Information Security Officer

Jobtailor

Johannesburg

On-site

ZAR 1,200,000 - 1,800,000

Full time

4 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Jobtailor in Johannesburg seeks a senior cybersecurity leader to drive the organisation's security strategy, translate priorities into actionable initiatives, and oversee risk and compliance governance. You will lead cross-unit security programs, collaborate with executive teams, and embed secure practices across IT and business units.

The role requires extensive experience in information security, strong knowledge of NIST CSF, ISO/IEC 27001, and COBIT, and relevant certifications.

Qualifications

  • 6–8 years’ experience in information security, cybersecurity, or IT and Cyber risk, with demonstrated experience delivering security programmes, remediation initiatives, or resilience improvements across complex environments.
  • Experience translating strategy into prioritised roadmaps, measurable outcomes and executive reporting.
  • CISSP, CISM, CRISC or CISA certifications are preferred.
  • Working understanding of cloud services and best practices.
  • Agile training and knowledge of Agile Frameworks.
  • Strong analytical, problem-solving, facilitation, negotiation and conflict resolution skills.
  • Ability to work independently with a high level of integrity.

Responsibilities

  • Drive delivery of the organisation’s cybersecurity strategy across assigned business units.
  • Translate strategic priorities, security policies, regulatory obligations and risk requirements into practical initiatives and sustainable controls.
  • Lead and coordinate security improvement roadmaps and convert strategic commitments into measurable delivery outcomes.
  • Embed secure-by-design practices, improve control effectiveness, reduce material security exposures, support incident preparedness and recovery, and strengthen cyber resilience.
  • Develop and maintain Information Security and IT Risk Policies, control catalogues and related standards.
  • Manage bi-annual capability maturity assessments using NIST, COBIT and ITIL frameworks, and drive improvement plans.
  • Analyse outcomes and information to create insights that influence focus and budget decisions.
  • Provide feedback to senior leadership, steering committees and IT leadership forums.
  • Develop and embed reporting structures aligned with Information Security, IT management, Risk and Compliance Governance requirements.
  • Manage and review information submitted to cyber insurers and regulators, and provide commentary on draft regulatory standards.
  • Educate employees about information security practices and standards.
  • Ensure legislative, regulatory, policy, control catalogue, standards and industry guideline compliance.
  • Achieve agreed policy compliance targets.
  • Collaborate with IT, Audit, business units and project teams to obtain buy‑in, ensure alignment and deliver objectives.
  • Lead professionals and third‑party service providers within agreed objectives, timelines and budget.
  • Support optimisation, efficiency and enhancement opportunities aligned with IT strategy, including automation.
  • Champion and oversee execution of information and cybersecurity strategy within assigned business units.
  • Act as the primary security interface between business units and the CISO office.
  • Participate in design reviews and identify mitigation strategies for security risks.
  • Analyse business impact and exposure from emerging security threats.
  • Support strategic planning and tactical execution of security initiatives and controls.
  • Work with architects, functional specialists and security staff to ensure adequate security solutions across IT systems and platforms.
  • Integrate business-related security risk requirements into broader governance structures and evidence key risk decisions.
  • Track and report risk management trends, opportunities and remediation monthly.
  • Create and maintain reporting, problem resolution and continuous‑improvement activities.
  • Manage stakeholders, build relationships and promote a security‑aware culture.

Skills

NIST CSF knowledge
ISO/IEC 27001 knowledge
COBIT knowledge
Cybersecurity strategy
Security risk management
Analytical skills

Education

Master's degree in Information Security or related discipline
NQF Level 9 – Masters

Tools

AWS Cloud
Security testing tools
SOC 2 Type 2 reporting tools
Cloud security practices

