Get Matched To Jobs You Qualify For, Automatically!

P

Internal Control Officer (Network & User Administration, Data Center, Disruptions and It Security Control Officer) at Pishon and Brooks Advisory Services

Pishon and Brooks Advisory Services
July 23, 2026
Full-time
On-site
JOB PURPOSE


Network & User Administration, Data Center, Disruptions and IT Security Control is responsible for providing independent control oversight and assurance across network infrastructure, user administration, data centre operations, IT disruptions, and information security processes.
The role supports the effectiveness of the organization's IT and Operations Control framework through risk-based control reviews, IT control testing, operational risk assessments, information security reviews, incident investigations, and compliance monitoring. The incumbent works closely with Infrastructure, Information Security, Technology Operations, and Risk Management teams to ensure that technology services are secure, resilient, available, and compliant with regulatory and organizational requirements.


DUTIES & RESPONSIBILITIES

IT Infrastructure and Security Control Assurance


Lead risk-based control reviews across Network Administration, User Administration, Data Centre Operations, IT Security, and IT Service Operations.
Evaluate the adequacy and effectiveness of IT General Controls (ITGCs), infrastructure controls, and operational processes.
Conduct periodic walkthroughs and control testing to validate compliance with approved policies, procedures, and technology standards.
Review network security controls, firewall administration, endpoint protection, and infrastructure monitoring processes.
Assess user provisioning, de-provisioning, access reviews, privileged account management, and segregation of duties controls.
Review data centre operations, server administration, backup management, environmental controls, and physical security measures.


Information Security and Operational Risk Reviews


Review information security governance processes, cybersecurity controls, vulnerability management, and patch management activities.
Assess compliance with information security policies, data protection requirements, and regulatory obligations.
Review disaster recovery, business continuity, backup restoration, and resilience testing activities.
Monitor technology risk indicators and recommend improvements to strengthen operational resilience.
Participate in investigations relating to cybersecurity incidents, infrastructure failures, operational disruptions, fraud events, and control breaches.


Incident and Disruption Management


Review IT incident management, problem management, and root cause analysis processes.
Assess controls over system availability, service disruptions, outage management, and service recovery activities.
Monitor recurring operational incidents and recommend preventive control improvements.
Track implementation of corrective actions arising from operational incidents and post-incident reviews.
Escalate significant control weaknesses, security concerns, and operational risks to management.


Compliance and Governance


Monitor compliance with applicable regulatory requirements, including CBN guidelines, NDPR, PCI DSS, ISO 27001, COBIT, and other relevant standards.
Review audit findings, regulatory observations, vulnerability assessment reports, and penetration testing reports.
Track implementation of agreed remediation actions and validate their effectiveness.
Support internal, external, and regulatory audit activities relating to technology infrastructure and information security.
Promote adherence to technology governance and internal control requirements.


Reporting and Stakeholder Management


Prepare comprehensive control review reports, exception reports, and management reports.
Present findings, recommendations, and control observations to technology and business stakeholders.
Maintain effective working relationships with Infrastructure, Information Security, Technology Operations, Risk Management, Compliance, and Internal Audit teams.
Track remediation activities to ensure timely closure of identified issues.
Support the preparation of management reports relating to IT operational risk and control effectiveness.


Continuous Improvement


Support the Head, IT / Operations Control in executing departmental initiatives and strategic projects.
Identify opportunities for automation, control optimization, and operational efficiency improvements.
Contribute to the continuous enhancement of the IT and Operations Control framework.
Provide technical guidance and support to junior control officers where required


KEY PERFORMANCE INDICATORS


Quality and timeliness of IT control reviews and reports.
Timely closure of audit, regulatory, and control findings.
Reduction in recurring infrastructure and security control issues.
Timeliness of incident identification, escalation, and reporting.
Effectiveness of remediation monitoring and issue resolution.
Compliance with regulatory requirements and internal technology policies.
Improvement in IT General Control (ITGC) effectiveness.
Reduction in repeat audit findings and security vulnerabilities.
Stakeholder satisfaction with control advisory services.
Contribution to operational resilience and control enhancement initiatives.


REQUIREMENTS

Education: Bachelor's Degree in Computer Science, Information Technology, Information Systems, Cybersecurity, Engineering, or a related discipline.

Professional Certifications


CISA, CISM, CRISC, ISO 27001 Lead Implementer/Auditor, COBIT Foundation, ITIL, PCI DSS, or equivalent professional certification.
Additional certifications in Cybersecurity, Information Security, IT Governance, or Internal Audit will be an added advantage.


Experience:


Minimum of 5 - 6 years' relevant experience in IT Audit, IT Internal Control, Information Security, Technology Risk, Infrastructure Operations, or IT Governance.
Experience within fintech, banking, payment services, or other technology-driven organizations is preferred.
Demonstrated experience conducting IT control reviews, information security assessments, infrastructure audits, and operational risk reviews.


Skill/Competencies:


Strong knowledge of IT governance frameworks, including COBIT, COSO, and ISO 27001.
Good understanding of network infrastructure, user access management, data centre operations, and information security principles.
Knowledge of cybersecurity controls, disaster recovery, business continuity, and operational resilience.
Strong analytical, investigative, and problem-solving skills.
Excellent report writing and presentation skills.
Effective stakeholder management and communication skills.
Proficiency in Microsoft Excel, Power BI, SQL, ACL, IDEA, or similar audit and data analysis tools.
Ability to identify control weaknesses and recommend practical improvements.
High level of integrity, professionalism, confidentiality, and sound judgement.

Get Matched To Jobs You Qualify For, Automatically!