Cybersecurity Analyst at First Ally Capital Limited

New
Cybersecurity Analyst at First Ally Capital Limited
Job Title:
Cybersecurity Analyst at First Ally Capital Limited

Work Options
On-site
Experience Level
Entry-Level
Job Type
Full-Time

First Ally Capital was incorporated on May 20, 2014 as an Issuing House and Financial Advisory firm, with an authorized share capital of N2.5 billion, and an issued and fully-paid up capital of N1.9 billion. The Firm was licensed by the Securities and Exchange Commission on November 20, 2014. The firm commenced operations at a very significant point in the evolution of the Nigerian financial services industry and has leveraged its solid capital base and the excellent track-record and credentials of its team, directors and shareholders. The team behind the firm have been involved in various transactions ranging from Issuance of bonds, raising equity capital, mergers and acquisition, restructuring to project advisory services.

About the Role

The Cybersecurity Analyst will be a key member of the IT team, responsible for safeguarding First Ally Capital's digital assets, infrastructure, and customer data across the Group and its subsidiaries. The analyst will monitor, detect, investigate, and respond to cybersecurity threats across our Microsoft 365 (M365) and Azure cloud environments, as well as our retail-facing application. This role requires a hands-on professional with strong analytical capability and a working knowledge of cloud security, endpoint protection, and application security.

Key Responsibilities

Security Monitoring & Threat Detection

  • Monitor security alerts and events from Microsoft Sentinel, Defender for Endpoint, and Defender for Cloud Apps (MCAS) on a continuous basis.
  • Analyse logs and telemetry from Azure Monitor, Microsoft 365 security centre, and the retail application to identify anomalies and potential intrusions.
  • Triage and investigate security incidents, determine root causes, and escalate appropriately to the IT Manager.
  • Maintain and fine-tune detection rules, alert thresholds, and SIEM correlation queries to reduce false positives.

Identity & Access Management (IAM)

  • Administer and enforce Microsoft Entra ID (Azure AD) policies including Conditional Access, Privileged Identity Management (PIM), and Multi-Factor Authentication (MFA).
  • Conduct periodic user access reviews and entitlement assessments across M365, Azure subscriptions, and the retail app.
  • Detect and investigate suspicious sign-in activity, compromised credentials, and identity-based attacks.
  • Enforce least-privilege principles and Role-Based Access Control (RBAC) across all platforms.

Cloud Security (Microsoft Azure & M365)

  • Manage and improve the security posture of the company's Azure environment using Microsoft Defender for Cloud and the Azure Security Benchmark.
  • Conduct regular reviews of Azure Policy, security recommendations, and compliance scores in Microsoft Secure Score.
  • Ensure proper configuration of M365 services including Exchange Online Protection (EOP), Safe Links, Safe Attachments, and Data Loss Prevention (DLP) policies.
  • Review and harden Azure networking components including NSGs, Azure Firewall rules, and Private Endpoints.

Retail & Core Application Security

  • Collaborate with the application development team to integrate security into the SDLC (Secure-by-Design).
  • Perform and coordinate vulnerability assessments and DAST/SAST scans on the retail and banking application.
  • Monitor application logs for suspicious activity, injection attempts, authentication abuse, and API misuse.
  • Assist in managing Web Application Firewall (WAF) rules and API gateway security policies.
  • Track and follow up on remediation of identified application vulnerabilities within agreed SLAs.

Vulnerability Management & Patch Compliance

  • Run regular vulnerability scans using Microsoft Defender Vulnerability Management or third-party tools across endpoints, servers, and cloud workloads.
  • Track remediation status and produce dashboards showing patch compliance levels for servers, endpoints, and SaaS platforms.

Job Type

Full Time, Onsite

Qualification

BA/BSc/HND, Professional Certificate

Experience

3-5 years

Location

Lagos

Job Field

ICT / Computer

Disclaimer: This job description has been reformatted by AI for readability. Please verify all details with the employer before applying.

Note: This is a partial description. For complete details, please visit the application page.

Developer tools are disabled.

You can copy content with CNTR + C or CMD + C