This job has expired

Applications are no longer being accepted for this position.

The application deadline was August 25, 2026.

UGAFODE

ICT Security Officer

UGAFODE

Uganda Full time IT & Software
Posted: Aug 11, 2026 1 month ago Deadline: Aug 25, 2026 (Expired) 52 views

Job Description

 

ICT Security Officer – UGAFODE Microfinance Limited

Reference: HR/STAFF/VAC – 11/08/2026
Company: UGAFODE Microfinance Limited (MDI)
Job Title: ICT Security Officer
Location: Uganda
Employment Type: Full Time
Category: IT / Technology
Application Deadline: 25 August 2026
Reports To: Head Information Security
About UGAFODE Microfinance Limited
UGAFODE Microfinance Limited (MDI) is a registered financial institution in Uganda that operates in accordance with Central Bank regulations and guidelines.
The institution was founded in 1994 with the objective of providing quality microfinance services in Uganda.
UGAFODE is seeking a competent and experienced ICT Security Officer to strengthen its information security function and help protect the organization's data, ICT systems, networks and digital infrastructure against cybersecurity threats.
Job Summary
The ICT Security Officer will be responsible for enforcing compliance with all aspects of computer and information security at UGAFODE MDI.
The position will support the operationalization of the organization's Cyber Security Strategy, policies, standards, procedures, methods, best practices, architecture and security systems designed to protect organizational data and ICT systems from cyber threats.
The role will also involve evaluating UGAFODE's ICT environment and data processing activities to ensure compliance with applicable laws, regulatory requirements, information security standards and industry best practices.
Key Duties and Responsibilities
1. Cybersecurity Systems and Security Standards
  • Implement, maintain and monitor UGAFODE's cybersecurity systems.
  • Participate in the design and implementation of current IT standards, policies, guidelines and appropriate security architecture principles.
  • Ensure that the organization's IT security goals and objectives continue to be achieved.
  • Support continuous improvement of UGAFODE's information security environment.
  • Ensure security controls remain aligned with organizational requirements and industry best practices.
2. IT Security Systems and Tools Management
Manage and monitor UGAFODE's IT security systems and tools, including:
  • Firewalls
  • Data protection controls
  • Log analyzers
  • Endpoint security solutions
  • Patch management
  • Encryption controls
  • Vulnerability scanning
  • Penetration testing
  • Security access controls
The successful candidate will ensure these tools are optimally utilized while monitoring and enforcing appropriate access procedures for UGAFODE's information systems and networks.
3. Technology Evaluation and Security Improvements
  • Research, evaluate, design, test and recommend technology upgrades and improvements to the IT security environment.
  • Plan major changes to the security environment where required.
  • Analyze the potential impact of proposed changes on existing ICT systems.
  • Oversee proper deployment, configuration and operation of security technologies.
  • Ensure new security technologies are appropriately integrated into the existing ICT environment.
4. Security Awareness and Training
  • Provide IT security awareness training to UGAFODE personnel.
  • Deliver security awareness activities in accordance with established IT security training programmes.
  • Promote good cybersecurity hygiene and responsible use of organizational ICT resources.
  • Encourage employees to understand and comply with information security policies and procedures.
5. Security Audits and Assurance
  • Represent the department during IT security and operational audits.
  • Support audits conducted by internal assurance functions and third-party assessors.
  • Ensure UGAFODE maintains a strong information security posture.
  • Monitor compliance with service-level agreements involving outsourced ICT security service providers.
  • Support implementation and closure of audit recommendations.
6. Change and Incident Management
  • Enforce ICT change and incident management processes.
  • Ensure change and incident management activities comply with approved IT policies.
  • Support effective documentation and tracking of security incidents.
  • Ensure security implications are appropriately considered before significant ICT changes are implemented.
7. Risk, Vulnerability and Compliance Management
  • Work with ICT staff to identify and understand audit, risk, vulnerability and compliance findings.
  • Ensure identified findings are addressed and closed within agreed timelines.
  • Enforce day-to-day threat and vulnerability management activities.
  • Identify appropriate risk tolerances.
  • Recommend and support implementation of risk treatment plans.
  • Monitor emerging cybersecurity threats and vulnerabilities.
  • Support continuous improvement of the organization's security risk posture.
8. Security Incident Response and Investigation
  • Provide guidance during cybersecurity incidents and investigations.
  • Support appropriate incident response activities.
  • Ensure root-cause analysis is conducted following security incidents.
  • Recommend appropriate approaches for addressing identified weaknesses.
  • Capture lessons learned from security incidents and support implementation of corrective actions.
9. Data Protection and Regulatory Compliance
  • Ensure systems and information comply with Uganda's Data Protection and Privacy Act, 2019 and other applicable legal and regulatory requirements.
  • Monitor ICT security practices for compliance with relevant regulatory standards.
  • Support implementation of appropriate data protection and privacy controls.
  • Ensure security controls adequately protect organizational and customer information.
10. Secure Technology Deployment
  • Work with the IT team to ensure security considerations are incorporated into the evaluation, selection, installation and configuration of:
    • Hardware
    • Applications
    • Software
    • Network infrastructure
    • Third-party connections
  • Ensure new technologies are introduced into the ICT environment in accordance with current security policies and standards.
  • Assess security risks associated with third-party connections and technology deployments.
11. Security Knowledge Management
  • Maintain a technical security knowledgebase.
  • Maintain a technical reference library.
  • Monitor and document security advisories and alerts.
  • Maintain information on emerging security trends and practices.
  • Keep records of relevant laws, regulations and security standards.
