Technology

Cybersecurity Analyst At First Ally

First Ally·Lagos, nigeria·Full Time·Contract
TechnologyFull TimeContract

About the Role

The Cybersecurity Analyst will be a key member of the IT team, responsible for safeguarding First Ally Capital's digital assets, infrastructure, and customer data across the Group and its subsidiaries. The analyst will monitor, detect, investigate, and respond to cybersecurity threats across our Microsoft 365 (M365) and Azure cloud environments, as well as our retail-facing application. This role requires a hands-on professional with strong analytical capability and a working knowledge of cloud security, endpoint protection, and application security.

Key Responsibilities

Security Monitoring & Threat Detection

  • Monitor security alerts and events from Microsoft Sentinel, Defender for Endpoint, and Defender for Cloud Apps (MCAS) on a continuous basis.
  • Analyse logs and telemetry from Azure Monitor, Microsoft 365 security centre, and the retail application to identify anomalies and potential intrusions.
  • Triage and investigate security incidents, determine root causes, and escalate appropriately to the IT Manager.
  • Maintain and fine-tune detection rules, alert thresholds, and SIEM correlation queries to reduce false positives.

Identity & Access Management (IAM)

  • Administer and enforce Microsoft Entra ID (Azure AD) policies including Conditional Access, Privileged Identity Management (PIM), and Multi-Factor Authentication (MFA).
  • Conduct periodic user access reviews and entitlement assessments across M365, Azure subscriptions, and the retail app.
  • Detect and investigate suspicious sign-in activity, compromised credentials, and identity-based attacks.
  • Enforce least-privilege principles and Role-Based Access Control (RBAC) across all platforms.
  • Cloud Security (Microsoft Azure & M365)
  • Manage and improve the security posture of the company's Azure environment using Microsoft Defender for Cloud and the Azure Security Benchmark.
  • Conduct regular reviews of Azure Policy, security recommendations, and compliance scores in Microsoft Secure Score.
  • Ensure proper configuration of M365 services including Exchange Online Protection (EOP), Safe Links, Safe Attachments, and Data Loss Prevention (DLP) policies.
  • Review and harden Azure networking components including NSGs, Azure Firewall rules, and Private Endpoints.

Retail & Core Application Security

  • Collaborate with the application development team to integrate security into the SDLC (Secure-by-Design).
  • Perform and coordinate vulnerability assessments and DAST/SAST scans on the retail and banking application.
  • Monitor application logs for suspicious activity, injection attempts, authentication abuse, and API misuse.
  • Assist in managing Web Application Firewall (WAF) rules and API gateway security policies.
  • Track and follow up on remediation of identified application vulnerabilities within agreed SLAs.

Vulnerability Management & Patch Compliance

  • Run regular vulnerability scans using Microsoft Defender Vulnerability Management or third-party tools across endpoints, servers, and cloud workloads.
  • Track remediation status and produce dashboards showing patch compliance levels for servers, endpoints, and SaaS platforms.
  • Liaise with system administrators and vendors to prioritise and close critical vulnerabilities.

Incident Response & Forensics

  • Participate in the investigation, containment, eradication, and recovery phases of security incidents.
  • Document incident timelines, findings, and lessons learned in structured post-incident reports.
  • Support forensic data collection and preservation following confirmed incidents.
  • Maintain and update the Incident Response Playbooks tailored to M365 and Azure threat scenarios.

Compliance & Policy

  • Support compliance with relevant regulations and frameworks applicable to Nigerian financial institutions (e.g., CBN Cybersecurity Framework, NDPR, ISO 27001, PCI-DSS where applicable).
  • Assist with internal and external security audits by gathering evidence and coordinating remediation actions.
  • Maintain up-to-date security documentation, policies, standards, and procedures.

Endpoint & Email Security

  • Manage Microsoft Defender for Endpoint policies onboarding, configuration, and response actions.
  • Investigate email-based threats including phishing, Business Email Compromise (BEC), and malware delivery via M365 Defender and Threat Explorer.
  • Enforce and review Intune/Endpoint Manager device compliance and configuration Profiles

Qualifications & Experience

Education

  • Bachelor's degree in Computer Science, Information Security, Cybersecurity or a related field.

Required Experience

  • Minimum of 3 - 5 years of hands-on experience in a cybersecurity or IT security role.
  • Demonstrable experience working with Microsoft 365 security tools (Defender suite, Purview, Secure Score).
  • Practical exposure to Microsoft Azure security services (Defender for Cloud, Sentinel, Entra ID, Azure Policy).
  • Experience with vulnerability assessment tools and understanding common CVEs and exploitation techniques.
  • Familiarity with web/mobile application security concepts (OWASP Top 10, API security).
  • Working knowledge of KQL (Kusto Query Language) for creating Sentinel search queries, workbooks, and custom analytics rules (highly preferred).

