Enable job alerts via email!

Information Security Management System (ISMS) Specialist

Edge Executives

Johannesburg

On-site

ZAR 700 000 - 900 000

Full time

13 days ago

Generate a tailored resume in minutes

Land an interview and earn more. Learn more

Job summary

A prominent national enterprise in the FMCG logistics and distribution sector is searching for an Information Security Management System Specialist. This role focuses on designing and implementing robust security frameworks, ensuring compliance with ISO standards, and collaborating closely with leadership and service providers. Candidates should have extensive experience in cybersecurity, strong communication skills, and relevant certifications. This position offers an opportunity to lead security initiatives in a fast-paced environment.

Qualifications

  • 7-10 years' information security/cybersecurity experience with 1-3 years in a leadership capacity.
  • Proven end-to-end ISMS implementation and certification maintenance experience.
  • Strong knowledge of ISO / IEC, NIST, CIS Controls; familiarity with ITIL / COBIT.

Responsibilities

  • Own the design, rollout, and continual improvement of the ISMS aligned to ISO / IEC.
  • Lead risk assessments aligned to ISO and track mitigation to closure.
  • Prepare the organisation for external audits and certification.

Skills

Information Security Management
Cybersecurity
Risk Management
Stakeholder Management
Incident Response

Education

Bachelor’s degree in Information Security, Computer Science, IT, or related field
ISO / IEC Implementer certification

Tools

Microsoft Sentinel
Defender
Job description
Overview

Website / Socials Advert Information Security Management System (ISMS) Specialist | Westville, KZN | PermanentHelp a national operation achieve and sustain ISO / IEC

  • excellence.

If you thrive on building robust security frameworks and turning policy into practice, this role is for you.You will design, implement, and continuously improve the organisation's Information Security Management System (ISMS) in alignment with ISO / IEC

Working across technology and business teams, you'll safeguard the confidentiality, integrity, and availability of information assets while steering compliance with South African regulations and global best practices.

This senior role partners closely with leadership and managed service providers to embed security into day-to-day operations and strategic planning.Our client is a large, complex, and fast-moving national enterprise in the FMCG logistics and distribution space.

With technology at the core of its supply chain, they are investing in security maturity and seeking a specialist who can lead risk-driven improvements and guide the journey to certification and beyond.

What You’ll Do
  • Own the design, rollout, and continual improvement of the ISMS aligned to ISO / IEC
  • and mapped to frameworks such as NIST, CIS, and ITIL / COBIT where relevant
  • Develop, maintain, and govern security policies, standards, procedures, and SoA documentation
  • Lead risk assessments aligned to ISO
  • Define treatment plans and track mitigation to closure
  • Prepare the organisation for external audits and certification; coordinate internal audit cycles and evidence management
  • Build and deliver security awareness and training programmes across technical and non-technical audiences
  • Strengthen incident response: develop and test playbooks, support investigations, and drive post-incident reviews and preventive actions
  • Monitor ISMS performance, report KPIs / KRIs, and recommend enhancements based on audit findings, risks, and emerging threats
  • Partner with managed service providers and internal teams on vulnerability management, patching, JML, BIA / BCM / DR, and tooling (e.g., Microsoft Sentinel, Defender, EDR)
What You Bring
  • Bachelor’s degree in Information Security, Computer Science, IT, or related field
  • ISO / IEC Implementer certification (mandatory); Auditor, CISM, CRISC, or CISA advantageous
  • 7–10 years' information security / cybersecurity experience with 1–3 years in a leadership capacity
  • Proven end-to-end ISMS implementation and certification maintenance experience, including work with certification bodies
  • Strong knowledge of ISO / IEC, ISO, NIST, CIS Controls; familiarity with ITIL / COBIT
  • Solid exposure to South African regulatory requirements (e.g., POPIA, Cybercrimes Act)
  • Hands‑on experience in risk, audit, incident response, vulnerability management, patching, JML, and security awareness
  • Excellent communication, stakeholder management, and the ability to translate complex security concepts for diverse audiences
What Success Looks Like
  • ISO / IEC certification achieved and sustained, with clean audit outcomes and timely closure of findings
  • Measurable reduction in priority risks and improved security KPIs / KRIs across the estate
  • Policies and SoA are current, adopted, and evidenced; the lifecycle is managed effectively
  • Incident response is tested, repeatable, and reduces time‑to‑detect and time‑to‑contain
  • Security awareness improves across the business, with strong engagement from leadership and end‑users
  • Effective collaboration with managed service partners, delivering consistent, high‑quality security operations
Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.