Head: Information Security & GRC

Development Bank of Southern Africa (DBSA)

Midrand

On-site

ZAR 1,200,000 - 1,800,000

Full time

4 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Development Bank of Southern Africa (DBSA) seeks Head: Information Security & GRC to lead enterprise ICT, information security, cyber resilience, and compliance across the bank. You will develop strategy, policies, and assurance reporting with alignment to risk appetite and regulatory obligations.

The role drives governance, control frameworks (ISO 27001, NIST, COBIT), incident response, and embedding a culture of security and continuous improvement across infrastructure, cloud, data and

Qualifications

  • Develop and implement ICT, information security, and GRC strategies.
  • Establish and enforce information security policies, standards, and procedures.
  • Liaise with legal, risk, compliance and audit teams to manage regulatory risks and compliance obligations.
  • Oversee Security Operations Centre (SOC) and incident response planning.

Responsibilities

  • Develop and execute a comprehensive ICT, information security, and GRC strategy aligned to business objectives.
  • Maintain regulatory compliance with POPIA, GDPR, ISO/IEC 27001 and related frameworks.
  • Oversee SOC operations, threat monitoring, and incident investigations.
  • Drive governance, risk, and assurance reporting to executives and board.

Job description

The Head: Information Security & GRC provides enterprise-wide leadership for the Bank’s ICT environment, information and systems security, cyber resilience, technology risk, governance, compliance and assurance. The role is accountable for establishing and maintaining a secure, resilient, compliant and business-aligned technology environment across infrastructure, cloud, applications, data, identity, third-party platforms and emerging technologies. The incumbent develops and executes integrated ICT and information security strategies, policies, standards, controls and operating models aligned to the Bank’s mandate, business strategy, risk appetite, regulatory obligations and recognised frameworks such as ISO/IEC 27001, NIST Cybersecurity Framework, COBIT, ITIL, POPIA and King V. The role enables secure digital transformation, strengthens operational resilience, provides executive and board-level reporting on technology and cyber risk, and embeds a culture of security, accountability, service excellence, innovation and continuous improvement across the organisation.

Key Responsibilities
KEY PERFORMANCE AREAS
1. Strategic Delivery
  • Develop and execute a comprehensive ICT, information security, and GRC strategy aligned to the organisation’s overall business objectives and long-term vision.
  • Identify strategic priorities and deliverables for Information / Security, and GRC based on the overall Bank strategy, ensuring alignment with organisational priorities.
  • Own the enterprise ICT and security operating model, ensuring clear accountability for infrastructure, systems security, cloud security, identity and access management, data protection, resilience and GRC outcomes.
  • Translate strategic priorities into clear digitalisation goals, initiatives, milestones, and measurable outcomes.
  • Develop both long-term and short-term digitalisation strategies and implementation plans aligned to approved budgets and resource frameworks.
  • Drive enterprise-wide adoption of digital solutions through structured communication and stakeholder engagement internally and externally.
  • Lead the communication of the strategy to all stakeholders internally and externally.
  • Drive ICT and cybersecurity as strategic business enablers by aligning technology and security initiatives with business objectives, digital transformation priorities, and enterprise risk management outcomes.
2. Governance and Compliance
  • Establish and enforce information security policies, standards, and procedures.
  • Maintain compliance with South African and international regulations (e.g.., POPIA, GDPR, ISO/IEC 27001).
  • Conduct regular policy reviews and updates in line with regulatory changes.
  • Liaise with legal, risk, compliance and audit teams to manage regulatory risks and compliance obligations.
  • Promote cyber risk ownership across business units by embedding cybersecurity risk management into business processes and decision-making.
  • Maintain an integrated technology, cyber and compliance control framework, including control ownership, testing, evidence management, remediation tracking and assurance reporting.
  • Facilitate and drive appropriate, reasonable technical and organisational measures are implemented and evidenced to protect personal information, critical systems and sensitive business information.
3. Cyber Security Operations
  • Oversee the Security Operations Centre (SOC) and ensure effective threat monitoring and response.
  • Manage incident response plans and lead investigations into security breaches.
  • Implement and maintain security technologies (
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Strategic Head of Information Security & GRC
Strategic Head of Information Security & GRC

Development Bank of Southern Africa (DBSA) • Midrand

On-site
ZAR 1,200,000 - 1,800,000
IT Governance, Risk and Compliance Manager
IT Governance, Risk and Compliance Manager

Impronics Technologies • Gauteng

On-site
ZAR 700,000 - 1,100,000
Junior GRC Security Analyst
Junior GRC Security Analyst

Network Recruitment • Johannesburg

On-site
ZAR 1,000,000 - 1,600,000
Information Security Officer
Information Security Officer

Oldmutual • Cape Town

On-site
ZAR 900,000 - 1,300,000
ICT Risk & Projects Officer
ICT Risk & Projects Officer

Durpro Workforce Solutions • Durban

On-site
ZAR 600,000 - 800,000
Manager: IT Risk and Governance
Manager: IT Risk and Governance

Tafadzwa • Pretoria

On-site
ZAR 900,000 - 1,500,000
Information Security Specialist
Information Security Specialist

KPMG South Africa • Johannesburg

On-site
ZAR 650,000 - 950,000
Information Security Manager
Information Security Manager

Placements24 • Richards Bay

Hybrid
ZAR 1,200,000 - 2,000,000
Executive bonus structure
Medical insurance
Retirement plan
+1
Information Security Officer
Information Security Officer

Jobtailor • Johannesburg

On-site
ZAR 1,200,000 - 1,800,000
General Manager Information Technology
General Manager Information Technology

Hire Resolve • Durban

On-site
ZAR 1,500,000 - 2,600,000