Enable job alerts via email!

Specialist : IT Security

Tower Group South Africa (Pty) Ltd

Johannesburg

On-site

ZAR 300,000 - 600,000

Full time

30+ days ago

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

An established industry player is seeking a dedicated Information Security professional to oversee the management of security risks and compliance across the organization. This role involves developing and implementing a comprehensive Information Security management framework, ensuring adherence to national legislation and international standards. You will provide expert consultancy on risk management practices, oversee security governance, and maintain the alignment of security architecture with business objectives. If you are passionate about safeguarding information and driving security awareness, this position offers an exciting opportunity to make a significant impact in a dynamic environment.

Qualifications

  • 3+ years of IT Security experience required.
  • Knowledge in Risk Management and IT Security best practices.

Responsibilities

  • Develop and implement Information Security management framework.
  • Ensure compliance with security policies and national legislation.
  • Provide expert advice on risk management practices.

Skills

IT Security
Risk Management
Information Security Management
Compliance (PCI DSS)
Vulnerability Management
Incident Management
Security Architecture

Education

Relevant 3-year Computer Science Degree
Relevant IT Certification
Grade 12 with IT Certification

Job description

Responsible for the identification, measurement, control and minimisation of loss associated with uncertain information and cyber security risks throughout the ICT and business environment. The development, documentation, implementation and monitoring of an Information Security management framework including policies, standards, procedures, and security architecture to ensure delivery and awareness of sound Information Security Management practices company wide, including compliance with national legislation and international standards. Researches and stays abreast of worldwide best practice and regulations.

Provides expert advice and consultancy with respect to risk management practices and concerns within IT and business architectures, applications, changes, solutions and operational processes.

Information Security Governance
  • Create / Maintain / Communicate Information Security Policies and Standards.
  • Ensure Regulatory and Security Policy Compliance and Business Risk alignment.
  • Manage policy reviews, updates and approval process.
  • Support Security Governance Forum and ISMS Processes.
  • Maintain Information Security Strategy and ensure business strategy alignment.
Information Security Assurance & Compliance
  • Ensure Information Security related Operational and Service Level Agreements are established.
  • Ensure Security Operations Assurance and Delivery.
  • Ensure Security Operations compliance with policies, standards, and procedures including PCI DSS.
  • Ensure provision and compliance of Security Operations Management and Security Operations Centre.
  • Responsible for ensuring effective Vulnerability Management, Patch Management and Information Security Incident Management.
  • Report on enterprise Information Risk.
  • Research, Identify and Assess Information threats to business.
  • Project and Change Consultation and Assessment of Risk.
  • Information Risk assessment, rating, management, and resolution.
  • Represent Information Security in Governance and Business processes.
  • Monitor, Assess and Report on Operational Security Assurance process.
Information Security Architecture
  • Ensure Enterprise Security Architecture aligns with business requirements and risks.
  • Advise and recommend technical Security direction in support of Enterprise Security Architecture.
  • Define, Assess and Communicate Information Security elements within Business and IT Architecture.
  • Information Security input to Business Cases and Projects.
  • Ensure Information Security Architecture requirements are met within all systems and processes.
Information Security Awareness
  • Ensure Information Security Awareness of Policy and Business Risks.
  • Contribute to developing and implementing Information Security Awareness Programs and measuring the effectiveness thereof.

Understanding the IT Security discipline processes, concepts and best practices; Solid technical aptitude and knowledge; Understanding of what is happening in the ICT industry in general. Knowledge in Risk Management; IT Technologies; IT Security, PCI DSS compliance.

Minimum Requirements
  • Minimum 3-year in IT Security experience.
  • Relevant certification will be beneficial.
  • Relevant 3-year Computer Science, Information Management, Engineering or Business Degree / Diploma (NQF level 6).
  • Alternatively, Grade 12 (NQF 4) with relevant IT Certification and / or equivalent years of experience.
  • Driver's license.
Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.