Hiring.Camp

Cyber Security & IT Risk Lead

Oldmutual

·

Today

Location
KAMPALA, Uganda
Type
Full-time
Department
Security
Seniority
Lead
Education
Bachelor
Closing date
Today
Source
Workday

Description

Lets Write Africa's Story Together!

Old Mutual is a firm believer in the African opportunity and our diverse talent reflects this.

Job Description

The Lead, Cybersecurity and IT Risk is responsible for coordinating and strengthening the organization’s cybersecurity, information security, and IT risk management practices at country level. Reporting to the Country Head, Information Technology, the role helps protect business information, technology assets, digital services, and critical operations by identifying cyber and technology risks, implementing proportionate controls, supporting incident response, and monitoring compliance with organizational policies and applicable regulatory obligations.

The role combines hands-on cybersecurity knowledge with risk management, governance, stakeholder engagement, and oversight responsibilities. The successful candidate works closely with technology teams, business functions, internal audit, compliance, legal, enterprise risk, external service providers, and regional or global security teams to ensure that cybersecurity risks are understood, owned, treated, and reported effectively.

Key Responsibilities

Cybersecurity governance and planning: Support the development and implementation of the country’s cybersecurity and IT risk roadmap in alignment with business priorities and enterprise standards. Maintain local cybersecurity policies, standards, procedures, control requirements, and exception processes, and provide practical guidance on their application.

IT and cyber risk management: Lead or coordinate cybersecurity and IT risk assessments across applications, infrastructure, projects, business processes, cloud services, and third parties. Maintain the IT risk register, document risk scenarios and control gaps, agree treatment plans with accountable owners, and monitor remediation through closure. Escalate overdue or material risks to the Country Head, Information Technology.

Security operations oversight: Monitor the effectiveness of preventive and detective security controls, including endpoint protection, email security, network security, identity controls, security logging, data protection, and threat monitoring. Coordinate with internal teams and service providers to investigate security alerts and ensure that identified weaknesses receive timely attention.

Incident preparedness and response: Coordinate the country-level response to cybersecurity incidents in accordance with approved incident response and crisis management procedures. Support triage, containment, investigation, evidence preservation, stakeholder communication, recovery, root-cause analysis, and post-incident improvement tracking. Participate in incident simulations and readiness exercises.

Vulnerability and security testing management: Coordinate vulnerability scanning, penetration testing, configuration reviews, and remediation tracking for in-scope technology assets. Work with system owners and technical teams to prioritize weaknesses according to risk, validate corrective action, and escalate unresolved critical or high-risk exposures.

Identity and access risk: Oversee periodic user access reviews and support the effective operation of joiner, mover, and leaver controls, privileged access management, authentication standards, segregation of duties, and access exception management. Help ensure that access is approved, appropriate, traceable, and reviewed regularly.

Third-party and cloud security risk: Conduct or coordinate cybersecurity due diligence for technology vendors, outsourcing partners, cloud providers, and other relevant third parties. Review security requirements, risk assessments, assurance reports, contractual controls, identified gaps, and remediation commitments throughout the supplier lifecycle.

Secure technology change: Provide cybersecurity and IT risk input into new systems, technology changes, digital initiatives, procurement decisions, and cloud adoption. Review solution designs and project risks, recommend appropriate controls, and help ensure that security requirements are addressed before implementation or go-live.

Compliance, assurance, and audit support: Support internal and external audits, control testing, regulatory examinations, certification activities, and management assurance reviews. Coordinate evidence collection, respond to findings, agree corrective actions, and monitor remediation. Track compliance with relevant internal standards, laws, regulations, and contractual obligations.

Awareness and security culture: Coordinate cybersecurity awareness activities, targeted communications, phishing simulations, and role-based training. Advise employees and managers on secure practices and help embed accountability for cyber and technology risk across the organization.

Metrics and management reporting: Prepare clear dashboards and reports covering the cyber risk profile, incidents, vulnerabilities, control performance, third-party risk, audit findings, policy exceptions, and remediation status. Present emerging concerns, decisions required, and recommended actions to the Country Head, Information Technology and relevant governance forums.

Leadership and stakeholder coordination: Provide day-to-day direction to assigned team members, analysts, consultants, or managed security providers. Coordinate cross-functional security activities, promote timely decision-making, and build effective working relationships with business and technology stakeholders

ANTI-MONEY LAUNDERING (AML) EXPECTATION

The incumbent will be responsible for ensuring adherence to, implementation of, and adoption of Compliance, Anti-Money Laundering (AML), and Sanctions-related policies, procedures, and process requirements within Old Mutual and its subsidiaries. This includes execution of customer due diligence processes, ensuring compliance with Know-Your-Customer (KYC) standards, conducting ongoing and enhanced due diligence, and maintaining data quality. Additionally, the role involves identifying and monitoring potential AML, Sanctions, or Compliance breaches and unusual activities, and escalating these concerns to the Risk and Compliance Office for further action.

Education and Experience

  • Bachelors degree in Cybersecurity, Information Security, Computer Science, Computer Engineering, or a related discipline is preferred.
  • Equivalent professional experience and relevant certifications may be considered.
  • Experience the following areas is expected: cyber risk assessments, security incident management, vulnerability management, identity and access management, security monitoring, cloud security, third-party risk, data protection, audit remediation, or security awareness.

