IT Risk Officer

Yako Bank (U) Limited

Kampala, Uganda Closes November 10, 2026
Never pay to apply. Yako Bank (U) Limited does not charge application fees. Report any request for money.
Job overview

Yako Bank (U) Limited, a Tier II credit institution licensed by the Bank of Uganda, is hiring an IT Risk Officer at its Kampala head office. The role gives independent oversight of the bank’s ICT environment: identifying and reporting IT, cybersecurity, and information security risks, testing IT controls, and overseeing incident, business continuity, and third-party risk. The IT Risk Officer reports to the Risk Manager. Candidates need a Bachelor’s degree in IT, Computer Science, Information Systems, or a related field, plus 3 to 4 years of experience in IT risk, IT audit, information security, or IT operations, with at least 1 to 2 years in a bank or financial institution. This is a solid opening among IT jobs in Uganda’s banking sector. Apply by Saturday, 10 October 2026. Browse more Banking Jobs in Uganda on NextRoleHub.

Overview & Context

Job Overview

  • PositionIT Risk Officer
  • CompanyYako Bank (U) Limited
  • LocationKampala, Uganda
  • Job TypeFull-Time
  • CategoryBanking Jobs in Uganda
  • IndustryBanking & Financial Services
  • Reports ToRisk Manager
  • DeadlineSaturday, 10 October 2026

About The Company

Yako Bank (U) Limited is a Tier II credit institution regulated by the Bank of Uganda. The company was incorporated in 2010 and started operating in September 2015 as Yako Microfinance (U) Limited, a deposit-taking microfinance institution. After building a track record as an MDI, it was upgraded by the Bank of Uganda to a Tier II credit institution licence in 2020 and became Yako Bank. Its founders, Mrs. Vandana Dhariwal and Mr. Rajnish Jain, set out to scale a microfinance business into a bank focused on impactful financing.

About The Role

The IT Risk Officer is the bank’s second line of defence for technology. You will identify, assess, monitor, and report IT, cyber, and information security risks across systems, processes, projects, and branches, and keep the IT risk register current. That includes running IT Risk and Control Self-Assessments, assessing new systems, products, digital channels, and major IT changes before they go live, and testing key controls such as access management, change management, backups, patching, and segregation of duties, including user access reviews on the core banking system.

The role also tracks the bank’s cybersecurity posture through vulnerability and penetration test results, makes sure incidents are logged, escalated, and reported within regulatory timelines, and leads root-cause analysis for significant incidents. You will review Business Continuity and Disaster Recovery plans, take part in DR tests, assess IT vendor and cloud risks, and keep the bank compliant with Bank of Uganda ICT and cyber requirements, the Data Protection and Privacy Act 2019, and the National Payment Systems Act 2020. You will also supervise junior risk staff and interns and support IT risk awareness training.

Requirements & Skills

Key Responsibilities

  • Identify, assess, document, and monitor Information Technology (IT), cyber, and information security risks across the bank’s systems, processes, projects, and branches, and maintain an up-to-date IT risk register.
  • Conduct IT Risk and Control Self-Assessments (RCSAs) and carry out risk assessments of new systems, products, digital channels, and major IT changes before they are introduced into the ICT environment.
  • Test the design and operating effectiveness of key IT controls, including access management, change management, backups, patching, and segregation of duties, and carry out periodic user access reviews on the core banking and other critical systems.
  • Monitor the bank’s cybersecurity posture, including vulnerability assessment and penetration test results, and track remediation of identified weaknesses to closure.
  • Ensure that IT and cyber incidents are logged, assessed, escalated, and reported in line with the bank’s Incident Management Policy and regulatory timelines, and lead root-cause analysis of significant incidents.
  • Review the bank’s Business Continuity and Disaster Recovery plans, participate in Disaster Recovery tests, and report on results, gaps, and recovery objectives for critical systems.
  • Assess and monitor risks from IT vendors, cloud, and outsourced service providers before onboarding and periodically after, including enforcement of service-level agreements.
  • Ensure compliance with Bank of Uganda ICT and cyber risk requirements, the Data Protection and Privacy Act, 2019, the National Payment Systems Act, 2020, and the bank’s internal IT policies.
  • Coordinate responses to IT-related internal audit, external audit, and regulatory findings, and work with ICT staff to close them on time.
  • Prepare and present IT risk reports to management and stakeholders.
  • Supervise, guide, and review the work of junior risk staff and interns assigned to IT risk, review IT risk policies and procedures annually, and support IT risk awareness training for staff.

Qualifications & Requirements

Required Education

  • Bachelor’s degree in Information Technology, Computer Science, Information Systems, or another relevant degree from a recognised university.
  • Professional certification in IT risk, audit, or security, such as CISA, CISSP, CEH, or CCNA, is an added advantage.