Job description

  • Drive delivery of the organisation’s cybersecurity strategy across assigned business units.
  • Translate strategic priorities, security policies, regulatory obligations and risk requirements into practical initiatives and sustainable controls.
  • Lead and coordinate security improvement roadmaps and convert strategic commitments into measurable delivery outcomes.
  • Embed secure-by-design practices, improve control effectiveness, reduce material security exposures, support incident preparedness and recovery, and strengthen cyber resilience.
  • Develop and maintain Information Security and IT Risk Policies, control catalogues and related standards.
  • Manage bi-annual capability maturity assessments using NIST, COBIT and ITIL frameworks, and drive improvement plans.
  • Analyse outcomes and information to create insights that influence focus and budget decisions.
  • Provide feedback to senior leadership, steering committees and IT leadership forums.
  • Develop and embed reporting structures aligned with Information Security, IT management, Risk and Compliance Governance requirements.
  • Manage and review information submitted to cyber insurers and regulators, and provide commentary on draft regulatory standards.
  • Educate employees about information security practices and standards.
  • Ensure legislative, regulatory, policy, control catalogue, standards and industry guideline compliance.
  • Achieve agreed policy compliance targets.
  • Collaborate with IT, Audit, business units and project teams to obtain buy‑in, ensure alignment and deliver objectives.
  • Lead professionals and third‑party service providers within agreed objectives, timelines and budget.
  • Support optimisation, efficiency and enhancement opportunities aligned with IT strategy, including automation.
  • Champion and oversee execution of information and cybersecurity strategy within assigned business units.
  • Act as the primary security interface between business units and the CISO office.
  • Participate in design reviews and identify mitigation strategies for security risks.
  • Analyse business impact and exposure from emerging security threats.
  • Support strategic planning and tactical execution of security initiatives and controls.
  • Work with architects, functional specialists and security staff to ensure adequate security solutions across IT systems and platforms.
  • Integrate business-related security risk requirements into broader governance structures and evidence key risk decisions.
  • Track and report risk management trends, opportunities and remediation monthly.
  • Create and maintain reporting, problem resolution and continuous‑improvement activities.
  • Manage stakeholders, build relationships and promote a security‑aware culture.
Requirements
  • Relevant tertiary qualification (Degree / Honours) in Information Security, Cybersecurity, Information Technology, or a related discipline.
  • 6–8 years’ experience in information security, cybersecurity, or IT and Cyber risk, with demonstrated experience delivering security programmes, remediation initiatives, or resilience improvements across complex environments.
  • Strong knowledge of NIST CSF, ISO/IEC 27001 and COBIT.
  • Experience translating strategy into prioritised roadmaps, measurable outcomes and executive reporting.
  • Experience in financial services, cyber resilience, cloud security, third-party risk, incident preparedness and security assurance is advantageous.
  • CISSP, CISM, CRISC or CISA certifications are preferred.
  • Working understanding of cloud services and best practices.
  • AWS Cloud Practitioner, AWS Certified Security – Specialty or related cloud certifications are advantageous.
  • Agile training and knowledge of Agile Frameworks.
  • Strong analytical, problem-solving, facilitation, negotiation and conflict resolution skills.
  • Experience analysing security and assurance reports, including penetration testing reports, vulnerability scans and SOC 2 Type 2 reports.
  • Excellent written and oral communication and networking skills.
  • Ability to work independently with a high level of integrity.
  • Resourceful, proactive and confident communicator, ensuring quality and timely deliverables.
  • Ability to work professionally and constructively as a leader and team member, providing advice and consultancy.
  • NQF Level 9 – Masters.
Core Competencies

Demonstrates expertise in driving cybersecurity strategy, managing risk, and ensuring compliance with regulatory standards. Proficient in developing security policies, leading improvement initiatives, and fostering a security‑aware culture across business units.

Highest-signal resume keywords
  • NIST CSF
  • ISO/IEC 27001
  • COBIT
  • CISSP
  • Cybersecurity Strategy
ATS Optimization Keywords
Hard Skills
  • Information Security
  • Cybersecurity
  • Risk Management
  • Security Program Delivery
  • Incident Preparedness
  • Cloud Security
  • Vulnerability Analysis
  • Agile Frameworks
  • Control Effectiveness
  • Regulatory Compliance
Soft Skills
  • Analytical Skills
  • Problem-Solving
  • Negotiation
  • Conflict Resolution
  • Communication
Certifications & Qualifications
  • CISSP
  • CISM
  • CRISC
  • CISA
  • AWS Certified Security – Specialty
Industry Keywords
  • Cyber Resilience
  • Financial Services
  • Third-Party Risk
  • Control Catalogues
  • Information Security Policies
Tools & Technologies
  • AWS Cloud
  • Security Assurance Tools
  • Penetration Testing Tools
  • Vulnerability Scanning Tools
  • SOC 2 Type 2 Reporting
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Associate Information Security Analyst
Senior Associate Information Security Analyst

Recruit-It • Gauteng

On-site
ZAR 900,000 - 1,300,000
Information Security Officer
Information Security Officer

soughtout • Springs

On-site
ZAR 1,000,000 - 1,700,000
ITSA: Senior Associate Information Security Analyst
ITSA: Senior Associate Information Security Analyst

Recruit-It • Gauteng

On-site
ZAR 700,000 - 1,000,000
Senior Cybersecurity Engineer - Compliance & Technology
Senior Cybersecurity Engineer - Compliance & Technology

ATS Client • Sandton

On-site
ZAR 900,000 - 1,600,000
IT Security Specialist x4
IT Security Specialist x4

ATNS SOC Limited • South Africa

On-site
ZAR 700,000 - 900,000
Senior Security Analyst
Senior Security Analyst

Interfront SOC • Somerset West

Hybrid
ZAR 900,000 - 1,300,000
Hybrid working conditions
Open to people with disabilities
Senior Security Analyst
Senior Security Analyst

Recruit-It • Somerset West

On-site
ZAR 900,000 - 1,600,000
Senior Security Analyst - Hybrid
Senior Security Analyst - Hybrid

Recruit-It • Somerset West

On-site
ZAR 900,000 - 1,200,000
Information Security Officer
Information Security Officer

LINKFIELDS INNOVATIONS (PTY) LTD • Noord-Kaap

On-site
ZAR 500,000 - 750,000
IT Security Manager (Compliance & Risk)
IT Security Manager (Compliance & Risk)

Top Vitae Recruitment • Gqeberha

On-site
ZAR 900,000 - 1,300,000