Professional Certification

The candidate should hold at least one relevant cybersecurity, information security, audit, or IT risk certification or be demonstrably progressing toward an appropriate certification. Highly suitable/ desirable certifications include: CISSP, CISM, CEH, or ISO/IEC 27001 Lead Implementer/Lead Auditor among other Cybersecurity related certificates.

Required Skills and competencies

  • Risk-based judgment: Evaluates cyber risks and prioritizes actions based on business impact.
  • Cybersecurity execution: Implements and coordinates security controls, incident response, and risk remediation.
  • Leadership and ownership: Takes accountability, drives execution, and ensures timely resolution of issues.
  • Stakeholder management: Builds effective relationships across business, technology, and external partners.
  • Communication and reporting: Communicates technical and risk issues clearly to diverse audiences.
  • Analysis and problem-solving: Identifies root causes and delivers practical, risk-based solutions.
  • Integrity and confidentiality: Maintains high ethical standards and protects sensitive information.
  • Adaptability and resilience: Responds effectively to change, pressure, and evolving cyber threats.

 

Skills

Business Intelligence (BI), Cyber Risks, Information Security

Competencies

Action Oriented

Communicates Effectively

Cultivates Innovation

Ensures Accountability

Manages Complexity

Nimble Learning

Optimizes Work Processes

Persuades

Education

Bachelors Degree (B): Information Technology And Computer Science: Information Technology Management (Required)

Closing Date

29 August 2026 , 23:59

The Old Mutual Story!

Skills

CybersecurityPenetration TestingAMLKYCRisk ManagementComplianceProcurementCISSP

Similar Jobs

30

Cyber Security

Caci · 0K6 NORFOLK VA (NORFOLK NAVAL BASE), United States of America · Onsite

1 month ago

Cyber Security

Btree Systems

1+ year ago

Cyber Security

Btree Systems · Remote

1+ year ago

Cyber Security

Comtech LLC · Washington, DC, United States

1+ year ago

Cyber Security Sales Specialist

Thales · MUMBAI, India · Remote

Today

Cyber Security Expert

Werken bij Stedin · Rotterdam, Blaak 8 (Kantoor functie), Netherlands

Today

Associate Manager, Cyber Security Operations

Scj · USA - Howe Street, United States of America

Today

Technical Business Analyst - Cyber Security Transformation (London)

Rbc · 10 FENCHURCH AVENUE:LONDON, United Kingdom

Today

Cyber Security Consultant

KBR Careers · AUS, Melbourne, Level 18, 180 Lonsdale St, Victoria, Australia +3 · Hybrid

Today

Engineer 3 - Cyber Security Engineering

Comcast · India - Chennai, Comcast India Engineering Cent

Today

Engineer 3 - Cyber Security

Comcast · India - Chennai, Comcast India Engineering Cent

Today

Engineer 2 - Cyber Security Engineering

Comcast · India - Chennai, Comcast India Engineering Cent

Today

Engineer 4 - Cyber Security

Comcast · India - Chennai, Comcast India Engineering Cent

Today

Engineer 2 - Cyber Security Engineering

Comcast · India - Chennai, Comcast India Engineering Cent

Today

Cyber Security Architect

Bunnings · Support Office WA, Australia +1

Today

Cyber Security Consulting Manager – Products Security Industries

Accenture · Amsterdam, Gustav Mahlerplein 90, Netherlands

Today

16267 Senior Cyber Security Specialist

Distro · Duluth, Georgia · Onsite

Yesterday

IT Manager - Cyber Security | Onsite: Hagerstown, Maryland

Meritus Health · Hagerstown, MD

Yesterday

Cyber Security Engineer (R-00206)

True Zero Technologies · 100% Remote · Remote

Yesterday

(Senior) Consultant Cyber Security (m/w/d)

Devoteam · Gera, TH, Germany · Hybrid

Yesterday

(Senior) Consultant Cyber Security (m/w/d)

Devoteam · Lübeck, SH, Germany · Hybrid

Yesterday

(Senior) Consultant Cyber Security (m/w/d)

Devoteam · Hamburg, HH, Germany · Hybrid

Yesterday

(Senior) Consultant Cyber Security (m/w/d)

Devoteam · Bremen, HB, Germany · Hybrid

Yesterday

(Senior) Consultant Cyber Security (m/w/d)

Devoteam · Köln, NRW, Germany · Hybrid

Yesterday

(Senior) Consultant Cyber Security (m/w/d)

Devoteam · München, BY, Germany · Hybrid

Yesterday

(Senior) Consultant Cyber Security (m/w/d)

Devoteam · Frankfurt am Main, HE, Germany · Hybrid

Yesterday

Cyber Security Analyst II

Smiths Group · Edgewood, MD, United States

Yesterday

Sales Executive - Cyber Security

Radius · Crewe, England, United Kingdom · Remote, Onsite

Yesterday

Cyber Security Analyst

Sigma Software · Warsaw, Masovian Voivodeship, Poland · Remote

Yesterday

Experienced Cyber Security Business Developer

Devoteam · Machelen, Vlaanderen, Belgium · Hybrid

Yesterday