Intelligence Match
Match: ??%
Unlock Your Personalized Match
Sign in to see your exact score breakdown and personalized insights.
Team Tagline
About the role
SterlingPRO is a leader in developing innovative fintech solutions that power the future of finance. We are a team of experts passionate about technology and driven by a mission to create seamless, secure, and inclusive financial experiences. We offer a dynamic and challenging environment where your work will have a direct impact on the security of millions of transactions.
Required Skills
Preferred Skills
Similar Skills not Listed
Responsibilities
- Lead security monitoring, threat detection, incident response, and SOC governance activities, ensuring 24/7 coverage for SterlingPRO’s payment applications.
- Develop and optimise SIEM use cases, detection rules, alert management, and security monitoring processes tailored to financial transaction patterns.
- Manage MSSP and SOC providers, ensuring service quality, performance, and compliance with agreed SLAs.
- Develop and maintain incident response procedures and coordinate security exercises and tabletop testing activities, specifically simulating payment fraud and data breach scenarios.
- Support business continuity, disaster recovery planning, testing, and security governance activities to ensure the uninterrupted availability of SterlingPRO’s POS, ATM, and Agency banking solutions.
- Manage identity security controls including MFA, Conditional Access, privileged access management (PAM), and identity risk monitoring to protect administrative access to core financial systems.
- Strengthen security across Azure/AWS environments, endpoints, collaboration platforms, and emerging technologies (including secure handling of biometric and payment data).
- Implement and oversee data classification, data protection, and access control frameworks to secure Personally Identifiable Information (PII) and financial data in transit and at rest.
- Ensure compliance with client, contractual and regulatory security requirements, including the Central Bank of Nigeria (CBN) guidelines, Nigeria Data Protection Commission (NDPC) regulations, and other applicable laws.
- Understand fintech Structure and security architecture Requirements.
- Manage end-to-end compliance with PCI DSS standards, aligning with the latest PCI DSS v4.0 requirements, including continuous monitoring and risk-based security management.
- Interpret and implement global standards such as ISO 9564-1 for PIN management and EMVCo's security requirements for payment systems.
- Develop, review, and maintain security policies, standards, and procedures, ensuring they are technically enforceable and auditable.
- Lead audits and regulatory reviews, managing remediation activities and tracking compliance findings to closure.
- Conduct technology risk assessments for all new and existing products.
- Establish a robust vulnerability management program, coordinating penetration testing and overseeing the remediation of identified weaknesses.
- Manage the vendor risk management process, conducting thorough security assessments of third-party vendors and partners.
- Monitor security events using SIEM platforms, leading incident response, threat hunting, and digital forensics activities.
- Champion operational resilience, ensuring the organization can maintain critical functions during and after a security incident.
- Integrate security controls into CI/CD pipelines (SAST, DAST, SCA), working directly with engineering teams to promote secure coding practices.
- Manage supplier security assessments and third-party risk assurance activities for vendors supporting our payment ecosystem.
Job Application Safety Disclaimer
Your security and privacy are our top priorities. Please be aware that InStreamIQ will never ask you to pay any fees for job applications, placements, or training as a condition of employment.
Furthermore, legitimate employers will not ask for sensitive personal identification such as your Bank Verification Number (BVN), National Identification Number (NIN), or Passport details during the initial application phase. Do not share financial information or make any payments to individuals or organizations claiming to represent an employer. If you encounter any suspicious requests, please report the listing immediately via our support channels.