Cybersecurity and Compliance Expert
SterlingPRO Business Application Limited
Key Responsibilities
Security Operations & Incident Response:
- Lead security monitoring, threat detection, incident response, and SOC governance activities, ensuring 24/7 coverage for SterlingPRO’s payment applications.
- Develop and optimise SIEM use cases, detection rules, alert management, and security monitoring processes tailored to financial transaction patterns.
- Manage MSSP and SOC providers, ensuring service quality, performance, and compliance with agreed SLAs.
- Develop and maintain incident response procedures and coordinate security exercises and tabletop testing activities, specifically simulating payment fraud and data breach scenarios.
- Support business continuity, disaster recovery planning, testing, and security governance activities to ensure the uninterrupted availability of SterlingPRO’s POS, ATM, and Agency banking solutions.
- Identity, Cloud & Data Security
- Manage identity security controls including MFA, Conditional Access, privileged access management (PAM), and identity risk monitoring to protect administrative access to core financial systems.
- Strengthen security across Azure/AWS environments, endpoints, collaboration platforms, and emerging technologies (including secure handling of biometric and payment data).
- Implement and oversee data classification, data protection, and access control frameworks to secure Personally Identifiable Information (PII) and financial data in transit and at rest.
Compliance & Governance:
- Ensure compliance with client, contractual, and regulatory security requirements, including the Central Bank of Nigeria (CBN) guidelines, Nigeria Data Protection Commission (NDPC) regulations, and other applicable laws.
- Understand fintech Structure and security architecture Requirements.
- Manage end-to-end compliance with PCI DSS standards, aligning with the latest PCI DSS v4.0 requirements, including continuous monitoring and risk-based security management.
- Interpret and implement global standards such as ISO 9564-1 for PIN management and EMVCo's security requirements for payment systems.
- Develop, review, and maintain security policies, standards, and procedures, ensuring they are technically enforceable and auditable.
- Lead audits and regulatory reviews, managing remediation activities and tracking compliance findings to closure.
Vulnerability & Threat Management:
- Conduct technology risk assessments for all new and existing products.
- Establish a robust vulnerability management program, coordinating penetration testing and overseeing the remediation of identified weaknesses.
- Manage the vendor risk management process, conducting thorough security assessments of third-party vendors and partners.
- Monitor security events using SIEM platforms, leading incident response, threat hunting, and digital forensics activities.
- Champion operational resilience, ensuring the organization can maintain critical functions during and after a security incident.
DevSecOps&Third-Party Security:
- Integrate security controls into CI/CD pipelines (SAST, DAST, SCA), working directly with engineering teams to promote secure coding practices.
- Manage supplier security assessments and third-party risk assurance activities for vendors supporting our payment ecosystem.
Education& Certifications:
- Educational Background: Bachelor’s degree in Cybersecurity, Computer Science, Information Technology,a related field; or equivalent proven experience. A Master’s degree or MBA is a plus.
- Certifications: One or more of the following is highly preferred: CISSP, CISM, CISA, CRISC, or ISO 27001 Lead Implementer/Auditor.
- Standards: Expert knowledge of PCI DSS, ISO 27001, NIST, and OWASP.
Professional Experience
- 5+ years of experience leading security operations within a hybrid SOC environment (Fintech industry experience is an advantage)
- Track record of successfully managing regulatory relationships and navigating complex compliance landscapes (CBN, NDPC).
- Strong knowledge of SIEM platforms, particularly Microsoft Sentinel or equivalent technologies (e.g., Splunk, QRadar).
- Expertise in threat detection, incident response, vulnerability management, and security monitoring.
- Hands-on experience with modern security tooling: EDR/XDR (e.g., Microsoft Defender), IAM (Entra ID), Cloud Security (Azure/AWS native tools), and Data Loss Prevention technologies.
- Strong understanding of Zero Trust architecture, identity security, cloud security, and DevSecOps principles.
- Working knowledge of ISO 27001, SOC 2, risk management frameworks, and audit processes.
- Ability to communicate effectively with technical teams, senior stakeholders, clients, and external partners.
Salary
N400,000 Monthly.
Application Closing Date
Not Specified.
How to Apply
Interested and qualified candidates should send their updated CV to using the Job Title as the subject of the email.
Share this job:
Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Cybersecurity and Compliance Expert in Maryland, Lagos vacancy
- ...by ensuring timely movement of personnel and telecom-related assets while maintaining high standards of vehicle care, safety, and compliance with road regulations. Responsibilities Safely transport staff, visitors, and management to designated locations as...
- ...administrative processes. Support employee relations, performance management, training, and staff engagement initiatives. Ensure compliance with company policies and applicable labour regulations. Prepare HR reports and provide support on workforce planning and...
200000 - 250000 NGN per month
...SharePoint and OneDrive is an advantage. Experience in using Sage accounting software is a plus. Experience with Nigerian tax compliance (VAT, CIT, PAYE), pension, filed without external prompting Attention to detail that borders on obsessive, professional,...- ...Meet daily and weekly onboarding, quality, and productivity targets. Adhere strictly to call scripts, onboarding procedures, and compliance guidelines. Deliver a professional and positive customer experience at all times. Work collaboratively with Team Leads and QA...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cybersecurity and Compliance Expert. Be the first to apply!

