Information Security Officer

soughtout

Springs

On-site

ZAR 1,000,000 - 1,700,000

Full time

8 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

soughtout seeks a senior information security leader to develop and maintain the enterprise information security strategy, roadmap, and operating model aligned with IT strategy and regulatory obligations.

The role requires 8–10 years’ experience in information security, cyber risk, governance, and leadership, with preference for CISSP or CISM certifications. Strong collaboration with executives and auditors is essential.

Qualifications

  • Bachelor’s degree in Information Security or Computer Science/Information Technology/Information Systems.
  • Relevant Information Security or Cybersecurity certification.
  • 8–10 years’ experience in information security, cyber risk, governance, and leadership roles.

Responsibilities

  • Develop and maintain the enterprise information security strategy and roadmap.
  • Govern security policies, standards, and governance practices across the organisation.
  • Identify, assess, monitor and report cyber risks across IT and business processes.
  • Lead security architecture alignment with cloud, IAM, data protection, and OT.
  • Oversee security operations, monitoring, vulnerability management and incident readiness.
  • Provide executive and board-level reporting on security posture and investments.
  • Coordinate audits, control testing and remediation activities.

Skills

Security leadership
Governance & risk
Policy development
Security architecture

Education

Bachelor's degree in Information Security
Information security certification

Job description

  • Lead Information Security Strategy: Develop and maintain company’s enterprise information security and cybersecurity strategy, roadmap, operating model, and maturity plan aligned to IT strategy, business priorities, risk appetite, and regulatory obligations;
  • Govern Security Policies and Standards: Establish, maintain, and enforce information security policies, standards, procedures, minimum control requirements, and governance practices across the organisation;
  • Manage Cyber Risk: Identify, assess, prioritise, monitor, and report cyber and information security risks across applications, infrastructure, cloud services, operational technology, data platforms, third parties, and business processes;
  • Security Architecture and Secure Design: Align with enterprise architect regarding cloud adoption, network segmentation, identity and access management, data protection, application security, operational technology, and digital transformation initiatives;
  • Direct Security Operations Oversight: Ensure effective monitoring, detection, vulnerability management, endpoint protection, security event management, threat intelligence, and operational security controls across the IT environment;
  • Lead Cyber Incident Readiness and Response: Own and coordinate cyber incident response governance, escalation, investigation, containment, recovery, lessons learned, and executive communication processes in line with company’s incident response arrangements;
  • Drive Governance, Risk and Compliance: Ensure compliance with internal policies, legal, regulatory, contractual, audit, data protection, and governance requirements relating to information security and cyber risk;
  • Strengthen Identity, Access and Data Protection Controls: Oversee access governance, privileged access, segregation of duties, data loss prevention, information classification, encryption, retention, auditability, and monitoring controls;
  • Manage Third-Party and Supply Chain Security Risk: Define and monitor security requirements for vendors, service providers, cloud platforms, implementation partners, outsourced IT services, and technology suppliers;
  • Promote Security Awareness and Culture: Lead cybersecurity awareness, training, communication, phishing readiness, policy adoption, and behavioural change initiatives across the organisation;
  • Provide Executive and Board-Level Reporting: Report security posture, cyber risks, incidents, vulnerabilities, compliance status, control gaps, remediation progress, and investment requirements to IT leadership and governance forums;
  • Support Audits and Assurance Reviews: Coordinate security evidence, audit responses, control testing, remediation tracking, and continuous improvement activities arising from internal and external reviews
  • Lead Cybersecurity Capability Development: Build, mentor, and coordinate internal and external cybersecurity resources, including cyber risk, security operations, security architecture, GRC, and specialist provider capabilities;
  • Attend to audit queries as and when required; and
  • Perform ad hoc duties as and when required within reasonable job scope

Qualifications:

  • Bachelor's Degree in Information Security or Computer Science or Information Technology or Information Systems, or a related discipline; and
  • Relevant Information Security or Cybersecurity certification.

Preferred Qualifications:

  • Postgraduate qualification in Information Security, Cybersecurity, Information Technology, Business Management, Risk Management, or a related field;
  • Certified Information Systems Security Professional (CISSP); and
  • Certified Information Security Manager (CISM).

Requirements:

  • 8 - 10 years' experience in Information Security, Cybersecurity, IT Risk Management, IT Governance, Infrastructure Security, Security Operations, or related technology disciplines;
  • Experience in information security governance, risk management, and compliance practices;
  • At least five (5) years' experience in a cybersecurity leadership, management, or senior specialist role;
  • Proven experience developing and implementing information security strategies, frameworks, policies, standards, and governance processes;
  • Experience conducting cybersecurity risk assessments, security audits, compliance reviews, and control effectiveness evaluations;
  • Experience managing security incidents, vulnerability management programmes, and cybersecurity monitoring activities;
  • Experience implementing and maintaining information security controls across infrastructure, applications, cloud environments, data platforms, and operational technology environments; and
  • Experience engaging with executive leadership, auditors, regulators, technology teams, and business stakeholders on cybersecurity matters.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Officer
Information Security Officer

Network Finance • Gauteng

On-site
ZAR 1,000,000 - 1,800,000
Information Security Officer
Information Security Officer

LINKFIELDS INNOVATIONS (PTY) LTD • Noord-Kaap

On-site
ZAR 500,000 - 750,000
Information Security Officer
Information Security Officer

Network Recruitment • Johannesburg

On-site
ZAR 1,000,000 - 2,000,000
Information Security Manager
Information Security Manager

ATS Client • Midrand

On-site
ZAR 900,000 - 1,500,000
IT Security Manager
IT Security Manager

Performit Personnel • Gqeberha

On-site
ZAR 600,000 - 900,000
IT Security Manager (Compliance & Risk)
IT Security Manager (Compliance & Risk)

Top Vitae • Oos-Kaap

On-site
ZAR 900,000 - 1,200,000
IT Security Manager (Compliance & Risk)
IT Security Manager (Compliance & Risk)

Top Vitae Recruitment • Gqeberha

On-site
ZAR 900,000 - 1,300,000
IT Security Specialist x4
IT Security Specialist x4

ATNS SOC Limited • South Africa

On-site
ZAR 700,000 - 900,000
Information Security & Compliance Officer
Information Security & Compliance Officer

ATS Client • Cape Town

On-site
ZAR 700,000 - 1,100,000
Information Security Officer
Information Security Officer

Dots Africa • Midrand

On-site
ZAR 600,000 - 800,000
Competitive Compensation
Generous paid time off
Wellness program
+1