Job Location : Gauteng, Pretoria Deadline : May 14, 2025
Detailed Description
The successful candidate will be responsible for the following key performance areas:
Advise and drive security minded thinking to ensure effective consideration of security control objectives across the SARB Group, while optimising processes.
Provide technical direction, oversight, coaching and mentoring to BSTD team members in the operational and development landscape regarding security controls, ensuring the delivery of secure implementations.
Define, design and optimise effective security mechanisms that enable secure business processes.
Research and stay abreast of the threat landscape and the latest developments to mitigate cyber and system security risks, aligned to governance controls for systems on-premises and in the cloud.
Identify security requirements, from business requirements, and define and guide the development and maturing of controls to enable a mitigated business risk.
Liaise with security architects and technical teams as well as security service providers to share best practices and insights both within SARB Group and the industry.
Assess the effectiveness and completeness of existing architectural artifacts and security patterns and provide direction on artifacts and pattern expansion in order to reduce the SARB Group’s risk posture.
Evaluate implemented security controls and mechanisms for their effectiveness and identify gaps to improve and extend the use of such controls.
Guide and ensure effective compliance measurement interpretation in order to ensure effective SARB Group risk posture reporting across all domains.
Create, and provide input into the maintenance and definition of, security policies, frameworks and standards in accordance with corporate governance including the Bank’s policies, procedures and other legislative requirements.
Develop and evaluate Requests for Information (RFIs) and Requests for Proposals (RFPs) for security specific solutions and provide guidance on security requirements for business solutions.
Act on management requests to address or mitigate risks in the SARB Group environment as identified.
Play a consulting role in responding to critical security incidents within the SARB Group as a member of the Incident Response team (CSIRT).
Job Requirements
To be considered for this position, candidates must be in possession of:
A minimum of a BSc. Computer Science Honours / BSc. Engineering Honours (NQF 8) plus Industry specific qualifications OR equivalent;
CISSP qualification is required.
8–10 years’ experience in an information security function with at least 3-5 years of job-related experience in application/infrastructure/cloud security design and consultation.
Additional Requirements Include
Other industry specific qualifications such as SSCP, CCSP, CSSLP, CISM, TOGAF etc. will be advantageous to aid in the selection of the focus area between applications and infrastructure both on premises and cloud.
Application security design
Data security design
Infrastructure security design
System integration
ICT industry standards
Information security
Services design
Architecture views and viewpoints design
Threat and Risk Analysis
IT governance, risk and compliance
Security frameworks and standards such as ISO 27000-series, NIST, etc.