We are seeking an experienced Systems Auditor to strengthen our Information Security Governance, Risk and Compliance (GRC) and technology assurance capabilities.
The successful candidate will provide assurance over the security, resilience, risk management and regulatory compliance of our technology environment. The role combines IT audit, information security governance, cybersecurity, regulatory compliance, technical security reviews and vulnerability assessments.
Key Responsibilities
Information Security Governance, Risk & Compliance
Develop, maintain and periodically review the organization's Information Security Governance and GRC framework.
Assess compliance with applicable CBN circulars, guidelines, regulatory requirements and information-security standards.
Maintain an information security and technology risk register, including risk identification, assessment, treatment, ownership and remediation tracking.
Develop and maintain security policies, standards, procedures, control frameworks and control matrices.
Conduct periodic reviews of information security controls and assess their design and operating effectiveness.
Monitor regulatory changes affecting the organization's technology, cybersecurity, payments and information-security obligations.
Prepare regulatory and management reports relating to technology risk, cybersecurity and control effectiveness.
Support regulatory examinations, internal audits, external audits and compliance reviews.
Track audit and regulatory findings through to effective remediation.
CBN & Financial Services Regulatory Compliance
Assess technology and cybersecurity controls against applicable CBN requirements, including the Nigerian Payments System Risk and Information Security Management Framework (NPSR-ISMF) and other applicable CBN payment system regulations and guidelines.
Maintain a regulatory obligations register covering relevant CBN requirements and monitor compliance.
Evaluate the organization's readiness for CBN supervisory reviews, inspections and information requests.
Review controls supporting the security, availability, integrity and resilience of payment services.
Assess technology controls supporting electronic payment channels, transaction processing, APIs, integrations and other critical payment infrastructure.
Monitor compliance with applicable requirements relating to operational resilience, business continuity, disaster recovery, access control, transaction security, logging and monitoring.
Keep abreast of changes to CBN requirements affecting fintechs, Payment Solution Service Providers (PSSPs), switches, processors, payment infrastructure and other applicable license categories.
Data Protection & Privacy Assurance
Assess compliance of technology and business processes with the Nigeria Data Protection Act and other applicable NDPC requirements.
Review controls for the collection, processing, storage, transmission, retention and disposal of personal and financial data.
Conduct or support privacy and data protection control assessments, including reviews of data flows and third party processing arrangements.
Assess security safeguards protecting customer and employee personal data.
Review data protection risks associated with cloud services, APIs, vendors and other third parties.
Support privacy impact/risk assessments for new products, systems and technology initiatives.
Work with all teams to identify and remediate data protection control gaps.
IT & Systems Auditing
Plan and execute risk based IT and systems audits
Evaluate IT General Controls (ITGCs) and application controls.
Review access management, privileged access, segregation of duties and authentication mechanisms.
Assess system development lifecycle and secure software development practices.
Review change management processes and production deployment controls.
Evaluate business continuity and disaster recovery capabilities for critical technology services.
Prepare detailed audit reports identifying control weaknesses, root causes, risk implications and corrective actions.