About the position
ENVIRONMENT:
A reputable Travel & Tourism Agency seeks the technical expertise of a Cybersecurity & Risk Specialist whose core focus will be to manage technology and Information Security risks while maintaining appropriate security controls. The role will coordinate day-to-day Cybersecurity, Information Security, compliance and technology risk activities, working closely with the Technology & Digital Transformation team and business stakeholders. The successful incumbent must possess a Degree/Diploma in Information Security, Cybersecurity/IT/Computer Science or a related field (NQF 6–7) with 3-5 years' relevant experience in Cybersecurity, Information Security, technology risk, IT governance, compliance or a related environment. You will also require a practical understanding of Information Security, Risk Management and Governance& POPIA and information protection principles.
DUTIES:
Cybersecurity, Risk & Governance -
- Assist with identifying and assessing technology and information security risks.
- Maintain risk registers, action plans and security documentation.
- Support the implementation and review of security policies, procedures and controls.
- Assist with POPIA and information security compliance activities.
- Support security audits and follow up on remediation actions.
- Prepare reports and updates on Cybersecurity risks and activities.
Security & Incident Support -
- Assist with monitoring security alerts, vulnerabilities and security controls.
- Support Microsoft 365 security activities, including MFA and Conditional Access.
- Assist with Cybersecurity incident management and escalation.
- Track vulnerability and security remediation activities.
Technology & Digital Projects -
- Support technology projects by identifying security and risk considerations.
- Assist with security assessments of new technologies, cloud and SaaS solutions.
- Support the application of appropriate security controls within digital initiatives.
Third-Party Risk -
- Assist with supplier and third-party security assessments.
- Support the review and tracking of security requirements and risks relating to service providers.
Awareness & Resilience -
- Support Cybersecurity awareness and cyber hygiene initiatives.
- Assist with security training and phishing awareness activities.
- Support business continuity and disaster recovery activities and testing.
- Assist with tracking actions arising from security and continuity exercises.
REQUIREMENTS:
Qualifications –
- Degree or Diploma in Information Security, Cybersecurity, IT, Computer Science or a related field (NQF 6–7).
Experience/Skills –
- 3–5 Years' relevant experience in Cybersecurity, Information Security, technology risk, IT governance, compliance or a related environment.
- Practical understanding of Information Security, Risk Management and Governance.
- Understanding of POPIA and information protection principles.
Advantageous -
- Exposure to Microsoft 365 security, including MFA, Conditional Access or Defender.
- Exposure to frameworks such as ISO 27001, NIST or CIS.
- Exposure to vulnerability management, audits, third-party risk, business continuity or disaster recovery.
ATTRIBUTES:
You are a proactive and dependable professional who:
- Takes ownership and follows through.
- Handles sensitive information with integrity and discretion.
- Is organised and detail oriented.
- Communicates clearly with technical and non-technical stakeholders.
- Takes a practical, solutions-focused approach.
- Can work independently while collaborating effectively with others.
- Is comfortable working in a changing technology environment.
- Demonstrates curiosity and a willingness to learn.
Desired Skills:
- Cybersecurity
- Risk
- Specialist