Preferred Certifications

  • Microsoft Certified: Azure Security Engineer Associate (AZ-500)
  • Microsoft Certified: Security Operations Analyst Associate (SC-200)
  • CompTIA Security+
  • Certified Ethical Hacker (CEH) or equivalent

Technical Skills

CATEGORY / TOOLS / TECHNOLOGIES

  • Microsoft 365 Security Microsoft Defender for Endpoint, Defender for Office 365, Purview DLP, Compliance Centre, Secure Score, Threat Explorer
  • Azure Cloud Security Microsoft Sentinel (SIEM/SOAR), Defender for Cloud,
  • Entra ID (Conditional Access, PIM, MFA), Azure Policy, NSGs, Azure Firewall
  • Identity & Access RBAC, Privileged Identity Management, Zero Trust
  • Architecture, SSO, SAML/OAuth 2.0
  • Application Security OWASP Top 10, DAST/SAST tools, WAF management,
  • API security, SDLC integration
  • Endpoint & Device Mgmt Microsoft Intune, Defender for Endpoint, Windows Defender policies
  • Vulnerability Mgmt Microsoft Defender Vulnerability Mgmt, Nessus / Qualys (desirable), CVSS scoring
  • Networking TCP/IP, DNS, HTTP/S, VPN, Firewall rules, Zero Trust networking
  • Scripting & Automation PowerShell, KQL (Kusto Query Language) for
  • Sentinel/Log Analytics advantageous

Key skills

BA/BSc/HNDProfessional Certificate

At a glance

Company

First Ally

Location

Lagos, nigeria

Employment

Full Time

Experience

Valid until

Not specified

Created

July 24, 2026

More opportunities

Similar roles you might like

Cybersecurity Analyst At Proforce Limited

Proforce Limited

Lagos, nigeria

full-time

Job Summary Are you passionate about protecting digital assets and staying ahead of evolving cyber threats? We are seeking a proactive and highly skilled Cybersecurity Analyst to join our growing team. This is an exciting opportunity to work in a dynamic environment where innovation, security, and continuous improvement are at the heart of everything we do. Key Responsibilities Monitor, detect, investigate, and respond to cybersecurity incidents. Conduct vulnerability assessments and penetration testing. Implement and maintain security controls, policies, and best practices. Analyze security logs and monitor network traffic for suspicious activities. Perform digital forensic investigations when security incidents occur. Manage endpoint security solutions, firewalls, antivirus, and intrusion detection/prevention systems. Conduct security awareness training for employees. Ensure compliance with cybersecurity standards, regulatory requirements, and company policies. Prepare security reports, risk assessments, and incident documentation. Stay informed about emerging threats, vulnerabilities, and cybersecurity trends. Requirements Bachelor's Degree in Computer Science, Cybersecurity, Information Technology, or a related discipline. 3 - 4 years of relevant cybersecurity experience. Strong knowledge of network security, operating systems, and cloud security. Hands-on experience with SIEM tools, firewalls, endpoint protection, and vulnerability management solutions. Experience in incident response and digital forensics is an added advantage. Professional certifications such as CompTIA Security+, CEH, CySA+, CISSP, CISM, or equivalent are highly desirable. Excellent analytical, problem-solving, and communication skills. Ability to work independently and collaboratively within a team.

3 hours ago

Managed Security Services (mss) Cybersecurity Analyst At Ethnos Cyber Limited

Ethnos Cyber Limited

Lagos, nigeria

full-time

Job Description We are seeking a Cybersecurity Analyst to join our Managed Security Services (MSS) team. The successful candidate will play a key role in monitoring security environments, investigating alerts, responding to security incidents, supporting VAPT activities, and ensuring that assigned security tasks are completed accurately and within defined SLA timelines. This role is ideal for a cybersecurity professional who is analytical, detail-oriented, responsive, and passionate about detecting and responding to cybersecurity threats. Responsibilities: Execute comprehensive penetration tests across Web (APIs, REST, GraphQL), Mobile (iOS & Android), Network infrastructure, and Cloud environments (AWS, Azure, GCP). Identify and exploit business logic flaws, OWASP Top 10 vulnerabilities, API security risks, network misconfigurations, and cloud IAM permission gaps. Conduct reverse engineering, static/dynamic analysis, and security assessments on iOS and Android mobile binaries. Simulate adversary tactics, techniques, and procedures (TTPs) to assess security posture and defensive coverage. Produce detailed technical reports with proof-of-concept exploits, risk ratings, and actionable remediation steps for technical and non-technical stakeholders. Assist the Security Operations Center (SOC) with real-time threat monitoring, alert analysis, threat hunting, and SIEM rule tuning. Conduct digital forensic investigations into security incidents, analyzing disk images, memory dumps, system artifacts, and network logs to establish root cause and attack timelines. Support incident response teams during active breaches by analyzing attack vectors and containing security threats. Collaborate with software developers, DevOps, and system administrators to validate security patches and ensure effective vulnerability remediation. Mentor junior analysts and security engineers in offensive security practices, incident analysis, and threat detection techniques. Qualifications: Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Information Systems, or a related field. 2-4 years of relevant experience in cybersecurity, security monitoring, incident response, VAPT, or a related role. Practical experience in analyzing security alerts and investigating cybersecurity incidents. Working knowledge of VAPT processes and security testing methodologies. Experience with SIEM, security monitoring, incident management, or ticketing tools. Good understanding of network security, endpoint security, vulnerabilities, and common cyberattack techniques. Ability to produce clear, accurate, and well-structured technical reports. Strong understanding of incident response procedures and security escalation processes. Ability to work effectively within established security playbooks and operational procedures.

