Advance your career with BetaJob Certificates
Create account, take courses and earn verifiable certificates. Download and add certifications to your profile for better chance of getting hired.
Paystack is a technology company solving payments problems for ambitious businesses. Paystack's mission is to help merchants in Africa get paid by anyone, anywhere in the world. Over 9,000 of some of the best businesses in Nigeria use Paystack’s modern payments gateway, including MTN, Taxify, Domino’s Pizza, Smile Communications, Opera, God is Good Motors, Axa Mansard Insurance, and many others. We are recruiting to fill the position below:
Job Title: Senior IT Engineer
Location: Lagos (Hybrid) About the Role
Our IT Operations team is a small, high-impact platform engineering unit. We manage the identity, endpoint, network, and access infrastructure for over 300 employees and 100+ outsourced agents across six offices (Lagos, Nairobi, Accra, Cape Town, and Dubai). We manage a fully automated macOS fleet, every physical office network, and roughly thirty core applications secured behind SSO. We do all of this inside a highly regulated fintech environment that holds PCI-DSS and ISO 27001 certifications and operates under the CBN. Our environment is heavily integrated and highly automated. We’ve built an identity lifecycle that flows automatically from our HR systems into our identity provider. Macs deploy zero-touch, and access requests provision themselves. As our scale and complexity increase, we are bringing on a Senior IT Infrastructure Engineer to expand our engineering capacity and provide critical redundancy across our Tier-1 systems. Reporting directly to the Head of IT, you will help drive, manage, and maintain this integrated ecosystem while executing on our long-term infrastructure roadmap.
We’ll trust you to
Drive Identity Management: Manage our identity lifecycle. You will configure SAML and OIDC across our application estate, maintain SCIM provisioning, manage attribute-driven RBAC, and enforce phishing-resistant authentication. Maintain Lifecycle Automation: Support and improve the joiner/mover/leaver pipeline. Build automated processes for accessmenent from approval to access provisioning Manage the Fleet & Device Trust: Oversee our macOS environment. This includes automated enrollment, configuration profiles, EDR, and enforcing DLP on outsourced devices. You will help maintain device trust as a real, certificate-backed control that rejects unmanaged or unpatched devices. Maintain Global Networks: Manage the physical network across six locations. You’ll handle multi-WAN failover, VLAN segmentation, centrally managed wireless/switching, server rooms, and the carrier connectivity linking our on-premise infrastructure to the cloud. Drive the Zero Trust Migration: Help us execute the transition away from legacy VPNs. You will drive our move to Zero Trust Network Access (ZTNA), enforcing per-application authorization based on real-time device posture. Build as Code: Treat the IT environment as code. You’ll use Terraform, Git-based staging-to-production pipelines, and Python/Bash where no provider exists. Your first instinct should always be to reach for an API before logging into an admin console. Enforce Automated Compliance: Turn regulatory requirements into automated controls that generate their own evidence. We balance ISO 27001, ISO 20000, PCI-DSS, NDPR, and the CBN IT Blueprint simultaneously. Resolve Complex Tickets: We all work tickets leadership included. You will handle complex escalations and diagnose faults that span a firewall, a carrier, and a cloud provider all at once. Document for the Future: Write documentation to a standard that survives your absence.
You’ll thrive in this role if you
5+ years in infrastructure or systems engineering, ideally including time on a small, high-leverage team. Real depth in at least two of the four areas below, and enough baseline competence in the rest to handle an escalation (we are not looking for a unicorn who is a master of all four): Identity & Access Management: SAML 2.0, OIDC, OAuth 2.0, SCIM 2.0, LDAP, WebAuthn/FIDO2. You have actually built lifecycle automation, not just clicked through SSO setup wizards. Endpoint Management at Scale: Apple MDM protocols, zero-touch enrollment, declarative configurations, and compliance enforcement across hundreds of devices. Network Engineering: Multi-site and multi-carrier setups, VLANs, complex routing, firewall policies, multi-WAN failover, 802.1X, and RADIUS. Infrastructure as Code: Terraform, Git workflows (with peer review), and enough Python, Go, or Bash to confidently build against a REST API.
Experience operating under external assessors with multiple active compliance frameworks. A track record of inheriting live, critical systems and improving them without breaking what already works. The engineering judgment to know when not to automate. (Not everything needs to be code). Strong technical writing skills. You write specs, procedures, and audit responses that other teams can actually understand and act on.
Not Specified. How to Apply
Click Apply Now button to apply
Monthly based
Worldwide
Lagos
Create account, take courses and earn verifiable certificates. Download and add certifications to your profile for better chance of getting hired.