Chumcred Intelligence Logo
Back to jobs

JSearch

Cybersecurity Analyst at First Ally

First AllyLagos, Nigeriaonsite

Job Description

First Ally Capital was incorporated on May 20, 2014 as an Issuing House and Financial Advisory firm, with an authorized share capital of N2.5 billion, and an issued and fully-paid up capital of N1.9 billion. The Firm was licensed by the Securities and Exchange Commission on November 20, 2014. The firm commenced operations at a very significant point in the evolution of the Nigerian financial services industry and has leveraged its solid capital base and the excellent track-record and credentials of its team, directors and shareholders. The team behind the firm have been involved in various transactions ranging from Issuance of bonds, raising equity capital, mergers and acquisition, restructuring to project advisory services. Cybersecurity Analyst About the Role The Cybersecurity Analyst will be a key member of the IT team, responsible for safeguarding First Ally Capital's digital assets, infrastructure, and customer data across the Group and its subsidiaries. The analyst will monitor, detect, investigate, and respond to cybersecurity threats across our Microsoft 365 (M365) and Azure cloud environments, as well as our retail-facing application. This role requires a hands-on professional with strong analytical capability and a working knowledge of cloud security, endpoint protection, and application security. Key Responsibilities Security Monitoring & • Threat Detection Monitor security alerts and events from Microsoft Sentinel, Defender for Endpoint, and Defender for Cloud Apps (MCAS) on a continuous basis. Analyse logs and telemetry from Azure Monitor, Microsoft 365 security centre, and the retail application to identify anomalies and potential intrusions. Triage and investigate security incidents, determine root causes, and escalate appropriately to the IT Manager. Maintain and fine-tune detection rules, alert thresholds, and SIEM correlation queries to reduce false positives. Identity & • Access Management (IAM) Administer and enforce Microsoft Entra ID (Azure AD) policies including Conditional Access, Privileged Identity Management (PIM), and Multi-Factor Authentication (MFA). Conduct periodic user access reviews and entitlement assessments across M365, Azure subscriptions, and the retail app. Detect and investigate suspicious sign-in activity, compromised credentials, and identity-based attacks. Enforce least-privilege principles and Role-Based Access Control (RBAC) across all platforms. Cloud Security (Microsoft Azure & • M365) Manage and improve the security posture of the company's Azure environment using Microsoft Defender for Cloud and the Azure Security Benchmark. Conduct regular reviews of Azure Policy, security recommendations, and compliance scores in Microsoft Secure Score. Ensure proper configuration of M365 services including Exchange Online Protection (EOP), Safe Links, Safe Attachments, and Data Loss Prevention (DLP) policies. Review and harden Azure networking components including NSGs, Azure Firewall rules, and Private Endpoints. Retail & • Core Application Security Collaborate with the application development team to integrate security into the SDLC (Secure-by-Design). Perform and coordinate vulnerability assessments and DAST/SAST scans on the retail and banking application. Monitor application logs for suspicious activity, injection attempts, authentication abuse, and API misuse. Assist in managing Web Application Firewall (WAF) rules and API gateway security policies. Track and follow up on remediation of identified application vulnerabilities within agreed SLAs. Vulnerability Management & • Patch Compliance Run regular vulnerability scans using Microsoft Defender Vulnerability Management or third-party tools across endpoints, servers, and cloud workloads. Track remediation status and produce dashboards showing patch compliance levels for servers, endpoints, and SaaS platforms. Liaise with system administrators and vendors to prioritise and close critical vulnerabilities. Incident Response & • Forensics Participate in the investigation, containment, eradication, and recovery phases of security incidents. Document incident timelines, findings, and lessons learned in structured post-incident reports. Support forensic data collection and preservation following confirmed incidents. Maintain and update the Incident Response Playbooks tailored to M365 and Azure threat scenarios. Compliance & • Policy Support compliance with relevant regulations and frameworks applicable to Nigerian financial institutions (e.g., CBN Cybersecurity Framework, NDPR, ISO 27001, PCI-DSS where applicable). Assist with internal and external security audits by gathering evidence and coordinating remediation actions. Maintain up-to-date security documentation, policies, standards, and procedures. Endpoint & • Email Security M

Related Jobs

Similar opportunities based on industry, country or work type.

