IT Security Manager

Careerbox · Umhlanga

Posted 6 August 2026

Stop applying one at a time.

JobAlertsZA auto-applies to South African jobs like this one for you, overnight. Upload your CV once — we do the applying.

Start free — we apply for you →

Introduction

The Security Manager is responsible for the strategic leadership and day-to-day management of two key security functions: the Technical Assurance and Controls (TAC) team and the Vulnerability Management team. This role ensures that security controls across the organization are continuously verified, maintained, and improved, and that vulnerabilities across the technology estate are identified, prioritized, and remediated in a timely and risk-informed manner. The Security Manager acts as a bridge between operational security teams and senior leadership, translating technical risk into business impact and driving a culture of continuous security improvement across the organization.

Duties & Responsibilities

Leadership & Team Management

  • Provide direct line management, coaching, and professional development for analysts within the TAC and Vulnerability Management teams.
  • Set team objectives, manage workloads, and conduct regular performance reviews in alignment with organizational goals.
  • Foster a high-performance team culture built on trust, accountability, and continuous learning.
  • Recruit, onboard, and develop talent within both teams, identifying training needs and certification pathways.
  • Act as an escalation point for complex or high-severity issues raised by either team.
  • Promote collaboration between the TAC team, Vulnerability Management team, and the broader SOC and IT Operations functions.

Technical Assurance & Controls Oversight

  • Oversee the TAC team’s program of technical floor walks, ensuring regular, structured verification of security control functionality across all operational areas.
  • Review and approve TAC assurance reports, ensuring findings are accurately documented and escalated to relevant stakeholders.
  • Ensure DLP alert monitoring activities are effectively managed through Microsoft Defender and Microsoft Purview, with appropriate triage and escalation processes in place.
  • Drive the identification and remediation of security control gaps, misconfigurations, and degraded controls, tracking outcomes to closure.
  • Maintain oversight of the organisation’s security control health metrics and produce executive-level reporting on control effectiveness.
  • Ensure the TAC team operates in accordance with applicable frameworks including ISO 27001, NIST, and PCI-DSS.

Vulnerability Management Oversight

  • Lead the strategic direction of the Vulnerability Management program, ensuring the full vulnerability lifecycle discovery, triage, prioritization, remediation, and validation is effectively managed.
  • Oversee patch and vulnerability management processes, ensuring vulnerabilities are remediated within risk-appropriate timeframes and in line with policy.
  • Review and approve vulnerability assessment reports, risk ratings, and remediation recommendations produced by the Vulnerability Management team.
  • Ensure effective coordination between the Vulnerability Management team, IT Operations, Infrastructure, and GRC to drive timely remediation.
  • Monitor KPIs and SLAs for vulnerability remediation and report on programme effectiveness to senior leadership.
  • Ensure the vulnerability management toolset (e.g., Qualys, Tenable, Microsoft Defender) is fit for purpose and continuously optimized.

Risk, Governance & Compliance

  • Ensure both teams operate within established governance frameworks and that security activities are fully documented and audit-ready.
  • Act as a point of contact for internal and external audits relating to security controls and vulnerability management.
  • Identify and manage security risks arising from control gaps or unresolved vulnerabilities, escalating to senior leadership where appropriate.
  • Contribute to the development and review of security policies, standards, and procedures.
  • Ensure compliance with regulatory requirements including PCI-DSS, SOC II and relevant industry standards.
  • Maintain change control discipline across both teams, ensuring all changes to production systems follow approved processes.

Stakeholder Management & Reporting

  • Produce regular management reports on the security posture of the organization, covering control effectiveness, vulnerability exposure, and remediation progress.
  • Present security metrics and risk dashboards to senior leadership and relevant governance committees.
  • Engage with third-party security vendors, managed service providers, and industry bodies to remain current on the threat landscape and emerging security technologies.
  • Liaise with the SOC team to ensure operational alignment between assurance activities and live threat detection and response.
  • Support the organisation’s security awareness initiatives and champion a security-first culture across all business units.

Desired Experience & Qualification

Minimum Requirements

  • Minimum 6 months experience in CCI.
  • Minimum average of 95% attendance over the last 12 months.
  • No active warnings over the last 12 months.
  • Degree or equivalent in Information Technology, Cyber Security, or related discipline.
  • Relevant certifications: CISSP, CISM, CISA or equivalent management-level security qualification.
  • 5+ years’ experience in information security or IT operations, with at least 2 years in a team lead or management role.
  • Demonstrated experience managing vulnerability management programs or technical security assurance functions.
  • Strong working knowledge of Microsoft security technologies including Microsoft Defender, Microsoft Purview, and Microsoft Sentinel.
  • Familiarity with DLP policy management, SIEM platforms, and EDR tooling in enterprise environments. • Deep understanding of security frameworks including ISO 27001, NIST, PCI-DSS, and ITIL.
  • Experience liaising with internal and external auditors and producing audit-ready evidence packs.

Additional Desirable Qualifications

  • Microsoft SC-200, SC-100, AZ-500.
  • CompTIA CySA+, PenTest+ or Fortinet NSE certifications.
  • Experience with scripting or automation (Bash, Python, or PowerShell) to support security operations workflows.
  • Familiarity with vulnerability scanning platforms such as Qualys or Tenable.
  • Previous experience in a managed services or multi-client security environment.
Auto-apply to this jobView original posting ↗