Engineering

Security Engineer At Kredete

Kredete·Lagos, nigeria·Full Time·Internship
EngineeringFull TimeInternship
-

About The Role

  • We are seeking a seasoned Security Engineer to safeguard our critical digital assets and infrastructure from evolving cyber threats. In this role, you will be the frontline defender, responsible for implementing robust security measures, proactively hunting for vulnerabilities, and rapidly responding to security incidents to ensure the integrity, confidentiality, and availability of our systems.

What You'll Do

  • Defend & Monitor: Continuously monitor security alerts from our SIEM, EDR, firewalls, and other security systems to detect and investigate malicious activity.
  • Respond & Recover: Lead the response to security incidents, performing containment, eradication, and forensic analysis to identify root cause and prevent recurrence.
  • Identify Weaknesses: Conduct regular vulnerability assessments and penetration tests on our networks, applications, and cloud environments to find security gaps before attackers do.
  • Harden Defenses: Configure, manage, and optimize our security infrastructure, including firewalls, WAF (Web Application Firewall), IDS/IPS, and endpoint protection tools.
  • Automate Security: Develop scripts (e.g., in Python, Bash, or PowerShell) to automate repetitive security tasks and improve our operational efficiency.
  • Enforce Policy: Help implement and enforce IT security policies and controls, ensuring compliance with relevant standards like ISO 27001 or the NDPA.
  • Promote Awareness: Contribute to company-wide security training initiatives to foster a strong culture of security awareness.

Qualifications

  • You hold a Bachelor's degree in Computer Science, Cybersecurity, or a related field.
  • You have 3-5 years of hands-on experience in a cybersecurity role such as Security Engineer, SOC Analyst, or Network Security Administrator.
  • You possess proven, practical experience with:
  • Core security tools: Firewalls (Palo Alto, Fortinet), SIEM (Splunk, Elastic, Sentinel), and EDR (CrowdStrike, SentinelOne).
  • Networking fundamentals: Deep understanding of TCP/IP, DNS, VPNs, and network segmentation.
  • Cloud security: Hands-on experience securing cloud platforms, preferably AWS or Azure.
  • Operating Systems: Strong administration skills for both Windows and Linux environments.
  • You have a strong grasp of common cyber threats, attack vectors, and vulnerability management lifecycles.
  • You are a proactive problem-solver with excellent analytical skills and the ability to remain calm under pressure during incidents.
  • You can communicate complex security concepts clearly to both technical and non-technical colleagues.

Nice To Have

  • Professional cybersecurity certifications such as CEH, CompTIA Security+, CySA+, or CISSP (Associate).
  • Experience with scripting for automation using Python, PowerShell, or Bash.
  • Knowledge of securing containerized environments (Docker, Kubernetes).
  • Experience participating in internal or external security audits.
  • A passion for continuous learning and staying updated with the latest security trends and threats.

Key skills

BA/BSc/HNDProfessional Certificate

At a glance

Company

Kredete

Location

Lagos, nigeria

Employment

Full Time

Experience

Valid until

Not specified

Created

October 1, 2026

More opportunities

Similar roles you might like

Network & Security Engineer At Creastech Limited

Creastech Limited

Lagos, nigeria

full-time

About the Role We are looking for a skilled and proactive Network & Security Engineer to join our team. The successful candidate will be responsible for designing, implementing, maintaining, and securing the company's network infrastructure while ensuring reliable connectivity and protection of IT systems. Key Responsibilities Design, configure, maintain, and troubleshoot LAN/WAN and network infrastructure. Monitor network performance and resolve connectivity and network-related issues. Configure and manage routers, switches, firewalls, access points, and other network devices. Implement and maintain network security controls, including firewalls, VPNs, access controls, and endpoint security measures. Monitor networks for security threats, vulnerabilities, and unusual activities. Perform network and security assessments and recommend improvements. Manage user access, network permissions, and security configurations. Maintain accurate documentation of network infrastructure, configurations, and security procedures. Respond to network outages, security incidents, and other technical issues promptly. Carry out regular system updates, patches, backups, and preventive maintenance. Work with other technical teams to implement and support IT infrastructure projects. Stay updated on emerging networking technologies, cybersecurity threats, and best practices. Requirements Bachelor's Degree / HND in Computer Science, Information Technology, Cybersecurity, or a related field. 2 - 4 years of relevant experience in network administration, network engineering, or cybersecurity. Strong knowledge of networking concepts, including TCP/IP, DNS, DHCP, VLANs, VPNs, routing, and switching. Experience configuring and troubleshooting routers, switches, firewalls, and wireless networks. Knowledge of network security principles and cybersecurity best practices. Experience with network monitoring and troubleshooting tools. Strong problem-solving and analytical skills. Good communication and documentation skills. Ability to work independently and as part of a team. Certifications: Relevant certifications such as CCNA, CCNP, CompTIA Security+, Fortinet, or equivalent certifications will be an advantage.

