Get Matched To Jobs You Qualify For, Automatically!

P

Internal Control Officer (Compliance, Information Security Officer, Enterprise Risk Mgt., Legal / Company Secretary and Executive Office/Special Assistant) at Pishon and Brooks Advisory Services

Pishon and Brooks Advisory Services
July 23, 2026
Full-time
On-site
JOB PURPOSE


The Compliance, Information Security, Enterprise Risk Management, Legal / Company Secretary and Executive Office Control Officer is responsible for providing independent control oversight and assurance across Compliance, Information Security, Enterprise Risk Management, Legal/Company Secretariat, Executive Office, and assigned subsidiary functions.
The role supports the effectiveness of the organization's governance and control framework through risk-based reviews, control testing, compliance monitoring, governance assessments, incident investigations, and advisory support. The incumbent works closely with business and control functions to ensure adherence to regulatory requirements, internal policies, governance standards, and industry best practices while supporting the achievement of organizational objectives.


DUTIES & RESPONSIBILITIES

Governance and Control Assurance


Lead risk-based control reviews across Compliance, Information Security, Enterprise Risk Management, Legal/Company Secretariat, Executive Office, and assigned subsidiary functions.
Assess the adequacy and effectiveness of governance frameworks, policies, procedures, and internal controls.
Conduct periodic control testing and independent reviews to evaluate compliance with approved standards and regulatory requirements.
Review governance structures, committee activities, policy administration processes, and decision-making frameworks to ensure compliance with corporate governance requirements.
Evaluate the effectiveness of whistleblowing, ethics, and governance-related processes and controls.
Monitor implementation of governance policies, standards, and control requirements across assigned functions and subsidiaries.


Compliance and Regulatory Oversight


Monitor compliance with applicable regulatory requirements, including CBN regulations, NDPR requirements, AML/CFT obligations, PCI DSS standards, ISO standards, and other relevant regulatory frameworks.
Review regulatory submissions, compliance reports, and control documentation for completeness and accuracy.
Track regulatory observations, audit findings, and compliance exceptions to ensure timely remediation.
Support reviews arising from regulatory examinations, audits, and governance assessments.
Escalate regulatory breaches, policy violations, and control deficiencies promptly.


Information Security and Risk Management Reviews


Perform control reviews of information security governance processes, cybersecurity controls, access management, data protection practices, and related risk management activities.
Assess compliance with information security policies, standards, and regulatory requirements.
Review enterprise risk management processes, risk registers, risk assessments, and mitigation plans for adequacy and effectiveness.
Monitor key risk indicators and control effectiveness across assigned functions.
Participate in investigations relating to security incidents, operational losses, fraud events, and governance breaches.


Subsidiary Control Assurance


Conduct periodic control reviews and assurance activities across assigned subsidiaries.
Review control reports, exception reports, unusual incident reports, and open-item reports received from subsidiaries.
Monitor implementation of group control frameworks, policies, and standards across subsidiary operations.
Validate the adequacy of control remediation activities and follow up on outstanding issues.
Support control environment assessments and control standardization initiatives across subsidiaries.


Advisory and Business Support


Provide control advisory support to Compliance, Information Security, Enterprise Risk Management, Legal/Company Secretariat, Executive Office, and subsidiary stakeholders.
Review new policies, governance initiatives, operational changes, and strategic projects from a control and risk perspective.
Support process improvement initiatives aimed at strengthening governance, compliance, and operational effectiveness.
Promote awareness of governance, risk, compliance, and control requirements across assigned functions.


Reporting and Stakeholder Management


Prepare control review reports, governance assessment reports, management reports, and exception reports.
Present findings, recommendations, and control observations to management and relevant stakeholders.
Track remediation activities and engage process owners to ensure timely resolution of identified issues.
Maintain effective working relationships with Compliance, Information Security, Enterprise Risk Management, Legal, Executive Office, Internal Audit, Risk Management, and subsidiary stakeholders.
Support the preparation of management, committee, and Board reports relating togovernance and control matters.


Continuous Improvement


Support the Head, Business & Shared Services Control in executing departmental initiatives, projects, and special assignments.
Identify opportunities for control enhancement, process optimization, and automation.
Contribute to the continuous improvement of governance and control practices across the organization and its subsidiaries.
Provide guidance and support to junior team members where required.


KEY PERFORMANCE INDICATORS


Quality and timeliness of control reviews and reports.
Timely closure of audit, regulatory, and control exceptions.
Number and significance of governance and control issues identified.
Reduction in control incidents, policy breaches, and regulatory infractions.
Effectiveness of remediation monitoring and issue resolution.
Compliance with regulatory and governance requirements.
Quality of subsidiary control oversight and reporting.
Timeliness of incident escalation and reporting.
Stakeholder satisfaction and engagement.
Contribution to governance and control environment improvements.


REQUIREMENTS

Education: Bachelor's Degree or HND in Accounting, Finance, Economics, Business Administration, Law, Information Systems, Risk Management, or a related discipline.

Professional Certifications


ACA, ACCA, CISA, CIA, CRISC, ISO 27001 Lead Implementer/Auditor, CFE, or equivalent professional certification.
Additional governance, risk management, compliance, information security, or audit certifications will be an added advantage.


Experience:


Minimum of 6 years' relevant experience in Internal Control, Internal Audit, Compliance, Enterprise Risk Management, Information Security Governance, Operational Risk, or Corporate Governance.
Experience within fintech, banking, financial services, payments, or other regulated industries is strongly preferred. Demonstrated experience conducting independent control reviews, governance assessments, investigations, and risk-based reviews.


Skill/Competencies:


Strong knowledge of corporate governance principles, internal control frameworks, and risk management practices.
Good understanding of compliance management, information security governance, enterprise risk management, and regulatory requirements.
Strong analytical, investigative, and problem-solving skills.
Excellent report writing and presentation skills.
Effective stakeholder management and communication skills.
Ability to evaluate processes and recommend practical control improvements.
Strong attention to detail and professional judgement.
Working knowledge of applicable financial services regulations and governance standards.
Proficiency in Microsoft Office applications and data analysis tools.
High level of integrity, professionalism, confidentiality, and sound judgement.

Get Matched To Jobs You Qualify For, Automatically!