Pearl Bank logo

Company

Pearl Bank

Information TechnologyFull-timeFeatured

IT Risk Officer

Kampala
Full-time
Deadline 2026-10-02
Posted Today

Role overview

What you'll be stepping into

The IT Risk Officer will provide independent assurance to management that established controls relating to IT systems are operating as intended, ensuring compliance with applicable regulations, Bank policies, and established procedures.

The role will also support the Risk Department in driving Second Line Technology Risk Assurance activities across the Bank, ensuring that business and support functions have deployed and are executing the necessary key controls in line with the Bank's standards.

The officer will also contribute to an effective Management Risk Committee process for the identification, assessment, mitigation, and monitoring of Information Technology and Cyber risks.

Key Responsibilities and Deliverables

IT Risk Assessment and Assurance

  • Conduct Information Systems risk assessments for new and existing systems, applications, and programmes to ensure compliance with the Bank's security policies, regulatory requirements, and industry best practices.

  • Identify weaknesses and security exposures and recommend appropriate solutions to mitigate associated risks.

  • Conduct periodic and surprise security assessments covering areas such as operating systems, database management systems, firewalls, intrusion detection systems, and web-based applications.

  • Identify and evaluate business technology risks and assess the effectiveness of internal controls designed to mitigate those risks.

  • Recommend opportunities for strengthening internal controls and develop appropriate risk treatment plans to address identified gaps.

IT Governance and Control

  • Provide guidance on the Bank's information technology activities, including governance, policies, control design, operational effectiveness, and internal controls.

  • Liaise and coordinate with relevant Risk Champions and review IT Risk and Control Self-Assessments.

  • Work with control owners to ensure control accuracy and the timely remediation of control exceptions.

  • Ensure that controls and checks associated with IT Risk Management are properly implemented and remain effective.

  • Conduct annual Quality Assurance Reviews of IT-related policies, processes, and procedure manuals.

IT Findings and Risk Events

  • Maintain and track all IT findings arising from Risk, Internal Audit, External Audit, and Bank of Uganda (BoU) reviews through to closure.

  • Monitor and track IT risk events and follow up on associated action plans until completion.

  • Maintain a forward-looking technology risk profile for the Bank, capturing major technology risks and risks that may affect multiple business or support functions.

  • Ensure appropriate actions are initiated to mitigate and control identified risks and contribute to reducing operational losses.

Disaster Recovery and Business Continuity

  • Oversee the Disaster Recovery Governance framework and its implementation.

  • Support the Bank in maintaining effective technology-related disaster recovery controls and governance arrangements.

Risk Assessments and Monitoring

  • Support the review of IT Risk and Control Self-Assessments (RCSAs) and Key Risk Indicators (KRIs).

  • Conduct IT Project Risk Assessments as required.

  • Provide risk oversight and assurance over the activities of the Business Technology, Digitization, and Innovation Units.

  • Support elements of IT-related investigations.

  • Participate in fraud risk management and monitoring.

Risk Reporting and Management Committees

  • Support the preparation of monthly ICT risk reports for submission to the Management Risk Committee.

  • Provide relevant ICT risk information and analysis for quarterly Board Risk Committee meetings.

  • Ensure that technology risks, control weaknesses, risk events, and remediation actions are appropriately monitored and reported.

IT Risk Awareness and Training

  • Ensure staff receive adequate training on IT Risk Management, relevant policies, and procedures.

  • Conduct IT Risk awareness training across the Bank.

  • Share IT risk control communications to strengthen risk awareness and promote effective risk management practices.

Business Behaviours

Passion

Committed to excellence, delivering outstanding results, and making a positive impact on customers and stakeholders.

Teamwork

Collaborates effectively, demonstrates mutual respect, and values diverse perspectives to achieve shared success and deliver greater value to the Bank.

Integrity

Upholds honesty, transparency, and accountability while ensuring ethical practices in every action.

Innovation

Embraces creativity and forward-thinking approaches and continually seeks new solutions to enhance customer experience and drive business growth.

Qualifications, Experience and Competencies

  • Bachelor's degree (BA or BS) in Information Systems Technology, Computer Science, Engineering, or an equivalent qualification.

  • Possession of, or partial qualification in, one or more relevant professional certifications, such as:

    • Certified in Risk and Information Systems Control (CRISC)

    • Certified Information Systems Auditor (CISA)

    • Other relevant IT risk, audit, cybersecurity, or information systems certifications.

  • At least 2 years of experience in IT Audit, IT Risk Management, or Banking Operations.

  • Strong understanding of IT risk management, information systems controls, technology governance, and risk assessment.

  • Ability to identify technology risks, evaluate controls, and recommend appropriate risk mitigation measures.

  • Good understanding of regulatory requirements and information security best practices.

  • Strong analytical, communication, coordination, and reporting skills.

  • Ability to work effectively with control owners, Risk Champions, business units, technology teams, auditors, and other stakeholders.

How to apply

Submit your application online

Apply on external site
Share