Senior Manager- Cyber Security Assurance job at DFCU Bank
Posted by: great-volunteer
Posted date: 2026-Apr-16
Location: kampala, Kampala
Senior Manager- Cyber Security Assurance 2026-04-15T17:47:29+00:00 DFCU Bank https://cdn.ugashare.com/jsjobsdata/data/employer/comp_7435/logo/dfcu%20Bank.jpeg https://www.dfcugroup.com/ FULL_TIME kampala Kampala 00256 Uganda Banking Management, Computer & IT, Protective Services 2026-04-22T17:00:00+00:00 8 Background Reporting to the Chief Information Security Officer, the role holder will be responsible for ensuring the design, implementation, oversight, testing, and continuous improvement of cybersecurity controls. This role not only provides assurance that security measures, policies, and programs meet regulatory standardsâincluding ISMS, PCI DSS, and Bank of Uganda requirementsâbut also actively drives the deployment and operationalization of these controls across the Bank. Responsibilities - Develop, implement, and enforce baseline security standards across all systems.
- Integrate security into the software development lifecycle and product design.
- Establish secure coding practices and ensure continuous security testing within CI/CD pipelines.
- Oversee vulnerability assessments, penetration testing, and red team simulations.
- Ensure timely remediation of identified risks and communicate critical findings to stakeholders.
- Lead vulnerability identification, prioritization, and recommendation on resolution.
- Report on key metrics and ensure compliance with risk appetite thresholds.
- Ensure effective lifecycle management of user identities, including provisioning, access reviews, and deprovisioning.
- Drive organization-wide awareness programs to strengthen security culture and reduce human risk.
- Lead third party security assessments and ongoing monitoring of vendors and partners in line with the security baseline standard.
- Maintain compliance with the ISMS (ISO 27001), PCI DSS, and all relevant regulatory requirements.
- Manage Bank of Uganda (BOU) quarterly reporting.
- Exercise oversight of enterprise technology governance, including cybersecurity and IT project governanceâthrough the establishment of policies and standards, ongoing monitoring of compliance across technology initiatives, and management of governance issues to prevent control failures and recurrence.
- Manage internal and external audits, track findings, and oversee timely remediation to ensure no overdue findings, no failed validations and no repeat findings.
- Lead and mentor a high-performing cybersecurity team.
- Foster a culture of accountability, continuous improvement, and innovation.
Qualifications and Experience - Bachelorâs Degree in Information Technology, Computer Science, or related field (Masterâs preferred).
- Professional Certifications such as CISSP, CISM, CISA, or ISO 27001 Lead Auditor/Implementer.
- 5+ years of experience in cybersecurity, with at least 3 years in a leadership role.
- Strong knowledge of ISO27001 ISMS, PCI DSS, and regulatory compliance requirements.
- Experience in DevSecOps, vulnerability management, and penetration testing.
- Strong leadership and people management skills.
- Excellent understanding of cybersecurity frameworks and risk management.
- Exceptional communication and executive reporting skills.
- Ability to balance strategic planning with hands-on technical oversight.
- Develop, implement, and enforce baseline security standards across all systems.
- Integrate security into the software development lifecycle and product design.
- Establish secure coding practices and ensure continuous security testing within CI/CD pipelines.
- Oversee vulnerability assessments, penetration testing, and red team simulations.
- Ensure timely remediation of identified risks and communicate critical findings to stakeholders.
- Lead vulnerability identification, prioritization, and recommendation on resolution.
- Report on key metrics and ensure compliance with risk appetite thresholds.
- Ensure effective lifecycle management of user identities, including provisioning, access reviews, and deprovisioning.
- Drive organization-wide awareness programs to strengthen security culture and reduce human risk.
- Lead third party security assessments and ongoing monitoring of vendors and partners in line with the security baseline standard.
- Maintain compliance with the ISMS (ISO 27001), PCI DSS, and all relevant regulatory requirements.
- Manage Bank of Uganda (BOU) quarterly reporting.
