First Ally Capital

Job Overview

First Ally Capital is hiring a Cybersecurity Analyst in Lagos with 3–5 years’ experience in Microsoft 365, Azure security, SIEM, IAM, and threat response.

Cybersecurity Analyst at First Ally Capital – Lagos

Location: Lagos, Nigeria
Employment Type: Full-Time, Onsite
Job Field: ICT / Computer
Experience: 3–5 years
Qualification: BA/BSc/HND, Professional Certificate
Application Deadline: Not Specified

First Ally Capital is seeking a Cybersecurity Analyst to help protect its digital infrastructure, customer information, cloud environments, and business applications across the Group and its subsidiaries.

This is a hands-on cybersecurity role covering security monitoring, threat detection, incident response, identity and access management, Microsoft 365 and Azure security, vulnerability management, application security, and regulatory compliance.

The position is likely to suit a cybersecurity professional with 3–5 years of practical experience who is comfortable working with Microsoft’s security ecosystem and understands how to investigate and respond to threats in a financial services environment.

About First Ally Capital

First Ally Capital was incorporated on May 20, 2014, as an Issuing House and Financial Advisory firm. The company was licensed by the Securities and Exchange Commission (SEC) on November 20, 2014.

According to the supplied company information, the firm operates within Nigeria’s financial services industry and has been involved in transactions covering areas such as bond issuance, equity capital raising, mergers and acquisitions, restructuring, and project advisory services.

What the Cybersecurity Analyst Will Do

The successful candidate will work as part of the IT team to monitor security environments, investigate potential threats, strengthen controls, and support the organisation’s wider cybersecurity programme.

Monitor Security Alerts and Investigate Threats

A central part of the position involves identifying and responding to suspicious activity across the company’s technology environment.

Responsibilities include:

  • Monitoring security alerts and events from Microsoft Sentinel.
  • Using Microsoft Defender for Endpoint and Defender for Cloud Apps (MCAS) to identify potential threats.
  • Analysing logs and telemetry from Azure Monitor, Microsoft 365 security tools, and the retail application.
  • Investigating unusual activity and potential security breaches.
  • Triaging security incidents and identifying possible root causes.
  • Escalating incidents appropriately to the IT Manager.
  • Fine-tuning detection rules, alert thresholds, and SIEM correlation queries to help reduce false positives.

The role requires strong analytical thinking and the ability to distinguish genuine security threats from routine system activity.

Manage Identity and Access Security

The Analyst will help protect user accounts, applications, and cloud resources by applying appropriate identity and access controls.

This includes:

  • Administering Microsoft Entra ID policies.
  • Managing Conditional Access policies.
  • Supporting Privileged Identity Management (PIM).
  • Enforcing Multi-Factor Authentication (MFA).
  • Conducting periodic user access reviews.
  • Assessing access entitlements across Microsoft 365, Azure subscriptions, and the retail application.
  • Investigating suspicious sign-ins and compromised credentials.
  • Identifying identity-based attacks.
  • Applying least-privilege principles.
  • Managing Role-Based Access Control (RBAC) across relevant platforms.

Experience with modern identity security and access management will be important for this part of the role.

Strengthen Microsoft Azure and Microsoft 365 Security

The Cybersecurity Analyst will be responsible for helping maintain and improve the security posture of the company’s cloud and productivity environments.

Key activities include:

  • Managing security improvements within the Azure environment.
  • Using Microsoft Defender for Cloud to identify and address security recommendations.
  • Reviewing Azure Policy configurations.
  • Monitoring security recommendations and compliance scores.
  • Reviewing Microsoft Secure Score.
  • Supporting secure configuration of Microsoft 365 services.
  • Managing controls such as Exchange Online Protection (EOP), Safe Links, Safe Attachments, and Data Loss Prevention (DLP).
  • Reviewing Azure networking components.
  • Supporting the security of Network Security Groups (NSGs), Azure Firewall rules, and Private Endpoints.

Candidates should have practical experience working with Microsoft cloud security technologies rather than only theoretical knowledge.

Support Application and API Security

The role also covers security across the company’s retail and banking applications.

