Enable job alerts via email!

Business Information Security Officer

Absa Group

Randburg

On-site

ZAR 700 000 - 900 000

Full time

Today
Be an early applicant

Job summary

A leading financial institution is seeking a Business Information Security Officer to integrate cybersecurity measures into its strategy. The successful candidate will bridge the gap between business operations and IT security while ensuring compliance with security frameworks such as ISO 27001. Ideal applicants should possess a relevant bachelor's degree and significant experience in the IT security field. This role offers an opportunity to enhance security awareness and response strategies within the organization.

Qualifications

  • Minimum of 8 years in IT or related field required.
  • At least 3 years in IT Project Management preferred.

Responsibilities

  • Act as a liaison between business operations and IT security.
  • Develop, implement, and enforce information security policies.
  • Conduct risk assessments and business impact analyses.
  • Create security awareness and training programs.
  • Monitor and respond to security incidents.

Skills

Knowledge of ISO 27001
Risk Management expertise
Developing security policies
Incident Response skills
Familiarity with firewalls and IDS

Education

Bachelor's degree in Information Security
CISM, CISSP, or CRISC certification
Job description

Empowering Africa’s tomorrow, together…one story at a time.

Job Summary

The Business Unit Business Information Security Officer (BISO) is responsible for integrating cybersecurity measures into the business unit’s strategy, ensuring that information security initiatives align with and support its specific goals. The BU BISO acts as a bridge between the central security function and business unit leadership, providing expertise on risk management, compliance, and data protection within the unit’s unique operational context. This role involves implementing security policies, conducting risk assessments, and managing security incidents to safeguard the unit’s information assets.

Job Description
Key accountabilities
  • Bridge the gap between business operations and IT security. Act as a liaison and translator between technical security teams and business units, ensuring security initiatives align with business objectives and risk appetite.
  • Implement and maintain information security policies and procedures. Develop, implement, and enforce information security policies, standards, and procedures aligned with industry best practices and regulatory requirements.
  • Conduct risk assessments and business impact analyses. Identify, assess, and prioritize information security risks across the organization, and develop mitigation plans to address them.
  • Oversee security awareness and training programs. Develop and implement security awareness programs to educate employees on security best practices and promote a security-conscious culture.
  • Collaborate with IT security teams. Work closely with IT security teams to ensure technical security controls are implemented effectively and aligned with business needs.
  • Monitor and respond to security incidents. Assist in the investigation and response to security incidents, ensuring appropriate actions are taken to contain and remediate threats.
  • Manage third-party security risks. Assess and manage security risks associated with third-party vendors and partners.
  • Ensure compliance with regulations and standards. Maintain compliance with relevant regulations and standards, such as GDPR, HIPAA, PCI-DSS, and ISO 27001.
  • Report on security posture and KPIs. Provide regular reports to senior management on the organization's security posture, risks, and key performance indicators.
Role/person specification
Preferred Education
  • Relevant Bachelor's degree in Information Security, Computer Science, or a related field.
  • Industry certifications such as Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP), or Certified in Risk and Information Systems Control (CRISC).
  • Ongoing training in information security, risk management, and regulatory compliance.
Preferred Experience
  • 8 years’ experience in the information technology or related field
  • 3 years in IT Project Management
Knowledge and Skills
  • Information Security Frameworks and Standards. Knowledge of relevant information security frameworks and standards, such as ISO 27001, NIST Cybersecurity Framework, and COBIT.
  • Risk Management. Experience in conducting risk assessments, business impact analyses, and developing risk mitigation plans.
  • Security Policies and Procedures. Ability to develop, implement, and enforce information security policies and procedures.
  • Incident Response. Understanding of incident response processes and procedures.Data Privacy and Protection. Knowledge of data privacy regulations and best practices for protecting sensitive information.
  • Third-Party Risk Management. Experience in assessing and managing security risks associated with third-party vendors and partners.
  • IT Security Technologies. Familiarity with key IT security technologies, such as firewalls, intrusion detection systems, and vulnerability scanners.
Education

Bachelor`s Degrees and Advanced Diplomas: Physical, Mathematical, Computer and Life Sciences (Required)

Absa Bank Limited is an equal opportunity, affirmative action employer. In compliance with the Employment Equity Act 55 of 1998, preference will be given to suitable candidates from designated groups whose appointments will contribute towards achievement of equitable demographic representation of our workforce profile and add to the diversity of the Bank.

Absa Bank Limited reserves the right not to make an appointment to the post as advertised

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.