About Quidax
Quidax is where money meets limitless possibilities. We’re making it super easy for individuals, businesses, and fintechs in Africa to access crypto. Our goal? Providing real value for our customers today while shaping the future of money.
About the Role
We’re looking for a Cybersecurity Governance, Risk & Compliance (GRC) analyst who will be responsible for maintaining policies, assessing risks, supporting audits, regulatory requirements, third-party reviews, and security awareness. You’ll help us carry out audits that help us understand where our risks are, verify that the right controls are operating effectively, and ensure we remain continuously audit-ready — not just when an auditor comes knocking.
You’d also serve as our Data Protection Officer (DPO) leading our privacy programme, ensuring Data Privacy best practices are enforced in the organization, and ensuring compliance with data protection regulations across jurisdictions.
If you’re the kind of person who is meticulous, curious, enjoys carrying out audits, documenting policies, processes and bringing them to life, and passionate about cybersecurity governance, risk, compliance and data privacy — you’ll fit right in.
What You’ll Be Owning
- Cybersecurity Governance
- Within 60 days: Review all existing information security policies, standards, procedures, and SOPs. Identify gaps, outdated content, and areas for improvement while ensuring alignment with the organization’s current technology stack and business operations.
- Within 90 days: Update, implement, and communicate approved improvements to security policies, standards, and procedures. Establish a reporting cycle to leadership on Cybersecurity Governance, Risk & Compliance.
- Cybersecurity Certifications & External Audits
- Within 30 days: Become familiar with Quidax’s compliance landscape, including ISO 27001, PCI DSS, NDPA, and other applicable regulatory & certification requirements.
- Within 60 days: Coordinate audit readiness activities by ensuring evidence is collated in advance rather than during audit periods, reducing last-minute audit preparation.
- Within 90 days: Support internal and external auditors, coordinate stakeholder responses, track audit findings, and ensure remediation activities are completed within agreed timelines.
- Security Awareness
- Within 30 days: Review the organization’s existing security training program and security training policies and identify opportunities to improve employee engagement and effectiveness. Take responsibility of the organization’s security awareness program and drive approved improvements.
- Within 60 days: Promote a security-first culture by ensuring employees understand their role in protecting customer data and company assets.
- Within 180 days: Drive the annual org-wide security culture awareness programme that includes role-based training, data protection and policy awareness.
- Third Party Security Review & Evaluation
- Within 30 days: Review previous 3rd party security evaluations. Review historical Due Diligence questionnaires completed for partners. Conduct a review of our template for conducting vendor Due Diligence.
- Within 60 days: Respond to cybersecurity due diligence questionnaires from partners and regulators. Carry out security reviews on 3rd party applications on-request and create a cadence for scheduled review of the current list of 3rd party apps to verify their eligibility for continued use.
- Within 90 days: Ensure all 3rd party services in use must have completed security reviews, and maintain a central repository of 3rd party security evaluations.
- Regulatory Engagement
- Within 60 days: Build a deep understanding of Quidax regulatory landscape, regulatory obligations and expectations across all operating jurisdictions. Be able to provide responses to regulatory requests, assessments, and evidence collation by collaborating with relevant internal teams. Create a working process for monitoring regulatory developments, recommended changes to policies, controls, and processes to maintain ongoing compliance.
- Data Protection
- Within 60 days: Audit existing data protection processes, privacy controls, and data handling procedures to identify compliance gaps and opportunities for improvement. Take ownership of data protection processes, controls, data handling procedures, Data Privacy Impact Assessments (DPIAs), and new initiatives involving sensitive data.
- Within 90 days: Implement approved improvements to existing data protection processes, privacy controls, and data handling procedures.
Biggest Challenges You’ll Tackle
Here are the challenges that will keep you thinking and learning every day:
- Building enterprise-grade governance in a startup environment. You’ll be helping mature our governance, risk, and compliance program while supporting a business that continues to evolve rapidly.
- Balancing speed with governance. You’ll need to build security processes and controls that enable the business — not slow it down.
- Influencing without authority. Success in this role depends on working across Engineering, Product, Legal, Compliance and Operations to drive audit readiness, risk remediation, and certification/regulatory initiatives.
- Maintaining continuous compliance instead of audit readiness. Our goal isn’t to prepare for audits once a year — it’s to build processes that make us audit-ready every day.
- Staying ahead of a constantly changing threat and regulatory landscape. Cybersecurity risks, cloud technologies, blockchain ecosystems, and regulatory requirements evolve continuously. You’ll need to keep learning and ensure Quidax stays one step ahead.
What We’re Looking For
Must-Haves
- You have 3 - 6 years of experience in Cybersecurity Governance, Risk & Compliance (GRC), IT Audit, Risk Management, Data Protection or a similar cybersecurity discipline.
- You understand security frameworks such as ISO 27001, NIST CSF, CIS, PCI DSS, SOC 2 and know how to apply them in the real world.
- Experience implementing or maintaining certifications such as ISO 27001, PCI DSS, SOC 2, or similar compliance programs.
- Experience in internal or external audits and understand what good audit evidence looks like.
- Familiarity with privacy and data protection regulations such as NDPA, GDPR, UK GDPR, or other international privacy frameworks.
- Experience conducting vendor or third-party security risk assessments.
- You know how to perform risk assessments, identify control gaps, and help drive remediation efforts from start to finish.
- You enjoy writing and maintaining clear, practical security policies, standards, procedures, and documentation that people can actually follow.
- You can translate technical risks into language that business stakeholders understand, helping teams make informed decisions.
- You’re highly organized and can manage multiple audits, risk assessments, and compliance initiatives without losing attention to detail.
- You can build strong working relationships across multiple internal teams to move security initiatives forward.
- You are naturally curious, ask good questions, and enjoy understanding how systems, technologies, and business processes work.
- You take ownership of your work and don’t wait to be told what needs improving.
Nice-to-Haves
- Understanding of blockchain technology, digital assets, or cryptocurrency security concepts.
- Experience working in financial services, fintech, cryptocurrency, blockchain, or other highly regulated industries.
- Understanding & Experience in AI governance, AI security & frameworks like ISO 42001, and the emerging risks introduced by AI technologies.
- Experience using GRC platforms, audit management tools, or risk management software.
- Understanding of cloud security concepts and shared responsibility models across AWS, Azure, or GCP.
- Familiarity with vulnerability management, security operations, incident response, or application security concepts.
- Basic scripting or automation experience (Python, PowerShell, SQL, or similar) to improve reporting and compliance workflows.
- Professional certifications such as ISO 27001 Lead Implementer/Lead Auditor, CRISC, CISA, CISM, Security+, CISSP, PCI Professional (PCIP), CCSK, CDPSE or similar are appreciated, but they’re not a deal-breaker.
We’re looking for someone who believes governance is about enabling the business, not slowing it down. Someone who enjoys bringing structure to complexity, solving problems collaboratively, and continuously raising the security and compliance maturity of the organization.
Reporting Line
You’ll report directly to the Chief ...
Quidax Technologies Ltd uses JOIN to manage applications for this job. Your information will be submitted to the employer via JOIN, where you can always check your application status. By clicking "Apply now" you agree to JOIN's
Terms & Conditions and
Data Privacy Policy