- Exercise oversight of enterprise technology governance, including cybersecurity and IT project governanceâthrough the establishment of policies and standards, ongoing monitoring of compliance across technology initiatives, and management of governance issues to prevent control failures and recurrence.
- Manage internal and external audits, track findings, and oversee timely remediation to ensure no overdue findings, no failed validations and no repeat findings.
- Lead and mentor a high-performing cybersecurity team.
- Foster a culture of accountability, continuous improvement, and innovation.
- Strong leadership and people management skills.
- Excellent understanding of cybersecurity frameworks and risk management.
- Exceptional communication and executive reporting skills.
- Ability to balance strategic planning with hands-on technical oversight.
- Bachelorâs Degree in Information Technology, Computer Science, or related field (Masterâs preferred).
- Professional Certifications such as CISSP, CISM, CISA, or ISO 27001 Lead Auditor/Implementer.
- Strong knowledge of ISO27001 ISMS, PCI DSS, and regulatory compliance requirements.
- Experience in DevSecOps, vulnerability management, and penetration testing.
JOB-69dfcf3193635 Vacancy title: Senior Manager- Cyber Security Assurance Jobs at: DFCU Bank Deadline of this Job: Wednesday, April 22 2026 Duty Station: kampala | Kampala Summary Date Posted: Wednesday, April 15 2026, Base Salary: Not Disclosed JOB DETAILS:
Background Reporting to the Chief Information Security Officer, the role holder will be responsible for ensuring the design, implementation, oversight, testing, and continuous improvement of cybersecurity controls. This role not only provides assurance that security measures, policies, and programs meet regulatory standardsâincluding ISMS, PCI DSS, and Bank of Uganda requirementsâbut also actively drives the deployment and operationalization of these controls across the Bank. Responsibilities - Develop, implement, and enforce baseline security standards across all systems.
- Integrate security into the software development lifecycle and product design.
- Establish secure coding practices and ensure continuous security testing within CI/CD pipelines.
- Oversee vulnerability assessments, penetration testing, and red team simulations.
- Ensure timely remediation of identified risks and communicate critical findings to stakeholders.
- Lead vulnerability identification, prioritization, and recommendation on resolution.
- Report on key metrics and ensure compliance with risk appetite thresholds.
- Ensure effective lifecycle management of user identities, including provisioning, access reviews, and deprovisioning.
- Drive organization-wide awareness programs to strengthen security culture and reduce human risk.
- Lead third party security assessments and ongoing monitoring of vendors and partners in line with the security baseline standard.
- Maintain compliance with the ISMS (ISO 27001), PCI DSS, and all relevant regulatory requirements.
- Manage Bank of Uganda (BOU) quarterly reporting.
- Exercise oversight of enterprise technology governance, including cybersecurity and IT project governanceâthrough the establishment of policies and standards, ongoing monitoring of compliance across technology initiatives, and management of governance issues to prevent control failures and recurrence.
- Manage internal and external audits, track findings, and oversee timely remediation to ensure no overdue findings, no failed validations and no repeat findings.
- Lead and mentor a high-performing cybersecurity team.
- Foster a culture of accountability, continuous improvement, and innovation.
Qualifications and Experience - Bachelorâs Degree in Information Technology, Computer Science, or related field (Masterâs preferred).
- Professional Certifications such as CISSP, CISM, CISA, or ISO 27001 Lead Auditor/Implementer.
- 5+ years of experience in cybersecurity, with at least 3 years in a leadership role.
- Strong knowledge of ISO27001 ISMS, PCI DSS, and regulatory compliance requirements.
- Experience in DevSecOps, vulnerability management, and penetration testing.
- Strong leadership and people management skills.
- Excellent understanding of cybersecurity frameworks and risk management.
- Exceptional communication and executive reporting skills.
- Ability to balance strategic planning with hands-on technical oversight.
Work Hours: 8 Experience in Months: 60 Level of Education: bachelor degree Job application procedure
Application Link:Click Here to Apply Now
|