Cyber Security & IT Risk Lead
AI summary
Lead cybersecurity and IT risk management at country level, coordinating governance, risk assessments, incident response, vulnerability management, access controls, third-party risk, and compliance. Works closely with technology, audit, compliance, legal, and regional security teams to protect information, systems, and digital services.
- Country-level cybersecurity and IT risk leadership role
- Covers governance, incident response, and third-party risk
- Coordinates with internal audit, compliance, legal, and regional teams
- Includes vulnerability management and access control oversight
AI job guide
Use this guide to check salary signals, requirements, documents, application steps and safety before you apply.
AI salary guide
Not enough public dataNot enough public salary data is available for this exact role. Before applying, prepare to ask about gross pay, benefits, contract length, probation period, transport and any allowances.
Can you qualify for this role?
- UnclearRelated work experienceThe text mentions experience, but the exact level should be confirmed at source.
- RequiredEducation or certification mentioned in the postThe captured text mentions education, a diploma, certificate, or licence.
- PreferredPractical evidence in security, internship, segurancaThe tags and summary point to skills connected with this role.
- RequiredAvailability to work in Not specifiedThe vacancy is associated with this location.
Documents to prepare
- Likely requiredUpdated CV
- Role specificCover letter or short employer message
- OptionalProfessional references
- Role specificAcademic or professional certificates
- VerifyID or passport only after verifying the employer
Application tips for this job
- Place your strongest Cyber Security & IT Risk Lead evidence in the first half of your CV.
- In your cover letter or employer message, connect your experience to BrighterMonday Uganda and the role in Not specified.
- Add concrete examples related to security, internship, seguranca, ideally with measurable outcomes or clear responsibilities.
- Follow the instructions from BrighterMonday Uganda; avoid sending documents to unofficial contacts or copied links.
- Confirm the deadline, interview location and employer contact before sharing personal documents.
- Prepare a polite question about pay, benefits and contract terms for later interview stages.
Source and safety check
- BrighterMonday Uganda
- Original source link available
- Application method is clear
- Deadline not specified
- No major risk signal was detected in the captured text.
Never pay for interviews, shortlisting, medical checks, uniforms, or job placement. Confirm every application at the original source before sharing personal documents. Report suspicious listing.
Interview preparation
- What experience makes you a strong fit for this Cyber Security & IT Risk Lead role in security, internship?
- How have you handled responsibilities similar to those in this job post?
- Are you available to work in Not specified under the listed contract or schedule?
- Prepare examples with clear responsibilities, tools used and measurable outcomes.
- Review the source and research BrighterMonday Uganda before the interview.
Ask what the first priorities will be in the role and how success will be measured.
Similar jobs to consider
Use AI to apply better
After confirming the original source, use Career Assistant to check role fit, tailor your CV and prepare a cover letter or employer message.
Original source description
The Lead, Cybersecurity and IT Risk is responsible for coordinating and strengthening the organization’s cybersecurity, information security, and IT risk management practices at country level. Reporting to the Country Head, Information Technology, the role helps protect business information, technology assets, digital services, and critical operations by identifying cyber and technology risks, implementing proportionate controls, supporting incident response, and monitoring compliance with organizational policies and applicable regulatory obligations.
The role combines hands-on cybersecurity knowledge with risk management, governance, stakeholder engagement, and oversight responsibilities. The successful candidate works closely with technology teams, business functions, internal audit, compliance, legal, enterprise risk, external service providers, and regional or global security teams to ensure that cybersecurity risks are understood, owned, treated, and reported effectively.
Key
Responsibilities
Cybersecurity governance and planning:
Support the development and implementation of the country’s cybersecurity and IT risk roadmap in alignment with business priorities and enterprise standards. Maintain local cybersecurity policies, standards, procedures, control requirements, and exception processes, and provide practical guidance on their application.
IT and cyber risk management:
Lead or coordinate cybersecurity and IT risk assessments across applications, infrastructure, projects, business processes, cloud services, and third parties. Maintain the IT risk register, document risk scenarios and control gaps, agree treatment plans with accountable owners, and monitor remediation through closure. Escalate overdue or material risks to the Country Head, Information Technology.
Security operations oversight:
Monitor the effectiveness of preventive and detective security controls, including endpoint protection, email security, network security, identity controls, security logging, data protection, and threat monitoring. Coordinate with internal teams and service providers to investigate security alerts and ensure that identified weaknesses receive timely attention.
Incident preparedness and response:
Coordinate the country-level response to cybersecurity incidents in accordance with approved incident response and crisis management procedures. Support triage, containment, investigation, evidence preservation, stakeholder communication, recovery, root-cause analysis, and post-incident improvement tracking. Participate in incident simulations and readiness exercises.
