Posted on Tue 03rd Mar, 2026 - hotnigerianjobs.com --- (0 comments)
Pishon and Brooks Advisory Services is a Professional Services firm that support our clients by managing their end-to-end HR Processes in order to enhance their productivity. At PBAS, we have the expertise to connect and manage every business process within the employee lifecycle.
We are recruiting to fill the position below:
Job Title: Chief Information Security Officer (CISO)
Location: Lagos
Job type: Full-time
Job Objectives
The Group Head, CISO is responsible for developing, implementing, and overseeing enterprise-wide information security, cyber risk, and data protection strategy across the group, developing security policies and procedures that provide adequate business application protection without interfering with core business requirements.
The role ensures the confidentiality, integrity, and availability of information assets, while maintaining full compliance with regulatory, contractual, and industry security standards relevant to a fintech environment.
Duties and Responsibilities
Establish and maintain security governance frameworks, policies, standards, and procedures across all subsidiaries.
Provide regular cyber risk reporting to Executive Management and the Board.
Oversee the design and implementation of secure IT and cloud architectures for fintech platforms, APIs, payment systems, and digital channels.
Approve security controls for applications, infrastructure, endpoints, networks, and data environments.
Identify, assess, and manage information security and cyber risks, including thirdparty and cloud-related risks.
Ensure compliance with applicable regulations and standards such as: ISO 27001 / ISO 22301, PCI-DSS, NDPR / GDPR, Central Bank and financial services cybersecurity guidelines.
Define and execute the Group-wide information security and cybersecurity strategy aligned with business objectives and regulatory expectations.
Ensure robust data protection, privacy, and information classification frameworks across the Group.
Establish and enforce third-party security risk management processes.
Review and approve security requirements for vendors, fintech partners, and service providers.
Monitor compliance with outsourced services with Group security standards.
Oversee threat intelligence, vulnerability management, penetration testing, and red-team exercises.
Lead the Cybersecurity Incident Response Framework, including detection, response, investigation, and recovery.
Champion responsible for data usage and protection of customer and corporate data
Work closely with Legal and Compliance to manage data breaches, regulatory notifications, and customer communications.
Keep abreast of the IT industry development & awareness, trends, latest security and privacy legislation, including legal considerations, e.g. privacy.
Delivering new security technology approaches and implementing next generation solutions.
Developing and implementing business continuity plans to ensure service is continuous when a change program is introduced, or a security breach occurs or if the disaster recovery plan needs to be triggered.
Conducting a continuous assessment of current cybersecurity practices and systems and identifying areas for improvement.
Staff Attraction, Motivation and Retention:
Fill vacant roles within the department in a timely manner and provide opportunities for growth and development.
Provide training, mentorship, and up-skilling programs.
Recognize and reward individual and team achievements and contribution.
Encourage open communication and feedback.
Give employees autonomy and ownership of their work to motivate them.
Foster a positive work culture that encourages collaboration, innovation, and creativity.
Regularly engage direct reports to understand their needs and concerns.
Requirements
Educational Qualification:
Bachelor’s Degree in Computer Science, Information Security, or related field.
Knowledge:
Excellent interpersonal and written communications skills.
Solid knowledge of electronic and site security issues, and a firm understanding of the organization’s business requirements.
The CISO must also be able to stay abreast of any new developments in the rapidly changing security environment to avoid serious and/or costly mistakes as well as focus and determine on what actions could and should be carried out for an organization’s infrastructure at a given time.
Excellent communication skill to balance between business and security requirements.
Very strong analytical and creative problem-solving skills.
Technical Skills: Understanding of failover mechanisms and replication technologies to ensure seamless recovery of IT infrastructure.
Familiarity with cloud platforms like AWS, Azure, and Google Cloud, and their business continuity features, including automated backups and high availability configurations.
Understanding of cloud-based disaster recovery strategies and the use of multi-region or multi-cloud deployments for business continuity.
Basic understanding of network and infrastructure components (e.g., TCP/IP, DNS, firewalls, routers) to identify vulnerabilities in systems that could impact continuity.
Understanding of integrated Governance, Risk, and Compliance (GRC) platforms for risk assessment and reporting.