1,338,985open jobs
78,444companies
206,994added this week
Browse all
Salary
≈ $74k – $171k per year (Estimated)
Location
Hybrid (Lagos, Nigeria)
Seniority
Senior · 6+ years exp
Employment
Full-Time

Confirmed on the employer's own hiring board on Oct 8, 2026. First seen by Alion on Sep 17, 2026.

Overview
Company
Impact
Profile match
We are building Africa's leading embedded finance business by integrating credit into supply chains and payment flows of our partners, unlocking financial success for individuals and businesses.

To design, implement and continuously improve the technical security controls that protect the organization's AWS cloud estate, Kubernetes (EKS) platform, software delivery pipelines and data stores; and to provide expert detection, response and assurance capability that keeps the organization's digital services resilient, auditable and compliant with CBN, PCI DSS, ISO 27001 and NDPR requirements.

Responsibilities

RESPONSIBILITIES:

Cloud and Security Engineering:

  • Design, implement and maintain preventive and detective security controls across all AWS accounts, including AWS Organizations service control policies, AWS Config rules and conformance packs, AWS WAF and AWS Shield.
  • Enforce least privilege through IAM roles, permission boundaries, IAM Identity Center and IAM Access Analyzer; drive the elimination of long-lived access keys in favour of federated and role-based access.
  • Own AWS Secrets Manager end to end - secret lifecycle, automatic rotation, resource and cross-account policies - and lead the removal of hard-coded credentials from application code, manifests and pipelines.
  • Configure and maintain organization-wide AWS CloudTrail (including data and management events), CloudWatch log groups, metric filters, alarms and retention aligned to regulatory record-keeping requirements.
  • Implement AWS Config baselines with automated drift detection and remediation against CIS AWS Foundations and PCI DSS benchmarks.
  • Manage AWS WAF rule sets, rate limiting, bot control and geo restrictions for internet-facing applications behind CloudFront and ALB, and tune rules to minimise false positives without weakening protection.
  • Operate Amazon GuardDuty, AWS Security Hub, Amazon Inspector and Amazon Detective as a single triage workflow - from finding, to enrichment and root-cause investigation, to verified closure.
  • Define and review secure landing zone and VPC network patterns (segmentation, private subnets, VPC endpoints, security groups, managed prefix lists) and assess new architectures against them.

Kubernetes & Container Security (Amazon EKS):

  • Harden EKS clusters: private API endpoints, control plane audit logging to CloudWatch, node group hardening, and timely patching of cluster versions and node AMIs.
  • Design, implement and periodically review Kubernetes RBAC, namespace isolation, service accounts and IAM Roles for Service Accounts (IRSA) / EKS Pod Identity.
  • Enforce Pod Security Standards, admission control policy (OPA Gatekeeper or Kyverno) and Kubernetes network policies to restrict east-west traffic.
  • Secure the container supply chain - approved base images, ECR and Amazon Inspector image scanning, image signing and admission-time signature verification.
  • Deploy and tune runtime threat detection for containers (GuardDuty EKS Runtime Monitoring, Datadog Cloud Security Management) and investigate detections through to resolution.
  • Secure secret delivery into workloads using the External Secrets Operator or Secrets Store CSI driver backed by AWS Secrets Manager, removing plaintext secrets from manifests and Helm values.

Security Monitoring, Detection & Incident Response (Datadog):

  • Build and maintain detection coverage in Datadog Cloud SIEM - log pipelines, detection rules, signal correlation, suppression tuning and security dashboards.
  • Operate Datadog Cloud Security Management (misconfiguration, identity and workload risk) and Application Security Management (runtime protection and vulnerability detection) alongside native AWS security services.
  • Configure Datadog Sensitive Data Scanner to detect and redact PII and cardholder data in logs and telemetry.
  • Ensure complete, tamper-evident log coverage across AWS, EKS, applications and databases, with defined retention, archiving and log integrity controls.
  • Lead technical security incident response - triage, containment, eradication, recovery and post-incident review - and maintain runbooks, escalation paths and tabletop exercises.
  • Define, track and report security metrics and posture trends to management and risk committees.

Data & Database Security:

  • Enforce encryption at rest and in transit across RDS, Aurora, DocumentDB, DynamoDB, S3, EBS and EFS using AWS KMS, with defined key policies, rotation and separation of duties.
  • Implement IAM database authentication and Secrets Manager-driven credential rotation; remove shared, static and over-privileged database accounts in favour of least-privilege roles.
  • Enable, centralise and monitor database audit logging (RDS and Aurora audit logs, DocumentDB auditing, SQL Server audit, CloudTrail data events) within the central log platform.
  • Apply data classification, masking or tokenisation and access controls for sensitive and regulated data, and support data loss prevention requirements.
  • Eliminate public database exposure - private subnets, restrictive security groups, no public accessibility - and validate backup and snapshot encryption, snapshot sharing controls and restore testing.
  • Review database migrations, schema changes and access grants for security impact before approval.

