Financial Services

Systems Auditor At Digitvant Microfinance Bank

Digitvant Microfinance Bank·Lagos, nigeria·Full Time·Contract
Financial ServicesFull TimeContract
-
  • We are seeking an experienced Systems Auditor to strengthen our Information Security Governance, Risk and Compliance (GRC) and technology assurance capabilities.
  • The successful candidate will provide assurance over the security, resilience, risk management and regulatory compliance of our technology environment. The role combines IT audit, information security governance, cybersecurity, regulatory compliance, technical security reviews and vulnerability assessments.

Key Responsibilities

Information Security Governance, Risk & Compliance

  • Develop, maintain and periodically review the organization's Information Security Governance and GRC framework.
  • Assess compliance with applicable CBN circulars, guidelines, regulatory requirements and information-security standards.
  • Maintain an information security and technology risk register, including risk identification, assessment, treatment, ownership and remediation tracking.
  • Develop and maintain security policies, standards, procedures, control frameworks and control matrices.
  • Conduct periodic reviews of information security controls and assess their design and operating effectiveness.
  • Monitor regulatory changes affecting the organization's technology, cybersecurity, payments and information-security obligations.
  • Prepare regulatory and management reports relating to technology risk, cybersecurity and control effectiveness.
  • Support regulatory examinations, internal audits, external audits and compliance reviews.
  • Track audit and regulatory findings through to effective remediation.

CBN & Financial Services Regulatory Compliance

  • Assess technology and cybersecurity controls against applicable CBN requirements, including the Nigerian Payments System Risk and Information Security Management Framework (NPSR-ISMF) and other applicable CBN payment system regulations and guidelines.
  • Maintain a regulatory obligations register covering relevant CBN requirements and monitor compliance.
  • Evaluate the organization's readiness for CBN supervisory reviews, inspections and information requests.
  • Review controls supporting the security, availability, integrity and resilience of payment services.
  • Assess technology controls supporting electronic payment channels, transaction processing, APIs, integrations and other critical payment infrastructure.
  • Monitor compliance with applicable requirements relating to operational resilience, business continuity, disaster recovery, access control, transaction security, logging and monitoring.
  • Keep abreast of changes to CBN requirements affecting fintechs, Payment Solution Service Providers (PSSPs), switches, processors, payment infrastructure and other applicable license categories.

Data Protection & Privacy Assurance

  • Assess compliance of technology and business processes with the Nigeria Data Protection Act and other applicable NDPC requirements.
  • Review controls for the collection, processing, storage, transmission, retention and disposal of personal and financial data.
  • Conduct or support privacy and data protection control assessments, including reviews of data flows and third party processing arrangements.
  • Assess security safeguards protecting customer and employee personal data.
  • Review data protection risks associated with cloud services, APIs, vendors and other third parties.
  • Support privacy impact/risk assessments for new products, systems and technology initiatives.
  • Work with all teams to identify and remediate data protection control gaps.

IT & Systems Auditing

  • Plan and execute risk based IT and systems audits
  • Evaluate IT General Controls (ITGCs) and application controls.
  • Review access management, privileged access, segregation of duties and authentication mechanisms.
  • Assess system development lifecycle and secure software development practices.
  • Review change management processes and production deployment controls.
  • Evaluate business continuity and disaster recovery capabilities for critical technology services.
  • Prepare detailed audit reports identifying control weaknesses, root causes, risk implications and corrective actions.

Technical Security Reviews & Vulnerability Assessments

  • Conduct technical security assessments of applications, APIs, networks, servers, cloud environments and other technology assets.
  • Perform vulnerability assessments and review vulnerability management processes.
  • Analyze vulnerability scan and security testing results and assess risks based on business impact.
  • Review remediation of identified vulnerabilities and validate closure of critical findings.
  • Conduct security configuration reviews against recognized security benchmarks and industry best practices.
  • Review application security controls, including authentication, authorization, session management, encryption and API security.
  • Assess security controls around critical payment systems and customer facing digital channels.
  • Review penetration testing reports and independently assess the adequacy of remediation.
  • Identify emerging technology and cybersecurity risks and recommend appropriate mitigating controls.

Third Party & Technology Risk

  • Assess cybersecurity and technology risks associated with vendors, service providers, cloud providers and other third parties.
  • Review vendor due diligence and ongoing security assurance processes.
  • Assess contractual security requirements, data protection obligations, service level agreements and incident notification provisions.
  • Review third party audit reports, certifications and security assessments.
  • Monitor remediation of security and control weaknesses identified in third party assessments.

