About the position
Role Purpose:
- Lead the establishment, operation and continuous improvement of Vodacom's Continuous
- Threat Exposure Management capability. The role is accountable for providing a unified, risk
- based view of cyber exposure across critical business services, infrastructure,
- telecommunications platforms, cloud environments, applications, APIs, identities, data, AI
- systems and approved third parties.
- The role will drive the complete exposure lifecycle, from discovery and prioritisation through
- remediation, validation, exception management and executive reporting, with success
- measured by verified risk reduction rather than vulnerability volumes.
Experience and Qualifications
- Relevant degree or equivalent experience in cybersecurity, technology, engineering or
risk management.
- Significant experience leading vulnerability management, exposure management,
cyber-risk reduction, security testing or a related enterprise security capability.
- Strong knowledge of infrastructure, cloud, identity, application, API, network and
telecommunications security.
- Experience coordinating remediation across complex technology and business
environments.
- Strong understanding of attack-path analysis, threat-informed prioritisation, security
assurance and exception governance.
- Experience managing executive reporting, governance forums, senior stakeholders and
service providers.
- Relevant certification such as CISSP, CISM, CRISC, CCSP, OSCP or GIAC is
advantageous.
- Knowledge of NIST CSF 2.0, MITRE ATT&CK, CISA KEV and FIRST EPSS is advantageous.
Desired Skills:
- Prioritise exposures using business criticality
- customer impact
- internet exposure
- reachability
- attackpaths
- privilege
- known exploitation
- threat intelligence
- CVSS
- CISA KEV and EPSS
- rather than technical severity alone.
Desired Work Experience:
Desired Qualification Level:
About The Employer:
Telecommunications.