Governance, Risk & Compliance:

  • Translate CBN cybersecurity framework, PCI DSS, ISO 27001, NIST CSF and NDPR requirements into enforceable technical controls and repeatable evidence.
  • Maintain security standards, secure configuration baselines and control documentation, and support internal and external audits with automated evidence collection.
  • Conduct security assessments, vulnerability management cycles and configuration reviews; coordinate penetration testing and track remediation to closure.
  • Perform security reviews of third-party vendors, SaaS integrations and exposed APIs
  • Contribute to risk register maintenance, security exception management and management reporting.

Collaboration, Enablement & Technical Leadership:

  • Act as senior security advisor to infrastructure, platform, DevOps and application teams during architecture, design and change reviews.
  • Mentor junior security and platform engineers, and raise the standard of security code and configuration review across engineering.
  • Automate recurring security operations using Python, Bash, Terraform and AWS-native tooling to reduce manual effort and human error.
  • Deliver targeted, role-relevant security training for engineering teams covering secure coding, secrets handling and incident escalation.

Requirements

  • Bachelor's degree in Computer Science, Information Security, Engineering or a related discipline.
  • Professional certification is strongly preferred, for example: AWS Certified Security - Specialty, Certified Kubernetes Security Specialist (CKS), CISSP, CISM, CCSP, OSCP, or GIAC certifications (GCSA, GCIH, GWAPT, GCLD).
  • Minimum of 6-8 years' experience in cybersecurity or security engineering, including at least 4 years securing production AWS workloads and at least 2 years securing Kubernetes (preferably Amazon EKS) and CI/CD pipelines.
  • Demonstrable, hands-on experience implementing cloud, container, pipeline and database security controls in a regulated environment; financial services experience is an advantage.
  • Proven track record of leading security incident investigations and remediation in production environments

COMPETENCIES REQUIREMENTS:

Technical:

  • Deep, hands-on AWS security expertise: IAM, KMS, Secrets Manager, CloudTrail, CloudWatch, AWS Config, WAF and Shield, GuardDuty, Security Hub, Inspector, Detective and VPC network security.
  • Strong Kubernetes and Amazon EKS security skills: RBAC, IRSA, Pod Security Standards, admission controllers (OPA Gatekeeper or Kyverno), network policies, image scanning, image signing and runtime security.
  • Practical experience implementing SCA, SAST, DAST, secret scanning and IaC scanning within GitHub Actions, and enforcing branch protection rules, rulesets and OIDC-based pipeline authentication.
  • Working knowledge of Datadog security capabilities: Cloud SIEM, Cloud Security Management, Application Security Management, Sensitive Data Scanner, log pipelines and dashboards.
  • Database security across RDS, Aurora, DocumentDB, SQL Server and NoSQL stores: encryption and key management, IAM authentication, audit logging, masking and least-privilege access.
  • Infrastructure as code and automation: Terraform, Helm and GitOps workflows, with proficient scripting in Python and Bash.
  • Solid grounding in security frameworks and regulation: CBN cybersecurity guidelines, PCI DSS, ISO 27001, NIST CSF, NDPR and GDPR; threat modelling (STRIDE) and MITRE ATT&CK.
  • Vulnerability management, incident response and digital forensics fundamentals.

Behavioural:

  • Strong analytical and problem-solving skills, with sound risk judgement and the ability to prioritise what matters most.
  • Excellent written and verbal communication; able to explain technical risk to non-technical stakeholders and influence engineering teams without direct authority.
  • Ownership mindset - detail-oriented, proactive and persistent in identifying and closing control gaps.
  • Pragmatic and collaborative; balances security rigour against delivery velocity.
  • Calm, structured and decisive under incident pressure.
  • Coaching and knowledge-sharing orientation, with a commitment to raising security capability across the organization.

Benefits

At Credit Direct Limited, we value our employees and strive to provide a comprehensive benefits package that recognizes their contributions and supports their well-being. As part of our commitment to a positive work environment, we offer the following benefits:

Competitive Salary: We offer a competitive salary structure that is commensurate with industry standards and recognizes the skills and experience of our employees.

Quarterly Performance Pay: We recognize and reward exceptional performance. Our quarterly performance pay program allows employees to earn additional compensation based on their individual and team achievements.

Transport Subsidy: We understand the importance of accessible transportation for our employees. To assist with commuting expenses, we provide a transport subsidy to help alleviate the financial burden associated with travel to and from work.

Staff Bus: We offer a convenient and reliable staff bus service for eligible employees, ensuring a comfortable and stress-free commute to the workplace.