The Analyst will work with development teams to:

  • Integrate security into the software development lifecycle.
  • Support a Secure-by-Design approach.
  • Coordinate vulnerability assessments.
  • Conduct or coordinate DAST and SAST scans.
  • Monitor application logs for suspicious behaviour.
  • Investigate possible injection attempts.
  • Identify authentication abuse.
  • Monitor potential API misuse.
  • Assist with Web Application Firewall (WAF) rules.
  • Support API gateway security policies.
  • Track remediation of identified vulnerabilities within agreed service-level timelines.

Knowledge of application security principles, OWASP Top 10 risks, and API security will be particularly relevant.

Manage Vulnerabilities and Patch Compliance

The Cybersecurity Analyst will help identify vulnerabilities across endpoints, servers, cloud workloads, and SaaS platforms.

Responsibilities include:

  • Running regular vulnerability scans using Microsoft Defender Vulnerability Management or third-party tools.
  • Tracking the status of vulnerability remediation.
  • Preparing dashboards showing patch compliance.
  • Monitoring vulnerabilities affecting servers and endpoints.
  • Following up with system administrators and vendors.
  • Helping prioritise and close critical vulnerabilities.

Knowledge of common CVEs, exploitation techniques, and vulnerability prioritisation will be useful in this area.

Participate in Incident Response and Forensics

When security incidents occur, the Analyst will support the organisation’s response process.

This may include:

  • Participating in incident investigation.
  • Supporting containment and eradication activities.
  • Assisting with system recovery.
  • Documenting incident timelines and findings.
  • Preparing structured post-incident reports.
  • Recording lessons learned from security events.
  • Supporting the collection and preservation of forensic data.
  • Maintaining and updating incident response playbooks for Microsoft 365 and Azure-related threats.

The successful candidate should be able to work calmly and methodically during security incidents.

Support Compliance and Security Governance

Because the position is within a financial services environment, cybersecurity activities must also align with relevant regulatory and industry requirements.

The Analyst will support compliance with applicable frameworks and regulations, which may include:

  • CBN Cybersecurity Framework.
  • Nigeria Data Protection Regulation (NDPR).
  • ISO 27001.
  • PCI-DSS, where applicable.

Additional responsibilities include:

  • Supporting internal and external security audits.
  • Gathering evidence required for audits.
  • Coordinating remediation activities.
  • Maintaining security documentation.
  • Updating security policies, standards, and procedures.

Candidates with experience supporting cybersecurity audits or compliance programmes may have an advantage.

Manage Endpoint and Email Security

The role includes protecting company devices and email systems from common security threats.

Responsibilities include:

  • Managing Microsoft Defender for Endpoint policies.
  • Supporting endpoint onboarding and configuration.
  • Taking appropriate response actions when threats are detected.
  • Investigating phishing attacks.
  • Investigating Business Email Compromise (BEC).
  • Reviewing malware delivery attempts through Microsoft 365.
  • Using Microsoft Defender and Threat Explorer to investigate email-based threats.
  • Enforcing device compliance through Microsoft Intune or Endpoint Manager.
  • Reviewing and maintaining device configuration profiles.

This area requires a good understanding of endpoint security, email threats, and Microsoft security tools.

Education and Experience Requirements

Applicants should have a Bachelor’s degree in one of the following or a related discipline:

  • Computer Science
  • Information Security
  • Cybersecurity
  • A related technical field

The employer is seeking candidates with:

  • 3–5 years of hands-on experience in cybersecurity or IT security.
  • Demonstrable experience with Microsoft 365 security tools.
  • Experience with Microsoft Defender security solutions.
  • Practical exposure to Microsoft Azure security services.
  • Experience with Defender for Cloud and Microsoft Sentinel.
  • Knowledge of Entra ID and Azure Policy.
  • Experience with vulnerability assessment tools.
  • Understanding of common CVEs and exploitation techniques.
  • Familiarity with web and mobile application security concepts.
  • Knowledge of OWASP Top 10 and API security.
  • Working knowledge of KQL (Kusto Query Language) is highly preferred.

Candidates should be able to demonstrate practical experience rather than relying solely on academic qualifications or certification credentials.

Preferred Professional Certifications

The following certifications are listed as preferred:

  • Microsoft Certified: Azure Security Engineer Associate (AZ-500)
  • Microsoft Certified: Security Operations Analyst Associate (SC-200)
  • CompTIA Security+
  • Certified Ethical Hacker (CEH) or an equivalent certification

These certifications may strengthen an applicant’s profile, particularly where they complement hands-on experience in security operations and cloud environments.

