An international automotive OEM producing vehicles in 14 countries and delivering to over 150 markets worldwide is seeking qualified and experienced candidates for the position of Chief Information Security Officer (CISO) in the Infrastructure and Security Department - Information Technology, based in Kariega, Eastern Cape.
Job Role
- The CISO manages complex business issues, establishing an Enterprise Security Stance through policy, architecture, training, and security solutions aligned with company standards under the leadership of the Group IS Security Organisation (ISSO).
- Responsible for delivering, maintaining, and assessing the effectiveness of the Information Security Management Systems (ISMS).
- Prepares the organization to counter threats, establishes and communicates best practices for data security, and monitors security operations' effectiveness.
- Protects data and intellectual property, designs policies for breaches and disasters, and maintains best practices.
Key Responsibilities
- Achieves information security objectives within the legal entity by operationally managing the ISMS.
- Maintains and evaluates ISMS effectiveness.
- Identifies IT risks, recommends responses, and validates control effectiveness to reduce vulnerabilities.
- Supports stakeholders (internal/external) to ensure security matters are understood and managed.
- Leads application review processes to ensure compliance and security considerations.
- Manages vulnerabilities and oversees penetration testing and scanning.
- Ensures external partners conform to security policies through contract management.
- Develops security policies, guidelines, and delivers training and awareness campaigns.
- Keeps abreast of security trends and proposes improvements.
- Aligns risk management with group and local approaches.
- Supports risk acceptance for complex projects.
- Performs roles of PISO and Security Officer, overseeing security controls in shopfloor and vehicle manufacturing environments.
- Identifies threats, recommends measures, and oversees security policies and incident investigations.
Minimum Qualifications and Experience
- 3-year IT-related qualification (Degree or National Diploma).
- CISSP or other advanced security certification.
- 4-8 years experience as a Senior Information Security Officer.
- Understanding of business processes, project leadership, and industry-specific system knowledge.
- Knowledge of IS resources and financial management.