Job Search and Career Advice Platform

Enable job alerts via email!

Business Information Security Officer

Absa Group Limited

Gauteng

On-site

ZAR 700 000 - 900 000

Full time

Today
Be an early applicant

Generate a tailored resume in minutes

Land an interview and earn more. Learn more

Job summary

A financial services organization seeks a Business Information Security Officer in Gauteng to integrate cybersecurity into unit strategies, manage security incidents, and ensure compliance with regulations. The ideal candidate has a relevant Bachelor's degree, industry certifications, and extensive experience in IT security. The role involves implementing security policies, conducting risk assessments, and training staff on security practices.

Qualifications

  • 8 years of experience in information technology, with at least 3 years in IT Project Management.
  • Ongoing training in information security, risk management, and regulatory compliance.

Responsibilities

  • Integrate cybersecurity measures into business unit's strategy.
  • Implement security policies and conduct risk assessments.
  • Manage security incidents to safeguard information assets.
  • Oversee security awareness and training programs.
  • Report on security posture and compliance with regulations.

Skills

Knowledge of information security frameworks
Experience in risk assessments
Ability to enforce security policies
Understanding of incident response
Knowledge of data privacy regulations
Experience with third-party risk management
Familiarity with IT security technologies

Education

Relevant Bachelor's degree in Information Security or related field
Certified Information Security Manager (CISM)
Certified Information Systems Security Professional (CISSP)
Certified in Risk and Information Systems Control (CRISC)
Job description

Job title: Business Information Security Officer

Location: Gauteng, Randburg

Application deadline: November 30

Job Summary

The Business Unit Business Information Security Officer (BISO) is responsible for integrating cybersecurity measures into the business unit's strategy, ensuring that information security initiatives align with and support its specific goals.

The BU BISO acts as a bridge between the central security function and business unit leadership, providing expertise on risk management, compliance, and data protection within the unit's unique operational context.

This role involves implementing security policies, conducting risk assessments, and managing security incidents to safeguard the unit's information assets.

Key Accountabilities
  • Bridge the gap between business operations and IT security.
  • Act as a liaison and translator between technical security teams and business units, ensuring security initiatives align with business objectives and risk appetite.
  • Implement and maintain information security policies and procedures.
  • Develop, implement, and enforce information security policies, standards, and procedures aligned with industry best practices and regulatory requirements.
  • Conduct risk assessments and business impact analyses.
  • Identify, assess, and prioritize information security risks across the organization, and develop mitigation plans to address them.
  • Oversee security awareness and training programs.
  • Develop and implement security awareness programs to educate employees on security best practices and promote a security-conscious culture.
  • Collaborate with IT security teams to ensure technical security controls are implemented effectively and aligned with business needs.
  • Monitor and respond to security incidents, assisting in the investigation and ensuring appropriate containment and remediation.
  • Manage third‑party security risks, assessing and mitigating risks associated with vendors and partners.
  • Ensure compliance with regulations and standards such as GDPR, HIPAA, PCI‑DSS, and ISO.
  • Report on security posture and KPIs, providing regular reports to senior management on risks and key performance indicators.
Preferred Education

Relevant Bachelor's degree in Information Security, Computer Science, or a related field.

Industry certifications such as Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP), or Certified in Risk and Information Systems Control (CRISC).

Ongoing training in information security, risk management, and regulatory compliance.

Preferred Experience

8 years' experience in the information technology or related field, with at least 3 years in IT Project Management.

Knowledge and Skills
  • Knowledge of information security frameworks and standards such as ISO, NIST Cybersecurity Framework, and COBIT.
  • Experience in conducting risk assessments, business impact analyses, and developing risk mitigation plans.
  • Ability to develop, implement, and enforce information security policies and procedures.
  • Understanding of incident response processes and procedures.
  • Knowledge of data privacy regulations and best practices for protecting sensitive information.
  • Experience assessing and managing security risks associated with third‑party vendors and partners.
  • Familiarity with key IT security technologies such as firewalls, intrusion detection systems, and vulnerability scanners.
Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.