Job Search and Career Advice Platform
  • Jobs
  • Headhunters
  • Free resume review
  • About Us
EN
2 982

Security jobs in South Africa

Business Information Security Officer

Sanlam

Bellville
On-site
ZAR 500,000 - 800,000
Today
Be an early applicant
I want to receive the latest job alerts for “Security” jobs

IT Security Lead

Ruby Labs

South Africa
Remote
ZAR 80,000 - 110,000
Today
Be an early applicant

Cyber Security Engineer_Pipeline

Capitec Bank Ltd.

Cape Town
On-site
ZAR 400,000 - 800,000
Today
Be an early applicant

Cyber Security Engineer_Pipeline

Capitec Bank

Cape Town
On-site
ZAR 300,000 - 400,000
Today
Be an early applicant

Team Lead: Security Engineer

Hire Resolve

Gauteng
On-site
ZAR 300,000 - 400,000
Today
Be an early applicant
discover more jobs illustrationDiscover more opportunities than anywhere else. Find more jobs now

Risk and Security Manager

Cash Crusaders

Gqeberha
On-site
ZAR 400,000 - 500,000
Yesterday
Be an early applicant

TECHNICAL SPECIALIST: CYBER SECURITY

Believe Resourcing

Cape Town
On-site
ZAR 784,000 - 924,000
Today
Be an early applicant

CCTV Operator

M.S Security Group

Cape Town
On-site
ZAR 50,000 - 200,000
Today
Be an early applicant
HeadhuntersConnect with headhunters to apply for similar jobs

Senior Security Inspector - Epping

SA Metal Group (Pty) Ltd

Cape Town
On-site
ZAR 200,000 - 240,000
Yesterday
Be an early applicant

IT Security Specialist

Top Vitae Recruitment

Gqeberha
On-site
ZAR 500,000 - 700,000
Yesterday
Be an early applicant

Network Engineer

Biovac

Wes-Kaap
On-site
ZAR 200,000 - 300,000
Today
Be an early applicant

Site Manager - Mbombela

Architectural Services

Mbombela
On-site
ZAR 400,000 - 500,000
Today
Be an early applicant

Site Manager - Mbombela

Fidelity Services Group

Mpumalanga
On-site
ZAR 400,000 - 500,000
Yesterday
Be an early applicant

Account Executive (SMB/MM) (Position located in Cape Town, South Africa)

KnowBe4

Cape Town
On-site
ZAR 200,000 - 300,000
Today
Be an early applicant

Solutions Consulting Manager

Palo Alto Networks

Johannesburg
Remote
ZAR 500,000 - 600,000
Today
Be an early applicant

Content Writer Manager

UpGuard

South Africa
Remote
ZAR 600,000 - 800,000
Yesterday
Be an early applicant

Control Room Operator (P001343)

North-West University / Noordwes-Universiteit

Potchefstroom
On-site
ZAR 200,000 - 300,000
Yesterday
Be an early applicant

Senior Database Engineer

Kurtosys Systems Inc.

Cape Town
Hybrid
ZAR 600,000 - 800,000
Today
Be an early applicant

Strategic Information Security Leader

Sanlam

Bellville
On-site
ZAR 500,000 - 800,000
Today
Be an early applicant

Branch Manager- Queenstown

Fidelity Services Group

Oos-Kaap
On-site
ZAR 400,000 - 500,000
Today
Be an early applicant

Director, Finance Business Partner

Mastercard

Johannesburg
On-site
ZAR 1,200,000 - 1,500,000
Today
Be an early applicant

Branch Manager- Kimberley

Fidelity Services Group

Noord-Kaap
On-site
ZAR 400,000 - 500,000
Today
Be an early applicant

Solutions Architect - Identity & Access Management

Parvana

South Africa
Remote
ZAR 500,000 - 600,000
Today
Be an early applicant

Security Manager - Durban

Fidelity Services Group

KwaZulu-Natal
On-site
ZAR 200,000 - 300,000
Yesterday
Be an early applicant

IT Specialist (Commercial Applications Systems)

Anglo American / De Beers Group

Rosebank
On-site
ZAR 500,000 - 800,000
Today
Be an early applicant

Top job titles:

Legal jobsQuantity Surveying jobsRisk Management jobsRegistered Nurse jobsFacilities Management jobsData Entry Remote jobsLogistic Manager jobsBoard Member jobsContent Writer jobsExecutive jobs

Top companies:

Jobs at EskomJobs at MediclinicJobs at MarriottJobs at PwcJobs at FidelityJobs at United NationsJobs at ShellJobs at MicrosoftJobs at World BankJobs at Appen

Top cities:

