Information Security GRC Officer
Job description
About the role
You will own the end-to-end governance, risk, and compliance (GRC) lifecycle for the information security function at Paystack, driving alignment between technical security controls and enterprise objectives. You will act as the central subject matter expert, interpreting complex regulatory landscapes and translating them into actionable policies and standards that protect our business and customers. This role requires you to partner with leadership across the organization to embed security into strategic initiatives while maintaining a clear view of the evolving threat environment. You will design and monitor key risk indicators, evaluate the effectiveness of existing controls, and ensure that security governance keeps pace with business growth. Your work will directly influence the trust our merchants and stakeholders place in Paystack's ability to safeguard their data and transactions. By leveraging frameworks and proven methodologies, you will establish a resilient and auditable security posture that supports innovation.
Key facts
What you'll do
Conduct comprehensive risk assessments to identify, analyze, and prioritize information security risks across the organization.
Develop, maintain, and evolve the information security governance framework, ensuring policies and standards reflect best practices and regulatory requirements.
Establish and monitor key risk indicators (KRIs) and key control indicators (KCIs) to measure the effectiveness of the security program.
Perform independent testing and evaluation of internal controls to verify design integrity and operational effectiveness.
Map business processes to regulatory and contractual obligations, identifying gaps and implementing remediation plans.
Own the vendor risk management program, assessing third-party controls and ensuring compliance with security standards.
Coordinate with internal audit, legal, and compliance teams to streamline assessments and respond to inquiries efficiently.
Maintain a documented exception management process, tracking, reviewing, and escalating exceptions to senior leadership.
Implement security awareness training programs to foster a strong security culture across the organization.
Stay current with emerging threats, trends, and regulatory changes, advising the business on potential impacts and mitigation strategies.
Collaborate with security and technology teams to integrate security controls into products, services, and workflows.
Prepare executive-level reporting on the security posture, risk exposure, and compliance status for informed decision-making.
Leverage frameworks such as ISO 27001, NIST Cybersecurity Framework, and other relevant standards to guide control implementation.
Drive continuous improvement initiatives to mature the security governance program and respond to evolving business needs.
Requirements
You possess a bachelor's degree in information security, cybersecurity, information technology, or a closely related field.
You bring a minimum of five years of progressive experience in information security governance, risk, and compliance roles.
You have hands-on experience implementing and managing security frameworks such as ISO 27001, NIST Cybersecurity Framework, and Secure Controls Framework.
You demonstrate a thorough understanding of regulatory and compliance requirements relevant to financial services and payment platforms.
You have experience developing, publishing, and maintaining company-wide policies, standards, and procedures.
You are proficient in identifying control gaps and testing the design and implementation of existing security controls.
You can manage multiple priorities simultaneously while providing clear guidance and support to cross-functional teams.
You have a proven track record of managing and developing strong customer relationships, including interactions with senior management and stakeholders.
You communicate complex technical concepts clearly and effectively to both technical and non-technical audiences.
You operate with a high level of ownership, urgency, and drive, delivering results even in ambiguous situations.
You are comfortable working in a fast-paced, dynamic environment where priorities may shift rapidly.
You have experience leveraging cloud platforms and understanding the associated security and compliance considerations.
You maintain awareness of current information security trends, threats, and industry best practices.
Nice to have
Experience with automated risk and compliance tools to streamline monitoring and reporting activities.
Knowledge of payment industry standards and specific regulatory frameworks such as PCI DSS.
Practical notes
This is a full-time position based in Lagos. No specific working hours, travel requirements, visa needs, or application deadlines are provided in the source material.