IT Risk Officer

Pearl Bank Uganda

Kampala, Uganda Full Time Closes October 2, 2026
Never pay to apply. Pearl Bank Uganda does not charge application fees. Report any request for money.
Job overview

Are you an IT risk or audit professional looking for IT Jobs in Uganda within banking? Pearl Bank Uganda is hiring an IT Risk Officer to provide independent assurance that IT controls are operating as intended, drive Second Line Technology Risk Assurance activities, and ensure effective identification, assessment, and mitigation of Information Technology and Cyber risks. Reporting to the Manager IT Risk, this role requires a Bachelor’s degree in Information Systems Technology, Computer Science, or Engineering, plus at least two years of experience in IT audits, IT risk management, or banking operations. Pearl Bank Uganda is a government-owned Tier 1 commercial bank with 59 branches, 831 staff, and profit after tax of UGX 47.3 billion in 2025. Applications close on Friday, 2nd October 2026 at 5:00 PM.

Overview & Context

Job Overview

  • PositionIT Risk Officer
  • CompanyPearl Bank Uganda
  • LocationKampala, Uganda
  • Job TypeFull-Time
  • CategoryIT Jobs in Uganda
  • IndustryBanking & Financial Services
  • DepartmentRisk
  • Reports ToManager IT Risk
  • Experience2+ Years
  • DeadlineFriday, 2nd October 2026 at 5:00 PM

About Pearl Bank Uganda

Pearl Bank Uganda (formerly PostBank Uganda) is a Tier 1 commercial bank wholly owned by the Government of Uganda through the Ministry of Finance, Planning and Economic Development. The bank’s heritage spans over 28 years, tracing back to the Post Office Savings Department established in 1926, incorporated as PostBank Uganda in 1998, and elevated to Tier 1 commercial bank status in 2021. The rebrand to Pearl Bank was approved by shareholders in June 2024, with the Bank of Uganda granting the new operating licence under the direction of Managing Director Julius Kakeeto.

About The Role

The IT Risk Officer provides independent assurance to management that IT controls across Pearl Bank Uganda’s systems, applications, and infrastructure are operating as intended. Reporting to the Manager IT Risk, you sit in the Second Line of Defence, ensuring that the Business Technology, Digitization, and Innovation units have deployed and are executing all necessary key controls in a manner consistent with the bank’s standards, regulatory requirements, and best practices.

Day to day, you will conduct information system risk assessments for new and existing systems, perform periodic and surprise security assessments of operating systems, databases, firewalls, intrusion detection systems, and web applications, track IT audit findings to closure, maintain the bank’s forward-looking technology risk profile, oversee the Disaster Recovery governance framework, conduct IT project risk assessments, and deliver IT risk awareness training across the bank. You will also support the monthly Management Risk Committee and quarterly Board Risk Committee reporting processes. With only two years of experience required, this is an excellent entry point into IT risk management within a bank that is actively scaling its technology footprint.

Requirements & Skills

Key Responsibilities

IT Risk Assessment and Security Reviews

  • Conduct Information System risk assessments for new and existing systems, applications, and programmes to ensure compliance with the bank’s security policies, regulatory requirements, and adherence to best practices. Identify weaknesses or security exposures and prescribe solutions to mitigate the risks related to those weaknesses and exposures.
  • Perform periodic and surprise security assessments of areas such as operating systems, database management systems, firewalls, intrusion detection systems, and web-based applications.
  • Identify and evaluate business technology risks and the effectiveness of internal controls designed to mitigate those risks. Recommend opportunities for strengthening internal controls and develop appropriate risk treatment plans to address identified gaps.
  • Conduct IT Project Risk Assessments as and when required.

Controls Monitoring and Findings Tracking

  • Liaise and coordinate with respective Risk champions, review IT risk and control self-assessments.
  • Maintain and track for closure all IT findings arising out of Risk, Internal Audit, External Audit, and Bank of Uganda reviews.
  • Monitor and track IT risk events and follow up associated action plans to closure.
  • Work with control owners to ensure control accuracy and remediation of any issues related to control exceptions.
  • Ensure that controls and checks associated with IT Risk Management deployment are in place and are effective.
  • Support in the review of IT Risk Control Self-Assessments (RCSAs) and Key Risk Indicators.

Risk Profile and Governance

  • Maintain a forward-looking technology risk profile of the bank that captures the major risks, ensuring that risks that might impact multiple businesses and/or support functions are captured, and actions initiated to mitigate and control risks leading to a reduction in operational losses.
  • Provide guidance over the general activities and concerns of the bank’s information technology function, including governance, policy, control design, general operational effectiveness, and internal controls.
  • Oversee the Disaster Recovery Governance framework and implementation.
  • Perform annual Quality Assurance Reviews of IT-related policies, processes, and procedure manuals.
  • Provide risk oversight and assurance over the activities of the Business Technology, Digitization, and Innovation Units.

Reporting, Training, and Investigations

  • Provide support in the preparation of monthly ICT risk reports as part of input into the monthly Management Risk Committee meetings and quarterly Board Risk Committee meetings.
  • Conduct IT Risk awareness training and share IT risk control communication across the bank to improve on risk awareness.
  • Ensure that staff are adequately trained in IT Risk Management, policies, and procedures.
  • Support elements of IT-related investigations.
  • Participate in fraud risk management and monitoring.

Qualifications & Requirements

Required Education

  • Bachelor’s degree (BA or BS) in Information Systems Technology, Computer Science, or Engineering, or equivalent experience.

Professional Certifications

  • Possess or be partly qualified in one or more of the following: Certified in Risk and Information Systems Control (CRISC), Certified Information Systems Auditor (CISA), or other related certification.

