DFCU Bank

Manager – IT Security Governance

DFCU Bank

Uganda Full time IT & Software
Posted: Aug 03, 2026 4 hours ago 10 views

Job Description

 

Manager – IT Security Governance Jobs in Uganda – DFCU Bank

Employer: DFCU Bank
Job Title: Manager – IT Security Governance
Job Type: Full-Time
Industry: Banking & Financial Services
Category: Information Technology, Cybersecurity, Risk Management & Governance
Duty Station: DFCU Bank Head Office, Uganda
Deadline: 7 August 2026
Reports To: Chief – Information & Cyber Security Officer
Salary: Not Disclosed

About DFCU Bank

DFCU Bank is one of Uganda’s leading financial institutions, providing banking solutions to individuals, businesses, and corporate customers. The bank focuses on innovation, digital transformation, customer experience, and maintaining strong security standards to protect customer information and financial systems.
As banking continues to rely heavily on digital platforms, DFCU Bank prioritizes cybersecurity governance, technology risk management, regulatory compliance, and protection against emerging cyber threats.

Job Summary

DFCU Bank is seeking an experienced Manager – IT Security Governance to lead the development, implementation, and oversight of information security policies, frameworks, and governance practices.
The successful candidate will ensure cybersecurity strategies align with business objectives, regulatory requirements, and industry best practices. The role will oversee security risk management, compliance, audits, information security frameworks, reporting, and governance programs across the organization.
This position requires a senior cybersecurity professional with strong experience in banking security environments, IT governance, risk management, and information security frameworks such as ISO 27001, NIST, COBIT, and PCI DSS.

Key Responsibilities

Information Security Governance
  • Develop, implement, and maintain information security policies, standards, and guidelines.
  • Ensure security policies align with business objectives, regulatory requirements, and industry standards.
  • Review and update security policies to address emerging cybersecurity risks and technologies.
  • Establish and maintain an Information Security Management System (ISMS).
  • Develop long-term information security strategies aligned with organizational goals.
  • Participate in security governance committees and support enterprise security objectives.
Cybersecurity Risk Management
  • Lead information security risk assessment processes in line with ISO 27001 standards.
  • Conduct technology risk assessments and identify cybersecurity vulnerabilities.
  • Develop and monitor risk treatment plans to address security weaknesses.
  • Track resolution of high-priority security risks.
  • Assess security controls and implement improvements.
  • Support risk-based decision-making across the organization.
Compliance and Regulatory Management
  • Ensure compliance with cybersecurity laws, regulations, and contractual obligations.
  • Support regulatory reporting requirements including Bank of Uganda cybersecurity guidelines.
  • Monitor changes in cybersecurity regulations and update governance practices.
  • Ensure compliance with frameworks including:
    • ISO 27001
    • NIST Cybersecurity Framework
    • COBIT
    • PCI DSS
Audit and Assurance Management
  • Act as a key contact during cybersecurity audits and assessments.
  • Coordinate responses to audit findings.
  • Ensure timely remediation of identified security gaps.
  • Work with internal teams to prevent repeat audit issues.
Security Reporting and Management Support
  • Automate information security reporting dashboards.
  • Provide regular cybersecurity reports to executive management and the board.
  • Report on security posture, compliance status, and technology risks.
  • Support security decision-making through accurate security metrics.
Third-Party and Incident Governance
  • Develop and enforce third-party security agreements.
  • Ensure vendor security practices align with organizational risk tolerance.
  • Provide governance support during cybersecurity incidents.
  • Ensure incident response processes comply with security policies.
  • Incorporate lessons learned from incidents into security improvements.
Security Awareness and Improvement
  • Develop cybersecurity awareness programs for employees and customers.
  • Promote information security best practices across the organization.
  • Monitor emerging threats and cybersecurity trends.
  • Benchmark security programs against global industry standards.

Qualifications

Applicants should possess:
  • Bachelor’s Degree in Computer Science, Information Technology, Cybersecurity, or related numerical sciences field.
  • Master’s Degree specializing in Digital Security is an added advantage.
  • Professional cybersecurity certification such as:
    • CISSP
    • CISM
    • CEH
    • CISA
    • CRISC
    • GIAC certifications or equivalent.
  • Minimum 6 years of experience in Information Technology or Cybersecurity.
  • At least 3 years of experience reviewing and advancing information security within banking or financial services environments.

Required Technical Skills and Knowledge

Candidates should have knowledge and experience in:
  • Information security governance frameworks.
  • ISO 27001 Information Security Management System (ISMS).
  • NIST Cybersecurity Framework.
  • COBIT governance framework.
  • PCI DSS compliance.
  • Cybersecurity risk assessment and mitigation.
  • Technology risk management.
  • Authentication, authorization, and access controls.
  • Identity and access management.
  • Vulnerability assessment and cyber-defense tools.
  • Cryptography and encryption key management.
  • Security controls implementation.
  • Cybersecurity incident management.
  • Data protection and privacy requirements.

Required Professional Skills

Successful candidates should demonstrate:
  • Advanced IT security architecture skills.
  • Strong analytical and critical thinking abilities.
  • Strategic planning and organizational skills.
  • Problem-solving and decision-making abilities.
  • Excellent written and verbal communication skills.
  • Ability to present cybersecurity issues to senior management.
  • Strong leadership and team development skills.
  • Ability to influence stakeholders and drive security improvements.
  • Commitment to continuous professional development.

