Role overview
What you'll be stepping into
The IT Risk Officer will provide independent assurance to management that established controls relating to IT systems are operating as intended, ensuring compliance with applicable regulations, Bank policies, and established procedures.
The role will also support the Risk Department in driving Second Line Technology Risk Assurance activities across the Bank, ensuring that business and support functions have deployed and are executing the necessary key controls in line with the Bank's standards.
The officer will also contribute to an effective Management Risk Committee process for the identification, assessment, mitigation, and monitoring of Information Technology and Cyber risks.
Key Responsibilities and Deliverables
IT Risk Assessment and Assurance
Conduct Information Systems risk assessments for new and existing systems, applications, and programmes to ensure compliance with the Bank's security policies, regulatory requirements, and industry best practices.
Identify weaknesses and security exposures and recommend appropriate solutions to mitigate associated risks.
Conduct periodic and surprise security assessments covering areas such as operating systems, database management systems, firewalls, intrusion detection systems, and web-based applications.
Identify and evaluate business technology risks and assess the effectiveness of internal controls designed to mitigate those risks.
Recommend opportunities for strengthening internal controls and develop appropriate risk treatment plans to address identified gaps.
IT Governance and Control
Provide guidance on the Bank's information technology activities, including governance, policies, control design, operational effectiveness, and internal controls.
Liaise and coordinate with relevant Risk Champions and review IT Risk and Control Self-Assessments.
Work with control owners to ensure control accuracy and the timely remediation of control exceptions.
Ensure that controls and checks associated with IT Risk Management are properly implemented and remain effective.
Conduct annual Quality Assurance Reviews of IT-related policies, processes, and procedure manuals.
IT Findings and Risk Events
Maintain and track all IT findings arising from Risk, Internal Audit, External Audit, and Bank of Uganda (BoU) reviews through to closure.
Monitor and track IT risk events and follow up on associated action plans until completion.
Maintain a forward-looking technology risk profile for the Bank, capturing major technology risks and risks that may affect multiple business or support functions.
Ensure appropriate actions are initiated to mitigate and control identified risks and contribute to reducing operational losses.
Disaster Recovery and Business Continuity
Oversee the Disaster Recovery Governance framework and its implementation.
Support the Bank in maintaining effective technology-related disaster recovery controls and governance arrangements.
Risk Assessments and Monitoring
Support the review of IT Risk and Control Self-Assessments (RCSAs) and Key Risk Indicators (KRIs).
Conduct IT Project Risk Assessments as required.
Provide risk oversight and assurance over the activities of the Business Technology, Digitization, and Innovation Units.
Support elements of IT-related investigations.
Participate in fraud risk management and monitoring.
Risk Reporting and Management Committees
Support the preparation of monthly ICT risk reports for submission to the Management Risk Committee.
Provide relevant ICT risk information and analysis for quarterly Board Risk Committee meetings.
Ensure that technology risks, control weaknesses, risk events, and remediation actions are appropriately monitored and reported.
IT Risk Awareness and Training
Ensure staff receive adequate training on IT Risk Management, relevant policies, and procedures.
Conduct IT Risk awareness training across the Bank.
Share IT risk control communications to strengthen risk awareness and promote effective risk management practices.
Business Behaviours
Passion
Committed to excellence, delivering outstanding results, and making a positive impact on customers and stakeholders.
Teamwork
Collaborates effectively, demonstrates mutual respect, and values diverse perspectives to achieve shared success and deliver greater value to the Bank.
Integrity
Upholds honesty, transparency, and accountability while ensuring ethical practices in every action.
Innovation
Embraces creativity and forward-thinking approaches and continually seeks new solutions to enhance customer experience and drive business growth.
Qualifications, Experience and Competencies
Bachelor's degree (BA or BS) in Information Systems Technology, Computer Science, Engineering, or an equivalent qualification.
Possession of, or partial qualification in, one or more relevant professional certifications, such as:
Certified in Risk and Information Systems Control (CRISC)
Certified Information Systems Auditor (CISA)
Other relevant IT risk, audit, cybersecurity, or information systems certifications.
At least 2 years of experience in IT Audit, IT Risk Management, or Banking Operations.
Strong understanding of IT risk management, information systems controls, technology governance, and risk assessment.
Ability to identify technology risks, evaluate controls, and recommend appropriate risk mitigation measures.
Good understanding of regulatory requirements and information security best practices.
Strong analytical, communication, coordination, and reporting skills.
Ability to work effectively with control owners, Risk Champions, business units, technology teams, auditors, and other stakeholders.
How to apply