2 days ago

Application Security Analyst At Hydrogen Payment Services Company Limited

Hydrogen Payment Services Company Limited

Lagos, nigeria

full-time

We are seeking an Application Security Analyst to protect the applications powering our card issuance, card management, and switch/transaction processing platforms. You will embed security across the SDLC, conduct testing and code reviews, support PCI-DSS compliance, and drive remediation efforts. You'll partner with engineering, SOC, and security teams to secure card and switch infrastructure, including third-party and ISO 8583 integrations What you will do Secure Application Testing & Review - Conduct SAST, DAST, SCA, and manual secure code reviews, along with vulnerability assessments and penetration testing (web, API, mobile) across card management, switch, and POS/ATM integration systems. Secure SDLC & CI/CD Integration - Design and embed security checkpoints throughout the development lifecycle and CI/CD pipelines to ensure security is built into application development from the start. PCI-DSS Compliance & Risk Management - Support control validation, evidence collection, and remediation tracking for PCI-DSS compliance, while reviewing third-party and vendor integrations (including ISO 8583 messaging and card network interfaces) for security risk Monitoring & Incident Response - Monitor application-layer security events, collaborate with SOC teams to investigate anomalies in card/switch transaction flows, and participate in incident response for application- level security incidents Reporting & Security Enablement - Document findings and produce risk assessment reports, partner with engineering teams to track remediation to closure, and contribute to secure coding training and awareness sessions for developers. Requirements Bachelor's degree in cyber/information security, computer science, information technology or any related discipline. 3-5 years of relevant experience in application security, penetration testing, or software security engineering, with prior exposure to fintech, banking, card processing, or payment switch environments considered a strong advantage. Certifications: CompTIA Security+ (required or in progress); CEH, OSCP, CSSLP, PCI-DSS, or cloud security certifications (AWS Security Specialty. AZ-500) preferred; progress toward CISSP a plus. Strong analytical communication, and cross-functional collaboration skills; able to translate technical risk into business terms and perform under pressure.