  • Ensure relevant security information is accessible to appropriate ICT and management teams.
12. Budgeting and Work Planning
  • Support the Head of Information Security in developing annual IT Security budgets.
  • Support preparation of annual IT Security work plans.
  • Participate in execution and monitoring of approved security budgets and work plans.
  • Provide input into security technology and resource requirements.
13. Other Duties
  • Undertake other assignments related to information systems technology as may be assigned by supervisors from time to time.
  • Support broader ICT and information security initiatives as required by management.
Qualifications and Education
Applicants should have:
  • A minimum of a Bachelor's degree in Computer Science, Information Technology or another relevant field from a recognized university.
  • Certification in Systems, Databases or Networks.
  • Professional IT security certifications or training will be an added advantage.
Professional Certifications
The following certifications are an added advantage:
Information Security Certifications
  • CISSP – Certified Information Systems Security Professional
  • CEH – Certified Ethical Hacker
  • CCSP – Certified Cloud Security Professional
  • CISA – Certified Information Systems Auditor
  • CISM – Certified Information Security Manager
  • MCSE – Microsoft Certified Solutions Expert
Networking Certifications
  • CCNA – Cisco Certified Network Associate
  • CCNP – Cisco Certified Network Professional
Experience Requirements
Applicants should have:
  • At least three (3) years' relevant experience in an organization of a similar nature.
  • Experience in a financial institution, government institution, telecommunications organization or consulting firm is preferred.
  • Experience conducting risk assessments, business impact assessments, control assessments and vulnerability assessments.
  • Experience defining and implementing risk treatment strategies.
  • Practical experience in information security, cybersecurity, ICT risk or related technical roles.
Candidates with backgrounds in related IT positions such as the following may be considered:
  • Network Engineer
  • Network Administrator
  • Database Administrator
  • Systems Analyst
  • Applications Developer
  • IT Auditor
  • IT Risk Analyst
  • Information Security Specialist
  • Cybersecurity Analyst
  • Systems Administrator
Technical Knowledge and Skills
The successful candidate should have knowledge of:
  • UNIX operating systems
  • Microsoft Server operating systems
  • Virtualization technologies
  • Intrusion Prevention Systems (IPS)
  • Intrusion Detection Systems (IDS)
  • Advanced enterprise networks
  • LAN and WAN technologies
  • Firewalls
  • Endpoint security
  • Vulnerability management
  • Security monitoring
  • Patch management
  • Encryption
  • Penetration testing
  • Security architecture
  • Risk assessment
  • IT controls
  • Data protection and privacy
Information Security Frameworks and Standards
Applicants should have an understanding of information security principles and industry best practices, including:
  • ISO 27001 / ISO 27002
  • COBIT
  • NIST
  • PCI
  • ISF Standards of Good Practice for Information Security
Knowledge of these frameworks will help the successful candidate design, implement and assess appropriate information security controls.
Key Competencies
The ideal candidate should demonstrate:
  • Excellent analytical skills
  • Strong cybersecurity knowledge
  • Excellent problem-solving abilities
  • Security risk assessment
  • Vulnerability assessment
  • IT security controls
  • Security architecture
  • Incident management
  • Strong communication skills
  • Excellent interpersonal skills
  • Ability to influence and work with teams
  • Attention to detail
  • Ability to work independently
  • Ability to analyze complex security requirements
  • Ability to translate security requirements into appropriate security controls
  • Strong understanding of regulatory compliance
  • Continuous learning and awareness of emerging cybersecurity threats
Who Should Apply?
This opportunity is suitable for experienced ICT Security Officers, Cybersecurity Analysts, Information Security Specialists, IT Risk Analysts, Network Security Engineers, Systems Administrators, IT Auditors and other IT professionals with relevant cybersecurity and information security experience.
Candidates with experience in financial institutions, microfinance institutions, banks, telecommunications companies, government institutions or IT consulting firms will have particularly relevant backgrounds.
Professionals who have experience with firewalls, endpoint security, vulnerability management, penetration testing, security monitoring, risk assessments, ISO 27001, NIST, COBIT, data protection and ICT audits should consider applying if they meet the stated requirements.
How to Apply
Interested candidates who meet the requirements should submit:
  • An application letter
  • An up-to-date CV
Applications should be sent by email to:
Email Subject: ICT Security Officer
Applications should be addressed to:
Head of Human Resource
UGAFODE Microfinance Limited (MDI)
Application Deadline
25 August 2026
Applications will be reviewed on a rolling basis, and only shortlisted candidates will be contacted.
Note: Female candidates are encouraged to apply.
Application Tips
Applicants should tailor their CVs to clearly demonstrate:
  • Cybersecurity and information security experience
  • IT security systems administration
  • Firewall management
  • Endpoint security
  • Vulnerability scanning and management
  • Penetration testing
  • Security risk assessments
  • IT audits and compliance
  • Incident response
  • Security architecture
  • Network security
  • Microsoft Server and UNIX experience
  • Data protection and privacy compliance
  • ISO 27001, NIST or COBIT knowledge
  • Professional cybersecurity certifications
  • Experience in banking, microfinance, telecommunications, government or consulting environments
Where possible, candidates should quantify their achievements, such as security incidents resolved, vulnerabilities remediated, systems secured, audit findings closed, security controls implemented, infrastructure protected or compliance improvements achieved.

About Company

UGAFODE

UGAFODE

This job has expired

The application deadline has passed.

Deadline was: Aug 25, 2026

Apply via Email

Send your application to:

recruitment@ugafode.co.ug

Include CV and cover letter

Use job title as subject

Note: This job has expired.

Job Overview

  • Job Type: Full time
  • Experience Level: Intermediate
  • Education Level: Bachelors
  • Vacancies: 1
  • Category: IT & Software
  • Location: Uganda
  • Application: via Email
Join our WhatsApp group 1