Manager: ISGRC
Operating Division: Transnet Pipelines
Employee Group: Permanent
Department: ICT
Location: Durban Central
Reporting To: Head: ICT
Grade: E
Reference: req5835
The closing date is on 18/09/2026. It is the responsibility of the applicant to ensure that HR has received the application before the closing date of the advertisement.
Position Purpose
The position holder must lead the design and provide assurance to the CIO on the
sustainability of IT general controls, information and technology risks, security of information
assets and regulatory compliance (i.e., King IV, etc.) COBIT.
The position holder must advocate Information Security, IT risk and compliance to the
relevant laws and regulations, to Transnet employees as well as to senior management, to
ensure risks relating to the above are mitigated. (e.g., reputational, and non-compliance).
The position focuses on the provision of leadership and direction in the area of IT Risk,
Information Security, IT Governance, and IT Compliance across TPL.
The role develops and implements a comprehensive, enterprise-wide Information Security,
Governance, Risk and Compliance (ISGRC) strategy aligned to TPL’s business objectives,
industry best practice and applicable regulations/standards (COBIT, ITIL, ISO/IEC 27001).
Accountable for TPL-wide cyber incident response: establishing, maintaining and leading the
emergency response plan for cyber breaches, coordinating multi-disciplinary teams during
incidents, and ensuring rapid containment, recovery and post-incident improvement.
Drives a culture of information security awareness through targeted training, campaigns and
leadership engagement across all levels of the organisation.
Position Outputs
- IT GOVERNANCE, RISK & COMPLIANCE1. Governance/Strategy• Develop and maintain an ISGRC strategy that aligns to organisational goals and regulatoryrequirements; translate strategy into multi-year roadmaps and annual plans.• Establish and maintain governance frameworks that ensure accountability, transparency andintegrity of security and compliance initiatives across TPL.• Review current and proposed information systems for compliance with the organisation'sobligations (including legislation, regulatory, contractual, and agreed standards/policies) andadherence to overall strategy.• Provide advice to those accountable for governance to correct compliance issues.• Define KPIs/metrics for ISGRC effectiveness (e.g., audit closure, vulnerability SLAs, phishingrisk, MTTR); report to executive committees and relevant governance forums.
- 2. Risk Management• Conduct regular, formal risk assessments across information assets; define and implement riskmitigation strategies and track closure to tolerance levels set by executive management.• Maintain the IT risk register within the approved risk management system.• Carry out risk assessment within a defined functional or technical area of business.• Use consistent processes for identifying potential risk events, quantifying and documenting theprobability of occurrence and the impact on the business.• Refer to domain experts for guidance on specialised areas of risk, such as architecture andenvironment.• Co-ordinate the development of countermeasures and contingency plans.• Research and advise on risks related to new and existing technologies.• Third-party/vendor security risk management: define due-diligence processes, assesssupplier risks and ensure contractual controls and ongoing monitoring.
- 3. Manage Regulatory and Internal Compliance• Manage the organisation’s IT regulatory universe.• Carry out regulatory and compliance risk assessment of relevant ICT laws and regulations.• Use consistent processes for identifying potential regulatory and legal risk events, quantifyingand documenting the probability of occurrence and the impact on the business.• Refer to domain experts for guidance on specialised areas of regulatory and legal risk, such aslegal and regulatory compliance.• Co-ordinate the development of compliance control plans.• Manage the IT audit function by liaising with internal and external audit
• Provide a consulting service to TPL IT functional areas on compliance matters (regulatoryuniverse, compliance control plans), risk framework, and IT policies.• Ensure adherence to standards where appropriate (for e.g., ITIL, COBIT, ISO, etc.)• Prepare and submit compliance and assurance reports to regulatory bodies and auditors,evidencing conformity with applicable standards/frameworks. - 4. Manage Business Continuity and Disaster Recovery• Implement and contribute to the development of a continuity management plan.• Coordinate the assessment of risks to the availability, integrity and confidentiality of systems thatsupport critical business processes.• Coordinate the planning, designing, and testing of maintenance procedures and contingencyplans.• Lead and manage the organisation’s IT BCM and DR strategy
INFORMATION SECURITY
- 1. Information and Cyber Security Strategy• Define, present, and promote an information security policy for approval by the seniormanagement of the organisation.
- • Own (not just implement) the development, review and continuous improvement of securitypolicies, procedures and standards; ensure enforcement across the environment.
- • Apply relevant standards, best practices and legal requirements for information security.
- 2. Manage Information Security• Evaluate security management measures and indicators and decides if compliant to informationsecurity policy.• Investigate and instigate remedial measures to address any security breaches.• Provide guidance in defining access rights and privileges. Investigate security breaches inaccordance with established procedures and recommend required actions and support/follow upto ensure these are implemented.• Serve as a security expert in application development, database design, network, and/or platform(operating systems) efforts, helping project teams comply with enterprise and IT security policies,industry regulations, and best practices.
• Research and advocate new technologies, architectures, and security products that will supportsecurity requirements for the enterprise and its customers.
• Work with the IT team to ensure adequate security solutions are in place throughout all ITsystems and platforms.
• Establish relationships with key external information security bodies to stay abreast withinformation security matters in industry and how these could impact the organisation. - 3. Implement SIEM (Security Information & Event Management)• Contribute to the development of policies, standards, processes, and guidelines for the SIEMsolution.
Analyse and prioritise security incidents in line with the security incidents management policy.
Investigate and instigate remedial measures to address any security incidents. - 4. Manage Threat Protection• Coordinate and manage the planning of penetration tests.
Deliver objective insights into the existence of vulnerabilities, the effectiveness of defences andmitigating controls - both those already in place and those planned for future implementation.
Take responsibility for integrity of testing activities and coordinates the execution of theseactivities.