25 days ago

Cybersecurity Analyst At Netzence Sustainability Limited

Netzence Sustainability Limited

Lagos, nigeria

full-time

Role Summary The Cybersecurity Specialist is responsible for strengthening Netzence's security posture through proactive threat management, incident leadership, and continuous improvement of security controls. This role takes ownership of cybersecurity operations, risk mitigation, and audit readiness across applications, infrastructure, and cloud environments. The Cybersecurity Specialist partners closely with Engineering, DevOps, Compliance, and Operations teams to embed security into product development, platform design, and business processes while supporting resilience, regulatory compliance, and customer trust. FinTech experience is mandatory. Key Responsibilities Threat Prevention & Risk Management Proactively identify, assess, and mitigate cybersecurity risks and attack vectors. Lead vulnerability assessments, penetration testing, and remediation planning. Review system architecture and recommend security control enhancements. Incident Response & Recovery Lead or coordinate cybersecurity incident investigations and containment activities. Oversee incident response, recovery efforts, and post-incident reviews. Produce detailed incident reports and drive corrective and preventive actions. Audit Readiness & Regulatory Compliance Own security audit preparation, evidence management, and audit redress. Maintain and enhance security policies, standards, and procedures. Ensure alignment with regulatory, contractual, and industry security requirements. Security Leadership & Improvement Promote a strong security culture and awareness across the organization. Provide expert guidance on secure development, cloud security, and operational practices. Advise stakeholders on cybersecurity risks, controls, and business impact. Continuously improve security tooling, processes, and control effectiveness. Requirements Bachelor's degree in computer science, Information Security, or a related field. 4 - 7 years of experience in cybersecurity or information security roles. Proven experience in fintech, financial services, or complex technology environments. Strong knowledge of security frameworks, tools, and best practices. Demonstrated experience leading incident response and security initiatives. Strong analytical, investigative, and decision-making capabilities. Ability to clearly communicate security risks to both technical and non-technical stakeholders. Relevant certifications (e.g., CISSP, CISM, CEH, ISO 27001) are an advantage.

a month ago

Cybersecurity Specialist At Netzence Sustainability Limited

Netzence Sustainability Limited

Lagos, nigeria

full-time

Role Summary The Cybersecurity Analyst is responsible for monitoring, detecting, and responding to cybersecurity threats across Netzence's systems, applications, and infrastructure. This role focuses on day-to-day security operations, incident support, and continuous monitoring to ensure the confidentiality, integrity, and availability of systems and data. The Cybersecurity Analyst works closely with Engineering, DevOps, Compliance, and Operations teams to identify vulnerabilities, respond to security events, and support audit and regulatory requirements. FinTech experience is mandatory. Key Responsibilities Threat Monitoring & Detection Monitor security alerts, system logs, and vulnerability reports across platforms and infrastructure. Identify suspicious activity, potential threats, and security weaknesses. Support vulnerability assessments, security scans, and remediation efforts. Incident Response & Support Assist in investigating security incidents and supporting containment and recovery actions. Document incidents, findings, and lessons learned. Escalate high-risk security events in line with incident response procedures. Compliance & Audit Support Support internal and external security audits and assessments. Maintain security documentation, logs, and evidence for audit readiness. Assist in ensuring compliance with applicable security standards and regulatory requirements. Security Awareness & Continuous Improvement Support security awareness initiatives and internal training. Provide guidance on basic secure system and operational practices. Identify opportunities to improve monitoring, controls, and security processes. Requirements Bachelor's degree in computer science, Information Security, or a related field. 2 - 4 years of experience in cybersecurity, IT security, or security operations. Experience working in technology-driven or fintech environments is an advantage. Knowledge of cybersecurity fundamentals, security tools, and monitoring practices. Strong analytical and problem-solving skills. Ability to document and communicate security findings clearly.

a month ago

Cybersecurity Analyst At First Ally
Lagos, nigeria
Apply