Cyber Security Specialist

Woolworths

Cape Town

On-site

ZAR 700,000 - 950,000

Full time

12 days ago
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Woolworths in Cape Town is seeking a Cyber Security Specialist to enhance a high‑performing security function within the IT team. You will translate cyber risk into business risk and enable secure adoption of technology, data and digital partnerships across the organisation.

You’ll collaborate with IT GRC, cyber team and business partners to raise security maturity, embed practices into business processes and protect critical information assets.

Qualifications

  • Relevant tertiary qualification in IT, CS, cybersecurity, information systems, engineering or related discipline.
  • Minimum 3 years’ experience in cybersecurity or information security.
  • Hands-on in implementing, configuring, operating, or supporting cybersecurity technologies and controls.
  • Experience across identity, data protection, third‑party risk, awareness, vulnerability, and infrastructure security.

Responsibilities

  • Strengthen IAM and PAM processes and governance across the business.
  • Plan and deliver security awareness initiatives and drive security culture transformation.
  • Support data protection controls, including DLP and CASB, and investigate alerts.
  • Conduct vendor security assessments and monitor third‑party risk.
  • Advise business units on practical, risk-based security guidance and remediation.

Skills

Identity & Access Management
Security awareness
Vulnerability management
Security governance

Education

Diploma or Advanced Certificate in IT or related field

Tools

DLP
CASB
IAM
PAM

Job description

Closing Date 2026/09/09

Reference Number WWL260902-4

Job Title Cyber Security Specialist

Job Type Full Time

Business Unit Information Technology

Location - Country South Africa

Location - Province Western Cape

Location - Town / City Cape Town

Location Description Head Office

Minimum Education Level Diploma | Advanced Certificate

Job Advert Summary

At Woolworths we are on a mission to maintain and develop a high-performing cyber and information security function in support of a complex business undergoing digital transformation. We are looking for a passionate Cybersecurity Specialist: Business Information Security to help strengthen security where business and technology meet, influence behaviour and drive practical security improvements.

You’ll be working as part of the Business Information Security (BIS) team to defend Woolworths against cyber threats and information security risks. You will work closely with the rest of the Cyber team, IT GRC, and partners across the Group to continually improve our security posture, plus supporting and transforming our security capabilities by embedding security practices into business practices, third party ecosystems, data handling and workforce behaviours to reduce cyber risk while supporting business objectives.

This role acts as a bridge between cybersecurity and business, translating cyber risk into business risk and enabling secure adoption of technology, data and digital partnerships. The role also requires good people skills to effectively interact and communicate with various stakeholders across Woolworths.