Vulnerability and security testing management:
Coordinate vulnerability scanning, penetration testing, configuration reviews, and remediation tracking for in-scope technology assets. Work with system owners and technical teams to prioritize weaknesses according to risk, validate corrective action, and escalate unresolved critical or high-risk exposures.
Identity and access risk:
Oversee periodic user access reviews and support the effective operation of joiner, mover, and leaver controls, privileged access management, authentication standards, segregation of duties, and access exception management. Help ensure that access is approved, appropriate, traceable, and reviewed regularly.
Third-party and cloud security risk:
Conduct or coordinate cybersecurity due diligence for technology vendors, outsourcing partners, cloud providers, and other relevant third parties. Review security requirements, risk assessments, assurance reports, contractual controls, identified gaps, and remediation commitments throughout the supplier lifecycle.
Secure technology change:
Provide cybersecurity and IT risk input into new systems, technology changes, digital initiatives, procurement decisions, and cloud adoption. Review solution designs and project risks, recommend appropriate controls, and help ensure that security
Requirements
are addressed before implementation or go-live.
Compliance, assurance, and audit support:
Support internal and external audits, control testing, regulatory examinations, certification activities, and management assurance reviews. Coordinate evidence collection, respond to findings, agree corrective actions, and monitor remediation. Track compliance with relevant internal standards, laws, regulations, and contractual obligations.
Awareness and security culture:
Coordinate cybersecurity awareness activities, targeted communications, phishing simulations, and role-based training. Advise employees and managers on secure practices and help embed accountability for cyber and technology risk across the organization.
Metrics and management reporting:
Prepare clear dashboards and reports covering the cyber risk profile, incidents, vulnerabilities, control performance, third-party risk, audit findings, policy exceptions, and remediation status. Present emerging concerns, decisions required, and recommended actions to the Country Head, Information Technology and relevant governance forums.
Leadership and stakeholder coordination:
Provide day-to-day direction to assigned team members, analysts, consultants, or managed security providers. Coordinate cross-functional security activities, promote timely decision-making, and build effective working relationships with business and technology stakeholders
ANTI-MONEY LAUNDERING (AML) EXPECTATION
The incumbent will be responsible for ensuring adherence to, implementation of, and adoption of Compliance, Anti-Money Laundering (AML), and Sanctions-related policies, procedures, and process
within Old Mutual and its subsidiaries. This includes execution of customer due diligence processes, ensuring compliance with Know-Your-Customer (KYC) standards, conducting ongoing and enhanced due diligence, and maintaining data quality. Additionally, the role involves identifying and monitoring potential AML, Sanctions, or Compliance breaches and unusual activities, and escalating these concerns to the Risk and Compliance Office for further action.
Education
- And
- Bachelors Degree (B): Information Technology And Computer Science: Information Technology Management (Required)
- 29 August 2026 , 23:59
- The Old Mutual Story!
- <
- Log In and Apply
- Important safety tips
- Do not make any payment without confirming with the BrighterMonday Customer Support Team.
- If you think this advert is not genuine, please report it via the Report Job link below.
- Report Job
Experience
Bachelors degree in Cybersecurity, Information Security, Computer Science, Computer Engineering, or a related discipline is preferred.
Equivalent professional
and relevant certifications may be considered.
the following areas is expected: cyber risk assessments, security incident management, vulnerability management, identity and access management, security monitoring, cloud security, third-party risk, data protection, audit remediation, or security awareness.
Professional Certification
The candidate should hold at least one relevant cybersecurity, information security, audit, or IT risk certification or be demonstrably progressing toward an appropriate certification. Highly suitable/ desirable certifications include: CISSP, CISM, CEH, or ISO/IEC 27001 Lead Implementer/Lead Auditor among other Cybersecurity related certificates.
Required Skills And Competencies
Risk-based judgment: Evaluates cyber risks and prioritizes actions based on business impact.
Cybersecurity execution: Implements and coordinates security controls, incident response, and risk remediation.
Leadership and ownership: Takes accountability, drives execution, and ensures timely resolution of issues.
Stakeholder management: Builds effective relationships across business, technology, and external partners.
Communication and reporting: Communicates technical and risk issues clearly to diverse audiences.
Analysis and problem-solving: Identifies root causes and delivers practical, risk-based solutions.
Integrity and confidentiality: Maintains high ethical standards and protects sensitive information.
Adaptability and resilience: Responds effectively to change, pressure, and evolving cyber threats.
Skills
Business Intelligence (BI), Cyber Risks, Information Security
Competencies
Action Oriented
Communicates Effectively
Cultivates Innovation
Ensures Accountability
Manages Complexity
Nimble Learning
Optimizes Work Processes
Persuades