Related Jobs
%20(1).jpg)
Related Jobs
Related Jobs
Share this Job
Information Security Manager job at FINCA Uganda | Apply Now
Are you looking for Information Technology jobs in Uganda 2025 today? then you might be interested in Information Security Manager job at FINCA Uganda
About the Organisation
FINCA Uganda Limited is a dynamic financial institution dedicated to fostering economic empowerment and financial inclusion for underserved communities across Uganda, driven by a mission to create sustainable opportunities and enhance livelihoods through innovative microfinance solutions.
Recognized for its commitment to ethical banking and customer-centric service, the company has evolved from its pioneering beginnings into a modern, technology-driven organization with a strong market presence and widespread impact.
It boasts a vibrant work culture that values diversity, continuous learning, and employee well-being, offering extensive career opportunities and flexible work arrangements designed to nurture both professional and personal growth. Guided by core values such as integrity, accountability, and compassion, FINCA Uganda Limited continuously innovates its business model to blend cutting-edge digital solutions with traditional microfinance, ensuring robust outreach and measurable social impact.
Committed to corporate social responsibility, the institution actively supports community development, educational initiatives, and environmental sustainability programs, thereby reinforcing its reputation as a trusted leader in financial services. For more information, visit [Company Website].
Kampala, Uganda
Full Time
Job Title
Information Security Manager job at FINCA Uganda
FINCA Uganda
Job Description
Job Title: Information Security Manager
Organisation: FINCA Uganda
Duty Station: Kampala, Uganda
Job Summary: The Information Security Manager is responsible overseeing and implementing the institution’s cybersecurity program and enforcing the cyber and technology policy.
Duties, Roles and Responsibilities
Ensuring that the institution maintains a current enterprise-wide knowledge base of its users, devices, applications, software licenses and their relationships, Software and hardware asset inventory including Network maps and Network utilization and performance data.
Ensuring that the information systems align with the institutional needs, ICT strategy in particular information system development strategies and comply with the overall business strategies, risk appetite and ICT risk management policies of the institution while ensuring that application design development, and deployment meet FINCA Uganda’s security standards and providing cybersecurity expertise to all projects.
Designing user-focused cybersecurity controls for all internal and external users, and developing recommendations for security improvements, including documenting the cybersecurity posture of third-party vendors and their services against FINCA Uganda services.
Organizing professional cybersecurity trainings to enhance staff proficiency and ensure regular, comprehensive cyber risk assessments are conducted at least annually.
Maintaining and managing security logs and incident response, collaborating with IT teams to design, test, and monitor effective cybersecurity controls.
Ensuring that adequate processes are in place for monitoring IT systems for timely detection of cyber and technology events and incidents and supporting IT staff in resolving identified cyber incidents with proper response and reporting.
Facilitating the implementation and maintenance of IT security controls, ensuring timely delivery of assigned security tasks and activities.
Reviewing and assessing risks from exceptions/deviations to approved cyber and technology policies and procedures and obtaining senior management approval for risk assessments and ensure residual risks remain at acceptable level.
Reporting to Management and Board Risk Committees on the effectiveness of information systems, approved cybersecurity program, exceptions to the cyber and technology policies and procedures, and significant cyber or technology incidents that affected the institution during the period.
Ensuring timely update of the incident response mechanism and Business Continuity Plan using the latest cyber threat intelligence gathered and applying scenario analysis to assess potential cyber-attack, mitigating actions, and identifying potential control gaps.
Ensuring frequent data backups of critical IT systems are carried out to a separate storage location.
Ensuring the roles and responsibilities of managing cyber risks, including in emergency or crisis decision-making, are clearly defined, documented and communicated to relevant staff.
Coordinating the continuous testing of disaster recovery and Business Continuity Plans arrangements to ensure that the institution can operate and meet its regulatory obligations during cyber incidents
Safeguarding confidentiality, integrity and availability of information.
Leading FINCA Uganda’s data protection and privacy efforts by serving as the primary contact for staff, regulators, and public bodies; collaborating with Compliance function to train and raise awareness among employees; conducting routine compliance audits; advising on projects and privacy impact assessments; ensuring IT systems comply with relevant data protection laws, including data retention and destruction; maintaining records of data assets, processing activities, and security incidents; and promoting a culture of data protection across the organization.
Qualifications, Education and Competencies
Bachelor’s degree in computer science, Cybersecurity, Management Information systems, Business Administration or related field. Master’s degree will be an added advantage
5 years of demonstrated experience in Information Security, Risk Management in a Microfinance or Banking Organization, Financial Technology or Financial services company.
Working knowledge of national and international security regulatory compliances and frameworks such as ISO 27001, NIST, COBIT and PCI DSS; Industry Certifications in CISSP, CISM, SANS GIAC, CBCI; and Security Vendor Certifications e.g Cisco, TrendMicro, Splunk, Qualys is a plus.
Competencies
To perform the job successfully, an individual should demonstrate the following competencies:
Excellent at Analytics and reporting
Security acumen
Good communication and presentation skills
High Integrity/Ethics
Virtual team working and keeping good relationships is paramount
How to Apply
All candidates who so wish to take up this role in the aforementioned capacity are encouraged to send their applications with detailed CVs including present position and copies of relevant professional/academic certificates to: ug_jobs@fincaug.org
Deadline: 9th December 2025
NB: Only shortlisted candidates will be contacted.

.jpg)
.jpeg)

%20Limited.jpg)