Provide authoritative advice and guidance on the planning and execution of vulnerability tests.
Define and communicates the test strategy.
Manage all test processes and contribute to corporate security testing standards. - 5. Manage data/information security which includes data loss prevention andencryption• Provide advice and guidance on security strategies to manage identified risks and ensure adoptionand adherence to standards.
Obtain and act on vulnerability information and conduct security risk assessments, business impactanalysis and accreditation on complex information systems.
Investigate major breaches of security and recommends appropriate control improvements.
Contribute to development of information security policy, standards and guidelines - 6. Manage Identity, Access, and User Authentication• Ensure that access privileges to the organisation’s information technology assets and resources(including networks, systems, applications, computers and mobile devices) based on the principlesof need to know (users or resources are granted access to systems that necessary to fulfil theirroles and responsibilities) and least privilege ( users or resources are provided with the minimumprivileges necessary to fulfil their roles and responsibilities).
- 7. Manage network security• Maintain security administration processes and check that all requests for support are dealt withaccording to agreed procedures.• Provide guidance in defining access rights and privileges.• Investigate security breaches in accordance with established procedures and recommend requiredactions and support/follow up to ensure these are implemented.
- 8. Manage Data Centre, Server, and Storage Security• Review operational metrics of IT systems and environments and take appropriate action to ensurecorrective and proactive maintenance to support the requirement to protect and secure businessinformation.• Create reports and proposals for improvement and contribute to the planning and implementationof new installations and scheduled maintenance and changes within the system.• Review operational procedures from an information security perspective, and provide technicalexpertise and appropriate information to the senior management.
- 9. Manage end user device security• Implement information security policy• Monitor compliance to approved end user device configuration standards• Ensure end-user computing device applications and multimedia capabilities are not used to breachprivacy and confidentiality according to the Acceptable Use Policy• Minimize security risks associated with end-user computing devices by ensuring that all suchequipment is encrypted, password protected, and physically secured, minimizing the threat of lossor theft of the device itself and any confidential data contained therein.
- 10. Implement and maintain a robust incident response plan, including playbooks, roles,communications and post-incident reviews; coordinate response to incidents and breaches.
- 11. Evaluate and recommend security technologies, tools and services to enhance TPL’s securityposture; lead associated business cases.
- 12. Lead security awareness programme design and roll-out (campaigns, simulations, training).
- 13. Cross-functional collaboration with Legal, Compliance, HR, OT/SCADA, BCM and enterpriserisk to ensure alignment of security, compliance and business continuity with business objectives.
- 14. Manage the budget allocated for information security, governance and risk initiatives, ensuringvalue realisation and cost optimisation.
Qualifications and Experience
- Related B-degree / B.Tech / Advanced Diploma (NQF7) in Computer Science/IT/IS (or other degree +IT/IS diploma) with minimum 8 years’ relevantexperience, including ≥3 years at managerial level,in any of: IT/ICT Risk Management, Audit,Compliance, Governance, Information Security.
- OR: Relevant National Higher Diploma (NQF 6) +10 years’ relevant experience with ≥5 yearsmanagerial/specialist experience in the abovedomains.Further qualifications preferred:o Certified Information Systems Security Professional(CISSP)o Information Systems Security ArchitectureProfessional (CISSP-ISSAP)o Certified Information Security Manager (CISM)o Certified in Risk and Information Systems Controls(CRISC)o Certified Information Systems Auditor (CISA)o Certified in the Governance of Enterprise IT (CGEIT)o SAP Certified Technology Professional – SystemSecurity with SAP NetWeaver (SAP GlobalCertification)Further professional memberships preferred:o International Information Systems SecurityCertification Consortium (ISC2)o Information Systems Audit and Control Association(ISACA)Standard Job Requirements
- Standard Job Requirements
- Driver’s license code 08
- Travel as required and approved
Competencies
- Sound knowledge of ITIL and COBIT frameworks;understanding of governance frameworks for ICTand King IV; knowledge of IT laws and regulatoryobligations.
- Sound understanding of governance frameworks forICT.
- Sound knowledge of IT laws.
- Understanding of KING IV.
- Knowledge of software and hardware technologies -the individual should be familiar with a widerange of applications, operating systems, serverapplications and tools.
- Network and server security, including firewalls,VPN, IDS/IPS, anti-virus, patch management,vulnerability management.
- Business applications including SAP.
- Domain structures, user authentication, and digitalsignatures and PKI.
- Intranet, Extranet, Internet, eCommerce, EDI linkswith parties within and outside of the organization.
- Process Control/SCADA/PLC environments would beconsidered an advantage
- Common information security managementframeworks, such as International StandardsOrganization (ISO) 17799/27001, the ITInfrastructure Library (ITIL) and Control Objectivesfor Information and Related Technology (CobiT)frameworks.
- Knowledge of security issues, techniques, andimplications across all of the key platforms withinthe TPL environment, including:o Microsoft Windows Server and Desktop,o Microsoft SQL Server, SharePoint,o UNIX (AIX)o Oracle,o MaxDB,o VPN and remote access technologies,o CISCO networking platforms,o Palo Alto firewall technology,o Data leakage prevention,o Cryptography,o BCM/DRP,o Access Control,o Wireless Security,o Ethical hacking skills,o Application Security,o IT Risk Assessments.
Equity Statement
Preference will be given to suitably qualified Applicants who are members of the designated groups in line with the Employment Equity Plan and Targets of the Organisation/Operating Division.
Disclaimer
If you have not heard from Transnet within 90 days, please consider your application as unsuccessful.
Transnet, its employees or representatives never ask for a fee from job seekers. Any such requests are fraudulent. Please report any suspicious activities in this regard to the Transnet anti-fraud line on 0800 003 056 or email reportit@ethicshelpdesk.com