Data Protection Officer
NITA - U
About this role
To support the implementation, enforcement, and continuous improvement of information security, Cyber Security, and data protection programmes within the Personal Data Protection
Office (PDPO)
Responsibilities
- Protect PDPO information assets and systems by implementing effective information security controls, managing cyber security risks, responding to incidents and strengthening internal cyber resilience
- • Support regulated entities (data controllers and processors) through technical guidance, compliance assessments, security reviews, audits, inspections, capacity building, advisory services, and awareness programmes aimed at improving personal data protection practices across Uganda
- • Establish and maintain effective information security governance structures that ensure protection of information assets processed by PDPO and promote adoption of recognised security governance practices by regulated entities
- • Support the effective implementation of Uganda’s data protection and privacy framework by ensuring that personal data processed by organisations is protected through appropriate technical, organisational, and administrative safeguards
- • Identify, assess, manage, and reduce cyber security risks affecting personal data and information systems within PDPO and regulated entities.
- • Support PDPO’s regulatory and supervisory mandate by assessing whether organisations processing personal data have implemented appropriate security safeguards
- • Support prevention, detection, investigation, management and reporting of personal data breaches.
- • Identify weaknesses in ICT systems that may compromise personal data confidentiality, integrity, or availability.
Requirements
- Education
- Minimum of Bachelor’s degree in Information Technology, Computer Science, Information Security or a closely related field.
- Master’s degree in Business computing, Software Engineering, Information systems, Information Technology, or Computer Engineering will be added advantage
- Certification in CISA, CISM or CISSP is an added advantage
- Experience
- A Minimum of 5 years of progressive, demonstrable working experience in IT Security, risk management, data auditing, or privacy compliance.
- Hands-on experience in evaluating and mitigating cyber security threats, managing data breaches, and assessing Information Security controls
- Proven experience in translating complex technical systems into actionable regulatory governance, or interfacing directly with regulatory authorities is an added advantage
- Technical Competencies
- Strong working understanding of embedding privacy into IT Product development and system architecture
- Familiarity with cybersecurity incident response workflows, data breach containment and conducting privacy/Security Impact Assessments
- Proven experience in translating complex technical systems into actionable regulatory governance, or interfacing directly with regulatory authorities