Information Security Officer

Sought Out Talent · Springs · R1,2m - R1,35m per annum

Stop applying one at a time.

JobAlertsZA auto-applies to South African jobs like this one for you, overnight. Upload your CV once — we do the applying.

Start free — we apply for you →

Introduction

The Incumbent will be required to lead, govern, and continuously improve company's enterprise information security and cyber risk management function, ensuring that the confidentiality, integrity, and availability of information assets, systems, networks, applications, data, cloud platforms, and operational technology environments are protected in line with business objectives, legal and regulatory requirements, internal policies, risk appetite, and recognised security practices.

Duties & Responsibilities

  • Lead Information Security Strategy: Develop and maintain company’s enterprise information security and cybersecurity strategy, roadmap, operating model, and maturity plan aligned to IT strategy, business priorities, risk appetite, and regulatory obligations;
  • Govern Security Policies and Standards: Establish, maintain, and enforce information security policies, standards, procedures, minimum control requirements, and governance practices across the organisation;
  • Manage Cyber Risk: Identify, assess, prioritise, monitor, and report cyber and information security risks across applications, infrastructure, cloud services, operational technology, data platforms, third parties, and business processes;
  • Security Architecture and Secure Design: Align with enterprise architect regarding cloud adoption, network segmentation, identity and access management, data protection, application security, operational technology, and digital transformation initiatives;
  • Direct Security Operations Oversight: Ensure effective monitoring, detection, vulnerability management, endpoint protection, security event management, threat intelligence, and operational security controls across the IT environment;
  • Lead Cyber Incident Readiness and Response: Own and coordinate cyber incident response governance, escalation, investigation, containment, recovery, lessons learned, and executive communication processes in line with company’s incident response arrangements;
  • Drive Governance, Risk and Compliance: Ensure compliance with internal policies, legal, regulatory, contractual, audit, data protection, and governance requirements relating to information security and cyber risk;
  • Strengthen Identity, Access and Data Protection Controls: Oversee access governance, privileged access, segregation of duties, data loss prevention, information classification, encryption, retention, auditability, and monitoring controls;
  • Manage Third-Party and Supply Chain Security Risk: Define and monitor security requirements for vendors, service providers, cloud platforms, implementation partners, outsourced IT services, and technology suppliers;
  • Promote Security Awareness and Culture: Lead cybersecurity awareness, training, communication, phishing readiness, policy adoption, and behavioural change initiatives across the organisation;
  • Provide Executive and Board-Level Reporting: Report security posture, cyber risks, incidents, vulnerabilities, compliance status, control gaps, remediation progress, and investment requirements to IT leadership and governance forums;

Desired Experience & Qualification

Qualifications

  • Bachelor's Degree in Information Security or Computer Science or Information Technology or Information Systems, or a related discipline; and
  • Relevant Information Security or Cybersecurity certification.

Preferred Qualifications

  • Postgraduate qualification in Information Security, Cybersecurity, Information Technology, Business Management, Risk Management, or a related field;
  • Certified Information Systems Security Professional (CISSP); and
  • Certified Information Security Manager (CISM).

Key Requirements

  • 8 - 10 years' experience in Information Security, Cybersecurity, IT Risk Management, IT Governance, Infrastructure Security, Security Operations, or related technology disciplines;
  • Experience in information security governance, risk management, and compliance practices;
  • At least five (5) years' experience in a cybersecurity leadership, management, or senior specialist role;
  • Proven experience developing and implementing information security strategies, frameworks, policies, standards, and governance processes;
  • Experience conducting cybersecurity risk assessments, security audits, compliance reviews, and control effectiveness evaluations;
  • Experience managing security incidents, vulnerability management programmes, and cybersecurity monitoring activities;
  • Experience implementing and maintaining information security controls across infrastructure, applications, cloud environments, data platforms, and operational technology environments; and
  • Experience engaging with executive leadership, auditors, regulators, technology teams, and business stakeholders on cybersecurity matters.

Package & Remuneration

R1,2m - R1,35m ctc per annum

Auto-apply to this jobView original posting ↗