About the position
Job Purpose:
The purpose of this role is to provide enterprise security assurance, support client security governance, and ensure ongoing compliance with relevant standards while identifying and mitigating risks to safeguard the organisations and clients’ information assets, ensuring confidentiality, integrity, and availability
Key Performance Areas
Information security operations:
- Monitor security alerts and events from various systems (SIEM, IDS/IPS, endpoint tools)
- Investigate potential threats and escalate incidents as necessary
- Support implementation and monitoring of security controls (firewalls, access control, encryption)
- Maintain and administer security tools including antivirus, DLP, and endpoint protection
- Install and manage security software solutions to protect IT infrastructure
Risk management:
- Participate in enterprise risk assessments to identify threats and vulnerabilities
- Support vulnerability assessments, analyse results, and assist in remediation prioritisation
- Collaborate with IT and business teams to reduce identified risks
- Contribute to penetration testing activities and remediation efforts
- Assist in developing organisational security best practices
Incident management and response:
- Support incident response activities including investigation, documentation, and reporting
- Analyse security breaches and assess impact
- Maintain accurate incident records for audit and compliance purposes
- Collaborate with internal stakeholders during incident remediation
Compliance and governance
- Support compliance with industry standards and frameworks (PCI-DSS, ISO 27001, SOC 2, GDPR, POPIA, NIST),
- Participate in internal and external security assessments and audits
- Ensure compliance with Client Third Party Risk Reduction (CTPRR) requirements
- Assist in implementing security controls aligned with regulatory requirements
Client and stakeholder engagement:
- Engage with clients on security-related matters including risk remediation and onboarding
- Provide security advisory support for new software and system implementations
- Collaborate with cross-functional teams to embed security into business processes
Security awareness and continuous improvement:
- Contribute to security awareness initiatives and training programmes
- Develop training materials and educate staff on best security practices
- Research emerging threats and recommend enhancements
- Evaluate and support implementation of new security technologies
Key Internal and External Relationships
Internal
Stakeholder:
- IT Teams - Collaboration on security implementation and vulnerability remediation
- Risk and Compliance - Alignment on regulatory and governance requirements
- Business Units -Security guidance and risk awareness
- Security Operations Team - Coordination of monitoring and incident response
Stakeholder:
- Clients - Security governance, compliance alignment, and risk remediation
- Third-party Vendors - Security assessments and risk management
- Industry Bodies - Staying informed on security standards and trends
Organogram
Information Security Manager
This position
Competencies
Knowledge:
- Degree in Information Security, Cybersecurity, Computer Science, or related
- Familiarity with security frameworks (NIST, CIS, PCI-DSS, ISO 27001, GDPR)
- Understanding of network security, system architecture, and protocols
- Experience with SIEM tools, firewalls, IDS/IPS, & endpoint security
- Knowledge of vulnerability management and penetration testing practices
- Bachelor’s degree or equivalent in a relevant field
- Preferred Certifications: CompTIA Security+/ CISSP /CISM
Skills:
- Technical Expertise (L3)
- Problem Solving (L3)
- Planning and Organising (L3)
- Customer Service (L3)
- Oral and Written Communication (L3)
Attributes:
- Attention to detail
- Collaboration
- Resilience
Job Purpose:
The purpose of this role is to provide enterprise security assurance, support client security governance, and ensure ongoing compliance with relevant standards while identifying and mitigating risks to safeguard the organisations and clients’ information assets, ensuring confidentiality, integrity, and availability
Key Performance Areas
Information security operations:
- Monitor security alerts and events from various systems (SIEM, IDS/IPS, endpoint tools)
- Investigate potential threats and escalate incidents as necessary
- Support implementation and monitoring of security controls (firewalls, access control, encryption)
- Maintain and administer security tools including antivirus, DLP, and endpoint protection
- Install and manage security software solutions to protect IT infrastructure
Risk management:
- Participate in enterprise risk assessments to identify threats and vulnerabilities
- Support vulnerability assessments, analyse results, and assist in remediation prioritisation
- Collaborate with IT and business teams to reduce identified risks
- Contribute to penetration testing activities and remediation efforts
- Assist in developing organisational security best practices
Incident management and response:
- Support incident response activities including investigation, documentation, and reporting
- Analyse security breaches and assess impact
- Maintain accurate incident records for audit and compliance purposes
- Collaborate with internal stakeholders during incident remediation
Compliance and governance
- Support compliance with industry standards and frameworks (PCI-DSS, ISO 27001, SOC 2, GDPR, POPIA, NIST),
- Participate in internal and external security assessments and audits
- Ensure compliance with Client Third Party Risk Reduction (CTPRR) requirements
- Assist in implementing security controls aligned with regulatory requirements
Client and stakeholder engagement:
- Engage with clients on security-related matters including risk remediation and onboarding
- Provide security advisory support for new software and system implementations
- Collaborate with cross-functional teams to embed security into business processes
Security awareness and continuous improvement:
- Contribute to security awareness initiatives and training programmes
- Develop training materials and educate staff on best security practices
- Research emerging threats and recommend enhancements
- Evaluate and support implementation of new security technologies
Key Internal and External Relationships
Internal
Stakeholder:
- IT Teams - Collaboration on security implementation and vulnerability remediation
- Risk and Compliance - Alignment on regulatory and governance requirements
- Business Units -Security guidance and risk awareness
- Security Operations Team - Coordination of monitoring and incident response
Stakeholder:
- Clients - Security governance, compliance alignment, and risk remediation
- Third-party Vendors - Security assessments and risk management
- Industry Bodies - Staying informed on security standards and trends
Organogram
Information Security Manager
This position
Competencies
Knowledge:
- Degree in Information Security, Cybersecurity, Computer Science, or related
- Familiarity with security frameworks (NIST, CIS, PCI-DSS, ISO 27001, GDPR)
- Understanding of network security, system architecture, and protocols
- Experience with SIEM tools, firewalls, IDS/IPS, & endpoint security
- Knowledge of vulnerability management and penetration testing practices
- Bachelor’s degree or equivalent in a relevant field
- Preferred Certifications: CompTIA Security+/ CISSP /CISM
Skills:
- Technical Expertise (L3)
- Problem Solving (L3)
- Planning and Organising (L3)
- Customer Service (L3)
- Oral and Written Communication (L3)
Attributes:
- Attention to detail
- Collaboration
- Resilience
Desired Skills:
- Risk management:
- Incident management
- and response
- Security awareness
- Client and stakeholder engagement
- Compliance and governance