P

Governance & Policy Analyst

Easy apply New Additional Questions

Job summary

The Governance & Policy Analyst supports the development and maintenance of the organisation’s information security governance framework policies, risk register, compliance activities, and reporting. The role works closely with control owners, business units, and auditors to keep documentation current, findings tracked, and governance improving.

Min Qualification: Degree Experience Level: Mid level Experience Length: 3 years Language Requirement: English Working Hours: Full Time - 8 to 5 Applicant Location: Nigeria

Job descriptions & requirements

Responsibilities:

Governance & Policy:

  • Assist in drafting, reviewing, and maintaining information security policies, standards, procedures, and guidelines.
  • Map policies and controls against recognised frameworks (ISO/IEC 27001, PCI DSS) and flag gaps.
  • Maintain documentation of security governance structures, roles, and responsibilities.


Risk Management:

  • Support enterprise information security risk assessments and the development of risk treatment plans.
  • Maintain the security risk register and follow up with control owners on remediation status.
  • Prepare risk documentation to help business units evaluate mitigation, acceptance, transfer, or avoidance.


Compliance & Regulatory Assurance:

  • Support compliance activities across applicable laws, regulations, and contractual requirements (NDPR, PCI DSS, ISO 27001).
  • Coordinate evidence collection and logistics for internal and external audits, assessments, and certifications.
  • Track audit findings and compliance gaps to closure.


Metrics & Reporting:

  • Maintain security governance KPIs, KRIs, and dashboards.
  • Compile security posture reports for management, risk committees, and auditors.
  • Provide inputs into executive and board-level reporting.


Third-Party & Vendor Security:

  • Support third-party security risk assessments and due diligence reviews.
  • Review supplier security questionnaires and assist in assessing contractual security clauses.
  • Monitor ongoing compliance of critical vendors and escalate exceptions.


Awareness & Continuous Improvement:

  • Support delivery of security awareness and policy training initiatives.
  • Monitor regulatory changes and emerging governance trends, and summarise impact.
  • Contribute to improving governance processes and control maturity.


Requirements:

  • Bachelor’s degree in information security, computer science, information technology, or a related field.
  • Minimum of 3 years’ experience in information security governance, risk, and compliance (GRC), or in IT audit / internal control with GRC exposure.
  • Working knowledge of at least one recognised framework (ISO 27001, NDPR, PCI DSS).
  • Understanding of risk management methodologies and control frameworks.
  • Exposure to audits, compliance reviews, or regulatory assessments.
  • Strong documentation, analytical, and stakeholder communication skills.
  • Reliable internet connection and a suitable home work setup for remote delivery.


Added Advantage:

  • Familiarity with GRC tools or platforms.
  • Progress toward a relevant certification (ISO 27001 LI/LA, CISA, CRISC, Security+).
  • Experience in financial services, fintech, or telecommunications.

Important safety tips

  • Do not make any payment without confirming with the Jobberman Customer Support Team.
  • If you think this advert is not genuine, please report it via the Report Job link below.

This action will pause all job alerts. Are you sure?

Cancel Proceed

Similar jobs

Lorem ipsum

Lorem ipsum dolor (Location) Lorem ipsum Confidential
4 years ago

Stay Updated

Join our newsletter and get the latest job listings and career insights delivered straight to your inbox.

v2.homepage.newsletter_signup.choose_type

We care about the protection of your data. Read our

We care about the protection of your data. Read our  privacy policy .

Or your alerts