Minimum Requirements
  • A relevant tertiary qualification in Information Technology, Computer Science, Cybersecurity, Information Systems, Engineering, or a related discipline.
  • A minimum of three (3) years’ relevant experience in cybersecurity, information security, or a closely related role.
  • Demonstrable hands‑on technical capability in implementing, configuring, operating, assessing, or supporting cybersecurity technologies and controls.
  • Practical experience across multiple security domains, including identity and access management, data security and protection, third‑party risk management, security awareness and culture, vulnerability management, and infrastructure security across network, cloud, platform, and endpoint environments.
  • Strong working knowledge of cybersecurity principles, security architecture, technical control design, risk management practices, and commonly adopted security frameworks, standards, control libraries, and tools.
  • Ability to interpret technical security findings, assess associated business risks, identify control gaps, and recommend practical remediation actions.
  • Experience working with technical teams to investigate security issues, troubleshoot control‑related challenges, and support the implementation and continuous improvement of security solutions and processes.
  • Strong stakeholder engagement, communication, and interpersonal skills, with the ability to communicate technical security matters clearly to both technical and non‑technical audiences while maintaining professionalism.
  • Ability to work collaboratively across business, technology, risk, assurance, and third‑party teams and to influence security outcomes without relying solely on direct authority.
  • Evidence of active engagement with, and contribution to, the broader information security community through professional networks, knowledge sharing, industry events, research, mentoring, or similar activities.
Advantageous
  • Relevant qualifications and certifications such as ISO27001, CompTIA Security+, CISM, CISSP or similar certification is highly advantageous.
  • Knowledge of recognised frameworks and standards, including ISO/IEC 27001, NIST Cybersecurity Framework, CIS Critical Security Controls, COBIT and PCI DSS.
  • Experience working in environments with federated technology ownership, multiple business units, outsourced service providers and diverse application landscapes.
  • Experience within a large, complex or distributed enterprise environment—preferably retail, financial services or another highly regulated industry.
Additional Criteria
  • May be required to assist outside of working hours.
  • Working knowledge of PCI‑DSS.
  • Presents problem analysis and a recommended solution rather than just identifying and describing the problem itself
  • Demonstrates a results‑oriented mindset in planning and implementing activities/projects.
  • Monitors and tracks progress to ensure delivery of all planned commitments, and keeps the appropriate people informed
  • Prepares written reports and briefs and communicates ideas clearly
  • Speaks fluently in team meetings when presenting information
  • Manages existing partnerships within established agreements or contracts; negotiates adjustments when mutually beneficial to do so
  • Genuinely cultivates personal bonds with colleagues to enhance performance throughout the organisation
  • Adjusts to work effectively within new work structures, processes, requirements, or cultures
  • Demonstrates resourcefulness in acquiring necessary knowledge, skills, and competencies to adapt to change
Duties and Responsibilities
  • Identity and Access Management (IAM): Strengthen identity governance by supporting user access reviews and certifications, promoting the adoption of IAM standards and controls, and enabling the effective operation and continuous improvement of IAM and Privileged Access Management (PAM) processes across the business.
  • Security Awareness and Culture: Plan and deliver engaging security awareness initiatives, support security culture transformation programmes, and coordinate security champion networks in partnership with business teams.
  • Data Security and Protection: Support the implementation, operation and continuous improvement of data protection controls and technologies, including Data Loss Prevention (DLP) and Cloud Access Security Broker (CASB) solutions. Investigate data security alerts, identify potential control gaps and coordinate appropriate response and remediation actions.
  • Third-Party and Ecosystem Security: Conduct, review and track security assessments of vendors, service providers and business partners. Identify security risks and control deficiencies, monitor remediation commitments, and support the management of cyber risk across the broader third‑party ecosystem.
  • Business Security Advisory and Risk: Serve as a trusted security advisor to business units by providing practical, risk‑based guidance on projects, technology changes, business processes and emerging security concerns. Translate technical security risks into clear business impact and actionable recommendations.
  • Governance, Risk and Compliance: Support the implementation and maintenance of cybersecurity policies, standards, procedures and control frameworks. Assist with regulatory, audit, compliance and assurance activities, including evidence gathering, control assessments, finding remediation and progress tracking.
  • Vulnerability Management: Support the identification, validation, prioritisation and tracking of vulnerabilities. Coordinate remediation activities with infrastructure, application, cloud and other technical teams, and help stakeholders understand the associated business risks and required remediation actions.
  • Security Technology Operations and Enhancement: Maintain, administer and enhance existing and new cybersecurity technologies required to improve the organisation’s security posture and active defence capabilities, including DLP, CASB, IAM, PAM and related security platforms.
  • Security Investigation and Incident Support: Support the investigation, escalation and reporting of security events and incidents. Provide relevant business, data and risk context, coordinate with appropriate stakeholders, and contribute to lessons learned and control improvements.
  • Continuous Control Validation: Embed and support continuous control validation practices across technology, identity, cloud and data environments to confirm that cybersecurity controls are appropriately implemented and remain effective in protecting business operations and information assets.
  • Innovation and Automation: Research and evaluate emerging security approaches, technologies and automation opportunities. Challenge traditional practices and recommend improvements that increase control effectiveness, operational efficiency and security maturity.
  • Reporting and Metrics: Develop and mature Business Information Security reporting mechanisms, including dashboards, key risk indicators, key performance indicators and cybersecurity metrics. Analyse and present security trends, risks, control gaps and remediation progress to relevant stakeholders.
  • Stakeholder and Cross‑Team Collaboration: Establish and maintain effective working relationships with key stakeholders across business, technology, risk, compliance, assurance and third‑party teams to support the implementation and operation of security processes and controls.
  • Security Improvement and Remediation: Provide the technical context, guidance and coordination required to implement security improvements. Track agreed actions and help ensure that identified risks, vulnerabilities and control deficiencies are remediated within appropriate timeframes.
Additional Responsibilities
  • Collaborate with the broader Cyber Security Team to drive and support various operational and strategic initiatives.
  • Champion or co‑champion internal security solutions and/or processes.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Business-Focused Cybersecurity Advisor
Business-Focused Cybersecurity Advisor

Woolworths • Cape Town

On-site
ZAR 700,000 - 950,000
Cybersecurity Specialist (CPT Hybrid)
Cybersecurity Specialist (CPT Hybrid)

Datafin • Cape Town

On-site
ZAR 600,000 - 800,000
Cyber Security Specialist
Cyber Security Specialist

Placements24 • Bloemfontein

Hybrid
ZAR 420,000 - 600,000
Hybrid work model
Competitive salary with bonuses
Health & wellness benefits
+1
Senior Security Analyst
Senior Security Analyst

Interfront SOC • Somerset West

Hybrid
ZAR 900,000 - 1,300,000
Hybrid working conditions
Open to people with disabilities
Information Security Specialist
Information Security Specialist

Placements24 • Klerksdorp

On-site
ZAR 420,000 - 780,000
Salary plus bonuses
Medical aid
Pension fund contributions
+3
Specialist Cybersecurity Consultant
Specialist Cybersecurity Consultant

ATS Client • Johannesburg

Hybrid
ZAR 600,000 - 900,000
Hybrid/Remote work
Certification support
Professional development
+1
Governance, Risk and Compliance Specialist
Governance, Risk and Compliance Specialist

Rory Mackie & Associates • Cape Town

On-site
ZAR 600,000 - 800,000
Cybersecurity Specialist
Cybersecurity Specialist

Placements24 • Rustenburg

Hybrid
ZAR 900,000 - 1,200,000
Salary incentives
Health + Retirement
Paid time off
+2
Senior Cybersecurity Specialist
Senior Cybersecurity Specialist

Placements24 • Klerksdorp

Hybrid
ZAR 800,000 - 1,100,000
Hybrid work arrangement
Career development opportunities
Security Defence & Operations Lead
Security Defence & Operations Lead

Salix Recruitment • Johannesburg

On-site
ZAR 900,000 - 1,500,000