GP

GRADUATE TRAINEEE

GloVal Properties Nig, Ltd.

onsitegraduate trainee

Lagos, Nigeria

BeBee

Salary not stated

Posted 14 days ago

GLOVAL PROPERTIES IS ACTIVELY HIRING!! Post: GRADUATE SALES TRAINEEE REQUIREMENTS -Must reside around Lekki / Epe environment. (Ibeju Lekki or Eti Osa) • Academic qualification of either B.Sc, HND & OND. or any Certification in Sales and Marketing • Experience in sales and marketing or similar role • Possess solid networking, marketing and negotiation skills. • Excellent writing and verbal communication skill. • Must be a goal-getter and ability to work with little or no supervision. • Must be confident and smart. BENEFITS • Monthly Salary -10% monthly Sales Commission • HMO. -Training and Personal Development • 3 working days weekly Location: Ajah, Lekki Lagos How to Apply: Interested and qualified candidates should send their CV to: simeon.sunday@glovalproperties.ng using the Job Title as the subject of the email. or apply via Linkedin.

View Job
remoteentry level

Wilmington, NC

BeBee

Salary not stated

Posted 14 days ago

CHECK YOUR EMAIL, INCLUDING YOUR SPAM FOLDER, FOR INSTRUCTIONS AFTER APPLYING Are you ready to embark on a career that offers endless opportunities for growth and development? Do you have a passion for precision and an eye for detail? If so, we have the perfect entry-level opportunity for you as a Remote Data Entry Operator at our company. About Us: We believe that data is the lifeblood of modern business. Our mission is to empower organizations with the most accurate, up-to-date, and reliable data to drive their success. As a Remote Data Entry Operator, you will play a pivotal role in ensuring that our data remains pristine and ready for analysis

View Job
DE

Data Entry From Home

Data Entry Jobs

remotemid level

Becker, MN

BeBee

Salary not stated

Posted 16 days ago

Data Entry Specialist (Remote) We're looking for a detail-oriented Data Entry Specialist to join our team from home. In this role, you'll be responsible for accurately inputting, updating, and maintaining data across various systems and spreadsheets. The ideal candidate is organized, reliable, and comfortable working independently with minimal supervision.

View Job
onsiteinternship

Anywhere

BeBee

Salary not stated

Posted 11 days ago

About the Role BagginsHQ is seeking experienced and highly self-driven Regional Digital Marketing & Content Managers to establish, manage, and grow BagginsHQ's digital presence across assigned regional markets. This is not a traditional social media management role focused primarily on posting content, increasing followers, or generating engagement. The successful candidate will be responsible for building a strong regional digital presence while generating measurable commercial opportunities and verified revenue through digital marketing activities. Each Regional Digital Marketing & Content Manager will take ownership of the assigned regional BagginsHQ social media presence, independently develop and publish content, engage with audiences, identify opportunities for regional growth, generate qualified commercial leads, and work closely with Senior Key Accounts Managers and sales teams to ensure those leads progress towards paying customers. The role requires a commercially minded marketing professional who understands that successful marketing must ultimately contribute to business growth. Key Responsibilities Regional Digital Presence Take full ownership of BagginsHQ's assigned regional social media presence. Establish and maintain active regional pages across relevant platforms, including Facebook, Instagram, TikTok, LinkedIn, and YouTube, as assigned. Independently plan, create, publish, and manage high-quality regional marketing content. Maintain a structured content calendar covering BagginsHQ's products, services, packages, promotions, industries, and relevant customer needs. Ensure assigned regional pages remain active and consistently updated. Monitor audience activity, enquiries, comments, messages, and other forms of engagement. Respond professionally and promptly to relevant enquiries and audience interactions. Identify opportunities to improve the visibility, reach, positioning, and commercial performance of the regional digital presence. Content Creation Independently create professional graphics, promotional materials, short-form videos, videos, presentations, captions, and other digital marketing materials. Use appropriate tools such as Canva, Adobe Photoshop, Adobe Illustrator, Adobe Premiere Pro, CapCut, or comparable professional platforms. Convert publicly available BagginsHQ product and service information into engaging marketing content without requiring continuous supervision. Review BagginsHQ's existing product and service landing pages and use available information, pricing, features, and benefits to develop relevant marketing content. Create content that communicates value clearly and encourages potential customers to take action. Adapt content formats according to the requirements of each social media platform. Maintain high standards of accuracy, professionalism, branding, and visual quality. Regional Content Localization Adapt BagginsHQ's marketing content to suit the culture, language, preferences, and commercial characteristics of the assigned regional market. Identify opportunities to use local or regional languages where appropriate. Develop regionally relevant messaging, examples, visuals, and campaigns while maintaining BagginsHQ's overall brand standards. Monitor regional trends, customer behaviour, competitors, and emerging digital opportunities. Continuously identify new ways to make BagginsHQ's products and services relevant to local audiences. Lead Generation Generate qualified commercial leads through assigned regional social media channels and other approved marketing activities. Use appropriate calls-to-action, lead forms, enquiry mechanisms, landing pages, and other tools to convert audience interest into commercial enquiries. Ensure leads are properly recorded, identified, and attributed to the appropriate regional marketing channel. Monitor the volume and quality of leads generated from each platform and content type. Identify which products, services, campaigns, and content formats generate the strongest commercial interest. Continuously improve marketing activities based on lead-generation performance. Sales Collaboration & Lead Conversion Work closely with Senior Key Accounts Managers, Enterprise Sales Executives, Sales Agents, and other relevant commercial teams. Ensure qualified leads are promptly handed over to the appropriate commercial team. Maintain visibility on the progress of leads generated through assigned regional marketing channels. Follow up internally with the responsible Key Accounts Manager or sales representative regarding the progression of submitted leads. Monitor whether generated leads progress into opportunities and paying customers.

