32 Certified Protection Professional jobs in South Africa
Loss Prevention Analyst
Posted 3 days ago
Job Viewed
Job Description
Truworths is looking for an analytically inclined Loss Prevention Analyst with a passion for analytics and retail. As a Loss Prevention Analyst, you will assist the business in protecting its merchandise and cash by analysing store data, monitoring incidents and maintaining exception-based reports to identify theft and fraud. Join South Africa’s leading fashion retailer and become part of a winning team!
Responsibilities- Analyse store data, monitor incidents and maintain exception-based reports to identify theft and fraud.
- Support loss prevention initiatives and protect merchandise and cash across stores.
- Analytically inclined with an interest in analytics and retail.
- Ability to work with data and generate reports.
- Strong attention to detail and problem solving.
- Seniority level: Entry level
- Employment type: Full-time
- Job function: Finance and Sales
- Industries: Retail
Loss Prevention Business Partner
Posted 9 days ago
Job Viewed
Job Description
An opportunity has become available for a Loss Prevention Business Partner . The successful incumbent will be responsible for conducting stock takes at the store. This role requires an investigative, attention to detail and focused individual who is passionate about the work they do.
Responsibilities:
- Oversee end to end stock control process.
- Identify risk throughout the retail store.
- Stakeholder management and effective partnering.
Requirements:
- Matric or Grade 12 essential.
- Experience in stock takes and store administration essential .
- Intermediate to advanced Microsoft Skills in Excel, Outlook and Word is essential
- 1+ years experience working in stock control system with SIOCS and Cowhills will be advantageous.
- Willing to travel extensively.
- Valid Drivers License and own car is essential.
- Ability To work under pressure.
- Detail Orientated
- Team Player
- Organized
- Passionate
- Demonstrate excellent administrative and numerical skills.
Please note: The Cape Union Mart Group is committed to transformation. Appointments and promotions will be made based on candidates who best meet the requirements for the position. Preference will be given to candidates who will enhance the diversity of the team, aligned to our Employment Equity plan.
Senior Practitioner: Threat and Risk Assessment (3-Year Fixed Term Contract) at SIU
Posted 7 days ago
Job Viewed
Job Description
Join to apply for the Senior Practitioner: Threat and Risk Assessment (3-Year Fixed Term Contract) at SIU role at Special Investigating Unit
Senior Practitioner: Threat and Risk Assessment (3-Year Fixed Term Contract) at SIU4 days ago Be among the first 25 applicants
Join to apply for the Senior Practitioner: Threat and Risk Assessment (3-Year Fixed Term Contract) at SIU role at Special Investigating Unit
Introduction
The SIU has an exciting opportunity for an enthusiastic Talent to join our dynamic team, passionate about the fight against corruption and recovering financial losses suffered by the State.
The SIU hereby invites suitably qualified and experienced candidates to apply for the opportunities to serve the Unit:
Description
Main purpose: To proactively identify, analyse and mitigate risks that could impact SIU operations, assets, personnel and information. To lead a team to mitigate the risk and respond to incidents, and also collaborate with other State agencies (State Security Agency SSA), South African Police Service (SAPS, National Prosecution Authority (NPA) and Defence intelligence to address threats and intimidations and recommendations to mitigate the risks.
Key performance areas (Include but are not limited to): Threat Intelligence & Risk Identification. Risk Assessments & Analysis. Security Training & Awareness. Incident Response & Forensics. Vulnerability.
Technical skills: Communication, Presentation. Interpersonal, Risk Management and Risk Management Systems. Report Writing. Planning and organising. Project Management. Relationship Management. Time Management. Investigations. Security Audits and Contingency Planning. Analytical thinking. Contracts Management
Understand threats, vulnerabilities, and countermeasures in the physical environment, demonstrate your capability in real-world scenarios, and apply structured assessment methods.
