First Ally Capital is a wholly indigenous Financial Services firm, whose focus is on providing top notch advisory & investment services to individuals and organizations. First Ally Capital was incorporated on May 20, 2014 as an Issuing House, Financial Advisory and Investment Management firm, with authorized capital of N2.5 billion, and an issued and fully-paid capital of N1.65 billion. The firm was licensed by the Securities and Exchange Commission on November 20, 2014 as Issuing House and Underwriters.
The Firm commenced operations at a very significant point in the evolution of the Nigerian financial services industry and will leverage it’s solid capital base, the strong financial services background of its promoters and the excellent track-record and credentials of its directors and shareholders.
We are recruiting to fill the position below:
Job Title: Cybersecurity Analyst
Location: Lagos
Employment Type: Full-time
About the Role
- The Cybersecurity Analyst will be a key member of the IT team, responsible for safeguarding First Ally Capital's digital assets, infrastructure, and customer data across the Group and its subsidiaries.
- The analyst will monitor, detect, investigate, and respond to cybersecurity threats across our Microsoft 365 (M365) and Azure cloud environments, as well as our retail-facing application.
- This role requires a hands-on professional with strong analytical capability and a working knowledge of cloud security, endpoint protection, and application security.
Key Responsibilities
Security Monitoring & Threat Detection:
- Monitor security alerts and events from Microsoft Sentinel, Defender for Endpoint, and Defender for Cloud Apps (MCAS) on a continuous basis.
- Analyse logs and telemetry from Azure Monitor, Microsoft 365 security centre, and the retail application to identify anomalies and potential intrusions.
- Triage and investigate security incidents, determine root causes, and escalate appropriately to the IT Manager.
- Maintain and fine-tune detection rules, alert thresholds, and SIEM correlation queries to reduce false positives.
Identity & Access Management (IAM):
- Administer and enforce Microsoft Entra ID (Azure AD) policies including Conditional Access, Privileged Identity Management (PIM), and Multi-Factor Authentication (MFA).
- Conduct periodic user access reviews and entitlement assessments across M365, Azure subscriptions, and the retail app.
- Detect and investigate suspicious sign-in activity, compromised credentials, and identity-based attacks.
- Enforce least-privilege principles and Role-Based Access Control (RBAC) across all platforms.
- Cloud Security (Microsoft Azure & M365)
- Manage and improve the security posture of the company's Azure environment using Microsoft Defender for Cloud and the Azure Security Benchmark.
- Conduct regular reviews of Azure Policy, security recommendations, and compliance scores in Microsoft Secure Score.
- Ensure proper configuration of M365 services including Exchange Online Protection (EOP), Safe Links, Safe Attachments, and Data Loss Prevention (DLP) policies.
- Review and harden Azure networking components including NSGs, Azure Firewall rules, and Private Endpoints.
Retail & Core Application Security:
- Collaborate with the application development team to integrate security into the SDLC (Secure-by-Design).
- Perform and coordinate vulnerability assessments and DAST/SAST scans on the retail and banking application.
- Monitor application logs for suspicious activity, injection attempts, authentication abuse, and API misuse.
- Assist in managing Web Application Firewall (WAF) rules and API gateway security policies.
- Track and follow up on remediation of identified application vulnerabilities within agreed SLAs.
Vulnerability Management & Patch Compliance:
- Run regular vulnerability scans using Microsoft Defender Vulnerability Management or third-party tools across endpoints, servers, and cloud workloads.
- Track remediation status and produce dashboards showing patch compliance levels for servers, endpoints, and SaaS platforms.
- Liaise with system administrators and vendors to prioritise and close critical vulnerabilities.
Incident Response & Forensics:
- Participate in the investigation, containment, eradication, and recovery phases of security incidents.
- Document incident timelines, findings, and lessons learned in structured post-incident reports.
- Support forensic data collection and preservation following confirmed incidents.
- Maintain and update the Incident Response Playbooks tailored to M365 and Azure threat scenarios.
Compliance & Policy:
- Support compliance with relevant regulations and frameworks applicable to Nigerian financial institutions (e.g., CBN Cybersecurity Framework, NDPR, ISO 27001, PCI-DSS where applicable).
- Assist with internal and external security audits by gathering evidence and coordinating remediation actions.
- Maintain up-to-date security documentation, policies, standards, and procedures.
Endpoint & Email Security:
- Manage Microsoft Defender for Endpoint policies — onboarding, configuration, and response actions.
- Investigate email-based threats including phishing, Business Email Compromise (BEC), and malware delivery via M365 Defender and Threat Explorer.
- Enforce and review Intune/Endpoint Manager device compliance and configuration Profiles
Qualifications & Experience
Education:
- Bachelor's Degree in Computer Science, Information Security, Cybersecurity or a related field.
Required Experience:
- 3 - 5 years of hands-on experience in a cybersecurity or IT security role.
- Demonstrable experience working with Microsoft 365 security tools (Defender suite, Purview, Secure Score).
- Practical exposure to Microsoft Azure security services (Defender for Cloud, Sentinel, Entra ID, Azure Policy).
- Experience with vulnerability assessment tools and understanding common CVEs and exploitation techniques.
- Familiarity with web/mobile application security concepts (OWASP Top 10, API security).
- Working knowledge of KQL (Kusto Query Language) for creating Sentinel search queries, workbooks, and custom analytics rules (highly preferred).
Preferred Certifications:
- Microsoft Certified: Azure Security Engineer Associate (AZ-500)
- Microsoft Certified: Security Operations Analyst Associate (SC-200)
- CompTIA Security+
- Certified Ethical Hacker (CEH) or equivalent
Technical Skills
Category / Tools / Technologies:
- Microsoft 365 Security Microsoft Defender for Endpoint, Defender for Office 365, Purview DLP, Compliance Centre, Secure Score, Threat Explorer
- Azure Cloud Security Microsoft Sentinel (SIEM/SOAR), Defender for Cloud,
- Entra ID (Conditional Access, PIM, MFA), Azure Policy, NSGs, Azure Firewall
- Identity & Access RBAC, Privileged Identity Management, Zero Trust
- Architecture, SSO, SAML/OAuth 2.0
- Application Security OWASP Top 10, DAST/SAST tools, WAF management,
- API security, SDLC integration
- Endpoint & Device Mgmt Microsoft Intune, Defender for Endpoint, Windows Defender policies
- Vulnerability Mgmt Microsoft Defender Vulnerability Mgmt, Nessus / Qualys (desirable), CVSS scoring
- Networking TCP/IP, DNS, HTTP/S, VPN, Firewall rules, Zero Trust networking
- Scripting & Automation PowerShell, KQL (Kusto Query Language) for
- Sentinel/Log Analytics — advantageous
Application Closing Date
Not Specified.
https://www.hotnigerianjobs.com/hotjobs/929581/cybersecurity-analyst-at-first-ally-capital-limite.html