Work Experience

  • Minimum of 3 to 4 years’ relevant experience in IT risk, IT audit, information security, or IT operations.
  • At least 1 to 2 years of that experience in a bank or financial institution, including supervisory experience.
  • Experience performing risk, business impact, control, and vulnerability assessments, and defining risk treatment strategies.

Additional Requirements

  • Sound knowledge of IT risk and control frameworks and best practices.
  • Working knowledge of core banking systems, networks, databases, cloud services, and digital and mobile banking channels.
  • Knowledge of Bank of Uganda ICT and cyber risk requirements, the Data Protection and Privacy Act, 2019, the National Payment Systems Act, 2020, and other relevant legal and regulatory requirements.
  • Proficiency in advanced Microsoft Excel (pivot tables, dashboards, data analysis); experience with GRC or security monitoring tools is an added advantage.
  • High integrity and a demonstrated ability to handle confidential information with discretion.

Skills & Competencies

Technical Skills

  • IT Control Testing: Able to test design and operating effectiveness of access, change, backup, patching, and segregation-of-duties controls.
  • Cybersecurity Monitoring: Can read vulnerability scan and penetration test results and drive remediation to closure.
  • Incident & BCP/DR Management: Experience with incident escalation, root-cause analysis, and disaster recovery testing for critical systems.
  • Third-Party Risk: Able to assess vendor, cloud, and outsourcing risk and monitor SLAs.
  • Regulatory Compliance: Working knowledge of Bank of Uganda ICT and cyber requirements, the Data Protection and Privacy Act 2019, and the National Payment Systems Act 2020.
  • Data & Reporting: Advanced Excel for dashboards and risk analysis, with GRC or security tooling a plus.

Soft Skills

  • Clear Communication: Explains technical risks plainly to non-technical managers and staff.
  • Report Writing: Produces concise, accurate risk reports for management and stakeholders.
  • Analytical Thinking: Breaks down complex systems from both a technical and business angle.
  • Supervision: Guides and reviews the work of junior risk staff and interns.
  • Integrity & Discretion: Handles sensitive information and findings with confidentiality.
  • Influence: Works with ICT teams to close audit and regulatory findings on time.
Benefits & Application

Benefits

Yako Bank says the position carries an attractive salary and benefits package. Exact figures are not given. Beyond pay, the role offers broad, hands-on exposure: in a growing Tier II bank, the IT Risk Officer works across the core banking system, digital channels, vendors, branches, and senior management, which builds well-rounded technology risk experience quickly.

Why Apply

  • Own IT, cyber, and information security risk oversight for a Bank of Uganda regulated institution.
  • Cover the full technology risk scope: controls testing, cyber posture, incidents, BCP/DR, and third-party risk.
  • Gain direct experience with Bank of Uganda ICT and cyber requirements, the Data Protection and Privacy Act, and the National Payment Systems Act.
  • Get supervisory experience leading junior risk staff and interns.
  • Assess new digital channels and products before launch, shaping how the bank grows safely.
  • Work in a compact bank where your reports reach management directly.
  • Earn an attractive salary and benefits package.

How To Apply

Address your application letter to the Head, Human Resource, Yako Bank, and email it to hr@yakobank.com together with photocopies of your academic testimonials and your CV. Your CV must include the telephone contacts and email addresses of three referees, one of whom should be your most recent employer. The deadline is Saturday, 10 October 2026. Only shortlisted candidates will be contacted.

Application Tips

  • Address the letter to the Head, Human Resource, and attach your academic testimonials with your CV, as the advert asks for all three.
  • Show your banking or financial institution experience clearly, with dates, since at least 1 to 2 years is required.
  • List the specific controls you have tested, such as user access reviews on a core banking system, change management, or backup testing.
  • Mention CISA, CISSP, CEH, or CCNA if you hold them, or any you are studying for.
  • Reference real work with Bank of Uganda ICT requirements, the Data Protection and Privacy Act 2019, or the National Payment Systems Act 2020.
  • Give an example of explaining a technical risk to non-technical managers, as this is called out in the advert.
  • Include three referees with phone numbers and emails, one being your most recent employer, or your application may be incomplete.
Closes in 38 days 12 hours 28 mins 59 secs Applications close November 10, 2026 at 5:00 am

Apply on the Yako Bank (U) Limited portal

CV and cover letter required

Apply Now at Yako Bank (U) Limited →

Free to apply, always

Get jobs on WhatsApp

Every new role sent to your phone the moment it is published. No data-heavy app required.

IT Risk Officer 38 days left
Apply