Incident, Resilience & Security Assurance

  • Review the effectiveness of cybersecurity incident response processes.
  • Assess security monitoring, SIEM/logging, alerting and incident escalation controls.
  • Review controls for identifying, containing and recovering from cybersecurity incidents.
  • Participate in post incident reviews and assess root causes and remediation plans.
  • Evaluate technology resilience, business continuity and disaster recovery arrangements.

Reporting & Advisory

  • Prepare concise and actionable audit reports for management and relevant stakeholders.
  • Communicate technical vulnerabilities and cybersecurity risks.
  • Provide risk based recommendations that balance security, regulatory obligations, customer protection and business objectives.
  • Present significant technology and cybersecurity risks to management and relevant stakeholdres.
  • Maintain appropriate audit evidence and documentation to support regulatory and independent reviews.

Requirements

  • Bachelor's degree in Computer Science, Information Technology, or a related discipline.
  • 5 - 7 years experience in IT audit, systems audit, cybersecurity, information security, technology risk or GRC.
  • Experience within fintech, banking, payments, financial services.
  • Demonstrable experience conducting IT audits and control assessments.
  • Practical experience performing or reviewing vulnerability assessments and technical security reviews.
  • Good understanding of networks, operating systems, databases, cloud technologies, APIs and application security.
  • Strong understanding of IT General Controls and application controls.
  • Knowledge of information security risk management and regulatory compliance.
  • Experience interpreting regulatory requirements and translating them into operational controls.
  • Strong analytical and investigative skills.
  • High level of integrity, independence, confidentiality and professional judgment.
  • Possessing CISA/CISM/CRISC/CISSP/CEH/PCI/DSS certification(s) is strongly required.
  • The Ideal candidate must be an ISO 27001 Lead Auditor / Lead Implementer.

Key skills

BA/BSc/HND
Apply Now
Send your CV along with a cover letter tohr@digitvant.com

Please use the job title as the subject line of your email.

At a glance

Company

Digitvant Microfinance Bank

Location

Lagos, nigeria

Employment

Full Time

Work style

Contract

Experience

Valid until

Not specified

Created

September 26, 2026

More opportunities

Similar roles you might like

Auditor, Operational Compliance At Economic Community Of West African States (ecowas)

Economic Community of West African States (ECOWAS)

