Information Security Officer

JN Recruitment (Pty) Ltd · Springs (JHB) · R1,2m - R1,35m CTC

Stop applying one at a time.

JobAlertsZA auto-applies to South African jobs like this one for you, overnight. Upload your CV once — we do the applying.

Start free — we apply for you →

Introduction

A leading organisation is seeking an experienced and strategic Information Security Officer to lead and continuously improve its enterprise information security and cybersecurity function.

The successful candidate will be responsible for protecting the organisation’s information assets, systems, networks, applications, data, cloud platforms and operational technology environments. This role will provide strategic leadership across cybersecurity governance, cyber risk management, security operations, compliance, incident response and security awareness , ensuring that information security practices support business objectives and recognised industry standards.

Duties & Responsibilities

Key Responsibilities

  • Develop and maintain the enterprise Information Security and Cybersecurity Strategy, roadmap, operating model and maturity plan.
  • Establish, maintain and enforce information security policies, standards, procedures and governance frameworks.
  • Identify, assess, prioritise and monitor cybersecurity and information security risks across the organisation.
  • Provide security input into cloud adoption, network security, identity and access management, data protection, application security and digital transformation initiatives.
  • Oversee security operations, including monitoring, threat detection, vulnerability management, endpoint protection, security event management and threat intelligence.
  • Lead cyber incident readiness and response, including investigation, containment, recovery, escalation and lessons learned.
  • Drive Governance, Risk and Compliance (GRC) activities and ensure alignment with legal, regulatory, contractual and internal requirements.
  • Strengthen identity and access management, privileged access, segregation of duties, data loss prevention, encryption, information classification and monitoring controls.
  • Manage cybersecurity risks associated with third-party providers, suppliers, cloud platforms and outsourced technology services.
  • Lead cybersecurity awareness, training, phishing readiness and security culture initiatives.
  • Provide executive-level reporting on security posture, cyber risks, incidents, vulnerabilities, compliance, control gaps and remediation.
  • Coordinate internal and external security audits, assurance reviews, control testing and remediation activities.
  • Build, mentor and coordinate internal and external cybersecurity resources and specialist service providers.
  • Attend to audit queries and perform other reasonable duties within the scope of the role.

Key Competencies

  • Strong verbal and written English communication skills.
  • Strategic and analytical thinking.
  • Strong problem-solving and decision-making abilities.
  • Excellent attention to detail.
  • Strong prioritisation and time-management skills.
  • Ability to work effectively under pressure and meet deadlines.
  • Ability to work independently as well as collaboratively across multidisciplinary teams.
  • Strong leadership and stakeholder-management capabilities.
  • Continuous improvement mindset.
  • High level of integrity, professionalism and accountability.

Desired Experience & Qualification

Minimum Requirements

Qualifications

  • Bachelor's Degree in Information Security, Computer Science, Information Technology, Information Systems or a related discipline.
  • Relevant Information Security or Cybersecurity certification.

Preferred Qualifications

  • Postgraduate qualification in Information Security, Cybersecurity, Information Technology, Business Management, Risk Management or a related field.
  • CISSP certification.
  • CISM certification.

Experience Required

  • 8–10 years’ experience in Information Security, Cybersecurity, IT Risk Management, IT Governance, Infrastructure Security, Security Operations or a related technology discipline.
  • At least 5 years’ experience in a cybersecurity leadership, management or senior specialist role .
  • Proven experience developing and implementing information security strategies, frameworks, policies, standards and governance processes.
  • Strong experience in cybersecurity risk assessments, security audits, compliance reviews and control effectiveness evaluations.
  • Experience managing security incidents, vulnerability management programmes and cybersecurity monitoring.
  • Experience implementing security controls across infrastructure, applications, cloud environments, data platforms and operational technology.
  • Proven ability to engage effectively with executive leadership, auditors, regulators, technology teams and business stakeholders.

Package & Remuneration

R1,2m - R1,35m CTC

Auto-apply to this jobView original posting ↗