Yako Bank logo

Company

Yako Bank

Information TechnologyFull-timeFeatured

IT Risk Officer

Kampala
Full-time
Deadline 2026-10-10
Posted Today

Role overview

What you'll be stepping into

Yako Bank was incorporated in 2010 and began operations as a deposit-taking microfinance institution, Yako Microfinance Uganda Ltd, in September 2015. In 2020, the institution was upgraded and licensed by the Bank of Uganda as a Tier II Credit Institution under the name Yako Bank Uganda Limited, taking over the financial services business of its predecessor.

Today, Yako Bank is a fully-fledged credit institution serving a growing clientele through branches in Kampala and Jinja. The Bank offers savings accounts, term deposits, collateralised and non-collateralised loans, and basic mobile banking services to SMEs, salaried individuals, micro-entrepreneurs, and smallholder farmers.

The IT Risk Officer will be responsible for identifying, assessing, monitoring, and reporting on IT, cybersecurity, and information security risks across Yako Bank.

The role will provide independent oversight of the Bank's ICT environment, including testing IT controls, monitoring IT incidents, business continuity and third-party risks, and reporting to the Risk Manager.

The position will also support compliance with the Bank's Risk Management Framework, Bank of Uganda requirements, and applicable laws and regulations.

Key Responsibilities

The successful candidate will:

  • Identify, assess, document, and monitor IT, cyber, and information security risks across the Bank's systems, processes, projects, and branches.

  • Maintain an up-to-date IT risk register.

  • Conduct IT Risk and Control Self-Assessments (RCSAs).

  • Assess risks associated with new systems, products, digital channels, and major IT changes before implementation.

  • Test the design and operating effectiveness of key IT controls, including access management, change management, backups, patching, and segregation of duties.

  • Conduct periodic user access reviews for the core banking system and other critical systems.

  • Monitor the Bank's cybersecurity posture, including vulnerability assessment and penetration testing results.

  • Track remediation of identified cybersecurity weaknesses through to closure.

  • Ensure IT and cyber incidents are logged, assessed, escalated, and reported in accordance with the Bank's Incident Management Policy and applicable regulatory timelines.

  • Lead root-cause analysis of significant IT and cybersecurity incidents.

  • Review Business Continuity and Disaster Recovery plans and participate in Disaster Recovery tests.

  • Report on Disaster Recovery test results, identified gaps, and recovery objectives for critical systems.

  • Assess and monitor risks associated with IT vendors, cloud providers, and outsourced service providers before onboarding and periodically thereafter.

  • Monitor compliance with service-level agreements.

  • Ensure compliance with Bank of Uganda ICT and cybersecurity requirements, the Data Protection and Privacy Act, 2019, the National Payment Systems Act, 2020, and the Bank's internal IT policies.

  • Coordinate responses to IT-related internal audit, external audit, and regulatory findings.

  • Work with ICT teams to ensure identified findings are addressed and closed within the required timelines.

  • Prepare and present IT risk reports to management and relevant stakeholders.

  • Supervise, guide, and review the work of junior risk staff and interns assigned to IT risk.

  • Review IT risk policies and procedures annually.

  • Support IT risk awareness and training for staff.

Minimum Educational and Technical Requirements

Applicants should have:

  • A Bachelor's Degree in Information Technology, Computer Science, Information Systems, or another relevant field from a recognised university.

  • Professional certification in IT risk, audit, or security, such as CISA, CISSP, CEH, or CCNA, is an added advantage.

  • At least 3–4 years of relevant experience in IT risk, IT audit, information security, or IT operations.

  • At least 1–2 years of experience in a bank or financial institution, including supervisory experience.

  • Sound knowledge of IT risk and control frameworks and industry best practices.

  • Working knowledge of core banking systems, networks, databases, cloud services, and digital and mobile banking channels.

  • Knowledge of Bank of Uganda ICT and cybersecurity requirements, the Data Protection and Privacy Act, 2019, the National Payment Systems Act, 2020, and other relevant legal and regulatory requirements.

  • Experience conducting risk, business impact, control, and vulnerability assessments and developing appropriate risk treatment strategies.

  • Ability to understand and assess technology systems and applications from both technical and business perspectives.

  • Ability to communicate technical risks clearly to non-technical audiences.

  • Proficiency in Advanced Microsoft Excel, including Pivot Tables, dashboards, and data analysis.

  • Experience with GRC or security monitoring tools is an added advantage.

  • Excellent analytical, problem-solving, report-writing, verbal, written, and interpersonal communication skills.

  • High integrity and the ability to handle confidential information with discretion.

Application Deadline

Saturday, October 10, 2026

Interested and qualified candidates should apply through the official recruitment process provided by Yako Bank Uganda.

For more information about the organisation, visit Yako Bank Uganda.

How to apply

Submit your application online

Apply on external site
Share