About the position
Ensuring the company’s security posture is maintained by proactively identifying, tracking, and mitigating IT incidents.
JOB DESCRIPTION
Incident monitoring and response
- Monitor, track, and respond to IT security incidents in collaboration with the Managed Security Operations Center (MSOC)
- Assist in triaging, investigating, and mitigating cybersecurity threats and vulnerabilities.
- Support in incident containment, eradication, and recovery phases of the Incident Response Lifecycle.
- Document and report incidents following the company’s Incident Response Plan (IRP).
- Assist in developing and updating incident response documentation and playbooks
Risk and compliance management
- Support the GRC team in identifying, assessing, and mitigating IT risks.
- Track the status and effectiveness of risk mitigation actions.
- Complete KRIs for risk reporting.
- Assist in tracking and reviewing Policies, Procedures and Standards to ensure alignment with governance frameworks.
- Help ensure compliance with GOI 5, FSCA IT Joint Standard, POPIA, RICA, Cybercrimes Act, and other applicable industry regulations and legislations.
- Provide support in risk assessments related to IT services and vendor management.
- Work with the team on resolving IT audit findings and implementing corrective actions.
Procurement of IT goods and services
- Assist in procurement processes for GRC, ensuring compliance with internal policies and regulatory requirements.
- Work with Legal, Finance, and IT teams to ensure all IT service contracts align with governance and security standards.
Audit Findings Resolution & Compliance Monitoring
- Assist in tracking IT audit findings and ensure remediation actions are implemented effectively.
- Support the closure of compliance findings by ensuring documentation, procedural updates and CRMP are completed.
- Assist in compiling reports for internal audits, regulatory reviews, Manco and Board committee meetings.
Patch management
- Track and deploy security patches for critical systems.
- Ensure timely patching of vulnerabilities identified during incident response.
- Collaborate with IT teams to test and validate patches before deployment.
- Maintain patch management records for audit and compliance tracking.
JOB REQUIREMENTS
Qualifications
- Diploma/Degree in IT related studies
- Cybersecurity certifications will be an added advantage
Experience
- 1-2 years’ experience in IT security, risk management, or compliance monitoring.
- Familiarity with patch management processes, and IT governance frameworks.
- Knowledge of cybersecurity tools is advantageous
Desired Skills:
- Patch management
- Compliance Monitoring
- Incident monitoring and response