We are seeking a suitably qualified and experienced System Control Staff to strengthen our technology control, information security, and IT risk management framework.
The role will focus on monitoring system access, information security, application controls, cybersecurity, change management, data protection, backup and disaster recovery, and other technology-related risks
Key Responsibilities
Review and monitor user access rights, privileged accounts, and segregation-of-duties conflicts
Conduct periodic user-access recertification and ensure timely deactivation of access for exited or inactive employees
Review system configurations, application controls, automated workflows, system interfaces, audit trails, and exception reports
Monitor information-security risks, security incidents, and system vulnerabilities, and recommend appropriate corrective actions
Independently review system changes to ensure proper authorization, testing, approval, and segregation of development, testing, and production environments
Assess controls over customer information, financial data, mortgage documentation, databases, data transmission, and data retention
Review backup arrangements, restoration testing, disaster recovery procedures, and business continuity readiness
Provide independent technical input during User Acceptance Testing (UAT) and review application user interfaces and user experience where required
Provide independent technical assessment of IT-related costs, systems, equipment, and technology proposed for procurement
Track identified IT control exceptions and remediation actions to closure
Prepare periodic System Security/System Control reports for Management, highlighting control weaknesses, risk implications, incidents, and outstanding remediation actions
Person Specifications
B.Sc. or HND in Computer Science, Information Technology, Cybersecurity, or another relevant discipline
Minimum of 5 years of relevant experience, preferably in banking, financial services, IT control, cybersecurity, IT/system audit, or another regulated environment
Strong practical knowledge of IT controls, information security, and cybersecurity risk management
Knowledge of core banking applications and user-access management
Understanding of database and network controls
Knowledge of business continuity and disaster recovery
Experience in IT audit or system audit will be an advantage
Relevant professional certifications such as CISA, CISM, CISSP, CRISC, or ISO 27001-related certifications will be an added advantage
Strong analytical and problem-solving skills, attention to detail, and professional independence
Good report-writing and communication skills
Ability to identify control weaknesses and recommend practical solutions
Ability to work effectively with IT, Internal Control, Risk Management, Compliance, Internal Audit, and other business functions
3-4 years of relevant administrative experience.
Prior experience in banking or financial services.
‎Strong organizational skills, attention to detail, and proficiency in MS Office Suite.
‎Excellent communication skills (written and verbal) and ability to handle confidential information.