Enable job alerts via email!

Information Security Manager

Psg Konsult

Gauteng

On-site

ZAR 800 000 - 1 100 000

Full time

Today
Be an early applicant

Generate a tailored resume in minutes

Land an interview and earn more. Learn more

Job summary

A leading financial services group in Gauteng is seeking an Information Security Manager to lead cybersecurity strategy and operations. Responsibilities include managing security in a hybrid cloud infrastructure, overseeing SOC operations, ensuring compliance with regulations, and leading a high-performing cybersecurity team. Ideal candidates will have extensive experience in IT security and relevant certifications, alongside strong leadership and communication skills.

Qualifications

  • 8+ years of IT Security experience, with 5+ years in a leadership role.
  • Experience in managing BYOD environments and securing distributed branch networks.
  • Familiarity with scripting (PowerShell, Bash) and automation tools.

Responsibilities

  • Develop and maintain PSG's enterprise-wide cybersecurity strategy.
  • Oversee 24/7 SOC operations, ensuring effective threat detection.
  • Conduct regular risk assessments and vulnerability scans.

Skills

Leadership
Problem-solving
Microsoft security stack knowledge
Communication skills
Time management

Education

Bachelor's degree in Computer Science or related field
CISSP, CISM or equivalent
Microsoft Certified: Cybersecurity Architect Expert
GIAC Security Operations (GSOM) or equivalent

Tools

Microsoft E3/E5 security stack
SIEM systems
Security automation tools
Job description

Designation: Information Security Manager | Waterfall, Midrand, Gauteng | Permanent

Category: Information Technology | Job Level: Professionally qualified and experienced specialists and mid-management

Posted by: PSG Financial Services | Posted on: 03 Oct

  • Reference Number: POS
  • Closing date: 30-Oct
  • Position Type: Permanent
  • Location: Waterfall Magwa Crescent
Overview

PSG’s commitment to transform and embrace diversity is what drives us to achieve a diverse workplace with employment equity as a key goal to create an inclusive workforce. In achieving our employment equity goals, we give preference to applicants from designated groups and encourage people with disability to apply.

Job Description

The Information Security Manager will lead PSG's cybersecurity strategy, governance, and operations across a hybrid cloud infrastructure. This includes managing Microsoft security capabilities, integrating firewall technologies, overseeing the Cyber Security Operations Center (SOC), and ensuring compliance with regulatory and industry standards. The role also includes managing BYOD risks, securing branch networks, and aligning with globally recognized frameworks such as the NIST Cybersecurity Framework and Joint Security Standards (JSS).

Responsibilities
Strategic Leadership & Governance
  • Develop and maintain PSG's enterprise-wide cybersecurity strategy aligned with business objectives and regulatory requirements.
  • Establish and enforce security governance frameworks, policies, and standards.
  • Ensure alignment with the NIST Cybersecurity Framework (Identify, Protect, Detect, Respond, Recover) and Joint Security Standards.
  • Lead the implementation of relevant security compliance initiatives.
  • Collaborate with divisional CIOs and executive leadership to align security posture across business units.
  • Monitor emerging threats, regulatory changes, and industry trends to inform strategic decisions.
Architecture & Identity Management
  • Design secure solutions for hybrid environments (on-prem + Azure).
  • Integrate security into infrastructure and application projects.
  • Manage identity and access controls, including Azure AD, MFA, and privileged access management.
Security Operations
  • Manage day-to-day security monitoring, incident handling, and threat intelligence.
  • Administer Microsoft security features: Defender for Endpoint, Purview, Sentinel, Conditional Access, etc.
  • Ensure endpoint, network, and cloud security controls are effectively implemented and monitored.
  • Implement and enforce BYOD policies, including mobile device management (MDM), data loss prevention (DLP), and secure access controls.
  • Secure branch office networks, including firewalls, VPNs, segmentation, and remote access protocols.
Financial Management
  • Develop and manage the annual cybersecurity budget, including licensing, tools, training, and consulting services.
  • Track and report on security-related expenditures, ROI, and risk mitigation outcomes.
  • Support procurement and vendor management for security solutions.
Cyber Security Operations Center (SOC) Oversight
  • Oversee 24/7 SOC operations, ensuring effective threat detection, incident response, and escalation.
  • Define SOC roles, workflows, and incident response playbooks.
  • Integrate SIEM, SOAR, and threat intelligence platforms for proactive defense.
  • Monitor and improve KPIs such as MTTD (Mean Time to Detect) and MTTR (Mean Time to Respond).
  • Coordinate with external threat intelligence providers and law enforcement when necessary.
Security Technology Lifecycle Management
  • Oversee the deployment, maintenance, and upgrade of security technologies including Microsoft E3/E5 and Hailstone platforms.
  • Ensure timely patching, configuration updates, and feature adoption.
  • Maintain compatibility and integration of security tools with PSG's hybrid infrastructure.
  • Document system configurations and update operational procedures regularly.
Risk Management & Compliance
  • Conduct regular risk assessments, vulnerability scans, and penetration tests.
  • Ensure compliance with POPIA, GDPR, NIST CSF, JSS, and other relevant regulations and frameworks.
  • Maintain a risk register and track mitigation actions.
  • Coordinate internal and external audits and ensure timely remediation of findings.
Awareness, Education & Training
  • Lead organization-wide cybersecurity awareness programs.
  • Deliver targeted training for IT, business, and executive teams.
  • Promote secure behaviour and incident reporting culture.
Team Leadership & Culture
  • Build and lead a high-performing cybersecurity team, leveraging SOC analysts, engineers, and compliance specialists.
  • Define clear roles, responsibilities, and performance expectations.
  • Conduct regular coaching, performance reviews, and career development planning.
  • Foster a culture of accountability, innovation, and continuous improvement.
  • Promote cybersecurity awareness and ownership across all departments.
Reporting
  • Prepare operational, executive-level reports on security posture, risk exposure, and compliance status.
Minimum Requirements
  • Bachelor's degree in Computer Science, Information Technology, or related field.
  • 8+ years of IT Security experience, with 5+ years in a leadership role.
  • CISSP, CISM, or equivalent.
  • Microsoft Certified: Cybersecurity Architect Expert.
  • GIAC Security Operations (GSOM) or equivalent SOC certification.
  • Familiarity with scripting (PowerShell, Bash) and automation tools.
  • Experience in Microsoft and SharePoint Online.
  • Proven experience in cybersecurity leadership within hybrid cloud environments.
  • Deep knowledge of Microsoft E3/E5 security stack and Hailstone technologies.
  • Strong understanding of SIEM, SOAR, threat intelligence, and SOC operations.
  • Experience managing BYOD environments and securing distributed branch networks.
  • Familiarity with ISO/IEC, NIST, and CIS controls.
  • Excellent communication, stakeholder engagement, and team leadership skills.
Competencies Required
  • Strong leadership and problem‑solving skills.
  • Attention to detail.
  • Decision making prowess.
  • Resilience.
  • Good verbal and written communication skills.
  • Time management skills.
  • Deadline driven.
  • Technical documentation competency.

How to apply: Candidates interested must apply here by no later than 30 October.

By submitting your application, you are giving PSG Financial Services implicit consent to the storage and processing of your personal information.

If you are not contacted within 4 weeks of your application, please accept that your application was not successful.

For more information about careers at PSG, visit

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.