13 days ago

Senior Security Engineer At Credit Direct Limited

Credit Direct Limited

Lagos, nigeria

full-time

Job Summary To design, implement and continuously improve the technical security controls that protect the organization's AWS cloud estate, Kubernetes (EKS) platform, software delivery pipelines and data stores; and to provide expert detection, response and assurance capability that keeps the organization's digital services resilient, auditable and compliant with CBN, PCI DSS, ISO 27001 and NDPR requirements. RESPONSIBILITIES: Cloud and Security Engineering: Design, implement and maintain preventive and detective security controls across all AWS accounts, including AWS Organizations service control policies, AWS Config rules and conformance packs, AWS WAF and AWS Shield. Enforce least privilege through IAM roles, permission boundaries, IAM Identity Center and IAM Access Analyzer; drive the elimination of long-lived access keys in favour of federated and role-based access. Own AWS Secrets Manager end to end secret lifecycle, automatic rotation, resource and cross-account policies and lead the removal of hard-coded credentials from application code, manifests and pipelines. Configure and maintain organization-wide AWS CloudTrail (including data and management events), CloudWatch log groups, metric filters, alarms and retention aligned to regulatory record-keeping requirements. Implement AWS Config baselines with automated drift detection and remediation against CIS AWS Foundations and PCI DSS benchmarks. Manage AWS WAF rule sets, rate limiting, bot control and geo restrictions for internet-facing applications behind CloudFront and ALB, and tune rules to minimise false positives without weakening protection. Operate Amazon GuardDuty, AWS Security Hub, Amazon Inspector and Amazon Detective as a single triage workflow from finding, to enrichment and root-cause investigation, to verified closure. Define and review secure landing zone and VPC network patterns (segmentation, private subnets, VPC endpoints, security groups, managed prefix lists) and assess new architectures against them. Kubernetes & Container Security (Amazon EKS): Harden EKS clusters: private API endpoints, control plane audit logging to CloudWatch, node group hardening, and timely patching of cluster versions and node AMIs. Design, implement and periodically review Kubernetes RBAC, namespace isolation, service accounts and IAM Roles for Service Accounts (IRSA) / EKS Pod Identity. Enforce Pod Security Standards, admission control policy (OPA Gatekeeper or Kyverno) and Kubernetes network policies to restrict east-west traffic. Secure the container supply chain approved base images, ECR and Amazon Inspector image scanning, image signing and admission-time signature verification. Deploy and tune runtime threat detection for containers (GuardDuty EKS Runtime Monitoring, Datadog Cloud Security Management) and investigate detections through to resolution. Secure secret delivery into workloads using the External Secrets Operator or Secrets Store CSI driver backed by AWS Secrets Manager, removing plaintext secrets from manifests and Helm values. Security Monitoring, Detection & Incident Response (Datadog): Build and maintain detection coverage in Datadog Cloud SIEM log pipelines, detection rules, signal correlation, suppression tuning and security dashboards. Operate Datadog Cloud Security Management (misconfiguration, identity and workload risk) and Application Security Management (runtime protection and vulnerability detection) alongside native AWS security services. Configure Datadog Sensitive Data Scanner to detect and redact PII and cardholder data in logs and telemetry. Ensure complete, tamper-evident log coverage across AWS, EKS, applications and databases, with defined retention, archiving and log integrity controls. Lead technical security incident response triage, containment, eradication, recovery and post-incident review and maintain runbooks, escalation paths and tabletop exercises. Define, track and report security metrics and posture trends to management and risk committees. Data & Database Security: Enforce encryption at rest and in transit across RDS, Aurora, DocumentDB, DynamoDB, S3, EBS and EFS using AWS KMS, with defined key policies, rotation and separation of duties. Implement IAM database authentication and Secrets Manager-driven credential rotation; remove shared, static and over-privileged database accounts in favour of least-privilege roles. Enable, centralise and monitor database audit logging (RDS and Aurora audit logs, DocumentDB auditing, SQL Server audit, CloudTrail data events) within the central log platform. Apply data classification, masking or tokenisation and access controls for sensitive and regulated data, and support data loss prevention requirements. Eliminate public database exposure private subnets, restrictive security groups, no public accessibility and validate backup and snapshot encryption, snapshot sharing controls and restore testing. Review database migrations, schema changes and access grants for security impact before approval. Governance, Risk & Compliance: Translate CBN cybersecurity framework, PCI DSS, ISO 27001, NIST CSF and NDPR requirements into enforceable technical controls and repeatable evidence. Maintain security standards, secure configuration baselines and control documentation, and support internal and external audits with automated evidence collection. Conduct security assessments, vulnerability management cycles and configuration reviews; coordinate penetration testing and track remediation to closure. Perform security reviews of third-party vendors, SaaS integrations and exposed APIs Contribute to risk register maintenance, security exception management and management reporting. Collaboration, Enablement & Technical Leadership: Act as senior security advisor to infrastructure, platform, DevOps and application teams during architecture, design and change reviews. Mentor junior security and platform engineers, and raise the standard of security code and configuration review across engineering. Automate recurring security operations using Python, Bash, Terraform and AWS-native tooling to reduce manual effort and human error. Deliver targeted, role-relevant security training for engineering teams covering secure coding, secrets handling and incident escalation. COMPETENCIES REQUIREMENTS: Technical: Deep, hands-on AWS security expertise: IAM, KMS, Secrets Manager, CloudTrail, CloudWatch, AWS Config, WAF and Shield, GuardDuty, Security Hub, Inspector, Detective and VPC network security. Strong Kubernetes and Amazon EKS security skills: RBAC, IRSA, Pod Security Standards, admission controllers (OPA Gatekeeper or Kyverno), network policies, image scanning, image signing and runtime security. Practical experience implementing SCA, SAST, DAST, secret scanning and IaC scanning within GitHub Actions, and enforcing branch protection rules, rulesets and OIDC-based pipeline authentication. Working knowledge of Datadog security capabilities: Cloud SIEM, Cloud Security Management, Application Security Management, Sensitive Data Scanner, log pipelines and dashboards. Database security across RDS, Aurora, DocumentDB, SQL Server and NoSQL stores: encryption and key management, IAM authentication, audit logging, masking and least-privilege access. Infrastructure as code and automation: Terraform, Helm and GitOps workflows, with proficient scripting in Python and Bash. Solid grounding in security frameworks and regulation: CBN cybersecurity guidelines, PCI DSS, ISO 27001, NIST CSF, NDPR and GDPR; threat modelling (STRIDE) and MITRE ATT&CK. Vulnerability management, incident response and digital forensics fundamentals. Behavioural: Strong analytical and problem-solving skills, with sound risk judgement and the ability to prioritise what matters most. Excellent written and verbal communication; able to explain technical risk to non-technical stakeholders and influence engineering teams without direct authority. Ownership mindset detail-oriented, proactive and persistent in identifying and closing control gaps. Pragmatic and collaborative; balances security rigour against delivery velocity. Calm, structured and decisive under incident pressure. Coaching and knowledge-sharing orientation, with a commitment to raising security capability across the organization. Requirements Bachelor's degree in Computer Science, Information Security, Engineering or a related discipline. Professional certification is strongly preferred, for example: AWS Certified Security - Specialty, Certified Kubernetes Security Specialist (CKS), CISSP, CISM, CCSP, OSCP, or GIAC certifications (GCSA, GCIH, GWAPT, GCLD). Minimum of 6 - 8 years' experience in cybersecurity or security engineering, including at least 4 years securing production AWS workloads and at least 2 years securing Kubernetes (preferably Amazon EKS) and CI/CD pipelines. Demonstrable, hands-on experience implementing cloud, container, pipeline and database security controls in a regulated environment; financial services experience is an advantage. Proven track record of leading security incident investigations and remediation in production environments

