安全与技术风险分析师
Security & Technology Risk Analyst
我们是谁
Moniepoint Inc. 是非洲的一站式金融生态系统,自 2019 年以来,帮助 1000 万家企业和个人便捷地使用支付、银行、信贷和业务管理工具。
作为尼日利亚最大的商户收单机构,它支撑了该国大部分的销售点(POS)交易。通过其子公司,Moniepoint Inc. 每月为客户提供 220 亿美元的交易处理服务,同时保持盈利。
对 Moniepoint 是一个令人惊叹的工作场所的原因感到好奇吗?查看我们关于如何培养创新、团队合作和成长文化的帖子。
职位简介
我们正在寻找一位注重细节且具备严谨分析能力的安全与技术风险分析师,加入 Moniepoint 的信息安全保障团队。在这一职位上,您将负责识别、监控并报告我们金融科技生态系统中的安全和技术运营风险。您将把复杂的风险数据转化为可操作的情报,使高管层能够做出有依据的战略决策,同时确保我们的组织保持最高的合规标准和运营韧性。
作为一家金融科技公司,信任和安全是我们的品牌基础。您的工作直接有助于 Moniepoint 安全拓展新市场、推出创新产品,并维持客户和利益相关者的信心。
主要职责:
在安全和技术领域(云、网络、基础设施、产品、终端设备、第三方)进行全面的风险评估,使用 NIST 风险管理框架、FAIR 方法论以及定性和定量分析方法。
● 对关键系统进行业务影响分析(BIA),确定恢复时间目标(RTO)和恢复点目标(RPO),并与流程负责人合作验证结果,并随着业务运营的变化持续维护文档。
● 管理和维护安全风险登记表,包含当前和历史记录,确保完整的文档和审计证据,以应对监管审查和内部/外部审计。
● 指导制定与企业风险偏好一致的风险处理计划,与跨职能利益相关者(工程、法律、DevOps、IT、安全)协作,确定优先级、执行策略,并将其整合到产品开发和运营流程中。
● 跟踪并验证风险缓解措施的执行情况
查看英文原文
Who we are
Moniepoint Inc. is Africa’s all-in-one financial ecosystem, helping 10 million businesses and individuals access seamless payments, banking, credit, and business management tools since 2019.
As Nigeria’s largest merchant acquirer, it powers most of the country’s Point of Sale (POS) transactions. Through its subsidiaries, Moniepoint Inc. processes $22 billion monthly for its customers while operating profitably.
Curious about what makes Moniepoint an incredible place to work? Check out posts on how we cultivate a culture of innovation, teamwork, and growth.
About the role
We are seeking a detail-oriented and analytically rigorous Security & Technology Risk Analyst to join our Information Security Assurance Team at Moniepoint. In this role, you will be instrumental in identifying, monitoring, and reporting on security and technology operational
risks across our fintech ecosystem. You will translate complex risk data into actionable intelligence that enables executive leadership to make informed strategic decisions while ensuring our organization maintains the highest standards of regulatory compliance and
operational resilience. As a financial technology company, trust and security are foundational to our brand. Your work directly contributes to Moniepoint's ability to safely expand into new markets, launch innovative products, and maintain the confidence of our customers and stakeholders.
Key Responsibilities:
Conduct comprehensive risk assessments across security and technology domains (cloud, network, infrastructure, product, endpoint, third-party) using NIST Risk Management Framework, FAIR methodology, and qualitative/quantitative analysis methods.
● Perform Business Impact Analysis (BIA) on critical systems to determine Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO), collaborating with process owners to validate findings and maintain documentation as business operations evolve.
● Administer and maintain the security risk register with current and historical records, ensuring comprehensive documentation and audit evidence for regulatory examinations and internal/external audits.
● Guide development and documentation of risk treatment plans aligned with enterprise risk appetite, collaborating with cross-functional stakeholders (Engineering, Legal, DevOps, IT, Security) on prioritization, execution strategies, and integration into product development and operational processes.
● Track and validate execution of risk treatment plans, monitoring completion rates, escalating delays, and ensuring residual risk remains within tolerance levels while adjusting plans as needed based on mitigation and remediation progress.
● Design and maintain quantifiable risk metrics across exposure measurement, control effectiveness assessment, and risk treatment progress tracking for executive decision-making, with continuous monitoring against organizational risk appetite thresholds via real-time dashboards and reporting.
● Analyze emerging threats and regulatory changes to proactively surface new risks and support strategic initiatives including market expansion and new product launches.
● Ensure all security and technology risk management activities adhere to applicable financial regulations, industry standards, and relevant frameworks (ISO 27001, SOC 2, PCI-DSS, NDPA, NIST, FAIR).
● Support security teams in evaluating third-party and vendor risks, ensuring alignment with organizational security standards and conducting ongoing risk assessments as part of the vendor management program.
● Communicate risk findings, assessments, and recommendations in business-relevant terms to stakeholders at all levels, translating technical risk concepts into actionable intelligence for executive leadership and operational teams.
Required Qualifications
● Bachelor's degree in Computer Science, Information Security, Risk Management, Engineering, or related field.
● 5+ years of professional experience in operational risk management, cybersecurity risk, or technology risk assessment.
● Demonstrated experience conducting risk assessments, threat analysis, or vulnerability management.
● Experience developing risk metrics, KPIs, or dashboards for executive audiences.
● Familiarity with risk management frameworks (e.g., NIST Cybersecurity Framework, ISO 27001 or similar)
● Experience in financial services, fintech, or regulated industries preferred.
● Proficiency in risk assessment methodologies and qualitative/quantitative analysis
● Knowledge of business continuity and disaster recovery planning principles
Preferred Qualifications
● Professional certifications: CISM, CRISC, or equivalent risk/security certification.
● Experience with fintech, banking, or other highly-regulated industries
What to expect in the hiring process
- A preliminary phone call with the recruiter
- A Panel Interview
- A behavioural and technical interview with a member of the Executive team.
Moniepoint is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees and candidates.