This job has expired

Applications are no longer being accepted for this position.

The application deadline was August 19, 2026.

DFCU Bank

IT Security Specialist – Governance

DFCU Bank

Uganda Full time IT & Software
Posted: Aug 11, 2026 1 month ago Deadline: Aug 19, 2026 (Expired) 18 views

Job Description

 

IT Security Specialist – Governance | DFCU Bank

Company: DFCU Bank
Job Title: IT Security Specialist – Governance
Department: Information Security / IT
Duty Station: Head Office, Uganda
Employment Type: Full Time
Industry: Banking / Information Technology / Cybersecurity
Reports To: Manager – Information Security, Governance
Application Deadline: Wednesday, 19th August 2026
Job Summary
DFCU Bank is seeking a skilled and experienced IT Security Specialist – Governance to support the Bank's information security governance framework and continuously strengthen its cybersecurity posture.
The successful candidate will oversee key areas of IT security governance, Identity and Access Management (IAM), cybersecurity awareness, third-party security, security baselines, information security policies, regulatory compliance and security standards.
The role requires strong practical knowledge of ISO/IEC 27001:2022, PCI DSS, cybersecurity risk management, information security governance and technology risk. The successful candidate will also coordinate information security audits, monitor compliance, manage security findings and prepare security reports for management and the Bank of Uganda.
This is an excellent opportunity for experienced cybersecurity professionals, information security specialists, IT governance professionals, technology risk specialists and security compliance professionals seeking to advance their careers in Uganda's banking sector.
Key Accountabilities
1. Identity and Access Management (IAM)
  • Develop, implement and maintain IAM policies, standards and procedures.
  • Align IAM controls with industry best practices and regulatory requirements.
  • Oversee the complete lifecycle of user identities.
  • Manage user provisioning and de-provisioning processes.
  • Conduct periodic access reviews.
  • Implement and monitor Role-Based Access Control (RBAC).
  • Ensure access privileges are appropriate to users' roles and responsibilities.
  • Identify and address inappropriate or excessive access privileges.
  • Strengthen identity and access governance across the Bank's technology environment.
2. Cybersecurity Awareness and Training
  • Design and implement cybersecurity awareness programmes.
  • Develop training programmes tailored to different employee roles and risk levels.
  • Develop security awareness communication materials.
  • Coordinate cybersecurity awareness campaigns.
  • Conduct phishing simulations and related security exercises.
  • Monitor employee participation and awareness performance.
  • Track the effectiveness of security awareness initiatives.
  • Identify areas requiring additional cybersecurity education.
  • Promote a strong information security culture across the organisation.
3. Third-Party Security Management
  • Conduct third-party security assessments.
  • Monitor third-party access to Bank systems and information.
  • Monitor third-party activities from a security perspective.
  • Track third-party security exceptions.
  • Follow up on remediation activities.
  • Work with Legal and Procurement teams to incorporate security requirements into contracts.
  • Ensure service providers meet required information security standards.
  • Support effective third-party technology risk management.
4. Security Baseline Management
  • Define minimum security baseline standards.
  • Document security requirements for IT systems.
  • Establish security baselines for applications.
  • Develop security requirements for networks and infrastructure.
  • Collaborate with technical teams to implement approved security baselines.
  • Conduct regular compliance reviews.
  • Identify gaps in security baseline implementation.
  • Develop metrics to measure security baseline compliance.
  • Report on security baseline adherence to management.
5. Information Security Management System (ISMS)
  • Maintain the Bank's Information Security Management System.
  • Support continual improvement of the ISMS.
  • Ensure alignment with ISO/IEC 27001:2022.
  • Review information security controls.
  • Identify areas requiring improvement.