Required knowledge and Behavioural (include but not limited to): Sound Knowledge of safety and security laws, rules and procedures, including, without limitation, as amended from time to time. Public Finance Management Act. Treasury Regulations. Risk Management Framework in the Public Sector, encompassing public security, including the Minimum Information Security Standard (MISS) and the Minimum Physical Security Standards (MPSS). Sound knowledge of SHE legislation. Sound technical knowledge of information system security technology. Sound technical knowledge in security-related systems. Sound knowledge of risk identification and of risk management systems. Understanding of the public sector profile. Advanced MS Office proficiency. Attention to detail. Deadline driven. Result-oriented. Reliable. Integrity. Independent. Seld started. Innovative.
Minimum Requirements
Minimum qualification and experience: Grade 12 Certificate. PSIRA Certificate Grade A. National Diploma/Bachelor's Degree in Security Risk Management or Diploma in Policing or related field (NQF6/7). 3 Years of experience in the security-related field, of which 3 years are at a supervisory or management level. SSA Security Advisory/Management course as an added advantage.
Please Note
- The appointment of candidates will be at the Unit's sole discretion, and the Unit reserves the right not to make an appointment.
- The SIU is an Anti-Corruption Investigating Unit and requires applicants to make a full and frank disclosure in their application form.
- Fraudulent qualifications or documentation will automatically disqualify candidates.
- All candidates will be subjected to integrity screening procedures in line with the SIU Screening, Vetting and Lifestyle Audit Policy, and a favourable end report is essential.
- Other critical positions may be subjected to vetting procedures after appointments in line with the SIU Screening, Vetting and Lifestyle Audit Policy.
- Correspondence will be limited to shortlisted candidates only. Please be advised that applications received mean that processing may take some time. Candidates who have not been contacted within three (3) months of the closing date should consider their applications unsuccessful.
- POPIA disclaimer: In line with the Protection of Personal Information Act, 4 of 2013, by applying for this position, it is accepted that you have consented to your personal information being used and kept for the purposes of processing your application. The SIU will ensure the protection and safeguarding of personal information, and all information collected will not be shared with any third parties or be used for purposes other than those for which it was intended.
- The SIU is committed to equality, employment equity and diversity. Preference will be given to persons from designated groups, in particular Africans, Coloureds and people with disabilities, in line with the SIU Employment Equity Plan.
- The salary offered will be in line with SIU-approved salary scales, which may change subject to relevant approvals and annual increases.
- The SIU will not compensate any relocation costs for appointed incumbents.
- Late applications will not be considered after the closing date.
- PRISA
- Threat Intelligenc
- Risk Identification
- Seniority level Mid-Senior level
- Employment type Contract
- Job function Information Technology
- Industries Law Enforcement
Referrals increase your chances of interviewing at Special Investigating Unit by 2x
Get notified about new Senior jobs in Pretoria, Gauteng, South Africa .
Johannesburg, Gauteng, South Africa 5 months ago
Senior Manager: Office of the HoU Permanent X1 at SIUPretoria, Gauteng, South Africa 4 days ago
Centurion, Gauteng, South Africa 1 month ago
Centurion, Gauteng, South Africa 4 days ago
CONTRACT Senior Business Application Analyst Senior Manager Leadership Development and CultureMidrand, Gauteng, South Africa 3 weeks ago
Centurion, Gauteng, South Africa 3 days ago
Centurion, Gauteng, South Africa 20 hours ago
Africa Talent by Deloitte - Talent Acquisition - Senior ConsultantPretoria, Gauteng, South Africa 8 months ago
FUTURE OPPORTUNITIES: Africa Talent by Deloitte - NL Sustainability AssuranceMidrand, Gauteng, South Africa 2 weeks ago
Bryanston, Gauteng, South Africa 1 week ago
Woodmead, Gauteng, South Africa 2 weeks ago
Bryanston, Gauteng, South Africa 1 week ago
Johannesburg Metropolitan Area 1 week ago
Midrand, Gauteng, South Africa 2 weeks ago
Centurion, Gauteng, South Africa 2 weeks ago
Pretoria, Gauteng, South Africa 2 weeks ago
Centurion, Gauteng, South Africa 1 week ago
Senior Manager: Financial Planning & Analysis (FP&A)Johannesburg, Gauteng, South Africa 1 week ago
Senior Specialist, Special InvestigationsPretoria, Gauteng, South Africa 3 days ago
Centurion, Gauteng, South Africa 2 days ago
Senior Recruiter - 0715 - Pretoria, South AfricaPretoria, Gauteng, South Africa $1,800.00-$2,500.00 2 days ago
Johannesburg Metropolitan Area 2 days ago
Centurion, Gauteng, South Africa 2 weeks ago
We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.