13 days ago

Security Operations (secops) Engineer At Teknowledge

TeKnowledge

Lagos, nigeria

full-time

Responsibilities: Threat Detection & Incident Response Monitor, investigate, and respond to security alerts generated by SIEM, EDR/XDR, firewalls, email security, and cloud security platforms. Perform security event triage and escalate incidents as required. Support incident response activities including containment, remediation, and recovery. Participate in root cause analysis and post-incident reviews. Maintain incident documentation and response procedures. Security Operations Administer and support security solutions including: Microsoft Sentinel Microsoft Defender XDR Defender for Endpoint Defender for Office 365 Defender for Identity Defender for Cloud Apps Microsoft Purview DLP Microsoft Entra ID Protection Darktrace Email or equivalent email security platforms Support onboarding of log sources and security integrations. Assist with tuning alerts and improving detection capabilities. Network & Perimeter Security Implement and maintain firewall policies and security controls. Support management of Palo Alto firewalls and VPN services, including: Security Policies NAT Policies VPN Gateways Routing Configuration Security Hardening Assist in network segmentation and security reviews. Vulnerability Management Perform vulnerability assessments and coordinate remediation activities. Track remediation progress and validate resolution. Assist with security hardening initiatives. Azure Security Administration Support Azure security services including: Conditional Access Policies Microsoft Defender for Cloud Microsoft Entra ID Azure Arc Virtual Network Gateways Network Security Groups (NSGs) Assist with implementing security best practices in Azure environments. Compliance & Documentation Maintain security documentation, operational procedures, and knowledge articles. Support compliance initiatives including ISO 27001, GDPR, and customer security requirements. Participate in audit preparation and evidence collection activities. Preferred Certifications SC-200 Security Operations Analyst AZ-500 Azure Security Engineer Security+ CySA+ GIAC Certifications

14 days ago

Application Security Engineer At Moniepoint Inc.

Moniepoint Inc.

All, nigeria

full-time

About the role We are seeking a highly skilled and experienced Application Security Specialist to join our dynamic team. The ideal candidate will play a crucial role in safeguarding our organization's digital assets by implementing and maintaining robust security measures for our applications. The Application Security Specialist will be responsible for identifying and mitigating security vulnerabilities, ensuring compliance with industry standards, and contributing to the overall security posture of our applications. What you'll get to do Security Assessment: Conduct thorough security assessments of applications through manual and automated testing. Identify and evaluate vulnerabilities in web and mobile applications. Security Architecture: Collaborate with development teams to integrate security best practices into the application development lifecycle. Design and implement security controls to protect sensitive data and ensure the confidentiality, integrity, and availability of applications. Penetration Testing: Perform penetration testing on applications to simulate real-world cyber-attacks and identify potential weaknesses. Provide detailed reports on findings, including recommended remediation strategies. Incident Response: Act as a key contributor in incident response activities related to application security incidents. Collaborate with cross-functional teams to investigate and resolve security incidents. Compliance: Ensure applications comply with relevant security standards, regulations, and industry best practices. Stay abreast of emerging security threats and industry trends to proactively address potential risks. Training and Awareness: Develop and deliver security training programs for development teams to enhance awareness of secure coding practices. Keep stakeholders informed about the latest security vulnerabilities and mitigation strategies. Security Tools: Manage and configure security tools for continuous monitoring and analysis of application security. Stay current with advancements in security technologies and integrate them into the security framework. To succeed in this role,you should have Bachelor's degree in Computer Science, Information Security, or related field. Proven experience as an Application Security Specialist or in a similar role. In-depth knowledge of application security principles, practices, and common vulnerabilities. Hands-on experience with security testing tools and methodologies. Familiarity with secure coding practices and application security frameworks. Strong understanding of web application architecture and cloud-based environments. Certifications such as OSCP, CEH, LPT, GPEN, CISSP or equivalent are a plus. Advantage if you have; Analytical mindset with strong problem-solving skills. Excellent communication and interpersonal skills. Ability to work collaboratively in a team environment. Detail-oriented with a focus on delivering high-quality results. Strong knowledge of regulatory requirements related to application security. What we can offer you Culture -We put our people first and prioritize the well-being of every team member. We've built a company where all opinions carry weight and where all voices are heard. We value and respect each other and always look out for one another. Above all, we are human. Learning - We have a learning and development-focused environment with an emphasis on knowledge sharing, training, and regular internal technical talks. Compensation - You'll receive an attractive salary, pension, health insurance,, Employee Stock Options, annual bonus, plus other benefits.

