Cybersecurity & Risk Specialist

Cape Town Tourism · Cape Town, Western Cape

Stop applying one at a time.

JobAlertsZA auto-applies to South African jobs like this one for you, overnight. Upload your CV once — we do the applying.

Start free — we apply for you →

Job Description

About Cape Town Tourism

  • At Cape Town Tourism, we believe tourism can make a meaningful difference to the lives of Capetonians.
  • Our common purpose is simple: to improve the lives of Capetonians through tourism.
  • As a Destination Marketing Organisation, we bring visitors to Cape Town, create a frictionless visitor experience, enable our members, strengthen the tourism industry and advocate for sustainable tourism.
  • We are also transforming how we operate. As a leading destination organisation, we embrace purpose, innovation and sustainability to help transform our organisation, our industry and our city.
  • Our people are at the heart of that journey.

Why This Role Matters

  • The Cybersecurity & Risk Specialist will help protect Cape Town Tourism by identifying and managing technology and information security risks, strengthening controls and governance, and ensuring security keeps pace with our digital transformation.
  • You will help us protect sensitive information, strengthen compliance with POPIA, improve incident readiness and business resilience, and embed security into new technology, cloud, AI and digital initiatives.

Key Responsibilities

Information Security, Risk & Governance

  • Identify, assess and monitor cybersecurity and information security risks.
  • Maintain organisational risk registers, risk treatment plans and security control frameworks.
  • Develop and maintain cybersecurity policies, standards and procedures.
  • Support the development and implementation of the cybersecurity strategy.
  • Provide clear risk reporting and insights to management and governance structures, including the Executive Committee ExCo.
  • Support compliance with POPIA and requirements relating to access control, information classification and data protection.
  • Coordinate security audits and track the remediation of findings.

Security Operations & Incident Response

  • Monitor security alerts, vulnerabilities and the effectiveness of security controls.
  • Support Microsoft 365 security, including Microsoft Defender, Conditional Access, Data Loss Prevention DLP and Multi-Factor Authentication MFA.
  • Coordinate cybersecurity incident response and investigations.
  • Drive vulnerability remediation and strengthen preventative and detective security controls.
  • Support effective security monitoring, incident response and security improvement processes.

Secure Digital Transformation

  • Participate in technology projects to ensure security requirements are considered from project inception.
  • Embed secure-by-design principles across digital transformation initiatives.
  • Provide security oversight across cloud, AI, data, analytics and integration initiatives.
  • Assess risks associated with new technologies, platforms and suppliers.
  • Ensure cybersecurity is considered in operational decision-making and support responsible innovation.

Third-Party Risk

  • Conduct cybersecurity assessments of suppliers, vendors and service providers.
  • Monitor security risks relating to outsourced platforms and hosting environments.
  • Ensure appropriate security requirements are incorporated into procurement and supplier engagements.
  • Strengthen governance of third-party technology and information assets.

Awareness, Resilience & Continuity

  • Implement and manage cybersecurity awareness and cyber hygiene programmes.
  • Coordinate security training and phishing simulations.
  • Translate technical security risks into practical guidance for non-technical employees.
  • Support business continuity planning, testing and improvement.
  • Coordinate disaster recovery readiness and testing activities.

What We're Looking For

You will bring strong experience in

  • Cybersecurity governance, risk and compliance.
  • Information security frameworks such as ISO 27001, NIST and CIS.
  • Risk assessment and treatment.
  • Incident response and investigation.
  • Identity and access management.
  • Cloud and Microsoft 365 security, including Microsoft Defender, Conditional Access, DLP and MFA.
  • POPIA and information governance.
  • Vulnerability, audit and compliance management.
  • Third-party security risk.
  • Business continuity and disaster recovery.

You should have a Diploma or Degree in Information Security, Cybersecurity, Computer Science, Information Technology or a related field NQF 6–7 , together with 5–7 years' experience in cybersecurity, information security, risk, governance or a related technology security role.

Experience within a medium to large organisation, particularly across cloud and SaaS environments, will be advantageous.

The Person We Are Looking For

You are a trusted and proactive security professional who

  • Takes ownership and follows through.
  • Handles sensitive information with integrity and discretion.
  • Thinks analytically and focuses on practical solutions.
  • Can influence and educate people who aren't cybersecurity specialists.
  • Communicates complex risks clearly.
  • Remains calm and decisive during incidents.
  • Works collaboratively while being comfortable operating independently.
  • Is curious, adaptable and comfortable with change.
  • Wants to use technology and security to create meaningful organisational impact.
Auto-apply to this jobView original posting ↗
Cybersecurity & Risk Specialist at Cape Town Tourism — Cape Town, Western Cape · JobAlertsZA