  • Support risk-based information security decision-making.
  • Ensure security governance practices remain aligned with emerging threats and regulatory requirements.
6. PCI DSS Compliance
  • Support continuous compliance with Payment Card Industry Data Security Standard (PCI DSS) requirements.
  • Coordinate annual PCI DSS assessments.
  • Identify compliance gaps.
  • Coordinate remediation activities.
  • Monitor progress against PCI DSS requirements.
  • Maintain appropriate PCI DSS documentation.
  • Support internal and external PCI DSS assessments.
  • Report compliance status and outstanding issues to management.
7. Information Security Policies and Procedures
  • Develop information security policies.
  • Review existing security policies.
  • Update procedures and guidelines.
  • Ensure security documentation reflects emerging cybersecurity threats.
  • Align policies with technological changes.
  • Incorporate relevant regulatory changes.
  • Ensure employees and technical teams understand applicable security requirements.
  • Monitor compliance with information security policies.
8. Information Security Audits
  • Coordinate internal information security audits.
  • Coordinate external security audits.
  • Support ISO 27001 assessments.
  • Support PCI DSS assessments.
  • Coordinate regulatory audits.
  • Act as a key point of contact during audit engagements.
  • Provide required documentation and evidence.
  • Track audit findings.
  • Coordinate remediation activities.
  • Follow up until findings are formally closed.
9. Regulatory Compliance and Bank of Uganda Reporting
  • Prepare quarterly information security reports.
  • Submit accurate and timely reports to the Bank of Uganda as required.
  • Monitor regulatory cybersecurity requirements.
  • Ensure information security practices comply with applicable laws and regulations.
  • Track changes in cybersecurity and data-protection requirements.
  • Support management in addressing regulatory findings.
10. Security Reporting and Management Dashboards
  • Develop information security metrics.
  • Prepare security dashboards.
  • Prepare management reports.
  • Highlight key cybersecurity risks.
  • Report on compliance status.
  • Monitor security improvement initiatives.
  • Present security performance information to management.
  • Provide actionable insights to support security decision-making.
Knowledge, Skills and Experience Required
Educational Qualifications
Applicants should have:
  • A minimum Bachelor's Degree in Computer Science, Information Technology or a related numerical sciences discipline.
  • A Master's Degree is an added advantage.
Professional Certifications
An information security or IT certification is required. Relevant certifications include:
  • CISSP
  • CISM
  • CEH
  • CISA
  • CRISC
  • ISO 27001 Lead Implementer
Candidates should clearly state their relevant certifications and professional qualifications on their CV.
Professional Experience
Applicants should have:
  • At least 3 years of information security experience.
  • Proven experience identifying technology risks.
  • Experience assessing technology and cybersecurity risks.
  • Experience developing and implementing risk mitigation strategies.
  • Strong understanding of cybersecurity risk management frameworks.
  • Experience with information security governance.
  • Experience with compliance and security audits.
  • Experience with security policies and procedures.
  • Experience with third-party security risk.
  • Experience with Identity and Access Management.
Technical Knowledge
The successful candidate should have practical knowledge of:
  • ISO/IEC 27001
  • PCI DSS
  • Information security governance.
  • Cybersecurity risk management.
  • Identity and Access Management.
  • Role-Based Access Control.
  • Security awareness.
  • Third-party security.
  • Security baselines.
  • Information security policies.
  • Technology risk.
  • Data privacy and protection.
  • Security compliance.
  • Audit management.
  • Regulatory compliance.
Key Competencies
DFCU Bank is looking for a professional with strong:
  • Effective communication.
  • Analytical thinking.
  • Inductive reasoning.
  • Problem-solving.
  • Stakeholder management.
  • Risk assessment.
  • Security governance.
  • Attention to detail.
  • Report writing.
  • Presentation skills.
  • Self-driven development.
  • Professional judgement.
  • Collaboration.
