The Head: Information Security & GRC provides enterprise-wide leadership for the Bank’s ICT environment, information and systems security, cyber resilience, technology risk, governance, compliance and assurance. The role is accountable for establishing and maintaining a secure, resilient, compliant and business-aligned technology environment across infrastructure, cloud, applications, data, identity, third-party platforms and emerging technologies. The incumbent develops and executes integrated ICT and information security strategies, policies, standards, controls and operating models aligned to the Bank’s mandate, business strategy, risk appetite, regulatory obligations and recognised frameworks such as ISO/IEC 27001, NIST Cybersecurity Framework, COBIT, ITIL, POPIA and King V. The role enables secure digital transformation, strengthens operational resilience, provides executive and board-level reporting on technology and cyber risk, and embeds a culture of security, accountability, service excellence, innovation and continuous improvement across the organisation.
Key Responsibilities
KEY PERFORMANCE AREAS
1. Strategic Delivery
- Develop and execute a comprehensive ICT, information security, and GRC strategy aligned to the organisation’s overall business objectives and long-term vision.
- Identify strategic priorities and deliverables for Information / Security, and GRC based on the overall Bank strategy, ensuring alignment with organisational priorities.
- Own the enterprise ICT and security operating model, ensuring clear accountability for infrastructure, systems security, cloud security, identity and access management, data protection, resilience and GRC outcomes.
- Translate strategic priorities into clear digitalisation goals, initiatives, milestones, and measurable outcomes.
- Develop both long-term and short-term digitalisation strategies and implementation plans aligned to approved budgets and resource frameworks.
- Drive enterprise-wide adoption of digital solutions through structured communication and stakeholder engagement internally and externally.
- Lead the communication of the strategy to all stakeholders internally and externally.
- Drive ICT and cybersecurity as strategic business enablers by aligning technology and security initiatives with business objectives, digital transformation priorities, and enterprise risk management outcomes.
2. Governance and Compliance
- Establish and enforce information security policies, standards, and procedures.
- Maintain compliance with South African and international regulations (e.g.., POPIA, GDPR, ISO/IEC 27001).
- Conduct regular policy reviews and updates in line with regulatory changes.
- Liaise with legal, risk, compliance and audit teams to manage regulatory risks and compliance obligations.
- Promote cyber risk ownership across business units by embedding cybersecurity risk management into business processes and decision-making.
- Maintain an integrated technology, cyber and compliance control framework, including control ownership, testing, evidence management, remediation tracking and assurance reporting.
- Facilitate and drive appropriate, reasonable technical and organisational measures are implemented and evidenced to protect personal information, critical systems and sensitive business information.
3. Cyber Security Operations
- Oversee the Security Operations Centre (SOC) and ensure effective threat monitoring and response.
- Manage incident response plans and lead investigations into security breaches.
- Implement and maintain security technologies (