Jobs in JohannesburgJobs in Cape TownJobs in DurbanJobs in PretoriaJobs in Port ElizabethJobs in BloemfonteinJobs in GqeberhaJobs in SowetoJobs in PietermaritzburgJobs in East London

Similar jobs:

Security Guard jobsCyber Security jobsManager Security jobsSecurity Officer jobsSecurity Supervisor jobs
Business Information Security Officer
Sanlam
Bellville
On-site
ZAR 500 000 - 800 000
Full time
Yesterday
Be an early applicant

Job summary

A leading financial services provider is seeking a Business Information Security Officer to oversee the Information Security Management System and ensure compliance with Group Governance requirements. The role requires establishing and managing a Business Information Security Programme, effective participation in initiatives, and the implementation of security controls. Key qualifications include experience in policy writing, relevant certifications, and a strong understanding of risk management practices. This position is critical in maintaining the organization's cyber and information security posture.

Qualifications

  • Experience in policy writing and reviews.
  • Familiarity with security practices and standards such as OWASP.
  • Knowledge of Information Risk Methodologies (ideally ISF IRAM2).

Responsibilities

  • Establish and manage a Business Information Security Programme.
  • Report cyber security incidents to SGT CSIRT.
  • Document Security risk management action plans and processes.

Skills

Infiltration testing (hacking)
Risk management
Project Management Tools
Reporting and Administration
Research and trend analysis on IT security leading practice

Education

Grade 12
Bachelor's degree in Information Technology, Commerce, Science, or Social Science
Information Security Certifications such as CISM, CISSP, CCSP, CISA, ISO 27000 Lead Implementer/Auditor
Job description
Who are we?

Sanlam Group Technology is responsible for the provision of a digitally enabled technology service as a group COE, drive business and transformation and provide group-wide digital and data architecture. We operate the various technology platforms and shared services, ensure Cyber and Information Security resilience, and act as technology governance and risk orchestrator for technology across Sanlam.

What will you do?

The Business Information Security Officer (BISO) is responsible for identifying and assessing the Information Security requirements of the business. The BISO in conjunction with the Business CIO, is responsible for the establishment and maintenance of an Information Security Management System (ISMS) and ensure that the appropriate Information Security controls are implemented, maintained and aligned with the Group Governance requirements (i.e. Policies, Standards, Procedures and Guidelines and Cyber Resilience Framework). The BISO is responsible for Security Awareness, Information Risk Management and translating risks and the effect thereof to Lines of Business to ensure informed risk assessment. Other responsibilities include: participation in Group Information Security bodies and initiatives, logical access management, incident response, vulnerability management, IT audit coordination, ensuring new systems adhere to security policy and providing management assurance regarding the Cyber and Information Security posture of the Business.

What will make you successful in this role?

Establish and manage a Business Information Security Programme, effective participation in Group Information Security Programme (GISP) initiatives, Information Security Incident response and Cyber Crisis Management, Information Security Governance and assurance, Application (including cloud) and Infrastructure Security, and Cybersecurity Education, Training and Awareness.
The BISO will implement processes and controls as agreed with the CISO and the Business CIO. The BISO will be responsible for quality and cost effectiveness of delivery of information security services in the BU and will report on these metrics to the GISP.