Abuja, nigeria

full-time

Job Code - 20003782 Institution Office of the Auditor General of Ecowas Institutions Grade - P3/P4 Annual Salary P3/1 - Ua40,696.78 (Usd52,648.78) Directorate - Programme Performance Audit Division - Operational Compliance Line Supervisor - Principal Auditor, Operational Compliance ROLE OVERWIEW Under the supervision of the Principal Auditor, Operational Compliance, the incumbent will be responsible for comprehensive compliance audit assignments across all ECOWAS Institutions, Specialized Agencies and Offices covering all risks relating to the applicable areas of intervention and in line with the OAG Strategic Plan, Audit Charter, and applicable professional auditing standards & guidelines. S/he shall also perform any related official assignment, other duties and special projects as assigned by the OAG leadership. ROLE AND RESPONSIBILITIES Work in a team to carry out compliance audit assignments in designated areas in line with the approved OAG Strategic and Annual Work Plan or as may be directed. Contribute towards the identification and selection of prospective audit areas/topics through area watch, audit/environmental scan, literature review, and other means/criteria adopted for this purpose. Assist in the planning and design of compliance audit assignments by carrying out necessary tasks as assigned to build knowledge, assess risks, and obtain relevant information to effectively design and execute the audit assignment. Assist in the elaboration and implementation of a detailed audit program for the audit team. Execute assigned tasks in a timely and result-oriented manner through practical application of the principles & techniques of performance auditing standards, risk management, research methodology, project management and performance reporting. Apply appropriate audit procedures to research, gather and validate audit information and related data. Identify findings and supporting conclusions based on analysis and develop recommendations that are fair, meaningful, and timely, following appropriate methodology and meeting applicable quality assurance and professional standards. Collect and document sufficient appropriate audit evidence to support conclusions and recommendations. Draft components of the audit report, incorporating where necessary graphic illustrations and visual aids to best communicate audit findings, describe conditions, information/data, and report noteworthy achievements. Contribute towards reasonable and objective recommendations on the systems and procedures being reviewed and monitor management's response and implementation. Maintain proper records of working papers and audit evidence collected for review by a Supervisor and Quality Assurance in line with applicable auditing standards and charter. Ensure the timely completion of the audit assignment by completing all assigned tasks on time. Manage work efficiently and contribute to a competent, committed, and professional team that upholds mutual respect, trust, and synergy. Maintain confidentiality of information gathered, and ensure against inadvertent, premature, and unauthorized communication of audit findings and conclusions. Prepare and maintain a compendium of Directives, Rules, and Regulations applicable to all Community Institutions, Specialized Agencies and Offices. Assist in the monitoring and review of transactions and operations in key business areas (budget, procurements, contracts, recruitments, assets management, etc.) to assess compliance with extant regulations and procedures, and that internal control mechanisms are adequate and functioning as intended. Analyze operational practice, databases & records, periodic reports, and other forms of documentation to identify deficiencies and areas for improvement and coordinate with stakeholders to strategize remediation and/or mitigation methods and timelines for implementation and closure. Document risks and mitigating controls through risk-control matrices, regularly evaluate the design and adequacy of controls to ensure that key risks are properly managed and ensure proper rationalization of controls. Investigate and report violations of processes, procedures, and regulatory standards across the operations of the organization including but not limited to finance with effective action plans in response to discoveries and compliance violations. Make useful input for improvement of audit procedures and programs where necessary, in line with the OAG Charter and applicable auditing standards. Engage in continuous knowledge development regarding sector's rules, regulations, best practices, tools, techniques, and performance standards. Maintain healthy working relationships with managers and staff at all levels. Serve on a variety of teams, committees and task forces as may be needed or assigned. Ensure compliance with all extant regulations and texts (ECOWAS Staff Regulations, OAG Code of Ethics, Management directives, Laws of the host country, etc.) Perform any other task as assigned by the Supervisor. ACADEMIC QUALIFICATIONS AND EXPERIENCE Minimum of a bachelor's degree or equivalent from an accredited university in Finance, Accounting, Auditing, Business Administration, or related field. Relevant professional certification in audit, risk management and information technology such as Certified Internal Auditor (CIA), Certified Public Accountant (CPA), Chartered Accountant (CA), Certified Information Systems Auditor (CISA), etc. from an accredited institution will be an added advantage. 5 years of progressively responsible professional experience in audit, finance, accounting, administration, statistics, or related area. Recent experience (minimum of 2 years) in compliance or internal audit assignments is desirable. Hands on experience in using enterprise risk management tools and applications such as SAP Governance, Risk & Compliance (GRC) and others will be an added advantage. Experience using audit management software (e.g TEAM-MATE, ACL, IDEA, etc.) AGE LIMIT Be below 45 years old. This provision does not apply to internal candidates. ECOWAS KEY COMPETENCIES Knowledge of auditing principles, standards, practices, procedures, and methodologies with an emphasis on compliance audit. Strong knowledge of enterprise risk management framework, governance, financial management and internal controls procedures and best practices. In-depth working knowledge of the procedures, and best practices in the core operational areas of ECOWAS Institutions, Specialized Agencies and Offices. Ability to read and interpret laws, rules, regulations, contractual provisions including regional, national, and state laws, regulations, and operations within the ECOWAS Community. Ability to build knowledge and understanding of the OAG's business and of ECOWAS sectoral areas. Ability to analyze business operations, policies, procedures, and control mechanisms, identify deficiencies and problem areas, and prepare appropriate recommendations for remedial action. Ability to conduct a full range of compliance, operational and program audits of complex systems and structures. Ability to analyze a situation by using indicators to assess the costs, benefits, risks, and chances for success in making decisions. Ability to pull together information from different sources to identify the cause of problems, consequences of alternative causes of action, potential obstacles, and ways to avoid the problem in the future. Ability to break down very complex situations/information into simple terms to explain recommendations and conclusions aimed at solving problems or improving operations/programs/projects. Ability to develop new insights into situations, apply innovative solutions to problems and to design new methods of addressing issues or disconnects where established methods and procedures are inapplicable or no longer effective. Ability to build knowledge of Auditee, research best practices and trends, and benchmark to bring about the best recommendations for the development and improvement of organizational capacity and service delivery. Ability to apply networking and interpersonal skills to seek feedback, information, and data from a network of professionals from multiple countries/sectors/organizations and to identify and prioritize the most critical community requirements. Ability to develop and implement stakeholder management plans, programs, and initiatives to obtain buy-in on new initiatives, to better understand dissenting views, to obtain resources and to increase perceptions of success. Ability to establish and sustain professional credibility with clients/stakeholders in a manner that anticipates their need, mitigates issues and that carefully balances professional obligations with the need to be sensitive and responsive to their needs, Understand the need for change and play an active role in supporting implementation of change initiatives. Demonstrate respect for cultural differences, fairness, and ability to relate well with people from varied backgrounds, nationality, gender, ethnicity, race, and religion, Understanding of diverse cultural views especially within West Africa, with sensitivity to group differences; ability to challenge bias and to practice tolerance and empathy, Ability to listen actively, consider people's concerns and apply judgement, tact, and diplomacy, Ability to work in a diverse and inclusive interactive environment that benefits from diverse strengths, Ability and responsibility for incorporating gender perspectives and ensuring the equal participation of women and men in all areas of work, Ability to encourage, empower, and advocate for people in an unbiased and transparent manner. Ability to articulate thoughts clearly, concisely, and express ideas effectively using oral, written, visual and non-verbal communication skills, as well as listening skills to gain understanding. Ability to understand and manage your emotions to avoid stress and communicate effectively, confidently, respectfully and empathize with others. Ability to listen intently and correctly interpret messages from others and respond appropriately. Ability to make sound use of graphics and tables to effectively present numerical data to write technical reports, presentations, briefings, proposals, and other official documents. etc. Exhibit active listening skills to encourage stronger communication amongst team members and to drive employee engagement in all institutions and agencies. Ability to give constructive feedback, provide recognition, address shortcomings, and motivate direct reports to work at peak performance. Proficiency in Information Communication Technology (ICT). Fluency in oral and written expressions in one of the ECOWAS official languages of the Community (English, French & Portuguese). Knowledge of an additional one will be an added advantage. Ability to develop and implement an individual action plan for achieving specific work goals. Ability to identify, organize and monitor tasks throughout to facilitate execution. Ability to contribute to team tasks or projects as per applicable standards and techniques and collaborate with meet deadlines. Ability to organize work, set priorities, and work within timelines, giving attention to details, stakeholders, indicators, and risks. Ability to identify, collect and assess indicators to monitor performance and to take proactive remedial action as required. Honest, encourages openness and transparency; demonstrates highest levels of Integrity. Knowledge of ECOWAS vision, mission, goals, institutions, sectors, programmes, projects, and activities. Understanding of organizational structures, management systems, strategic plans, business processes, operating procedures, and dynamics as to collaborate, participate, lead, and contribute effectively to achieve work assignments and meet performance goals. Knowledge of ECOWAS laws, rules, regulations, policies, culture, and operating environment and appropriately interpret and apply same to work, coach others and collaborate with partners. Knowledge of internal and external factors, development trends, indicators, challenges, and opportunities as it relates to the ECOWAS agenda, programmes, and project

