IT Security Analyst

Refined Naturals

Johannesburg

On-site

ZAR 350,000 - 520,000

Full time

11 days ago
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Refined Naturals in Johannesburg seeks an IT security professional to lead ISO 27001 compliance, risk assessments, and security operations. You will analyze security events, coordinate incidents, and support audits and continuous improvement across the DevSecOps lifecycle.

The role requires a Diploma or NQF Level 6 in CS/IS/IT with up to 3 years of relevant IT security experience, plus ISO 27001 certification experience. Preferred AZ-500 and ISMS certifications.

Qualifications

  • Diploma or NQF Level 6 qualification in Computer Science, Information Systems, Information Technology, or a related field.
  • Up to 3 years of relevant experience in IT security or information security.
  • Essential experience with ISO 27001 certification, consulting, and advisory activities.
  • Preferred ISO 27001 ISMS certification.
  • Preferred AZ-500 certification.
  • Experience in IT security operational execution, including security monitoring, incident response, and vulnerability management.

Responsibilities

  • Conduct IT security log analysis and monitor security events for potential threats and incidents.
  • Collaborate with internal and external stakeholders to investigate and resolve identified malware and security incidents.
  • Maintain security incident records, perform initial assessments, and support incident response investigations and remediation.
  • Lead annual vulnerability scanning and penetration testing activities.
  • Analyse information security risks and recommend appropriate solutions to protect information against unauthorised access, modification, destruction, or disclosure.
  • Log and manage information security risks, track remediation measures, provide stakeholder updates, and elevate critical risks.
  • Conduct periodic risk and vulnerability assessments, document findings, and track remediation activities.
  • Coordinate and support internal and external ISO 27001 audits, including documentation preparation, scheduling, and follow-up on findings.
  • Develop, maintain, and update ISO 27001 compliance documentation, including the statement of applicability, risk treatment plans, asset inventories, and ISMS documentation.
  • Monitor compliance with ISO 27001 and other relevant information security standards, reporting nonconformities and supporting corrective actions.
  • Administer information security governance documentation, policies, access controls, security audits, and service-provider compliance assessments.
  • Provide information security advice to business units and assist with the development and delivery of security awareness training.
  • Evaluate and test new technologies, security controls, policies, procedures, licensing, and project capabilities to ensure security requirements are met.
  • Analyse internal and external cyber threats, recommend infrastructure improvements, maintain awareness of emerging threats and technologies, and ensure security throughout the DevSecOps lifecycle.

Skills

Analytical skills
Problem solving
Communication
Judgment
Advisory capabilities
Integrity

Education

Diploma or NQF Level 6 in CS/IS/IT

Tools

ISO 27001 ISMS certification
AZ-500 Certification

Job description

Requirements:
  • Diploma or NQF Level 6 qualification in Computer Science, Information Systems, Information Technology, or a related field.
  • Up to 3 years of relevant experience in IT security or information security.
  • Essential experience with ISO 27001 certification, consulting, and advisory activities.
  • Preferred ISO 27001 Information Security Management Systems (ISMS) certification.
  • Preferred Microsoft Azure Security Technologies AZ-500 certification.
  • Experience in IT security operational execution, including security monitoring, incident response, and vulnerability management.
  • Strong analytical, problem-solving, judgment, communication, integrity, and advisory capabilities.
Responsibilities:
  • Conduct IT security log analysis and monitor security events for potential threats and incidents.
  • Collaborate with internal and external stakeholders to investigate and resolve identified malware and security incidents.
  • Maintain security incident records, perform initial assessments, and support incident response investigations and remediation.
  • Lead annual vulnerability scanning and penetration testing activities.
  • Analyse information security risks and recommend appropriate solutions to protect information against unauthorised access, modification, destruction, or disclosure.
  • Log and manage information security risks, track remediation measures, provide stakeholder updates, and elevate critical risks.
  • Conduct periodic risk and vulnerability assessments, document findings, and track remediation activities.
  • Coordinate and support internal and external ISO 27001 audits, including documentation preparation, scheduling, and follow-up on findings.
  • Develop, maintain, and update ISO 27001 compliance documentation, including the statement of applicability, risk treatment plans, asset inventories, and ISMS documentation.
  • Monitor compliance with ISO 27001 and other relevant information security standards, reporting nonconformities and supporting corrective actions.
  • Administer information security governance documentation, policies, access controls, security audits, and service-provider compliance assessments.
  • Provide information security advice to business units and assist with the development and delivery of security awareness training.
  • Evaluate and test new technologies, security controls, policies, procedures, licensing, and project capabilities to ensure security requirements are met.
  • Analyse internal and external cyber threats, recommend infrastructure improvements, maintain awareness of emerging threats and technologies, and ensure security throughout the DevSecOps lifecycle.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

ISO 27001 Security Specialist - Azure & Incident Response
ISO 27001 Security Specialist - Azure & Incident Response

Refined Naturals • Johannesburg

On-site
ZAR 350,000 - 520,000
Senior Security Analyst
Senior Security Analyst

Interfront SOC • Somerset West

Hybrid
ZAR 900,000 - 1,300,000
Hybrid working conditions
Open to people with disabilities
Senior Associate Information Security Analyst
Senior Associate Information Security Analyst

Recruit-It • Gauteng

On-site
ZAR 900,000 - 1,300,000
IT Security Specialist
IT Security Specialist

Network Finance • Lichtenburg

On-site
ZAR 420,000 - 660,000
Senior Security Analyst - Hybrid
Senior Security Analyst - Hybrid

Recruit-It • Somerset West

On-site
ZAR 900,000 - 1,200,000
Information Security Analyst
Information Security Analyst

Boardroom Appointments • Cape Town

On-site
ZAR 600,000 - 900,000
ITSA: Senior Associate Information Security Analyst
ITSA: Senior Associate Information Security Analyst

Recruit-It • Gauteng

On-site
ZAR 700,000 - 1,000,000
Information Security Manager
Information Security Manager

Parvana • Cape Town

On-site
ZAR 1,200,000 - 1,800,000
ICT Security Specialist
ICT Security Specialist

Boardroom Appointments • Cape Town

On-site
ZAR 600,000 - 900,000
Information Security Officer
Information Security Officer

Jobtailor • Johannesburg

On-site
ZAR 1,200,000 - 1,800,000