Outputs
  • Regular feedback to Business Manco on Group-wide information security issues.
  • The BISO must have an action plan to implement these initiatives in the Business.
  • The BISO will report to the GISP Manager on new initiatives, plans and progress which will be discussed at the Cyber Steering Committee.
  • Review and improve existing IT and Information Risk assessment, reporting and management practices.
  • Up to date and complete Business IT and Information Security Risk register.
  • Documented Security risk management action plan. This must include relative priorities of agreed actions; Ownership of the actions; Agree timelines. Priorities will be aligned to Business and GIS P priorities.
  • Up to date and complete Business Cloud register (if these services are used in the Business).
  • Review and respond to Policies, Standards, Procedures and Guidelines and Risk Acceptance requests within the agreed time.
  • Document processes and artefacts that prove that the relevant Governance and Assurance processes were implemented as designed.
  • Clear and timely communication to management and users regarding planned group awareness campaigns.
  • Risk assessment that identifies a requirement for additional awareness or targeted education, training and awareness interventions.
  • Maintenance of Business/Cluster and alignment with the Group annual security education, training and awareness plan.
  • Documented Logical Access review schedule for Line of Business Applications, review results, facilitate resolution, progress report on resolution of issues that were identified during the reviews.
  • Review and respond to audit findings related to application logical access and other Business specific Information Security findings. Ensure that the ratings are accurate.
  • Provide management comment to the audit observations/ findings, that is specific as far as actions and due dates are concerned.
  • Track and follow up on audit finding commitments.
  • Report all cyber security incidents, or information security incidents (including privacy related incidents) where the compromise was through technology to the SGT CSIRT.
  • Be contactable or provide alternative contact details for Cybersecurity incidents that are identified by the SGT CSIRT.
  • Ensure appropriate actions are taken when policy breaches are identified in the Business.
  • Assist by facilitating engagement and communication with key stakeholders in the Cluster during a major incident.
  • Provide context on system and process criticality.
  • Produce Quarterly Group ISO Forum and GISP reports.
  • Provide input into requirements documents - ensure security roles; auditing; data protection (in transit and rest); monitoring etc. are defined in line with approved. Information Security policies and standards.
  • Ensure that Security 'gates' are a formal part of the SDLC/ Agile/ relevant solution development methodology.
  • Interventions and role-players must be clearly specified.
  • Active participation in Sanlam sanctioned industry bodies (e.g. ISF Live, ISACA).
  • Timely escalation of new, high or escalating risks.
  • Engage with application owners and Group Cyber Security Centre Operations Team to ensure that system vulnerabilities are addressed that were identified during Penetration tests, Red Team exercises or Vulnerability scans. Ensure that the Business CIO’s are aware of risk and actions required.
  • Facilitate workshops and risk documentation during Control Self Assessments, or Crown Jewel Risk Assessment processes.
Qualifications
  • Grade 12
  • Bachelor’s degree in Information Technology, Commerce, Science, or Social Science (preferable).
  • In force Information Security Certifications such as CISM, CISSP, CCSP, CISA, ISO 27000 Lead Implementer/ Auditor.
Experience and Knowledge
  • Experience in policy writing and reviews.
  • Experience in agile/ relevant solution development methodologies.
  • Familiarity with security practices and standards in development like the security development life cycle (e.g. OWASP).
  • Understanding of the technical and application environment of the Cluster/ Business.
  • Experience in analysis and control design, strong written and verbal communication skills.
  • Knowledge of ISO27k, Cobit, ITIL, CIS and ISF best practices.
  • Knowledge of Information Risk Methodologies (ideally ISF IRAM2), threat modelling and Operational Risk management methodologies.
  • Knowledge of the key business processes, key stakeholders and have their contact details readily available.
  • Understanding of the risk management and governance structures within the Cluster.
Knowledge and Skills
  • Infiltration testing (hacking)
  • Risk management
  • Project Management Tools
  • Reporting and Administration
  • Research and trend analysis on IT security leading practice
  • Personal Attributes
  • Tech savvy - Contributing through others
  • Manages complexity - Contributing through others
  • Optimises work processes - Contributing through others
  • Communicates effectively - Contributing through others
Core Competencies
  • Cultivates innovation - Contributing through others
  • Customer focus - Contributing through others
  • Drives results - Contributing through others
  • Collaborates - Contributing through others
  • Being resilient - Contributing through others

We’re all about building strong, lasting relationships with our employees. We know that you have hopes for your future – your career, your personal development and achieving great things. We pride ourselves in helping our employees to realise their worth. Through its five business clusters – Sanlam Fintech, Sanlam Life and Savings, Sanlam Investment Group, Sanlam Allianz, Santam, as well as MiWay and the Group Office – the group provides many opportunities for growth and development.

The shortlisting process will only start once the application due date has been reached. The time taken to complete this process will depend on how far you progress and the availability of managers.

Our commitment to transformation

The Sanlam Group is committed to achieving transformation and embraces diversity. This commitment is what drives us to achieve a diverse, inclusive and equitable workplace as we believe that these are key components to ensuring a thriving and sustainable business in South Africa. The Group's Employment Equity plan and targets will be considered as part of the selection process.

  • 1
  • 2
  • 3
  • ...
  • 120

* The salary benchmark is based on the target salaries of market leaders in their relevant sectors. It is intended to serve as a guide to help Premium Members assess open positions and to help in salary negotiations. The salary benchmark is not provided directly by the company, which could be significantly higher or lower.

Job Search and Career Advice Platform

Empoweringjob seekers

Tools
  • Jobs
  • Resume review
  • Headhunters
  • Browse jobs
Company
  • About us
  • Careers at JobLeads
  • Site notice
  • Press
  • Reviews
Support
  • Help
  • Partner integration
  • ATS Partners
Social
  • JobLeads Blog
  • YouTube
  • LinkedIn
  • Instagram
  • Facebook
  • Privacy Policy
  • Terms of Use

© JobLeads 2007 - 2026 | All rights reserved