Chief Information Security Officer (CISO) at Remita
Remita
Role Overview
The Chief Information Security Officer (CISO) is the most senior security executive at Remita, responsible for defining and owning the organisation's information security strategy, cyber risk posture, regulatory compliance framework, and security culture across all technology platforms, products, business divisions, and third-party relationships. This individual reports directly to the Managing Director and maintains a reporting line to the Board Risk & Compliance Committee, ensuring that information security risk is visible, understood, and managed at the highest levels. The CISO will operate at the intersection of technology, risk, regulation, and business; building a security function that protects Remita's infrastructure, data, and reputation while enabling commercial growth.
Key Responsibilities
Security Strategy & Executive Leadership
Define and own Remita's enterprise-wide information security strategy and roadmap, aligned to the Company's commercial strategy, risk appetite, and regulatory obligations.
Serve as the primary security voice, translating complex cyber risk into clear, actionable intelligence for non-technical leadership and Board members.
Maintain the organisation's security operating model, including the Security Operations Centre (SOC), incident response, application security, infrastructure security, GRC, and identity & access management functions.
Establish Remita's security risk appetite in collaboration with senior executives, defining what risks are acceptable, which require mitigation, and which are transferable.
Champion a security-first culture across all business divisions, ensuring that security is embedded into product development, vendor selection, and strategic decisions; and not an afterthought.
Threat Intelligence & Security Operations
Lead and continuously mature the Security Operations Centre (SOC), ensuring 24/7 monitoring, detection, and response capability across all of Remita's environments.
Build and manage a threat intelligence programme that provides actionable, contextual intelligence on the threat actors, tactics, and vulnerabilities most relevant to Nigerian fintech and payment infrastructure.
Own the incident response framework including playbooks, escalation paths, communications protocols, and post-incident review processes; ensuring Remita can contain, recover from, and learn from security incidents at speed.
Oversee penetration testing, red team exercises, and vulnerability management programmes, whist ensuring findings are prioritised, tracked, and remediated within risk-proportionate timeframes.
Monitor the dark web, open-source intelligence (OSINT) channels, and financial sector threat sharing platforms for indicators of threats targeting Remita or its clients.
Application Security & Secure Development
Embed security into Remita's software development lifecycle (SDLC), implementing DevSecOps practices, automated security testing (SAST, DAST, SCA), and security code review as standard across all engineering teams.
Own the application security programme, including API security, mobile application security, and secure architecture reviews for all new products and major platform changes.
Partner with divisional technology leaders and engineering teams to establish secure coding standards, threat modelling practices, and security champions programmes that build security capability within development teams.
Ensure all payment APIs and partner integrations are designed and maintained to the highest security standards.
Infrastructure & Cloud Security
Own the security architecture for Remita's entire infrastructure footprint.
Define and enforce security baselines, hardening standards, and access controls across all infrastructure components — servers, databases, network, containers, and endpoints.
Lead the implementation and continuous improvement of zero-trust network architecture, micro-segmentation, and privileged access management (PAM) across the enterprise.
Ensure robust data security controls, including encryption at rest and in transit, data loss prevention (DLP), database activity monitoring, and data classification, for all customer and transactional data.
Oversee cloud security posture management (CSPM), ensuring cloud configurations are continuously assessed against security benchmarks and misconfigurations are remediated before they are exploited.
Identity, Access & Fraud Prevention
Partner with the Fraud, Risk, and Product teams to ensure that security controls at the transaction layer (including real-time fraud scoring, behavioural analytics, and anomaly detection), are technically sound and operationally effective.
Oversee the insider threat programme, ensuring that privileged user activity monitoring, data access logging, and behavioural analytics are in place to detect and respond to insider risk.
Governance, Risk & Regulatory Compliance
Own Remita's compliance with all applicable information security regulations and standards: CBN Cybersecurity Framework, PCI-DSS (Payment Card Industry Data Security Standard), NDPR (Nigeria Data Protection Regulation), ISO 27001, and applicable Visa/Mastercard security programme requirements.
Maintain Remita's ISO 27001 certification and drive continuous improvement of the Information Security Management System (ISMS).
Build and maintain a third-party and supply chain risk management programme, ensuring all vendors and technology partners with access to Remita's systems or data are assessed, monitored, and held to Remita's security standards.
Maintain and regularly test Remita's Business Continuity Plan (BCP) and Disaster Recovery Plan (DRP) from a security and cyber resilience perspective.
Provide regular, structured security risk reporting to the Board Risk & Compliance Committee, including threat landscape updates, incident trends, key risk indicators, and programme effectiveness metrics.
Security Culture & Awareness
Sustain and run an enterprise-wide security awareness and training programme, making sure that all employees, contractors, and third parties understand their security responsibilities and can recognise and respond to threats (phishing, social engineering, insider risk).
Work with HR and business leadership to embed security behaviours into onboarding, performance frameworks, and disciplinary processes.
Represent Remita in the Nigerian and broader African financial services security community; engaging with regulators, industry bodies, and peer organisations on threat intelligence sharing and industry security standards.
Required Qualifications & Experience
Minimum of 15 years of progressive information security experience, with at least 5 years in a senior security leadership role (CISO, Deputy CISO, Head of Information Security, or equivalent) within financial services, fintech, payments, or a comparably regulated and high-stakes industry.
Deep, hands-on expertise across the full security domain: threat intelligence, incident response, penetration testing, application security, cloud security, IAM, cryptography, and regulatory compliance.
Experience securing payment switching infrastructure, card processing environments, or real-time payment platforms.
Familiarity with the MITRE ATT&CK framework, NIST Cybersecurity Framework, and their application to financial services threat modelling.
Experience with AI/ML-based security tooling — including anomaly detection, fraud scoring, and automated threat response — and awareness of the emerging security risks introduced by AI in financial services.
Strong knowledge of the CBN Cybersecurity Framework, NDPR, and the regulatory obligations of a licensed payment service provider in Nigeria.
Internationally recognised security certifications: CISSP, CISM, or equivalent.
Bachelor's degree in Computer Science, Information Security, Engineering, or a closely related field. Master's degree or MBA preferred.
Core Competencies
Strategic & Business Acumen: Thinks and communicates in risk and business terms, not just technical terms.
Technical Depth: Maintains genuine, current technical depth across the security domain, not just managerial oversight.
Leadership & Influence: Builds high-performing security teams and commands credibility and trust with stakeholders.
Integrity & Crisis Leadership: Operates with absolute integrity whilst staying calm and decisive under pressure.