Information Security Officer
What is in it for you?
This is an opportunity to join the Shared Services division (East Rand based) of an established listed manufacturing group, where you will play a key role in shaping and strengthening the organisation's information security and cybersecurity landscape.
This is not simply an operational security role. You will have the opportunity to influence strategy, drive cyber- risk management and governance, strengthen security maturity and engage with senior stakeholders across the business.
What you will be doing
- Information security and cybersecurity strategy, roadmaps and governance
- Cyber-risk identification, assessment, monitoring and reporting
- Security policies, standards and control frameworks
- Security across infrastructure, applications, cloud, data and operational technology (OT)
- Security operations, vulnerability management and threat monitoring
- Cyber incident readiness and response
- Governance, Risk and Compliance (GRC)
- Identity, access and data-protection controls
- Third-party and supply-chain security risk
- Cybersecurity awareness and organisational security culture
- Security audits, assurance reviews and remediation
- Reporting on security posture, risks and priorities to senior leadership and governance forums
What do you need to bring?
- Degree in Computer Science, Information Technology, Information Systems or a related discipline
- Relevant Information Security or Cybersecurity certification
- 8-10 years' relevant experience within Information Security, Cybersecurity, IT Risk, IT Governance, Infrastructure Security, Security Operations or related disciplines
- At least 5 years' experience in a cybersecurity leadership, management or senior specialist role
- Strong experience in information security governance, risk and compliance
- Proven exposure to security strategies, frameworks, policies, audits, risk assessments and incident management
- Experience across infrastructure, applications, cloud environments, data platforms and/or OT environments
- The ability to engage confidently with executives, auditors, technology teams and business stakeholders
- CISSP and/or CISM certification and a relevant postgraduate qualification would be advantageous.