2 days ago

Head, It Audit At Unified Payment Services Limited

Unified Payment Services Limited

Lagos, nigeria

full-time

Job Objectives To provide independent assurance to management on IT General Controls. Ensure best assurance practice in the plan and execution of IS Audit Programs. Ensure enterprise wide compliance of business processes and operations to internal policies, procedures and documentations. Incorporation of standard practices, principles and processes into audit programs and execution. Review of risk related control issues and draft appriopriate remediation plans. Understand the business environment and develop relationships with audit client in providing value added solutions and best practices implementation. Duties & Responsibilities Audit Review of Database Management Systems, Enterprise Network security and Device configuration, Antivirus, Systems Patches and Log Management. Audit Review of Software Development Life Cycle, Project Management Implementation and Change Management Procedures. Audit Review of Data Encryption Processes, Key Management Lifecycle, and Operating Systems, physical and logical security of card holder environment. Audit Review of Active Directory, Operating Systems, Data backup and tape management. Assess systems and general IT controls and provide practical and Value-added remediation plans. Prepare audit reports that summarize the most significant control weaknesses and resulting impact to the organization. Participate in multiple and simultaneous risk Contribute to internal departmental initiatives such as training, departmental development initiatives and other internal projects as requested. Effectively discuss audit issues and develop business focused controls recommendations to strengthen control lapses and weaknesses-based audit while maintaining departmental quality standards. Function as part of a team or work independently when required. Job Requirements Education: University: First Degree(s) in Information Technology, Computer Science, or Related field. Others: Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM), ISO/IEC 27001 Lead Auditor or related professional certifications would be an added advantage. Experience: Minimum of 10 years' experience in IT Auditing or a similar role. Understanding of the key technology and general controls around enterprise Applications and information systems.

