Information Security Officer

oldmutual

Cape Town

On-site

ZAR 900,000 - 1,300,000

Full time

7 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Old Mutual is seeking an experienced Information Security Officer to drive the delivery of the organisation's cybersecurity strategy across assigned business units. The role translates strategies into practical initiatives, embedding secure-by-design practices and strengthening cyber resilience across applications, infrastructure, cloud, data, third parties and digital services.

You will lead and coordinate security improvement roadmaps, manage regulatory obligations, and collaborate with

Qualifications

  • Experience leading information security programmes and teams.
  • Knowledge of regulatory obligations and risk management in financial services.

Responsibilities

  • Drive delivery of the organisation's cybersecurity strategy across business units.
  • Embed secure-by-design practices and strengthen security maturity.
  • Coordinate governance, risk, and control activities with stakeholders across IT and risk functions.
  • Lead improvements in security posture and ensure regulatory compliance.

Skills

Security governance
Risk management
Incident response
IT governance

Tools

NIST framework
COBIT framework
ITIL

Job description

Let's Write Africa's Story Together! Old Mutual is a firm believer in the African opportunity and our diverse talent reflects this.

Job Description

We are looking for an experienced Information Security Officer to drive the delivery of the organisation's cybersecurity strategy across assigned business units.

The successful candidate will translate strategic priorities, security policies, regulatory obligations and risk requirements into practical initiatives and sustainable controls that strengthen cyber resilience across applications, infrastructure, cloud, data, third parties and digital services.

The role will lead and coordinate the execution of security improvement roadmaps, ensuring that strategic commitments are converted into measurable delivery outcomes. Key priorities include embedding secure-by-design practices, improving control effectiveness, reducing material security exposures, supporting incident preparedness and recovery, and strengthening the ability of critical business services to anticipate, withstand, respond to and recover from cyber disruption. Working closely with business leaders, technology teams, architects, risk functions and the group information security office, the Information Security Officer will remove delivery barriers, influence investment and risk decisions, track resilience outcomes and drive continual improvement in security maturity

Group Technology & Transformation | IT Governance Risk & Compliance
Governance

Develop and maintain Information Security and IT Risk Policies, supporting controls catalogue and related standards across the group to manage / mitigate associated risks.

Manage the capability maturity assessments of various IS and IT capabilities per the frameworks adopted (NIST, COBIT, ITIL) bi-annually drive ownership of the improvement plan to achieve agreed targets and to manage associated risks.

Analyze outcomes and information to create meaningful insights, to influence focus and budget decisions where input is required.

Provide feedback to senior leadership teams (Steering committees, IT leadership forums).

Develops and embeds reporting structures per the Information Security and IT management requirements, aligning with Old Mutual Risk and Compliance Governance structures, for risk aggregation and concentration of Old Mutual's risk exposures.

Manage and review various requests and submissions of information to group-wide cyber insurers to determine the best premium for the organisation.

Educate and inform employees about our practices and standards.

Regulatory

Ensure that the relevant legislative and regulatory requirements are implemented and enforced in the organisation based on risk appetite, risk tolerance, and capability maturity levels (e.g., Cybercrimes Act, draft joint standard: Cybersecurity and Cyber Resilience, draft joint standard: IT Risk Management).

Manage and review various requests and submissions of information to the regulator / provide commentary on draft standards issued by the regulator prior to government approval.

Compliance

Ensure compliance with Old Mutual's Information Security and IT requirements set out in policies, the controls catalogue, related standards, regulatory requirements, and industry guidelines.

Achieve agreed policy compliance targets for the Information Security and IT risk policies.

Leadership

Collaborate / partner with various stakeholders at different levels across the organization (IT, Audit, Business Units, Project teams, etc.) to obtain buy-in, ensure alignment, and achieve deliverables.

Lead a team of professionals and third-party service providers to achieve the agreed objectives per Old Mutual's values, timelines, and budget.

Recommended or support optimisation/efficiency / enhancement opportunities aligned to the IT strategy, e.g., automation.

Business Unit Security Strategy Embedment and Oversight

Champion and drive the execution of the information and cybersecurity strategy within assigned business units, ensuring alignment to group security objectives, business priorities, and segment-specific risk requirements.

Act as the primary security interface between assigned business units and the CISO office, providing trusted advice, challenge, and coordination on security priorities, risks, and decisions.

Participate in design reviews and identify potential mitigation strategies for security risks.

Analyze business impact and exposure based on emerging security threats.

Support the strategic planning and tactical execution of information security initiatives and controls within assigned business units to improve resilience, compliance, and risk management outcomes.

Work closely with architects, functional area specialists, and security staff to ensure adequate security solutions are in place throughout all IT systems and platforms to mitigate identified risks sufficiently, and to meet business objectives and regulatory requirements.

Facilitates and coordinates the integration

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Officer
Information Security Officer

Old Mutual Life Assurance Company (SA) Ltd • Cape Town

On-site
ZAR 900,000 - 1,500,000
Information Security Officer
Information Security Officer

Old Mutual South Africa • Cape Town

On-site
ZAR 1,100,000 - 1,800,000
Information Security Officer
Information Security Officer

Old Mutual Limited • Johannesburg, Durban

Hybrid
ZAR 900,000 - 1,200,000
Cyber Resilience & Information Security Lead
Cyber Resilience & Information Security Lead

oldmutual • Cape Town

On-site
ZAR 900,000 - 1,300,000
Strategic Information Security Officer (Hybrid)
Strategic Information Security Officer (Hybrid)

Old Mutual Limited • Johannesburg, Durban

Hybrid
ZAR 900,000 - 1,200,000
Information Security Leader: Strategy, Risk & Resilience
Information Security Leader: Strategy, Risk & Resilience

Old Mutual Life Assurance Company (SA) Ltd • Cape Town

On-site
ZAR 900,000 - 1,500,000
Cyber Resilience Lead — Information Security Strategy
Cyber Resilience Lead — Information Security Strategy

Old Mutual South Africa • Cape Town

On-site
ZAR 1,100,000 - 1,800,000
Chief Information Officer Retail
Chief Information Officer Retail

Old Mutual • Johannesburg

On-site
ZAR 2,500,000 - 4,000,000
Chief Information Officer Retail
Chief Information Officer Retail

oldmutual • Johannesburg

On-site
ZAR 4,000,000 - 7,000,000
Information Security Officer
Information Security Officer

Dots Africa • Midrand

On-site
ZAR 600,000 - 800,000
Competitive Compensation
Generous paid time off
Wellness program
+1