Job Search and Career Advice Platform

Enable job alerts via email!

Information Security Officer

Ithemba Recruitment- Sourcing Top Talent

Johannesburg

On-site

ZAR 900 000 - 1 200 000

Full time

3 days ago
Be an early applicant

Generate a tailored resume in minutes

Land an interview and earn more. Learn more

Job summary

A recruitment agency specializing in talent sourcing is seeking an Information Security Officer in Johannesburg. The role involves overseeing the strategic direction of technology security, ensuring compliance with regulations like POPI and GDPR, and managing risk exposure. Candidates should possess an IT-related bachelor's degree, relevant certifications, and at least 7 years of experience in Technology Security or Risk Management. This is a critical position with responsibilities ranging from policy writing to project coordination.

Qualifications

  • 7 years experience in Technology Security or Risk Management roles.
  • 4 years in Technology Policy writing.
  • 3 years experience in coordinating large projects across multiple areas.
  • 4 years in designing and implementing security controls.
  • 3 years experience in assessing and communicating risk exposures.

Responsibilities

  • Organize outputs aligned to Technology risk strategy and compliance.
  • Manage and coordinate zero data loss approach and optimize Cyber Risk landscape.
  • Drive continuous improvement in Cyber Risks management.
  • Implement information security management framework and policies.
  • Design and manage roadmap for information security and risk management.

Skills

Technology Security
Risk Management
Policy Writing
Project Coordination
People Management

Education

IT related bachelor's degree or Degree in Computer Science

Tools

COBIT
ITIL
CISSP
CISM
CRISC
CISA
ISO 27001
Job description
About the job Information Security Officer

Purpose:

Accountable to deliver upon the strategic direction that has been set in protecting the companys' tech and data. This includes being a key partner inthe design of success factors, solutions and compliance.

Duties and responsibilities:

  • Organize outputs aligned to the Technology risk strategy, internal controls and budget of internal resourcing and partnershipsto assure Technology Compliance to best practise and regulatory compliance (including but not limited to data protectioncompliance (e.g., POPI and GDPR), ECT Act, ESG, Cyber laws.
  • Manage and coordinate a Zero data or Technology loss approach, internal controls and budget of internal resourcing andpartnerships to manage and optimise the Cyber Risk landscape.
  • Drive a proactive, predictive and continuous improvement Cyber Risks managed environment
  • Drives the Information Technology Security Programme across the company landscape to protect its applications and supportinginfrastructure from both internal and external threats targeting zero downtime, zero audit findings and single view ofTechnology Risk
  • Implement and continuously enhance an information security management framework
  • Develop and implement Technology Security, policies and standards that supports and enable business strategy at thestrategic planning, tactical and operational business unit levels
  • Form and cascade a communication plan to the Technology team relating to the compliance of IT Security Policies, Standardsand Guidelines. Escalating non-compliance matters to CTO
  • Design and manage a roadmap for information security related to internal controls, compliance, regulatory and a proactive riskmitigation plan for the Technology department
  • Design, implement and monitor a comprehensive enterprise information security and IT risk management program inalignment with the Technology Risk strategy.
  • Contribute to project risk management consulting and technical reviews as required.
  • Cascade of the Enterprise risk framework into the Technology Risk Framework and functional area responsibilities.
  • Consolidate and review monthly payments to vendor providing an analysis on the spend
  • Track and monitor the spend vs the forecast and submit the findings for approval
  • Provide input to the departmental budget, reporting on monthly expenditure and craft proposals for funding
  • Create a cost catalogue linked to prescribed vendors and potential new vendors that will form the blueprint for all other departments in the company; amongst other duties

Qualifications and experience:

  • IT related bachelors degree or Degree in Computer Science, IT Best practise (COBIT, ITIL etc)
  • Professional Registration/Membership: Information Security Forums; ISACA; ISC2 (advantageous)
  • Security related certification (CISSP,CISM,CRISC,CISA, ISO 27001) (Advantageous)

7 years experience in Technology Security or Risk Management roles of which should include:

  • 4 years in Technology Policy writing (measurement of controls against Policy)
  • 4 years experience in designing, implementing and closing Technology general controls gaps
  • 3 years experience in directly assessing and communicating Risk Exposures and developing risk mitigation plans
  • 3 years experience in coordinating large projects or initiatives across multiple areas
  • 4 years experience in people management, including coaching and mentoring
Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.