized University and any certification in Systems, Databases or Networks JOB-6a7caa8b24cf6 Vacancy title: ICT Security Officer Jobs at: UGAFODE Microfinance Limited (MDI) Deadline of this Job: Tuesday, August 25 2026 Duty Station: Head office | Kampala Summary Date Posted: Wednesday, August 12 2026, Base Salary: Not Disclosed JOB DETAILS:
Background information about the job or company (e.g., role context, company overview) The job holder shall be responsible for enforcing compliance to all aspects of computer security in UGAFODE MDI especially in operationalizing of the Cyber Security Strategy, Policies, Standards, Procedures, Methods, best practices, architecture and systems to protect the bankâs data and ICT systems from Cyber threats while evaluating the MDIâs ICT environment and data processing to ensure compliance to applicable standards & laws and relevance with industry security norms. Responsibilities or duties KEY ACCOUNTABILITIES: - Implement, maintain and monitor UGAFODEâs Cyber Security systems and participation in the design and implementation of up-to-date IT standards, policies, guidelines and appropriate architectural principles to ensure the UGAFODEâs IT Security goals continue to be met
- Manage UGAFODEâs IT Security systems and tools, e.g. firewalls, data protection controls, log analyzers, end-point-security, patching, encryption, vulnerability scanning and pen testing etc. ensuring that they are use optimally, including, monitoring and enforcing security access procedures to UGAFODEâs Information Technology Systems and networks.
- Research, evaluate, design, test, recommend and/or plan technological upgrade improvements and major changes to the IT Security environment, and analyze their impact on the existing environment, while overseeing their proper deployment, configuration, and functioning.
- Providing training on IT Security Awareness trainings to UGAFODEâs personnel as per established IT security training programs to promote good security hygiene.
- Serve as the departmentâs representative to support IT security & operational audits by UGAFODEâs internal assurance functions or third-parties to ensure UGAFODE maintains a strong security posture including ensuring that service-level agreements with outsourced ICT security services providers are enforced.
- Enforce UGAFODEâs ICT Change and Incident management activities and processes ensuring that they are in line with the approved IT Policies.
- Work with ICT staffs to ensure that all Audit, Risk, Vulnerability & compliance findings are appreciated and closed in time.
- Enforce the day-to-day activities of threat and vulnerability management, identify risk tolerances, recommend and support implementation of treatment plans
- Provide guidance during security incidents and investigations, ensuring root-cause analysis is undertaken and input suggested approaches to deal with lessons identified
- Ensure that systems and the information within them comply with the Data-Protection-and-Privacy-Act-2019 of Uganda and other relevant legal and regulatory requirements.
- Work with the IT team to ensure that security is factored into the evaluation, selection, installation and configuration of hardware, applications, Softwareâs and 3rd party connections before being introduced into the ICT environment in compliance with current Security Policies
- Maintain a knowledgebase comprising a technical reference library, security advisories and alerts, information on security trends and practices, and laws and regulations
- Support the Head Information Security in developing and planning of the IT Security sectionâs annual Budgets and work plans and execution of the same.
- And undertake any other assignments related to information systems technology as may be assigned by supervisors from time to time
Qualifications or requirements (e.g., education, skills) KNOWLEDGE, SKILLS AND EXPERIENCE REQUIRED: - Minimum of a Bachelorâs degree in Computer Science, Information Technology or other relevant degree from a recognized University and any certification in Systems, Databases or Networks
- Knowledge of UNIX Operating Systems, Microsoft Server Operating Systems, Virtualization technologies, Intrusion Prevention & Detection systems and advanced enterprise networks (LANs & WANs).
- Have well-developed IT skills and experience in related jobs in IT, such as a network engineer/Administrator, a database administrator, a systems analyst, applications developer, IT auditing, IT risk analyst, etc.
- Must have excellent communication skills and excellent interpersonal skills with the ability to influence teams.
- Knowledge and understanding of the Data-Protection-and-Privacy-Act-2019 of Uganda and other relevant regulatory requirements.
- Knowledge of and experience in developing and documenting security architecture and plans,
- Understanding of information security principles and best practices (e.g., ISO27001/2, COBIT, NIST, PCI and ISF Standards of Good Practice for Information Security).
- Excellent analytical and problem-solving abilities to analyse security requirements and relate them to appropriate security controls
Experience needed Minimum of 3 yearsâ experience in an organization of at least the same nature preferably a, Financial institution, Government institution, Telecom institution or a consulting firm Experience in performing risk, business impact, control and vulnerability assessments, and in defining treatment strategies Any other provided details (e.g., benefits, work environment, team info, or additional notes) Professional IT Security Certifications / Trainings e.g. CISSP, CEH, CCSP, MSCE, CISA, CISM, etc. and Network certifications e.g. CCNA, CCNP are an added advantage Note: Ladies are encouraged to apply Work Hours: 8 Experience in Months: 36 Level of Education: bachelor degree Job application procedure Interested in applying for this job? ugafode.co.ug&form%5Bvalid-to%5D=Tuesday,%20August%2025%202026">Click here to submit your application now.
If you believe you meet the requirements as noted above, please submit application letter together with an up-to-date CV (please indicate the position you are applying for in the Subject Line e.g. âICT Security Officerâ). Applications should be addressed to the Head of Human Resource. Only shortlisted candidates will be contacted.
|