Posted 1 day ago

Department: Technical / GRC
Reports To: Designated GRC Lead / Chief Technology Officer
Employment Type: Full Time
Location: Lagos, Nigeria
Work Arrangement: Hybrid
Level: Associate
Salary Range: 250-500k

Role Overview

3Cs Aquarah is seeking an Associate GRC Analyst/Consultant to support our Governance, Risk, and Compliance engagements.

The successful candidate will work with internal teams and clients to identify cybersecurity and information security risks, support compliance assessments, develop documentation, and assist organisations in strengthening their governance and risk management practices.

This role is suited to an early-career professional with a strong interest in cybersecurity governance, risk management, compliance, and consulting.

Key Responsibilities

  • Support cybersecurity risk assessments and gap assessments for clients.
  • Assist in evaluating organisations against relevant regulatory and industry frameworks.
  • Support the development and review of information security policies, procedures, standards, and other governance documents.
  • Assist with identifying, documenting, assessing, and tracking information security risks.
  • Maintain risk registers, compliance trackers, and related documentation.
  • Support audit readiness and compliance initiatives.
  • Conduct research on cybersecurity regulations, standards, frameworks, and emerging requirements.
  • Assist in preparing client reports, presentations, recommendations, and remediation plans.
  • Track remediation activities and follow up on identified gaps.
  • Participate in client meetings, workshops, interviews, and assessment activities.
  • Maintain accurate project and engagement documentation.
  • Work collaboratively with technical teams and other stakeholders to understand and address security risks.

Requirements

  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Risk Management, or a related discipline.
  • Foundational understanding of cybersecurity governance, risk, and compliance concepts.
  • Familiarity with one or more relevant frameworks or standards, such as ISO 27001, NIST CSF, PCI DSS, or data protection requirements.
  • Strong research, analytical, and documentation skills.
  • Excellent written and verbal communication skills.
  • Ability to interpret requirements and translate findings into clear recommendations.
  • Strong attention to detail and organisational skills.
  • Ability to work effectively with clients and internal stakeholders.

Preferred Qualifications

  • Relevant cybersecurity or GRC certifications, or evidence of working towards one.
  • Previous internship or professional experience in cybersecurity, risk, audit, compliance, or consulting.
  • Familiarity with privacy and data protection requirements.
  • Experience preparing professional reports, policies, or assessment documentation.

Key Competencies Analytical thinking, attention to detail, communication, professionalism, integrity, client orientation, teamwork, and willingness to learn.

Apply For This Job

A valid phone number is required.

Schedule a Consultation

Please fill out the form and we will be in touch as soon as possible.