Advance your career with BetaJob Certificates
Create account, take courses and earn verifiable certificates. Download and add certifications to your profile for better chance of getting hired.
TopHire Africa is a timeless and innovative HR-Consulting Service provider that's geared towards delivering recruitment and training of qualitative verified talent. We are recruiting to fill the position below:
Job Title: Senior Cyber Analyst (Third-Party & Supply-Chain Cyber Risk) Freejob posting
Location: Lagos
Employment Type: Full-time Discover moreIndustry specific jobsRecruitmentSalesPrimary Responsibilities of Role
Maintain the cyber view of the third-party register: document each supplier's services, data access and criticality; prepare vendor tiering analysis (critical, material, high, medium, low); and map the Bank's reliance on suppliers' own subcontractors (Nth-party, or fourth-party, risk) to surface hidden concentration and unseen attack paths. Final classification and risk acceptance remain with the UK management and relevant FirstBank UK governance forums. Conduct cyber due diligence for new and existing vendors: evaluate security controls and certifications (for example ISO[1] 27001 and SOC 2[2]), breach history, and data-handling practices, and identify gaps before they affect the Bank. Run continuous monitoring of supplier security posture and supply-chain threats, using security-ratings services, threat intelligence and vendor security advisories (PSIRT[3] feeds) with automated alerts; operate coordinated disclosure and absorb vendor-disclosed and researcher-reported vulnerabilities at scale. Support the embedding of cyber security into vendor onboarding and contracts by identifying security and resilience obligations, audit and testing rights, prompt incident-reporting duties, and the cascade of key controls to subcontractors; apply the same scrutiny to intra-group providers. Establish a SBOM or equivalent dependency visibility for material software, including a contractual SBOM provision, so the Bank can answer 'are we affected?' quickly when a critical open-source vulnerability is disclosed. Assess vendors' frontier-AI cyber readiness as part of due diligence, and add a frontier-AI attribute to the vendor criticality assessment, aligned to NCSC[4] guidance on defending against frontier AI. Review and collate evidence that critical third parties have tested BCP[5] and DR[6] arrangements; support UK-owned resilience equivalence assessments for material vendors supporting IBS, and include key providers in scenario and severe-but-plausible tests. Analyse provider concentration, substitutability and exit: maintain exit and stressed-exit plans for material vendors, and provide third party exposure inputs to UK-owned operational resilience and the CTP[1] oversight processes. Approvals of exits substitutions, risk acceptances or operational resilience conclusions remain with the UK management and relevant governance forums.
Interested candidates should possess a Bachelor’s Degree with 10 - 15 years Proven experience in third-party or supply-chain cyber risk management, ideally in a regulated fina.
TPRM: tiering, inherent-risk scoring, continuous monitoring and Nth-party mapping.
12th October, 2026. How to Apply
Interested and qualified candidates should send their CV to: [Email hidden - Login to reveal] using the Job Title as the subject of the mail. Freejob posting
Note: Only shortlisted candidates are contacted.
Monthly based
Lagos
Lagos
Create account, take courses and earn verifiable certificates. Download and add certifications to your profile for better chance of getting hired.