Job Summary The IT Risk Specialist at Dangote Cement Plc will lead the identification, assessment, and mitigation of technology and cybersecurity risks across cement production plants and corporate operations. This role …
Skills: IT Risk Management, Cybersecurity Risk Assessment, GRC, ISO 27001, NIST
OFFICE ASSISTANT Office Assistant – HR/Admin Location: Apapa, Lagos Department: Human Resources & Administration Job Purpose To provide administrative and clerical support to the HR/Admin Department, ensuring efficient o…
Skills: Administrative Support, Filing, Documentation, Employee Records Management, Recruitment Coordination
Import and Clearing Officer Job Title: Import and Clearing Officer Job Summary The Import and Clearing Officer will be responsible for managing the end-to-end importation and clearing processes, ensuring timely, efficien…
SALES OPERATIONS MANAGER Sales Operations Manager Role Overview The Sales Operations Manager will lead and optimize sales and marketing operations across the business by driving efficient processes, data-driven decision-…
Skills: Sales Operations, Order-to-Cash (O2C), Data Analysis, S&OP Processes, CRM
Sustainability Manager Job Summary The role supports the Head of Sustainability in developing standards that embed sustainability and the integration of ESG for: • Clear articulation of Environmental, Social and Governan…
Skills: ESG KPI Tracking, Sustainability Reporting, Stakeholder Management, Data Analysis, Data Visualisation
Job Summary We are seeking a dedicated Sectional Head, Rawmill at Dangote - Okpella Cement Limited, who will lead the rawmill segment within the mechanical department, responsible for the efficient production and process…
Skills: Raw Mill Machinery, Preventive Maintenance, Corrective Maintenance, Team Management, Root Cause Analysis
Job Summary Dangote Cement Plc is looking for motivated professionals with SAP experience in the Finance module. The resource(s) would join our team of professionals to support the daily SAP operations of the business an…
Skills: SAP FI, Functional Support, Requirements Gathering, Functional Testing, End-user Training
Key Duties and Responsibilities Monitor various sections of the production line from the Central Control Room (CCR). To ensure precision and adherence to standards in the cement production process. Provide relevant infor…
Skills: Cement Production Process, Quality Control, Crushing Operations, Problem Solving, Analytical Skills
Sign up with Clera and we'll reach out the moment a role actually fits you — no more spraying applications into the void.
Full-time
professional certificate
Private Health Insurance, Paid Time Off, Training & Development, Career Development Opportunities
Posted 47d ago
Apply by Sep 30
~40 hrs/week
Responsibilities
Lead the identification, assessment, and mitigation of technology and cybersecurity risks across corporate operations and production plants. Develop cybersecurity defense strategies and ensure IT systems align with the Group's risk appetite and regulatory requirements.
Requirements
Requires over 5 years of experience in IT risk management or governance with certifications such as CRISC, CISA, CISM, or CISSP. Must possess strong knowledge of security standards like ISO 27001 and experience with risk management tools like Nessus and Tenable.
Full job description
Job Summary
The IT Risk Specialist at Dangote Cement Plc will lead the identification, assessment, and mitigation of technology and cybersecurity risks across cement production plants and corporate operations. This role ensures that IT systems supporting manufacturing, logistics, and enterprise functions are secure, resilient, and aligned with the Group’s risk appetite and regulatory requirements.
Key Responsibilities
Conduct objective, fact-based risk assessments on new and existing systems and share findings with all stakeholders within the information system.
Managing the IT Risk environment, including related policies, standards, and processes.
Manage the risk portfolio to include linking risk to controls, coordinating control owners to conduct RSCAs, and appropriately documenting control statements.
Understand and provide advice on managing cybersecurity risks; collaborate with other IT professionals as needed to address new emerging threats.
Manage the self-identified issue process; acceptance of issues; tracking SIIs and audit issues to closure.
Develop and implement a cybersecurity defence strategy, including business continuity and disaster recovery procedures.
Identify threats and conduct risk assessments to address cybersecurity risks.
Work with the team to improve the security posture of the business and reduce its risk profile.
Conduct on-site security assessments to measure the effectiveness of the third party's current control environment.
Knowledge and experience in information security standards. (ISO 27001, NIST, CIS, OWASP Top 10, Security Essentials)
Maintain close working relationships with appropriate teams across and outside of IT.
Work closely with all areas to ensure clear risk visibility with all IT staff.
Provide Continuous Control Monitoring through Key Risk Indicators, providing challenges to KRIs.
Establish and monitor key risk indicators and implement corrective action plans to mitigate risks.
Work closely with Group Risk Management, ensuring that IT Risks are reported as required to the Group Risk Board Committee and aligned with Risk appetite and Risk tolerance levels
Maintain an awareness of potential Emerging Risks and ensure these are recorded, visible, and considered in all new technology initiatives and financial planning activities
Provide oversight of all Risk Events, ensuring they are recorded, investigated, closed off, or escalated as necessary
Required Skills & Experience
Strong technical background with 5 + years of experience in risk management with proven IT risk and/or IT governance skills.
Certified CRISC/CISA/CISM/CISSP or other relevant qualifications.
An Information Security GRC position with strong knowledge of ISO27001, NIST, OWASP, and PSI-DSS
Knowledge of risk management/cyber security controls and tooling is desirable.
Has strong policy writing experience
Can communicate with Senior Stakeholders about Information risk.
Can build relationships with stakeholders at all levels.
Ability to communicate complex information to a variety of audiences.
Can work in a fast-paced environment
Knowledge and understanding of Privileged Access Management, Patch Management, SOC Visibility, and Business Continuity
Knowledge of Control/Vulnerability Assessment and Penetration Testing methodologies
Experience using and configuring information security and risk management tools like Nessus, Tenable, Acunetix, BULP suite, Nipper tool, and more to generate and report IT risks.
Able to work in a cross-cultural and cross-functional environment.
Benefits
Private Health Insurance
Paid Time Off
Training & Development
Career Development Opportunities
Related keywords
IT RiskCybersecurityISO 27001NISTCISOWASP Top 10PCI-DSSCRISCCISACISMCISSPGRCNessusTenableAcunetixBURP suite