  • Continuous learning.
Who Should Apply?
This position is suitable for experienced:
  • IT Security Specialists
  • Information Security Specialists
  • Cybersecurity Specialists
  • Cybersecurity Governance Officers
  • IT Governance Specialists
  • Technology Risk Specialists
  • Information Security Analysts
  • Cyber Risk Professionals
  • IT Compliance Specialists
  • Security Assurance Specialists
  • GRC Specialists
  • Information Security Auditors
Candidates with banking, financial services, fintech, telecommunications or other highly regulated industry experience may have particularly relevant exposure to cybersecurity governance and regulatory compliance.
CV Tips for IT Security Specialist – Governance Applicants
1. Put Your Security Certifications Prominently
If you hold any of the required certifications, make them easy for recruiters to find.
For example:
  • CISSP.
  • CISM.
  • CISA.
  • CRISC.
  • CEH.
  • ISO 27001 Lead Implementer.
Do not list certifications you have not obtained.
2. Emphasise Governance, Risk and Compliance
This position is strongly focused on information security governance, so your CV should not read like a purely technical cybersecurity CV.
Highlight experience in:
  • Security governance.
  • Cybersecurity policies.
  • Risk assessments.
  • Compliance.
  • Audit management.
  • ISO 27001.
  • PCI DSS.
  • Technology risk.
  • Security controls.
  • Regulatory reporting.
  • Third-party risk.
3. Highlight IAM Experience
Clearly demonstrate experience with:
  • User provisioning.
  • User de-provisioning.
  • Access reviews.
  • Privileged access.
  • RBAC.
  • Identity governance.
  • Access controls.
  • Segregation of duties.
4. Demonstrate Audit Experience
Mention specific experience supporting:
  • Internal audits.
  • External audits.
  • ISO 27001 audits.
  • PCI DSS assessments.
  • Regulatory audits.
  • Risk assessments.
  • Control testing.
  • Audit remediation.
5. Quantify Your Achievements
Where possible, include measurable results.
For example:
  • Number of users covered by IAM controls.
  • Percentage reduction in excessive privileges.
  • Number of security findings closed.
  • Number of employees trained.
  • Number of phishing simulations conducted.
  • Audit findings successfully remediated.
  • Number of third-party vendors assessed.
  • Security compliance improvement achieved.
6. Highlight Banking or Regulated-Industry Experience
If you have worked in banking, microfinance, insurance, fintech, telecommunications or another regulated environment, make this clear.
Show your experience with:
  • Regulatory requirements.
  • Customer data protection.
  • Financial systems.
  • Payment systems.
  • PCI DSS.
  • Technology risk.
  • Regulatory audits.
Cover Letter Tips
A strong cover letter should position you as an information security governance professional, rather than focusing only on technical cybersecurity.
Highlight:
  • Your Bachelor's Degree.
  • Your information security certification.
  • Your years of cybersecurity experience.
  • ISO 27001 experience.
  • PCI DSS experience.
  • IAM experience.
  • Technology risk management.
  • Security governance.
  • Audit coordination.
  • Third-party risk management.
  • Security awareness programmes.
  • Regulatory compliance.
  • Reporting and management dashboards.
Where possible, provide specific examples of security improvements you have delivered.
Likely Interview Questions
General Questions
  1. Tell us about your information security experience.
  2. Why are you interested in this position at DFCU Bank?
  3. Why should we hire you as an IT Security Specialist – Governance?
  4. What is your understanding of information security governance?
  5. What are the main cybersecurity risks facing banks today?
ISO 27001
  1. Explain the purpose of ISO/IEC 27001.
  2. What is an Information Security Management System?
  3. How would you maintain an effective ISMS?
  4. How do you approach an ISO 27001 audit?
  5. How would you handle an ISO 27001 non-conformity?
  6. How do you measure the effectiveness of security controls?
PCI DSS
  1. What is PCI DSS and why is it important to a bank?
  2. How would you prepare an organisation for a PCI DSS assessment?
  3. What would you do if a PCI DSS control was not being met?
  4. How would you manage PCI DSS remediation activities?
Identity and Access Management
  1. What is Identity and Access Management?
  2. Explain Role-Based Access Control.
