
Cybersecurity GRC Analyst
Posted Jul 28

Posted Jul 28
This is a fully remote position, open to applicants in Nigeria.
• Overseeing policies, evaluating risks, supporting audits, regulatory obligations, third-party assessments, and fostering security awareness.
• Conducting audits to identify risk areas, confirm the effectiveness of existing controls, and maintain continuous audit readiness.
• Acting as the Data Protection Officer (DPO) and spearheading the privacy program to ensure adherence to Data Privacy best practices within the organization.
• Reviewing and revising current information security policies, standards, procedures, and SOPs.
• Coordinating activities related to audit readiness and assisting both internal and external auditors.
• Leading the security awareness initiative and cultivating a security-first culture throughout the organization.
• Addressing regulatory inquiries, assessments, and keeping abreast of regulatory developments.
• Assuming responsibility for data protection processes and implementing enhancements.
• 3 - 6 years of experience in Cybersecurity Governance, Risk & Compliance (GRC), IT Audit, Risk Management, Data Protection, or a closely related cybersecurity field.
• Familiarity with security frameworks such as ISO 27001, NIST CSF, CIS, PCI DSS, SOC 2, and the ability to apply them effectively.
• Experience in implementing or maintaining certifications like ISO 27001, PCI DSS, SOC 2, or other comparable compliance programs.
• Background in conducting internal or external audits and an understanding of what constitutes strong audit evidence.
• Knowledge of privacy and data protection regulations such as NDPA, GDPR, UK GDPR, or other global privacy frameworks.
• Experience in performing vendor or third-party security risk evaluations.
• Proficiency in conducting risk assessments, identifying control deficiencies, and driving remediation efforts from initiation to completion.
• A passion for writing and maintaining clear, actionable security policies, standards, procedures, and documentation that can be easily implemented.
• Ability to communicate technical risks in a manner that business stakeholders can understand, facilitating informed decision-making.
• Highly organized, capable of managing multiple audits, risk assessments, and compliance projects without neglecting details.
• Strong relationship-building skills to collaborate across various internal teams to advance security initiatives.
• Naturally inquisitive, adept at asking insightful questions, and enthusiastic about understanding the workings of systems, technologies, and business processes.
• Willingness to take ownership of tasks and proactively seek out areas for improvement.
• Fully remote work opportunity with flexible working hours.
• Time Off That Respects Life.
• Genuine connections with colleagues.
Inova Health
VCA Animal Hospitals
Allied Benefit Systems
Grupo Boticário
Get handpicked remote jobs straight to your inbox weekly.