Back to Jobs
Team Lead, Information Systems Audit
Ecobank Transnational Incorporated · Lagos, Nigeria · Full-time
IT & Cybersecurity ["IT audit","cybersecurity","information systems","risk assessment","CISA","ISO 27001"]
Apply Now
Posted 1 month ago · Job #31
About the Role

About This Opportunity

As African banks deepen their digital capabilities — expanding mobile banking, open banking APIs, cloud infrastructure, and core system modernisation — robust IT audit has become a regulatory imperative, not merely good governance. Regulators including the CBN in Nigeria, Bank of Ghana, and the Central Bank of Kenya are increasingly mandating stronger IT control frameworks and expecting evidence of independent IS assurance at Board level.

Ecobank's IS Audit function provides independent assurance across 35 affiliate countries on a technology estate that includes core banking systems, digital banking platforms, payment infrastructure, and cybersecurity controls. This Team Lead role places you at the apex of that function, with responsibilities that range from designing the annual IT audit plan to presenting findings directly to Board Audit Committees.

CISA-qualified IT auditors with core banking audit experience are in strong demand across Africa. This role represents one of the most senior IS audit opportunities available outside of Big Four advisory practices.


JOB PURPOSE

To independently evaluate the adequacy and effectiveness of the controls, procedures and policies put in place by management to safeguard and minimise the risks associated with information systems in the bank. The role provides independent assurance to Senior Management and the Board of Directors that investments made in technology are enabling the business, creating the expected value to stakeholders, and achieving business objectives. The Team Lead also assists stakeholders to identify business pain points occasioned by the use of technology in provision of services to customers and improve business efficiency.

KEY RESPONSIBILITIES

Audit Planning & Execution

• Lead the planning, scoping, and execution of IT and information systems audit assignments in line with the annual audit plan.

• Conduct risk-based assessments of IT infrastructure, applications, databases, and cybersecurity controls.

• Evaluate the design and operating effectiveness of IT General Controls (ITGCs), including access management, change management, IT operations, and data backup/recovery.

• Review application controls for core banking systems, payment platforms, and critical business applications.

• Assess compliance with regulatory requirements (CBN, NDPC, PCI-DSS, ISO 27001) and internal IT policies.

Reporting & Communication

• Prepare high-quality audit reports communicating findings, root causes, risk implications, and actionable recommendations to Senior Management and the Board.

• Track and verify the timely remediation of identified audit observations and control weaknesses.

• Present audit findings to senior stakeholders, including the Audit Committee.

Team Leadership

• Lead and mentor a team of IS auditors, providing technical guidance and professional development support.

• Review and approve audit workpapers, ensuring quality, completeness, and accuracy.

• Foster a high-performance team culture centred on continuous improvement, objectivity, and professional scepticism.

Cybersecurity & Emerging Technology

• Assess cybersecurity frameworks, threat detection capabilities, incident response processes, and data protection controls.

• Stay current with evolving technology risks, cyber threats, and emerging audit methodologies to strengthen the audit function's relevance and value.

JOB PROFILE

Qualifications & Experience

• Bachelor's degree in Computer Science, Information Technology, Accounting, or a related field.

• Minimum 6–8 years of experience in IT audit, cybersecurity, or information risk management, with at least 2 years in a supervisory or team lead role.

• Professional certifications: CISA (required); CISM, CISSP, or CIA are added advantages.

• Strong knowledge of IT audit methodologies, frameworks (COBIT, ITIL, NIST), and international standards (ISO 27001, PCI-DSS).

• Experience auditing core banking systems (Finacle, T24, Temenos, etc.) is highly desirable.

Skills & Competencies

• Analytical mindset with strong problem-solving and critical-thinking skills.

• Excellent report writing and verbal communication skills.

• Ability to manage multiple audit assignments simultaneously and meet deadlines.

• Strong stakeholder management and interpersonal skills.

• High degree of professional integrity and ethical conduct.


Applying for This Role

  • CISA is listed as required — treat it as mandatory: If you hold CISM, CISSP, or CIA as well, ensure these are prominently displayed. The combination significantly strengthens your profile.
  • Core banking audit experience is a decisive differentiator: Experience auditing Finacle, T24, Temenos, or similar African banking platforms will set you apart from candidates with only general IT audit backgrounds.
  • Prepare substantive audit findings: The panel will expect you to discuss significant IT control weaknesses you have identified — what you found, why it mattered, and how it was remediated.
  • Regulatory framework depth: Knowledge of CBN IT Standards Framework, Bank of Ghana ICT guidelines, and PCI-DSS demonstrates the multi-jurisdictional awareness the role demands.
About Ecobank Transnational Incorporated
Ecobank Transnational Incorporated
Banking & Finance · 10,001+ employees

Ecobank Transnational Incorporated is Africa's leading pan-African banking group with a presence in 35 countries — the largest network of any bank on the continent. Headquartered in Lomé, Togo, Ecobank serves millions of individuals, businesses, and institutions with retail, corporate, and investment banking services, driving financial inclusion across Africa.

🧭
Application Guide for This Role
Tailored tips to help you stand out and prepare confidently
🔒 What IT & Cybersecurity Hiring Managers Look For

Security and IT roles demand precision, documentation discipline, and a risk-first mindset. Hiring managers look for candidates who can communicate threats in business terms, not just technical ones — and who stay ahead of threat vectors without needing to be told.

How to Stand Out
  • List certifications prominently (CompTIA Security+, CISSP, CEH, AWS Security Specialty) — they're taken seriously in this field.
  • Describe a real incident you responded to: what was the threat vector, your containment steps, and the post-incident review?
  • Show experience with the tools in the job description: SIEM platforms, EDR solutions, penetration testing tools, or cloud IAM.
  • Demonstrate compliance awareness (SOC 2, ISO 27001, GDPR, HIPAA) if the company operates in a regulated industry.
Likely Interview Questions
  1. Walk me through how you'd respond to a suspected phishing breach affecting 200 employees.
  2. How do you stay current with emerging CVEs and threat intelligence?
  3. Describe how you'd perform a risk assessment for a new SaaS tool the company wants to adopt.
  4. What's the most creative social engineering attack you've seen or simulated?
Pro tip: Set up a home lab using VirtualBox or TryHackMe rooms in the specific domain (cloud, network, web app) this role covers — it gives you concrete, recent examples to discuss.
📄 About Full-Time Employment Roles

Full-time roles typically include benefits (health insurance, pension contributions, paid leave). During salary negotiation, always consider the total compensation package — benefits can be worth 20–30% on top of base salary. Ask specifically about probation period, performance review cadence, and remote/hybrid flexibility before signing.

🛠 Highlighted Skills for This Role

The following skills appear in this posting. If you have experience with them, make them prominent in your CV and cover note — ideally with a concrete result attached to each one.

["IT audit","cybersecurity","information systems","risk assessment","CISA","ISO 27001"]
✅ Before You Hit Submit
📝
Tailor your CV
Remove irrelevant roles. Match your language to the job description — ATS systems score keyword alignment.
💌
Write a real cover note
One paragraph that explains why this specific company, this specific role, right now. Generic notes go unread.
🔍
Research the company
Know their product, recent news, funding stage, and competitors. Bring one insight to your interview.
🔗
Clean up your LinkedIn
Make sure your profile matches your CV and your headline reflects the role you want, not the one you are leaving.
Job Overview
Salary Competitive
Type Full-time
Location Lagos, Nigeria
Category IT & Cybersecurity
Posted Apr 22, 2026
Apply Now
Free Daily Digest
Stay ahead of the job market

New jobs, scholarships and career tips — delivered to your inbox daily. Unsubscribe any time.