  3. How would you manage user provisioning and de-provisioning?
  4. How frequently should access reviews be conducted?
  5. How would you identify excessive user privileges?
  6. How would you manage privileged access?
Third-Party Risk
  1. How would you assess a third-party service provider's security?
  2. What security requirements should be included in vendor contracts?
  3. How would you handle a vendor that fails a security assessment?
  4. How would you monitor third-party access to sensitive systems?
Cybersecurity Awareness
  1. How would you build a cybersecurity awareness programme?
  2. How would you measure whether security awareness training is effective?
  3. How would you design a phishing simulation?
  4. What would you do if employees repeatedly failed phishing simulations?
Risk and Compliance
  1. How do you conduct a technology risk assessment?
  2. How would you determine the appropriate treatment for an identified risk?
  3. What is the difference between a threat, vulnerability and risk?
  4. How would you prioritise multiple security risks?
  5. How do you ensure compliance with data protection requirements?
Scenario-Based Questions
  1. An employee has excessive access to critical banking systems. What would you do?
  2. A third-party vendor refuses to comply with a required security control. How would you respond?
  3. An audit identifies several high-risk security findings. How would you manage remediation?
  4. Management asks you to accept a security risk without remediation. What would you do?
  5. A phishing simulation shows a high employee failure rate. What actions would you take?
  6. A technical team deploys a system without meeting the required security baseline. How would you handle it?
Interview Preparation Tips
Before the interview, revise:
  • ISO/IEC 27001:2022
  • PCI DSS
  • Identity and Access Management.
  • RBAC.
  • Cybersecurity risk management.
  • Technology risk.
  • Third-party risk.
  • Security awareness.
  • Security controls.
  • Internal and external audits.
  • Data protection and privacy.
  • Security policies.
  • Regulatory compliance.
  • Information security metrics.
  • Management reporting.
  • Security governance frameworks.
Prepare practical examples demonstrating how you have identified a security risk, implemented a control, managed an audit finding, improved compliance or reduced exposure.
Salary Information
The vacancy provided does not state a specific salary range for the IT Security Specialist – Governance position.
Applicants should therefore focus on demonstrating the value of their information security governance experience, professional certifications, banking/regulated-industry exposure and ISO 27001/PCI DSS expertise during the recruitment process.
Application Checklist
Before applying, make sure your CV clearly demonstrates:
  • Bachelor's Degree in IT, Computer Science or related field.
  • At least 3 years of information security experience.
  • Relevant security certification.
  • ISO 27001 experience.
  • PCI DSS knowledge.
  • Cybersecurity risk management.
  • IAM experience.
  • Security governance.
  • Third-party security assessment.
  • Security awareness.
  • Audit coordination.
  • Technology risk management.
  • Data privacy and protection knowledge.
  • Security policies and procedures.
  • Strong analytical and problem-solving skills.
  • Stakeholder management experience.


How to Apply
Interested and qualified candidates should apply through the DFCU Bank careers platform.
Applicants should access the Career Opportunities section and search for the IT Security Specialist – Governance vacancy.
Recommended browser: Google Chrome.
Application Deadline: Wednesday, 19th August 2026
Applicants should submit their applications before the deadline and ensure their CV accurately reflects their information security governance, cybersecurity risk, IAM, ISO 27001, PCI DSS, audit and compliance experience.

About Company

DFCU Bank

DFCU Bank

This job has expired

The application deadline has passed.

Deadline was: Aug 19, 2026

Apply on External Website
You will be redirected to the employer's application page.

Note: This job has expired.

Job Overview

  • Job Type: Full time
  • Experience Level: Intermediate
  • Education Level: Bachelors
  • Vacancies: 1
  • Category: IT & Software
  • Location: Uganda
  • Application: External Website
Join our WhatsApp group 1