Talent Apply
Log in
All jobs
DM

Systems Auditor

Digitvant Microfinance Bank
Lagos, Nigeria Posted Sep 26, 2026
On-site

About this role

Systems Auditor

Digitvant Microfinance Bank - We offer a comprehensive digital banking experience, featuring savings, loans, fund transfers, and online payments via our website and App. Our platform allows customers to manage their finances efficiently and access a wide range of personalised services to meet evolving needs.

Systems Auditor

Job Type: Full Time Qualification: BA/BSc/HND Experience: 5 - 7 years Location: Lagos Job Field: ICT / Computer

We are seeking an experienced Systems Auditor to strengthen our Information Security Governance, Risk and Compliance (GRC) and technology assurance capabilities. The successful candidate will provide assurance over the security, resilience, risk management and regulatory compliance of our technology environment. The role combines IT audit, information security governance, cybersecurity, regulatory compliance, technical security reviews and vulnerability assessments.

Key Responsibilities

  • Information Security Governance, Risk & Compliance

  • Develop, maintain and periodically review the organization's Information Security Governance and GRC framework.

  • Assess compliance with applicable CBN circulars, guidelines, regulatory requirements and information-security standards.

  • Maintain an information security and technology risk register, including risk identification, assessment, treatment, ownership and remediation tracking.

  • Develop and maintain security policies, standards, procedures, control frameworks and control matrices.

  • Conduct periodic reviews of information security controls and assess their design and operating effectiveness.

  • Monitor regulatory changes affecting the organization's technology, cybersecurity, payments and information-security obligations.

  • Prepare regulatory and management reports relating to technology risk, cybersecurity and control effectiveness.

  • Support regulatory examinations, internal audits, external audits and compliance reviews.

  • Track audit and regulatory findings through to effective remediation.

  • CBN & Financial Services Regulatory Compliance

  • Assess technology and cybersecurity controls against applicable CBN requirements, including the Nigerian Payments System Risk and Information Security Management Framework (NPSR-ISMF) and other applicable CBN payment system regulations and guidelines.

  • Maintain a regulatory obligations register covering relevant CBN requirements and monitor compliance.

  • Evaluate the organization's readiness for CBN supervisory reviews, inspections and information requests.

  • Review controls supporting the security, availability, integrity and resilience of payment services.

  • Assess technology controls supporting electronic payment channels, transaction processing, APIs, integrations and other critical payment infrastructure.

  • Monitor compliance with applicable requirements relating to operational resilience, business continuity, disaster recovery, access control, transaction security, logging and monitoring.

  • Keep abreast of changes to CBN requirements affecting fintechs, Payment Solution Service Providers (PSSPs), switches, processors, payment infrastructure and other applicable license categories.

  • Data Protection & Privacy Assurance

  • Assess compliance of technology and business processes with the Nigeria Data Protection Act and other applicable NDPC requirements.

  • Review controls for the collection, processing, storage, transmission, retention and disposal of personal and financial data.

  • Conduct or support privacy and data protection control assessments, including reviews of data flows and third party processing arrangements.

  • Assess security safeguards protecting customer and employee personal data.

  • Review data protection risks associated with cloud services, APIs, vendors and other third parties.

  • Support privacy impact/risk assessments for new products, systems and technology initiatives.

  • Work with all teams to identify and remediate data protection control gaps.

  • IT & Systems Auditing

  • Plan and execute risk based IT and systems audits

  • Evaluate IT General Controls (ITGCs) and application controls.

  • Review access management, privileged access, segregation of duties and authentication mechanisms.

  • Assess system development lifecycle and secure software development practices.

  • Review change management processes and production deployment controls.

  • Evaluate business continuity and disaster recovery capabilities for critical technology services.

  • Prepare detailed audit reports identifying control weaknesses, root causes, risk implications and corrective actions.

  • Technical Security Reviews & Vulnerability Assessments

  • Conduct technical security assessments of applications, APIs, networks, servers, cloud environments and other technology assets.

  • Perform vulnerability assessments and review vulnerability management processes.

  • Analyze vulnerability scan and security testing results and assess risks based on business impact.

  • Review remediation of identified vulnerabilities and validate closure of critical findings.

  • Conduct security configuration reviews against recognized security benchmarks and industry best practices.

  • Review application security controls, including authentication, authorization, session management, encryption and API security.

  • Assess security controls around critical payment systems and customer facing digital channels.

  • Review penetration testing reports and independently assess the adequacy of remediation.

  • Identify emerging technology and cybersecurity risks and recommend appropriate mitigating controls.

  • Third Party & Technology Risk

  • Assess cybersecurity and technology risks associated with vendors, service providers, cloud providers and other third parties.

  • Review vendor due diligence and ongoing security assurance processes.

  • Assess contractual security requirements, data protection obligations, service level agreements and incident notification provisions.

  • Review third party audit reports, certifications and security assessments.

  • Monitor remediation of security and control weaknesses identified in third party assessments.

  • Incident, Resilience & Security Assurance

  • Review the effectiveness of cybersecurity incident response processes.

  • Assess security monitoring, SIEM/logging, alerting and incident escalation controls.

  • Review controls for identifying, containing and recovering from cybersecurity incidents.

  • Participate in post incident reviews and assess root causes and remediation plans.

  • Evaluate technology resilience, business continuity and disaster recovery arrangements.

  • Reporting & Advisory

  • Prepare concise and actionable a

Your next opportunity starts here

Prepare, apply, track, interview and get hired — all from one platform, with AI in your corner.

Download app

Or sponsor Premium for someone who's job hunting →