Full-time
NGN N150,000 - N250,000
Lagos
31 Aug 2026
Software/ Programming / Web development

SterlingPRO is a leader in developing innovative fintech solutions that power the future of finance. We are a team of experts passionate about technology and driven by a mission to create seamless, secure, and inclusive financial experiences. We offer a dynamic and challenging environment where your work will have a direct impact on the security of millions of transactions.


Job Location: Maryland (Mende), Lagos


Key Responsibilities

Security Operations & Incident Response

  • Lead security monitoring, threat detection, incident response, and SOC governance activities, ensuring 24/7 coverage forSterlingPRO’spayment applications.
  • Develop andoptimiseSIEM use cases, detection rules, alert management, and security monitoring processes tailored to financial transaction patterns.
  • Manage MSSP and SOC providers, ensuring service quality, performance, and compliance with agreed SLAs.
  • Develop andmaintainincident response procedures and coordinate security exercises and tabletop testing activities, specifically simulating payment fraud and data breach scenarios.
  • Support business continuity, disaster recovery planning, testing, and security governance activities to ensure the uninterrupted availability ofSterlingPRO’sPOS, ATM, and Agency banking solutions.


Identity, Cloud & Data Security:

  • Manage identity security controls including MFA, Conditional Access, privileged access management (PAM), and identity risk monitoring to protect administrative access to core financial systems.
  • Strengthen security across Azure/AWS environments, endpoints, collaboration platforms, and emerging technologies (including secure handling of biometric and payment data).
  • Implement and oversee data classification, data protection, and access control frameworks to secure Personally Identifiable Information (PII) and financial data in transit and at rest.


Compliance & Governance:

  • Ensure compliancewith client, contractualandregulatory security requirements, including the Central  Bank of Nigeria (CBN) guidelines, Nigeria Data Protection Commission (NDPC) regulations, and other applicable laws.
  • Understand fintech Structure and security architecture Requirements.
  • Manage end-to-end compliance with PCI DSS standards, aligning with the latest PCI DSS v4.0 requirements, including continuous monitoring and risk-based security management.
  • Interpret and implement global standards such as ISO 9564-1 for PIN management and EMVCo's security requirements for payment systems.
  • Develop, review, andmaintainsecurity policies, standards, and procedures, ensuring they are technically enforceable and auditable.
  • Lead audits and regulatory reviews, managing remediationactivitiesand tracking compliance findings to closure.


Vulnerability & Threat  Management:

  • Geographic ReferenceConduct technology risk assessments for all new and existing products.
  • Establish a robust vulnerability management program, coordinating penetrationtestingand overseeing the remediation ofidentifiedweaknesses.
  • Manage the vendor risk management process, conducting thorough security assessments of third-party vendors and partners.
  • Monitor security events using SIEM platforms, leading incident response, threat hunting, and digitalforensicsactivities.
  • Champion operational resilience, ensuring the organization canmaintaincritical functions during and after a security incident.

DevSecOps &Third-Party Security:

  • Integrate security controls into CI/CD pipelines (SAST, DAST, SCA), working directly with engineering teams to promote secure coding practices.
  • Manage supplier security assessments and third-party risk assurance activities for vendors supporting our payment ecosystem.


Requirements

Education & Certifications:

  • Educational Background: Bachelor’s Degree in Cybersecurity, Computer Science, Information Technology,a related field; or equivalent proven experience. A Master’s Degree or MBA is a plus.
  • Certifications: One or more of the following is highly preferred: CISSP, CISM, CISA, CRISC, or ISO 27001 Lead Implementer/Auditor.
  • Standards:Expert knowledge of PCI DSS, ISO 27001, NIST, and OWASP.


Professional Experience:

  • 5+ years of experience leading security operations within a hybrid SOC environment (Fintech industry experience is an advantage)
  • Track record of successfully managing regulatory relationships and navigating complex compliance landscapes (CBN, NDPC).
  • Strong knowledge of SIEM platforms, particularly Microsoft Sentinel or equivalent technologies (e.g., Splunk,QRadar).
  • Expertise inthreat detection, incident response, vulnerability management, and security monitoring.
  • Hands-on experience with modern security tooling: EDR/XDR (e.g., Microsoft Defender), IAM (Entra ID), Cloud Security (Azure/AWS native tools), and Data Loss Prevention technologies.
  • Strong understanding of Zero Trust architecture, identity security, cloud security, and DevSec Ops principles.
  • Working knowledge of ISO 27001, SOC 2, risk management frameworks, and audit processes.
  • Ability to communicate effectively with technical teams, senior stakeholders, clients, and external partners.


Method of Application 

Interested and qualified candidates should send their CV to: hr@sterlingprong.com using the Job Position as the subject of the mail.