Technical Skills and Tools

The position requires knowledge across several areas of cybersecurity.

Microsoft 365 Security

Experience with:

  • Microsoft Defender for Endpoint
  • Microsoft Defender for Office 365
  • Microsoft Purview DLP
  • Compliance Centre
  • Microsoft Secure Score
  • Threat Explorer

Azure Cloud Security

Knowledge of:

  • Microsoft Sentinel
  • SIEM/SOAR concepts
  • Defender for Cloud
  • Entra ID
  • Conditional Access
  • Privileged Identity Management
  • Multi-Factor Authentication
  • Azure Policy
  • Network Security Groups
  • Azure Firewall

Identity and Access Management

Understanding of:

  • Role-Based Access Control (RBAC)
  • Privileged Identity Management
  • Zero Trust architecture
  • Single Sign-On (SSO)
  • SAML
  • OAuth 2.0

Application Security

Knowledge of:

  • OWASP Top 10
  • DAST and SAST tools
  • Web Application Firewall management
  • API security
  • Secure software development lifecycle integration

Endpoint and Device Management

Experience with:

  • Microsoft Intune
  • Microsoft Defender for Endpoint
  • Windows Defender policies

Vulnerability Management

Knowledge of:

  • Microsoft Defender Vulnerability Management
  • Nessus or Qualys is desirable
  • CVSS scoring
  • Vulnerability scanning and remediation tracking

Networking

Understanding of:

  • TCP/IP
  • DNS
  • HTTP/S
  • VPN
  • Firewall rules
  • Zero Trust networking

Scripting and Security Automation

Knowledge of:

  • PowerShell
  • KQL (Kusto Query Language)
  • Sentinel
  • Log Analytics

PowerShell and KQL experience can be particularly useful for automating security tasks, querying logs, and building custom security detections.

Who Is This Role Suitable For?

This opportunity may suit a mid-level cybersecurity professional who has already worked in security operations and wants to apply those skills in a financial services environment.

The strongest candidates are likely to be comfortable working across several areas rather than focusing on only one cybersecurity discipline. The position covers cloud security, identity management, endpoint protection, application security, vulnerability management, incident response, and compliance.

Candidates should therefore review the full technical requirements carefully. Experience with Microsoft Sentinel, Defender, Azure, Entra ID, Microsoft 365 security, and KQL will be particularly relevant.

Application Deadline

The application closing date was not specified in the available vacancy information.

Applicants should confirm that the vacancy remains open before submitting their application.

Before applying, make sure your CV clearly demonstrates your cybersecurity experience, technical skills, certifications, and practical knowledge of tools such as Microsoft Sentinel, Defender, Azure, and Entra ID. You can also learn how to write a professional CV in Nigeria that gets interviews for practical tips on presenting your skills and experience effectively.

Application Preparation Tips

Before applying, review your CV against the technical requirements of the position.

Your CV should clearly demonstrate relevant experience with areas such as:

  • Microsoft Sentinel.
  • Microsoft Defender.
  • Microsoft 365 security.
  • Microsoft Azure security.
  • Entra ID.
  • Identity and access management.
  • Vulnerability management.
  • Incident response.
  • Application security.
  • KQL.
  • Security monitoring and threat detection.

Where possible, describe practical outcomes rather than simply listing tools. For example, highlight your experience investigating incidents, improving security controls, managing vulnerabilities, or supporting cloud security environments.

If you hold relevant certifications such as AZ-500, SC-200, Security+, or CEH, make sure they are clearly listed in your CV.

If you are shortlisted for the position, preparing for the interview is the next important step. Review 30 common job interview questions in Nigeria with sample answers and expert tips to help you prepare for questions about your cybersecurity experience, technical skills, problem-solving abilities, and previous projects.

How to Apply

Interested and qualified? Go to First Ally on docs.google.com to apply.

To apply for this job please visit docs.google.com.

Similar Jobs

Explore more job opportunities that may match your skills and interests.

Career Tips & Guides

Build your career with expert advice, interview tips and CV guides.

Scroll to Top
Verified by MonsterInsights