Why Join DFCU Bank?

Working with DFCU Bank provides an opportunity to:
  • Lead cybersecurity governance initiatives within a major financial institution.
  • Work on enterprise-level security programs.
  • Strengthen Uganda’s banking cybersecurity landscape.
  • Develop expertise in information security leadership.
  • Work with advanced security frameworks and technologies.
  • Build a career in cybersecurity management.

Career Growth Opportunities

A Manager – IT Security Governance can progress into roles such as:
  • Chief Information Security Officer (CISO)
  • Head of Cybersecurity
  • Information Security Director
  • Cybersecurity Risk Manager
  • IT Governance Director
  • Technology Risk Manager

What Should Be Included in Your CV

A strong CV for the Manager – IT Security Governance position should include:
  • Professional summary highlighting cybersecurity governance and banking security experience.
  • Bachelor’s Degree in IT, Computer Science, Cybersecurity, or related field.
  • Cybersecurity certifications such as CISSP, CISM, CISA, CRISC, CEH, or GIAC.
  • Minimum 6 years of cybersecurity or IT security experience.
  • Experience working in banking or financial services environments.
  • Experience developing and implementing security policies.
  • Experience managing ISO 27001, NIST, COBIT, or PCI DSS frameworks.
  • Cybersecurity risk assessment and mitigation experience.
  • Audit management and regulatory compliance experience.
  • Experience with vulnerability management and security controls.
  • Incident response governance experience.
  • Security reporting and dashboard development experience.
Highlight Achievements Such as:
  • Implemented ISO 27001 security controls.
  • Reduced cybersecurity risks through improved controls.
  • Led successful security audits.
  • Developed cybersecurity policies and procedures.
  • Improved regulatory compliance scores.
  • Managed security awareness programs.
  • Reduced vulnerabilities through risk treatment plans.

Cover Letter Tips

When writing a cover letter for this role:
  • Start by highlighting your cybersecurity leadership experience.
  • Mention your experience working in banking or financial services security environments.
  • Explain your expertise in security governance frameworks such as ISO 27001, NIST, COBIT, and PCI DSS.
  • Highlight achievements in risk reduction, compliance, and security improvement.
  • Demonstrate your ability to communicate cybersecurity risks to senior executives.
  • Explain how your skills can help DFCU Bank strengthen information security.
  • Mention relevant cybersecurity certifications.
  • Keep the letter focused on business impact, not only technical skills.

Interview Questions and Tips

1. Tell us about your cybersecurity and IT governance experience.
Tip: Highlight your years of experience, banking exposure, security frameworks handled, and major security projects.
2. How would you develop an effective information security governance framework?
Tip: Discuss policies, standards, risk assessments, controls, compliance monitoring, reporting, and continuous improvement.
3. Explain your experience with ISO 27001 implementation.
Tip: Describe your involvement in ISMS development, risk assessments, controls implementation, audits, and certification processes.
4. How do you manage cybersecurity risks in a banking environment?
Tip: Explain risk identification, assessment, mitigation plans, control testing, monitoring, and reporting.
5. What is the difference between ISO 27001, NIST, and COBIT?
Tip: Explain:
  • ISO 27001 – Information Security Management System standard.
  • NIST – Cybersecurity risk management framework.
  • COBIT – IT governance and management framework.
6. How do you prepare an organization for cybersecurity audits?
Tip: Discuss policy reviews, control testing, evidence collection, gap remediation, and stakeholder coordination.
7. How would you handle a major cybersecurity incident?
Tip: Explain incident response planning, containment, investigation, communication, recovery, and lessons learned.
8. How do you communicate cybersecurity risks to executives?
Tip: Focus on business impact, risk exposure, compliance requirements, and practical recommendations.
9. What cybersecurity trends concern financial institutions today?
Tip: Mention areas such as ransomware, phishing, cloud security risks, identity threats, third-party risks, and AI-enabled attacks.
10. Why do you want to join DFCU Bank?
Tip: Connect your cybersecurity expertise with DFCU’s digital transformation, risk management goals, and commitment to secure banking services.

How to Apply

Interested candidates should apply through the DFCU Bank careers portal:
careers.dfcugroup.com
Applicants should select “Career Opportunities” and complete the application process.
Deadline: Friday, 7 August 2026
Only shortlisted candidates will be contacted.

Related Jobs in Uganda

Candidates interested in this role may also consider:
  • Cybersecurity Manager Jobs
  • Information Security Officer Jobs
  • IT Risk Manager Jobs
  • Security Governance Specialist Jobs
  • Cybersecurity Analyst Jobs
  • IT Audit Manager Jobs
  • Information Security Architect Jobs
  • SOC Manager Jobs
  • Technology Risk Officer Jobs
  • CISO Jobs
 

About Company

DFCU Bank

DFCU Bank

Apply on External Website
You will be redirected to the employer's application page.

Job Overview

  • Job Type: Full time
  • Experience Level: Intermediate
  • Education Level: Bachelors
  • Vacancies: 1
  • Category: IT & Software
  • Location: Uganda
  • Application: External Website
Join our WhatsApp group 1