Heirs Holdings is an African proprietary investment company, with a track record of success and a firm belief in the opportunities that Africa offers. We are known for executing successful corporate turnarounds, and for our ability to identify growth opportunities, incubate new businesses and nurture them to maturity. As active investors, we aim to transform...
Read more about this company
The Platform Manager (Security) is the dedicated security authority for the platform — not a generic security function, but an embedded owner who lives inside the software factory. Reporting to the Cybersecurity Director and working hand-in-hand with the Platform Manager, you will sit at the intersection of platform engineering, DevSecOps, cybersecurity, legal, and vendor management. You will own the definition, implementation, and strict enforcement of the platform's security posture across every team, system, and workstream. On a platform handling the financial data of millions of Africans, the practical objective is not to make theft or compromise impossible — it is to ensure that any attempt is hard, incomplete, noisy, traceable, attributable, and commercially useless without the platform's cloud infrastructure, credentials, pipelines, and integrations.
What You'll Do
Security Standards & Governance — Define, enforce, and continuously improve the platform's end-to-end security standards, policies, and controls — covering encryption, identity, application security, network security, data protection, and compliance. Ensure every team, partner, and contributor operates within these standards at all times.
Identity & Access Management — Own the platform's IAM framework — including MFA enforcement for all human access, service-to-service authentication using short-lived tokens and managed identities, privileged access management (PAM), just-in-time elevation, session recording, and automatic expiry. Standing privileged access to production is prohibited without formal exception.
Source Code & Repository Integrity — Own the security of the platform's source-control environment end-to-end — including repository segmentation by domain, service, team, and access need; SSO and MFA enforcement across all contributors; branch protection on all critical branches with mandatory pull requests, CODEOWNERS approval, and peer review required; no direct commits to protected branches and no force-push permitted; secret scanning and push protection enabled across all repositories; and audit logs exported to SIEM. No developer or vendor has access to all repositories by default — access maps strictly to role, squad, and deliverable, and is reviewed at defined intervals.
Application Security — Own the platform's secure development lifecycle — ensuring security requirements are defined at design, not retrofitted at delivery. Govern SAST, DAST, SCA, and secrets detection gates across all CI/CD pipelines. No service may be promoted to production without passing every security gate.
Encryption & Data Protection — Enforce AES-256 encryption at rest and TLS 1.2+ in transit across all services. Own key management through Azure Key Vault and AWS KMS — including rotation schedules and access controls. Drive data classification, DLP enforcement, and protection of customer, payment, and authentication data across all environments.
Penetration Testing & Vulnerability Management — Commission and oversee penetration testing before every production launch and on a regular cadence thereafter. Own the vulnerability management process — ensuring all critical and high CVEs are tracked and remediated within agreed timelines. Critical findings must be resolved before go-live.
Regulatory Compliance — Own the platform's compliance posture across CBN guidelines, PCI DSS, and applicable data protection regulations in all operating markets. Manage data residency requirements, assess cross-border data transfers, and ensure compliance reviews are conducted periodically with regulatory changes tracked and incorporated on a timely basis.
Incident Response & Unified Monitoring — Own the platform's Incident Response Plan — covering detection, triage, containment, eradication, recovery, and post-incident review. Ensure critical incidents are escalated to senior management and relevant regulators within prescribed timelines. Establish and maintain a unified monitoring posture that correlates repository audit logs, endpoint DLP telemetry, identity and VPN logs, and CI/CD activity as a single control surface — fed into SIEM for continuous alerting and investigation. All production systems must be monitored 24/7 with alerts routing to an active SOC function.
Supply Chain & Container Security — Enforce security across the platform's software supply chain — including container image scanning (Trivy), runtime threat detection (Falco), and dependency vulnerability scanning (Snyk) integrated into every pipeline. No container may be deployed without passing security gates.
