IT Risk Officer – Yako Bank (U) Limited

IT Risk Officer – Yako Bank (U) Limited

Yako Bank is hiring an IT Risk Officer responsible for identifying, assessing, monitoring and reporting on Information Technology, cybersecurity and information security risks across Yako Bank. The job entails providing independent oversight of the Bank’s ICT environment, testing IT controls, overseeing IT incident, business continuity and third-party risks, and reporting to Risk Manager, while ensuring compliance with the Bank’s Risk Management Framework, Bank of Uganda requirements and applicable laws.

Volunteer opportunities board

Key Result Areas

  • Identify, assess, document and monitor Information Technology (IT), cyber and information security risks across the Bank’s systems, processes, projects and branches, and maintain an up-to-date IT risk register.
  • Conduct IT Risk and Control Self-Assessments (RCSAs) and carry out risk assessments of new systems, products, digital channels and major IT changes before they are introduced into the ICT environment.
  • Test the design and operating effectiveness of key IT controls, including access management, change management, backups, patching and segregation of duties, and carry out periodic user access reviews on the core banking and other critical systems.
  • Monitor the Bank’s cybersecurity posture, including vulnerability assessment and penetration test results, and track remediation of identified weaknesses to closure.
  • Ensure that IT and cyber incidents are logged, assessed, escalated and reported in line with the Bank’s Incident Management Policy and regulatory timelines, and lead root-cause analysis of significant incidents.
  • Review the Bank’s Business Continuity and Disaster Recovery plans, participate in Disaster Recovery tests, and report on results, gaps and recovery objectives for critical systems.
  • Assess and monitor risks arising from IT vendors, cloud and outsourced service providers before onboarding and periodically thereafter, including enforcement of service-level agreements.
  • Ensure compliance with Bank of Uganda ICT and cyber risk requirements, the Data Protection and Privacy Act, 2019 of Uganda, the National Payment Systems Act, 2020 and the Bank’s internal IT policies.
  • Coordinate responses to IT-related internal audit, external audit and regulatory findings, and work with ICT staff to ensure they are closed in time.
  • Preparing and presenting reports on IT Risk to management and stakeholders.
  • Supervise, guide and review the work of junior risk staff and interns assigned to IT risk, review IT risk policies and procedures annually, and support IT risk awareness training for staff.

Minimum Educational and Technical Competence Requirements

  • Bachelor’s degree in Information Technology, Computer Science, Information Systems or other relevant degree from a recognized University.
  • Professional certification in IT risk, audit or security, e.g CISA, CISSP, CEH or CCNA are an added advantage.
  • Minimum of 3–4 years’ relevant experience in IT risk, IT audit, information security or IT operations, of which at least 1-2 years should be in a bank or financial institution, including supervisory experience.
  • Sound knowledge of IT risk and control frameworks and best practices.
  • Working knowledge of core banking systems, networks, databases, cloud services, and digital and mobile banking channels.
  • Knowledge and understanding of Bank of Uganda ICT and cyber risk requirements, the Data Protection and Privacy Act, 2019 of Uganda, the National Payment Systems Act, 2020 and other relevant legal and regulatory requirements.
  • Experience in performing risk, business impact, control and vulnerability assessments, and in defining risk treatment strategies.
  • Ability to understand and assess technology systems and applications from both a technical and business function perspective, and to explain technical risks clearly to non-technical audiences.
  • Proficiency in Advanced Microsoft Excel (Pivot Tables, Dashboards, Data Analysis); experience with GRC or security monitoring tools is an added advantage.
  • Excellent analytical, problem-solving and report-writing skills, with excellent verbal and written communication and interpersonal skills.
  • High integrity and demonstrated ability to handle confidential information with discretion.

Remuneration

Position carries an attractive salary and benefits package.

Application Procedure

Suitably qualified candidates should address their application to Head, Human Resource, Yako Bank. Email it to hr@yakobank.com as well as photocopies of academic testimonials, and a CV.

The CV should include telephone contacts and email addresses of three referees, one of who should be the most recent employer.

Application Deadline: 10th October 2026

Only shortlisted candidates will be contacted.

Share this to:
LinkedIn
Facebook
WhatsApp
X