Jobs in Uganda - Officer ICT Security job at Uganda Revenue Authority (URA)

Officer ICT Security Job Post at URA

Location:  Jobs in Uganda 2021


Work Hours: Full-time, 08 hours per day

Salary: UGX

No. of vacancies: 01

Deadline: 15 May 2021

Hiring Organization: Uganda Revenue Authority (URA)

Job Details:

JOB ROLE/ PURPOSE:

Implement and maintain ICT security controls to safeguard the Authority’s Information Technology systems and infrastructure against security risks


PRINCIPLE ACCOUNTABILITIES

1. Participate in the design & building of the URA’s information security architecture in support of the URA’s mission

a)    Engage key stakeholders to elicit security requirements adequate to provide assurance of security

b)   Evaluate the efficacy of existing security controls & provide expert advisory services in this regard

c)    Carry out threat modelling and security reviews for Software Development projects

d)   Assist in developing information security policies, standards & guidelines

e)    Provide input into the development of URA’s IT Security Strategy

 

2. Support & maintain Information security solutions to ensure their continued efficacy

a) Test, deploy, maintain, review and administer the infrastructure hardware and software that are required to effectively manage network defenses.

b) Install, config, troubleshoot and maintain server security configurations to ensure their confidentiality, integrity, and availability.

c) Work with other teams to ensure good security practice is followed during deployments

3. Identify, analyse and mitigate threats to URA’s IT Infrastructure

a) Carry out vulnerability assessments & penetration testing to establish the effectiveness of internal controls

b) Use defensive measures and information collected from a variety of sources to identify, analyze, and report events that occur or might occur within the network to protect information, information systems, and networks from threats.

c) Analyze digital evidence and investigate security incidents to derive useful information in support of system/network vulnerability mitigation and investigations.

d) Keep abreast with emerging industry security threats that could potentially impact URA’s IT Infrastructure & work towards strengthening URA’s security posture

4. Facilitate information security awareness programs

a) Provide input into the security awareness content

b) Conduct security awareness training using various channels

c) Conduct phishing assessments and other testing to ascertain level of awareness among different categories of staff

 

Qualifications

 

PERSON SPECIFICATIONS

Essential Requirements

a) An honors Bachelor’s Degree in IT/Computer Science or related technical science degree from a recognised University.

Desirable Requirements

a) Information Security Certification Such as; CISSP, CSSLP, CEH, Security+, Any GIAC, OSCP, CCSA, CCNA or other Vendor Specific InfoSec Certification .

b)  Penetration testing & vulnerability assessments of network, web, or mobile platforms

b) Installing & Securing Server Infrastructure (Secure Builds, Secure Configuration & Assessment)

 

Knowledge

a) Knowledge of cyber threat actor categories

b) Knowledge of system administration, network, and operating system hardening techniques.

c) Knowledge of cyber-attack stages

d) Knowledge of computer networking concepts and protocols, and network security methodologies.

e) Knowledge of system administration concepts for operating systems such as but not limited to Unix/Linux, IOS, Android, and Windows operating systems.

f) Knowledge of packet-level analysis using appropriate tools (e.g., Wireshark, tcpdump).

g) Knowledge of OSI model and underlying network protocols

h) Knowledge of penetration testing principles, tools, and techniques.

i) Knowledge of Application Security Risks

j) Knowledge of prevalent cyber threats, tactics, techniques and procedures

k) Knowledge of information technology (IT) security principles and methods (e.g., firewalls, demilitarized zones, encryption).

l) Knowledge of how traffic flows across the network

m) Knowledge of basic system, network, and OS hardening techniques.

n) Knowledge of network tools (e.g., ping, traceroute, nslookup)

o) Knowledge of operating system command-line tools.

p) Knowledge of Security Service Management Frameworks & methodologies ( ISO 27001, ITIL4, DevSecOps )

q) Knowledge of concepts and practices of processing digital forensic data.

r) Knowledge of installation, integration, and optimization of system components.

s) Knowledge of Interpreted & compiled computer languages

 

SPECIAL SKILLS AND ATTRIBUTES

a) Skill in applying security controls.

b) Skill in system, network, and OS hardening techniques. (e.g., remove unnecessary services, password policies, network segmentation, enable logging, least privilege, etc.).

c) Skill in performing packet-level analysis.

d) Skill in technical writing.

e) Skill in writing about facts and ideas in a clear, convincing, and organized manner.

f) Ability to prepare and deliver education and awareness briefings to ensure that systems, network, and data users are aware of and adhere to systems security policies and procedures.

g) Ability to answer questions in a clear and concise manner.

h) Ability to ask clarifying questions.

i) Ability to communicate complex information, concepts, or ideas in a confident and well-organized manner through verbal, written, and/or visual means.

j) Ability to communicate effectively when writing.

k) Ability to conduct vulnerability scans and recognize vulnerabilities in security systems.

l) Ability to operate common network tools (e.g., ping, traceroute, nslookup)

m) Ability to execute OS command line (e.g., ipconfig, netstat, dir, powershell)

 
 

Organization

: ICT Security

Primary Location

: Uganda-Nakawa HQs

Job

: 10150.Officer ICT Security

Schedule

: Contractual

Shift

: Standard

Job Type

: Full-time

Job Level

: Day Job

Application procedure

To apply for this job, CLICK HERE

or visit the URA website: https://ura.go.ug and follow the link “Careers>Experiential hiring” to view the detailed job description, select and apply for the job of your choice. 

ONLY online applications will be considered. 

Please Note: 

1. All applicants will receive a “no reply” mail acknowledging receipt of your application from hr-ura@invalidemail.com and in case of any inquires please send an e-mail to recruitment@ura.go.ug or call 0323443642/0323443645 

2. All applicants who had earlier submitted their applications for the advertised jobs do not have to reapply. 

3. Candidates who submit false information will automatically be disqualified. 

“URA is an equal opportunity employer and does not charge money for recruitment”

Date Posted: 2021-04-26

MORE JOBS IN UGANDA HERE

NEVER MISS OUT ON A JOB ALERT, CLICK HERE TO JOIN THE RIYOW JOBS UGANDA WHATSAPP GROUP TODAY


CLICK HERE TO JOIN THE RIYOW JOBS UGANDA TELEGRAM GROUP

Post a Comment

0 Comments