Hybrid Work: We believe in providing flexibility and work-life balance. Our hybrid work policy allows eligible employees to work remotely for a certain number of days per week, promoting a healthy work-life integration.

13th Month Salary: As an additional financial benefit, we provide a 13th-month salary to our employees. This extra payment, usually received at the end of the year, serves as a bonus and acknowledges their dedication and commitment throughout the year.

Leave Allowance: We recognize the importance of taking time off for rest and relaxation. In addition to annual leave entitlement, we provide a leave allowance to eligible employees, offering financial support during their vacation time.

Profit Sharing: We believe in sharing our success with our employees. Through our profit-sharing program, eligible employees have the opportunity to receive a share of the company's profits, providing an additional incentive for their dedication and hard work.

These benefits are designed to support our employees' financial well-being, work-life balance, and professional growth. We continuously review and enhance our benefits package to ensure that it remains competitive and aligned with the needs and preferences of our valued employees.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
1,338,985 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
Lagos
≈ $88k – $164k per year (Estimated) • Hybrid • Full-Time • London
DevOps
Terraform
Azure DevOps
GitHub Actions
CloudFormation
GitLab CI
Azure
CI/CD
Jenkins
AWS
Docker
Kubernetes
Bicep
Cybersecurity
ISO 27001
OWASP Top 10
Apply
≈ $85k – $159k per year (Estimated) • Hybrid • Full-Time • London
DevOps
GCP
Azure
AWS
Cybersecurity
ISO 27001
PCI DSS
Microsoft Defender for Cloud
Microsoft Entra ID
Active Directory
SIEM
DLP
Apply
$100k – $150k per year • Remote (United States) • Full-Time
AI/ML
LLM
DevOps
CI/CD
Cybersecurity
OWASP Top 10
Management
Agile
Apply
$36k per year • In office • Internship • Beverly Hills
Python
TypeScript
AI/ML
Cursor
Claude
ChatGPT
AI Agents
Mobile
RevenueCat
DevOps
GCP
Cloudflare
SLI/SLO/SLA
GitHub
Cybersecurity
Okta
SOC 2
Least Privilege
Management
Slack
Google Workspace
Apply
≈ $17k – $46k per year (Estimated) • In office • Manila
Apply
In office • Full-Time • Master's Degree • Mumbai
Python
JavaScript
TypeScript
SQL
C#
Python
FastAPI
Pydantic
C#
ASP.NET Core
Databases
PostgreSQL
pgvector
OpenSearch
AI/ML
Copilot
Cursor
LangGraph
LangChain
Prompt Engineering
Function Calling
AI Agents
LLM
RAG
Structured Outputs
Tool Use
Frontend
Next.js
React.js
DevOps
Platform Engineering
QA
Pytest
Apply
≈ $12k – $27k per year (Estimated) • Hybrid • Full-Time • 5+ years exp • Bachelor's Degree • Chennai • Pune
Python
Java
SQL
C#
Mobile
JUnit
DevOps
GCP
Azure DevOps
GitLab CI
Azure
CI/CD
Jenkins
Git
AWS
Docker
Kubernetes
Management
Agile
QA
TestNG
Selenium
Cucumber
JMeter
Swagger
Postman
Pytest
Apply
≈ $51k – $110k per year (Estimated) • Hybrid • Master's Degree • Canada
Java
SQL
DevOps
SLI/SLO/SLA
Management
ServiceNow
Apply
Remote (United States)
Python
Apply
AI Engineer - K1 5 days ago
≈ $120k – $264k per year (Estimated) • In office • Bachelor's Degree • Manhattan Beach
Python
JavaScript
AI/ML
Copilot
Claude
Prompt Engineering
Anthropic
Agentic Workflows
Copilot Studio
Management
Power Automate
SharePoint
Apply
≈ $29k – $55k per year (Estimated) • In office • Contractor • Kaduna
Apply
≈ $35k – $100k per year (Estimated) • Hybrid • Full-Time • 3+ years exp • Bachelor's Degree • Lagos
Apply
Hybrid • Full-Time • 12+ years exp • Bachelor's Degree • Lagos
DevOps
Rest API
Apply
In office • Full-Time • Master's Degree • Lagos
Apply
Business Developer 10 hours ago
In office • Full-Time • Lagos
Apply
Forklift Driver 10 hours ago
≈ $23k – $57k per year (Estimated) • In office • Full-Time • Lagos
Apply
Technical Supervisor 11 hours ago
≈ $41k – $117k per year (Estimated) • In office • Full-Time • Lagos
Apply
Electrical Supervisor 11 hours ago
≈ $41k – $117k per year (Estimated) • In office • Full-Time • Lagos
Apply
See all jobs
This is one of many
1,338,985 more open roles from verified company boards, updated every day.