Jobs Career Advice Post Job
X

Send this job to a friend

X

Did you notice an error or suspect this job is scam? Tell us.

  • Posted: Sep 26, 2026
    Deadline: Not specified
    • @gmail.com
    • @yahoo.com
    • @outlook.com
  • Digitvant Microfinance Bank - We offer a comprehensive digital banking experience, featuring savings, loans, fund transfers, and online payments via our website and App. Our platform allows customers to manage their finances efficiently and access a wide range of personalised services to meet evolving needs.

     

    Systems Auditor

    • We are seeking an experienced Systems Auditor to strengthen our Information Security Governance, Risk and Compliance (GRC) and technology assurance capabilities.
    • The successful candidate will provide assurance over the security, resilience, risk management and regulatory compliance of our technology environment. The role combines IT audit, information security governance, cybersecurity, regulatory compliance, technical security reviews and vulnerability assessments.

    Key Responsibilities

    Information Security Governance, Risk & Compliance

    • Develop, maintain and periodically review the organization's Information Security Governance and GRC framework.
    • Assess compliance with applicable CBN circulars, guidelines, regulatory requirements and information-security standards.
    • Maintain an information security and technology risk register, including risk identification, assessment, treatment, ownership and remediation tracking.
    • Develop and maintain security policies, standards, procedures, control frameworks and control matrices.
    • Conduct periodic reviews of information security controls and assess their design and operating effectiveness.
    • Monitor regulatory changes affecting the organization's technology, cybersecurity, payments and information-security obligations.
    • Prepare regulatory and management reports relating to technology risk, cybersecurity and control effectiveness.
    • Support regulatory examinations, internal audits, external audits and compliance reviews.
    • Track audit and regulatory findings through to effective remediation.

    CBN & Financial Services Regulatory Compliance

    • Assess technology and cybersecurity controls against applicable CBN requirements, including the Nigerian Payments System Risk and Information Security Management Framework (NPSR-ISMF) and other applicable CBN payment system regulations and guidelines.
    • Maintain a regulatory obligations register covering relevant CBN requirements and monitor compliance.
    • Evaluate the organization's readiness for CBN supervisory reviews, inspections and information requests.
    • Review controls supporting the security, availability, integrity and resilience of payment services.
    • Assess technology controls supporting electronic payment channels, transaction processing, APIs, integrations and other critical payment infrastructure.
    • Monitor compliance with applicable requirements relating to operational resilience, business continuity, disaster recovery, access control, transaction security, logging and monitoring.
    • Keep abreast of changes to CBN requirements affecting fintechs, Payment Solution Service Providers (PSSPs), switches, processors, payment infrastructure and other applicable license categories.

    Data Protection & Privacy Assurance

    • Assess compliance of technology and business processes with the Nigeria Data Protection Act and other applicable NDPC requirements.
    • Review controls for the collection, processing, storage, transmission, retention and disposal of personal and financial data.
    • Conduct or support privacy and data protection control assessments, including reviews of data flows and third party processing arrangements.
    • Assess security safeguards protecting customer and employee personal data.
    • Review data protection risks associated with cloud services, APIs, vendors and other third parties.
    • Support privacy impact/risk assessments for new products, systems and technology initiatives.
    • Work with all teams to identify and remediate data protection control gaps.

    IT & Systems Auditing

    • Plan and execute risk based IT and systems audits
    • Evaluate IT General Controls (ITGCs) and application controls.
    • Review access management, privileged access, segregation of duties and authentication mechanisms.
    • Assess system development lifecycle and secure software development practices.
    • Review change management processes and production deployment controls.
    • Evaluate business continuity and disaster recovery capabilities for critical technology services.
    • Prepare detailed audit reports identifying control weaknesses, root causes, risk implications and corrective actions.

    Technical Security Reviews & Vulnerability Assessments

    • Conduct technical security assessments of applications, APIs, networks, servers, cloud environments and other technology assets.
    • Perform vulnerability assessments and review vulnerability management processes.
    • Analyze vulnerability scan and security testing results and assess risks based on business impact.
    • Review remediation of identified vulnerabilities and validate closure of critical findings.
    • Conduct security configuration reviews against recognized security benchmarks and industry best practices.
    • Review application security controls, including authentication, authorization, session management, encryption and API security.
    • Assess security controls around critical payment systems and customer facing digital channels.
    • Review penetration testing reports and independently assess the adequacy of remediation.
    • Identify emerging technology and cybersecurity risks and recommend appropriate mitigating controls.

    Third Party & Technology Risk

    • Assess cybersecurity and technology risks associated with vendors, service providers, cloud providers and other third parties.
    • Review vendor due diligence and ongoing security assurance processes.
    • Assess contractual security requirements, data protection obligations, service level agreements and incident notification provisions.
    • Review third party audit reports, certifications and security assessments.
    • Monitor remediation of security and control weaknesses identified in third party assessments.

    Incident, Resilience & Security Assurance

    • Review the effectiveness of cybersecurity incident response processes.
    • Assess security monitoring, SIEM/logging, alerting and incident escalation controls.
    • Review controls for identifying, containing and recovering from cybersecurity incidents.
    • Participate in post incident reviews and assess root causes and remediation plans.
    • Evaluate technology resilience, business continuity and disaster recovery arrangements.

    Reporting & Advisory

    • Prepare concise and actionable audit reports for management and relevant stakeholders.
    • Communicate technical vulnerabilities and cybersecurity risks.
    • Provide risk based recommendations that balance security, regulatory obligations, customer protection and business objectives.
    • Present significant technology and cybersecurity risks to management and relevant stakeholdres.
    • Maintain appropriate audit evidence and documentation to support regulatory and independent reviews.

    Requirements

    • Bachelor's degree in Computer Science, Information Technology, or a related discipline.
    • 5 - 7 years experience in IT audit, systems audit, cybersecurity, information security, technology risk or GRC.
    • Experience within fintech, banking, payments, financial services.
    • Demonstrable experience conducting IT audits and control assessments.
    • Practical experience performing or reviewing vulnerability assessments and technical security reviews.
    • Good understanding of networks, operating systems, databases, cloud technologies, APIs and application security.
    • Strong understanding of IT General Controls and application controls.
    • Knowledge of information security risk management and regulatory compliance.
    • Experience interpreting regulatory requirements and translating them into operational controls.
    • Strong analytical and investigative skills.
    • High level of integrity, independence, confidentiality and professional judgment.
    • Possessing CISA/CISM/CRISC/CISSP/CEH/PCI/DSS certification(s) is strongly required.
    • The Ideal candidate must be an ISO 27001 Lead Auditor / Lead Implementer.

    Check how your CV matches this job

    Method of Application

    Interested and qualified persons should send their CV to hr@digitvant.com, using the job title as the subject of the email.

    Build your CV for free. Download in different templates.

  • Get new ICT / Computer jobs like this on Telegram.Subscribe on Telegram
  • Send your application

    Join our WhatsApp Community Back To Home

Career Advice

View All Career Advice
 

Subscribe to Job Alert

 

Join our happy subscribers

 
 
Send your application through

GmailGmail YahoomailYahoomail