Role Overview
You will join a dedicated security function that protects one of Africa’s leading payment platforms, working across governance, risk, and compliance to keep both internal operations and customer trust intact. On a typical day, you will evaluate control effectiveness, map regulatory requirements to practical safeguards, and partner with engineering, product, and business teams to turn security guidance into clear, actionable standards. Your work matters because Paystack operates across multiple markets with different data protection expectations, and your ability to translate complex frameworks into everyday decisions helps the company move quickly without exposing customers or partners to unnecessary risk.
Key Responsibilities
- Shape and maintain the company-wide security strategy by aligning governance, risk, and compliance activities with Paystack’s broader business goals.
- Assess existing security controls by testing their design and implementation, then identify gaps and recommend concrete improvements to reduce risk across the platform.
- Translate regulatory and framework requirements—including ISO 27001, NIST, and the Secure Controls Framework—into practical, actionable policies and standards that teams can follow without friction.
- Own and manage specific parts of the security program, tracking progress and giving leadership clear, consistent updates on milestones, risks, and blockers.
- Support the vendor risk management program by evaluating third-party partners, reviewing their control environments, and ensuring they meet Paystack’s security expectations.
- Document exceptions to security policies and standards, then ensure those exceptions get periodic reviews and do not become permanent blind spots.
- Collaborate with internal teams on security messaging, training initiatives, and awareness campaigns that help employees understand and embrace secure behaviors.
- Stay informed on evolving threats, regulations, and best practices, and use that knowledge to challenge or refine existing security processes.
Requirements & Qualifications
- Several years of hands-on experience in information security governance, risk management, and compliance, ideally within a global organization that relies heavily on cloud infrastructure.
- Proven track record of writing and publishing company-wide policies, standards, and governance documents that are clear, practical, and usable for non-security audiences.
- Working knowledge of industry frameworks and regulations, including the Secure Controls Framework (SCF), ISO 27001, NIST Cybersecurity Frameworks, and business continuity principles aligned with ISO 22301.
- Strong ability to manage competing priorities across multiple projects, while also guiding teammates on what should be tackled first.
- Comfortable building and managing relationships with senior leaders across business units, plus external customers and vendors, in order to influence positive security outcomes.
- Excellent analytical skills with the ability to learn new technologies and regulatory nuances quickly.
- Superb written and verbal communication skills—able to explain risk, controls, and compliance topics to both technical and non-technical stakeholders.
- A bias for action, a sense of ownership, and the ability to escalate issues promptly while keeping precise documentation.
What We Offer / Why Join
Paystack provides a competitive compensation and benefits package, including full medical coverage, a wellbeing stipend, and generous leave along with sabbatical policies. You will work in a hybrid environment alongside smart, kind colleagues who are genuinely invested in your professional growth—and you will have the opportunity to shape security practices for a company operating across fast-growing African markets.
71 open positions on Semasocial right now
· 8456 open positions in Nairobi County, Kenya
· 5 posted in the last 7 days
Contact Information