Intelligence Match
Match: ??%
Unlock Your Personalized Match
Sign in to see your exact score breakdown and personalized insights.
Team Tagline
About the role
Digitvant Microfinance Bank offers a comprehensive digital banking experience featuring savings, loans, fund transfers, and online payments via its website and app. The bank is seeking an experienced Systems Auditor to strengthen its Information Security Governance, Risk and Compliance (GRC) and technology assurance capabilities. The role combines IT audit, information security governance, cybersecurity, regulatory compliance, technical security reviews, and vulnerability assessments, providing assurance over the security, resilience, risk management, and regulatory compliance of the technology environment.
Required Skills
Preferred Skills
Similar Skills not Listed
Responsibilities
- Develop, maintain and review the Information Security Governance and GRC framework.
- Assess compliance with CBN circulars, guidelines, regulatory requirements and information-security standards.
- Maintain an information security and technology risk register with risk identification, assessment, treatment, ownership and remediation tracking.
- Develop and maintain security policies, standards, procedures, control frameworks and control matrices.
- Conduct periodic reviews of information security controls and assess design and operating effectiveness.
- Monitor regulatory changes affecting technology, cybersecurity, payments and information-security obligations.
- Prepare regulatory and management reports on technology risk, cybersecurity and control effectiveness.
- Support regulatory examinations, internal audits, external audits and compliance reviews.
- Track audit and regulatory findings through to effective remediation.
- Assess technology and cybersecurity controls against CBN requirements including NPSR-ISMF and other payment system regulations.
- Maintain a regulatory obligations register and monitor compliance.
- Evaluate readiness for CBN supervisory reviews, inspections and information requests.
- Review controls supporting security, availability, integrity and resilience of payment services.
- Assess technology controls supporting electronic payment channels, transaction processing, APIs and integrations.
- Monitor compliance with operational resilience, business continuity, disaster recovery, access control, transaction security, logging and monitoring requirements.
- Assess compliance with the Nigeria Data Protection Act and NDPC requirements.
- Review controls for collection, processing, storage, transmission, retention and disposal of personal and financial data.
- Conduct privacy and data protection control assessments, including data flows and third-party processing.
- Assess security safeguards protecting customer and employee personal data.
- Review data protection risks associated with cloud services, APIs, vendors and third parties.
- Support privacy impact/risk assessments for new products, systems and technology initiatives.
- Plan and execute risk-based IT and systems audits.
- Evaluate IT General Controls (ITGCs) and application controls.
- Review access management, privileged access, segregation of duties and authentication mechanisms.
- Assess system development lifecycle and secure software development practices.
- Review change management processes and production deployment controls.
- Evaluate business continuity and disaster recovery capabilities for critical technology services.
- Prepare detailed audit reports identifying control weaknesses, root causes, risk implications and corrective actions.
- Conduct technical security assessments of applications, APIs, networks, servers, cloud environments and other technology assets.
- Perform vulnerability assessments and review vulnerability management processes.
- Analyze vulnerability scan and security testing results and assess risks based on business impact.
- Review remediation of identified vulnerabilities and validate closure of critical findings.
- Conduct security configuration reviews against recognized benchmarks and industry best practices.
- Review application security controls including authentication, authorization, session management, encryption and API security.
- Assess security controls around critical payment systems and customer-facing digital channels.
- Review penetration testing reports and independently assess adequacy of remediation.
- Identify emerging technology and cybersecurity risks and recommend appropriate controls.
Job Application Safety Disclaimer
Your security and privacy are our top priorities. Please be aware that InStreamIQ will never ask you to pay any fees for job applications, placements, or training as a condition of employment.
Furthermore, legitimate employers will not ask for sensitive personal identification such as your Bank Verification Number (BVN), National Identification Number (NIN), or Passport details during the initial application phase. Do not share financial information or make any payments to individuals or organizations claiming to represent an employer. If you encounter any suspicious requests, please report the listing immediately via our support channels.