View Job
NY

Service Sales Representative

New York Sports Club

onsitemid level

Somerville, MA

BeBee

Salary not stated

Posted 13 days ago

Job Posting Location: Davis Square, Somerville, MA, 02144, United States Base Pay: $15.00 - $17.95 / Hour Job Category: Boston, Club Team, Front Desk Employee Type: Non-Exempt Manage Others: No Contact Information Name: NYSC - Davis Square Phone: 617-776-0086 Description

View Job
QT

Cybersecurity GRC Analyst

Quidax Technologies Ltd

onsiteinternship

Lagos, Nigeria

BeBee

Salary not stated

Posted 11 days ago

Job description About Quidax Quidax is where money meets limitless possibilities. We’re making it super easy for individuals, businesses, and fintechs in Africa to access crypto. Our goal? Providing real value for our customers today while shaping the future of money. About the Role We’re looking for a Cybersecurity Governance, Risk & Compliance (GRC) analyst who will be responsible for maintaining policies, assessing risks, supporting audits, regulatory requirements, third-party reviews, and security awareness. You’ll help us carry out audits that help us understand where our risks are, verify that the right controls are operating effectively, and ensure we remain continuously audit-ready — not just when an auditor comes knocking. You’d also serve as our Data Protection Officer (DPO) leading our privacy programme, ensuring Data Privacy best practices are enforced in the organization, and ensuring compliance with data protection regulations across jurisdictions. If you’re the kind of person who is meticulous, curious, enjoys carrying out audits, documenting policies, processes and bringing them to life, and passionate about cybersecurity governance, risk, compliance and data privacy — you’ll fit right in. What You’ll Be Owning • Cybersecurity Governance • Within 60 days: Review all existing information security policies, standards, procedures, and SOPs. Identify gaps, outdated content, and areas for improvement while ensuring alignment with the organization’s current technology stack and business operations. • Within 90 days: Update, implement, and communicate approved improvements to security policies, standards, and procedures. Establish a reporting cycle to leadership on Cybersecurity Governance, Risk & Compliance. • Cybersecurity Certifications & External Audits • Within 30 days: Become familiar with Quidax’s compliance landscape, including ISO 27001, PCI DSS, NDPA, and other applicable regulatory & certification requirements. • Within 60 days: Coordinate audit readiness activities by ensuring evidence is collated in advance rather than during audit periods, reducing last-minute audit preparation. • Within 90 days: Support internal and external auditors, coordinate stakeholder responses, track audit findings, and ensure remediation activities are completed within agreed timelines. • Security Awareness • Within 30 days: Review the organization’s existing security training program and security training policies and identify opportunities to improve employee engagement and effectiveness. Take responsibility of the organization’s security awareness program and drive approved improvements. • Within 60 days: Promote a security-first culture by ensuring employees understand their role in protecting customer data and company assets. • Within 180 days: Drive the annual org-wide security culture awareness programme that includes role-based training, data protection and policy awareness. • Third Party Security Review & Evaluation • Within 30 days: Review previous 3rd party security evaluations. Review historical Due Diligence questionnaires completed for partners. Conduct a review of our template for conducting vendor Due Diligence. • Within 60 days: Respond to cybersecurity due diligence questionnaires from partners and regulators. Carry out security reviews on 3rd party applications on-request and create a cadence for scheduled review of the current list of 3rd party apps to verify their eligibility for continued use. • Within 90 days: Ensure all 3rd party services in use must have completed security reviews, and maintain a central repository of 3rd party security evaluations. • Regulatory Engagement • Within 60 days: Build a deep understanding of Quidax regulatory landscape, regulatory obligations and expectations across all operating jurisdictions. Be able to provide responses to regulatory requests, assessments, and evidence collation by collaborating with relevant internal teams. Create a working process for monitoring regulatory developments, recommended changes to policies, controls, and processes to maintain ongoing compliance. • Data Protection • Within 60 days: Audit existing data protection processes, privacy controls, and data handling procedures to identify compliance gaps and opportunities for improvement. Take ownership of data protection processes, controls, data handling procedures, Data Privacy Impact Assessments (DPIAs), and new initiatives involving sensitive data. • Within 90 days: Implement approved improvements

View Job