Key ResponsibilitiesAssist in developing, reviewing, and maintaining IT policies, procedures, and standards.Support implementation of governance frameworks (e.g., ISO 27001, NIST, PCI).Ensure alignment between business objectives and security/governance controls.Identify, assess, and document IT risks, and track mitigation actions and ensure risks are addressed within defined timelines.Ensure compliance with relevant standards such as: PCI, ISO 27001 / ISO 22301, and regulatory requirements (as applicable)Support internal and external audits (e.g., PCI audits, certification audits).Collect and validate compliance evidence.Coordinate internal audit activities and prepare documentation.Prepare GRC dashboards and reports for management.Qualifications & RequirementsEducationBachelor’s degree in information security, IT, Computer Science, or related field.Experience1–3 years of experience in GRC, or IT Security.Hands-on experience with compliance frameworks (PCI DSS,PCI CP preferred).Certifications (Preferred)ISO 27001 Lead Implementer / Lead AuditorCRISC, or CGRCPCI DSS-related certifications (e.g., PCIP)Technical SkillsKnowledge of: Risk assessment methodologiesSecurity controls and frameworksAudit processes and compliance requirementsSoft SkillsStrong analytical and problem-solving skillsExcellent communication and reporting skillsAttention to detailAbility to work cross-functionally with IT, Audit, and information security
Modupay is the leading payments tech enabler across the Middle East and Africa, empowering banks, fintechs, telcos, and non-banking financial institutions to build, launch, and operate payment products with flexibility and control.
With over 30 years of experience, we provide end-to-end solutions across the payments lifecycle—from personalized card production and payment processing to digital ba… read more