a month ago

It Audit Specialist At Unified Payment Services Limited

Unified Payment Services Limited

Lagos, nigeria

full-time

Job Objectives To provide independent assurance to management on IT General Controls. Ensure best assurance practice in the plan and execution of IS Audit Programs. Ensure enterprise wide compliance of business processes and operations to internal policies, procedures and documentations. Incorporation of standard practices, principles and processes into audit programs and execution. Review of risk related control issues and draft appriopriate remediation plans. Understand the business environment and develop relationships with audit client in providing value added solutions and best practices implementation. Duties & Responsibilities Audit Review of Database Management Systems, Enterprise Network security and Device configuration, Antivirus, Systems Patches and Log Management. Audit Review of Software Development Life cycle, Project Management Implementation and Change Management Procedures. Audit Review of Data Encryption Processes, Key Management Lifecycle, and Operating Systems, physical and logical security of card holder environment. Audit Review of Active Directory, Operating Systems, Data backup and tape management. Assess systems and general IT controls and provide practical and Value added remediation plans. Prepare audit reports that summarize the most significant control weaknesses and resulting impact to the organization. Participate in multiple and simultaneous risk Contribute to internal departmental initiatives such as trainings, departmental development initiatives and other internal projects as requested. Effectively discuss audit issues and develop business focused controls recommendations to strengthen control lapses and weaknesses based audit while maintaining departmental quality standards. Function as part of a team or work independently when requires. Requirements University: First Degree(s) in Information Technology, Computer Science, or Related field. Others: Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM), or related professional certifications would be an added advantage. Experience: Minimum of 7years' experience in IT Auditing or a similar role. Understanding of the key technology and general controls around enterprise Applications and information systems.

a month ago

Head, It Audit At Pishon And Brooks Advisory Services

Pishon and Brooks Advisory Services

Lagos, nigeria

full-time

Job Purpose To provide independent assurance to management on IT General Controls. Ensure best assurance practice in the plan and execution of IS Audit Programs. Ensure enterprise wide compliance of business processes and operations to internal policies, procedures and documentations. Incorporation of standard practices, principles and processes into audit programs and execution. Review of risk related control issues and draft appriopriate remediation plans. Understand the business environment and develop relationships with audit client in providing value added solutions and best practices implementation. Duties & Responsibilities Audit Review of Database Management Systems, Enterprise Network security and Device configuration, Antivirus, Systems Patches and Log Management. Audit Review of Software Development Life cycle, Project Management Implementation and Change Management Procedures. Audit Review of Data Encryption Processes, Key Management Lifecycle, and Operating Systems, physical and logical security of card holder environment. Audit Review of Active Directory, Operating Systems, Data backup and tape management. Assess systems and general IT controls and provide practical and Value-added remediation plans. Prepare audit reports that summarize the most significant control weaknesses and resulting impact to the organization. Participate in multiple and simultaneous risk Contribute to internal departmental initiatives such as training, departmental development initiatives and other internal projects as requested. Effectively discuss audit issues and develop business focused controls recommendations to strengthen control lapses and weaknesses-based audit while maintaining departmental quality standards. Function as part of a team or work independently when requires. Requirements Education: University: First Degree(s) in Information Technology, Computer Science, or Related field. Others: Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM), or related professional certifications would be an added advantage. Experience: Minimum of 10 years' experience in IT Auditing or a similar role. Understanding of the key technology and general controls around enterprise Applications and information systems. Candidates must possess the ability to Communicate effectively audit issues and remediation plans. Knowledge: Knowledge of Systems and General IT Controls. Analytical skills to access Operational and Compliance Requirements of Application Systems and infrastructure. Strong Data Analysis and experience with Computer Assisted Auditing Techniques. Skill / Competencies: Ability to multitask and manage competing priorities. Deductive reasoning abilities and eye for details. Interpersonal and Communication skills.

a month ago