14 days ago

Senior Security Operations Engineer At Teknowledge

TeKnowledge

Lagos, nigeria

full-time

At TeKnowledge, your work makes an impact from day one. We partner with organizations to deliver AI-First Expert Technology Services that drive meaningful impact in AI, Customer Experience, and Cybersecurity. We turn complexity into clarity and potential into progressin a place where people lead and tech empowers. You'll be part of a diverse and inclusive team where trust, teamwork, and shared success fuel everything we do. We push boundaries, using advanced technologies to solve complex challenges for clients around the world. Here, your work drives real change, and your ideas help shape the future of technology. We invest in you with top-tier training, mentorship, and career developmentensuring you stay ahead in an ever-evolving world. Why You'll Enjoy It Here: Be Part of Something Big - A growing company where your contributions matter. Make an Immediate Impact - Support groundbreaking technologies with real-world results. Work on Cutting-Edge Tech - AI, cybersecurity, and next-gen digital solutions. Thrive in an Inclusive Team - A culture built on trust, collaboration, and respect. We Care - Integrity, empathy, and purpose guide every decision. We're looking for innovators, problem-solvers, and experts ready to drive change and grow with us. We Are TeKnowledge. Where People Lead and Tech Empowers. Responsibilities: Security Operations Leadership Lead investigations of significant cyber security incidents and breaches. Act as technical escalation point for complex security events. Lead incident response activities including containment, forensics, recovery, and lessons learned. Conduct advanced threat hunting activities across endpoint, cloud, identity, and network environments. Develop and continuously improve security monitoring use cases and detection strategies. Security Engineering & Architecture Design, implement, and maintain enterprise-wide security controls. Lead security reviews for infrastructure, cloud, and application projects. Define and maintain security hardening standards. Drive adoption of Zero Trust security principles. Review and improve security architecture across hybrid environments. Microsoft Security Platforms Own and enhance security services including: Microsoft Sentinel Microsoft Defender XDR Defender for Endpoint Defender for Identity Defender for Office 365 Defender for Cloud Apps Microsoft Defender for Cloud Microsoft Purview Microsoft Entra ID Protection Privileged Identity Management (PIM) Responsibilities include: Creating advanced KQL detections. Designing custom analytics rules. Building SOAR automations using Logic Apps. Integrating new data sources and threat intelligence feeds. Developing playbooks and response automation. Azure Security & Azure Networking (Mandatory) Design, implement, secure, and troubleshoot Azure infrastructure including: Azure Security Microsoft Defender for Cloud Azure Policy Conditional Access Privileged Identity Management Key Vault Entra ID Security Controls Cloud Security Posture Management Azure Networking Virtual Networks (VNets) Hub-and-Spoke Architectures VNet Peering Virtual Network Gateways Azure Firewall Azure Application Gateway / WAF Azure Bastion Private Endpoints Private DNS Route Tables Virtual WAN Network Watcher ExpressRoute Site-to-Site VPN Connectivity The role requires practical hands-on experience designing and securing Azure network architectures within hybrid enterprise environments. Network Security Lead implementation and management of enterprise firewall platforms. Define network segmentation strategies. Support secure remote access solutions. Review routing, VPN, and perimeter security designs. Collaborate with Network Engineering teams on security improvements. Vulnerability & Exposure Management Lead vulnerability management activities. Prioritize remediation based on business risk and threat intelligence. Drive attack surface reduction initiatives. Validate remediation of critical findings. Mentoring & Collaboration Mentor and coach Security Operations Engineers. Provide technical leadership during major incidents. Develop operational standards, procedures, and playbooks. Partner with Infrastructure, Network, Cloud, DevOps, and Compliance teams.

14 days ago