Compliance and Data Security Expert (Contractor)
Kempton Park, South Africa | Posted on 03 / 20 / MUSE is a consulting company, specialising in resourcing, recruitment and outsourcing of software development teams. MUSE was founded and is run by experienced developers who are passionate about technology and innovation.
We have a vision to be the best in the industry and to provide software development skills that are cutting-edge and high-quality. We work with some of the leading companies in South Africa and we help them build software products and solutions that are game-changing and future-oriented.
We are also at the forefront of applying AI, AR and Machine-Learning concepts to real-world problems. Our main goal is to help our clients get the most value from their technology investments.
We do this by understanding their needs and providing them with the best talent available. We aim to be a vital part of the SDLC.
Job Description
The Compliance and Data Security Expert will be responsible for developing, implementing, and maintaining a robust compliance and data security program.
This role requires a deep understanding of relevant regulations, industry best practices, and security technologies.
The ideal candidate will be a proactive problem solver with excellent communication skills and a passion for ensuring the confidentiality, integrity, and availability of our data.
Responsibilities
- Develop and maintain policies and procedures to ensure compliance with relevant regulations (e.g., POPIA, GDPR, ISO, industry-specific regulations).
- Conduct regular compliance audits and risk assessments.
- Monitor and report on compliance status.
- Stay up-to-date with changes in regulations and industry standards.
- Provide guidance and training to employees on compliance requirements.
- Develop and implement data security policies and procedures.
- Conduct security risk assessments and vulnerability scans.
- Implement and manage security controls (e.g., access control, encryption, intrusion detection).
- Monitor and respond to security incidents.
- Manage data loss prevention and data backup/recovery processes.
- Implement and maintain data governance frameworks.
- Identify and assess potential compliance and security risks.
- Develop and implement risk mitigation strategies.
- Maintain a risk register.
- Conduct business impact analysis.
- Develop and maintain an incident response plan.
- Lead incident response activities.
- Communicate effectively with stakeholders on compliance and security matters.
- Provide regular reports to management.
- Liaise with external auditors and regulatory bodies.
Requirements
Qualifications and Skills
- Bachelor's degree in Computer Science, Information Security, Law, or a related field (or equivalent experience).
- Relevant certifications (e.g., CISSP, CISM, CISA, CDPO/DPO).
- Proven experience in compliance and data security management.
- Deep understanding of relevant regulations (POPIA, GDPR, ISO, etc.).
- Experience with security risk assessments and vulnerability scanning.
- Knowledge of security technologies and best practices.
- Strong analytical and problem-solving skills.
- Excellent communication and interpersonal skills.
- Ability to work independently and as part of a team.
- Experience with data governance frameworks.
- Experience with cloud security.
Desired Attributes
- Proactive and detail-oriented.
- Strong ethical principles.
- Ability to manage multiple priorities.