Work Experience

  • At least two (2) years of experience in IT Audits, IT Risk Management, or Banking Operations.

Skills & Competencies

Technical Skills

  • IT Risk Assessment: Ability to conduct comprehensive information system risk assessments across applications, infrastructure, databases, firewalls, intrusion detection systems, and web-based platforms.
  • IT Controls & Audit: Experience identifying, evaluating, and testing IT internal controls, tracking audit findings to closure, and reviewing Risk Control Self-Assessments (RCSAs) and Key Risk Indicators.
  • Cybersecurity Awareness: Understanding of security assessment methodologies for operating systems, database management systems, network infrastructure, and web applications.
  • Disaster Recovery: Knowledge of Disaster Recovery governance frameworks, including planning, testing, and implementation oversight.
  • Regulatory Knowledge: Familiarity with Bank of Uganda IT risk and cybersecurity guidelines, and the ability to translate regulatory requirements into control assessments and risk treatment plans.
  • Reporting: Ability to prepare clear ICT risk reports, dashboards, and committee papers for the Management Risk Committee and Board Risk Committee.

Soft Skills

  • Analytical Thinking: Strong ability to identify technology risk patterns, evaluate control effectiveness, and develop forward-looking risk profiles across multiple business and support functions.
  • Stakeholder Coordination: Skill in liaising with Risk champions, control owners, Internal Audit, External Audit, and the Business Technology, Digitization, and Innovation units.
  • Communication & Training: Ability to deliver IT risk awareness training, share risk control communications, and present findings clearly to technical and non-technical audiences.
  • Attention to Detail: Precision in tracking findings, monitoring risk events, and ensuring control accuracy across a bank with 59 branches and 13,000+ agents.
  • Integrity & Independence: High ethical standards aligned with Pearl Bank’s values of passion, teamwork, integrity, and innovation, with the ability to maintain second-line independence.

Benefits & Application

Benefits

Pearl Bank Uganda offers a competitive compensation package for this IT risk role. As a government-owned Tier 1 commercial bank with UGX 47.3 billion in profit after tax (2025) and UGX 1.42 trillion in customer deposits, Pearl Bank provides the stability of a national institution with the pace of a digitally transforming bank. Staff benefits include health insurance, wellness support, continuous training, and internal career advancement. The bank supports professional certification pathways (CRISC, CISA), making this an ideal environment to build your IT risk credentials while gaining real-world banking experience.

Why Apply

  • Enter IT risk management at a Tier 1 commercial bank with only two years of experience required, gaining exposure to enterprise-level technology risk, cybersecurity, and regulatory compliance from day one.
  • Work across Pearl Bank’s entire technology landscape: core banking, Wendi mobile wallet (1M+ users), agent banking (13,000+ agents), digital account opening, and new Innovation & Digitization systems, giving you breadth that smaller institutions cannot offer.
  • Contribute directly to Management Risk Committee and Board Risk Committee reporting, building visibility and credibility with senior management and the Board early in your career.
  • Oversee the Disaster Recovery governance framework and conduct IT project risk assessments, gaining experience in two of the most valued specialisations within IT risk management.
  • Build your professional credentials: Pearl Bank values CRISC and CISA certifications, and the role provides the hands-on experience needed to complete those qualification pathways.
  • Join a bank in active transformation mode: profit up 34%, deposits up 43%, and a modern technology stack being deployed, meaning the risk landscape is dynamic and your skills will develop rapidly.
  • Government-backed stability with a clear five-year strategy, UGX 62 billion AFD partnership, and Bank of Uganda oversight, ensuring the role is both funded and strategically important.

How To Apply

Interested candidates should send their application online to the Chief People & Strategy Officer, Pearl Bank Uganda at hr@pearlbank.com with the job title “IT Risk Officer” as the email subject line. Your application must include a cover letter, detailed CV, and copies of academic documents, all submitted as one file.

The closing date is Friday, 2nd October 2026 at 5:00 PM. Only shortlisted candidates will be contacted. Pearl Bank Uganda Ltd is an equal opportunity employer. NextRoleHub never charges for job applications. If anyone asks for payment, report them immediately.

Application Tips

  • Lead with your IT audit or IT risk management experience: Pearl Bank requires at least two years in IT audits, IT risk management, or banking operations. Describe the systems you have assessed, the findings you tracked, and the controls you evaluated.
  • If you hold or are pursuing CRISC, CISA, or a related certification, highlight it prominently. The advert specifically values these, and even partial qualification demonstrates commitment to the IT risk profession.
  • Show your security assessment experience: mention specific areas you have assessed (operating systems, databases, firewalls, intrusion detection systems, web applications) and the methodologies or frameworks you followed.
  • Demonstrate your reporting skills: this role feeds into the Management Risk Committee and Board Risk Committee. If you have prepared risk reports, dashboards, or committee papers, describe their scope and audience.
  • Mention Disaster Recovery experience if you have it: the role oversees the DR governance framework, so any involvement in DR planning, testing, or governance will strengthen your application.
  • Submit everything as one file (cover letter + CV + academic docs). Use the exact job title “IT Risk Officer” as your email subject line to ensure correct routing.
Closes in 2 days 18 hours 17 mins 15 secs Applications close October 2, 2026 at 5:00 am

Apply on the Pearl Bank Uganda portal

CV and cover letter required

Apply Now at Pearl Bank Uganda →

Free to apply, always

Get jobs on WhatsApp

Every new role sent to your phone the moment it is published. No data-heavy app required.

IT Risk Officer 2 days left
Apply