Insider Threat, Endpoint & Workforce Risk — Define and enforce developer workstation security requirements — including managed/compliant device standards for repository and cloud access, endpoint detection and response (EDR), disk encryption, OS patching, and device compliance. For high-risk contributors or sensitive workstreams, evaluate VDI or cloud-hosted development environments with download, clipboard, and USB controls. Implement insider-risk monitoring to detect and escalate abnormal behaviour — mass data downloads, unusual clone volume, privilege escalation, DLP violations, and access attempts after role change or termination. Ensure monitoring is privacy-aware, legally approved, and integrated with SIEM and SOC workflows.
Partner, IP & Third-Party Controls — Own security due diligence for all engineering partners and contractors — including contractual clauses covering IP assignment, confidentiality, data protection, right-to-audit, secure development, and incident notification. Ensure partner access is provisioned on a least-privilege basis, time-bound, reviewed at defined intervals, and revoked immediately upon exit. Enforce structured offboarding — access removal, device return, confirmation of no retained code or materials, and explicit reminder of IP and confidentiality obligations. Coordinate with Legal and HR on suspected IP infringement — ensuring evidence is preserved, incidents are triaged, and the appropriate enforcement or takedown process is followed.
Security Architecture Collaboration — Partner with the Enterprise Architect, Platform Manager, and engineering leads to ensure security is designed in from day one — not bolted on. Contribute security requirements at the design phase of every new service, feature, and integration.
Executive Reporting — Report regularly to the Cybersecurity Director on the platform's security posture, compliance status, incident activity, and risk profile. Represent the security function in key leadership forums and board-level discussions when required.
What We're Looking For
Must Have
8+ years of experience in information security or cybersecurity, including proven ownership of a security function in a large-scale, cloud-native, or financial services environment.
Deep expertise across the full security stack — identity & access management, encryption & key management, application security (SDLC, SAST, DAST, SCA), network security, DLP, and incident response.
Strong hands-on knowledge of cloud security on AWS and/or Azure — including native security services, IAM, private networking, zero-trust architecture, and cloud-native threat detection tools.
Demonstrated experience owning regulatory compliance in a financial services context — PCI DSS, CBN guidelines, or equivalent data protection and residency frameworks.
Experience designing and operating a Security Operations Centre (SOC) function — including 24/7 monitoring, SIEM integration, alert management, and incident escalation workflows.
Active security certification — CISSP (Certified Information Systems Security Professional) or CISM (Certified Information Security Manager) required.
Nice to Have
CSSLP (Certified Secure Software Lifecycle Professional) — highly relevant given the software factory focus of this role; and/or CCSP (Certified Cloud Security Professional) for cloud security depth.
AWS Certified Security – Specialty and/or Microsoft Certified: Security Operations Analyst Associate (SC-200) or Cybersecurity Architect Expert (SC-100).
Hands-on experience with container and supply chain security tooling — Trivy, Falco, Snyk, or equivalent.
Familiarity with IaC security scanning and policy enforcement — including reviewing Terraform, Ansible, and Bash-based provisioning scripts for misconfigurations, hardcoded secrets, and insecure defaults as part of CI/CD-integrated SAST workflows.
Experience implementing and operating insider threat monitoring programmes in a regulated financial services environment.
Familiarity with African regulatory frameworks — CBN guidelines, NDPR, and data residency requirements across multiple operating markets.
Best Freelance Skills You Need to Earn in USDThis article discusses the best freelance skills to learn if you want to earn in USD and shares tips on how you can get your first interantional client.
10 Signs You Need to Hire a Recruitment AgencyThis article discusses 10 clear signs you need to hire a recruitment agency, how recruitment agencies solve these problems, and when outsourcing recruitment makes the most business sense.
Best Online Platforms that Pay Nigerians in USD to Train AILooking for AI training jobs that pay in USD? Discover the best online platforms where Nigerians can earn dollars by training AI models, writing prompts, evaluating AI responses, annotating data, and more.