#J-18808-LjbffrApplication and Security Management Analyst
Posted 10 days ago
Job Viewed
Job Description
Experian Johannesburg, Gauteng, South Africa
Application and Security Management AnalystExperian Johannesburg, Gauteng, South Africa
Get AI-powered advice on this job and more exclusive features.
Experian is a global data and technology company, powering opportunities for people and businesses around the world. We help to redefine lending practices, uncover and prevent fraud, simplify healthcare, create marketing solutions, and gain deeper insights into the automotive market, all using our unique combination of data, analytics and software. We also assist millions of people to realize their financial goals and help them save time and money.
We operate across a range of markets, from financial services to healthcare, automotive, agribusiness, insurance, and many more industry segments.
We invest in people and new advanced technologies to unlock the power of data. As a FTSE 100 Index company listed on the London Stock Exchange (EXPN), we have a team of 22,500 people across 32 countries. Our corporate headquarters are in Dublin, Ireland. Learn more at experianplc.com.
Experian is a global data and technology company, powering opportunities for people and businesses around the world. We help to redefine lending practices, uncover and prevent fraud, simplify healthcare, create marketing solutions, and gain deeper insights into the automotive market, all using our unique combination of data, analytics and software. We also assist millions of people to realize their financial goals and help them save time and money.
We operate across a range of markets, from financial services to healthcare, automotive, agribusiness, insurance, and many more industry segments.
We invest in people and new advanced technologies to unlock the power of data. As a FTSE 100 Index company listed on the London Stock Exchange (EXPN), we have a team of 22,500 people across 32 countries. Our corporate headquarters are in Dublin, Ireland. Learn more at experianplc.com.
Principal Responsibilities
• Collaborate with technical and business teams to address security flaws and implement remediation plans.
• Oversee application security tasks, ensuring alignment with audit requirements and internal policies.
• Support change and incident management processes, with a focus on high-priority incidents (P1 & P2).
• Provide guidance to development and support teams on security-related ticket requirements and process expectations, ensuring SLA compliance.
• Act as a liaison with internal stakeholders to ensure clear communication and quality engagements.
• Support governance and administrative functions, including audit preparation and policy development.
• Compile and deliver regular reports, including weekly, monthly, and OSM-specific security metrics.
Required Key Skills (Functional/Technical)
Application Security & Vulnerability Management
• Familiarity with Common Vulnerability Scoring System (CVSS)
• Experience with tools like OWASP ZAP, Veracode, Rapid7 (on-prem), and Wiz.IO (cloud vulnerability management and CSPM)
• Track and assist in the closure of identified vulnerabilities, working closely with IT and Development teams
• Review and maintain secure configurations for systems, applications, and network devices
Security Fundamentals
• Working knowledge of encryption, authentication, and secure data transmission
• Knowledge of network security principles and firewall configurations
• Familiarity with SSO and MFA using OKTA, and directory services such as MS Active Directory
• Experience with CyberArk PAM for privileged access management
Security Information and Event Management (SIEM)
• Use of Splunk SIEM for real-time threat detection and log analysis
• Review and optimise SIEM use cases to enhance threat detection and response capabilities
Monitoring & Endpoint Security
• Experience with Tanium and MS Defender for server and endpoint security management
• Familiarity with IBM Guardium for database activity monitoring
• Exposure to Cyera for data identification and classification
Cloud & Infrastructure Security
• Experience with Wiz.IO for cloud security posture management (CSPM) and IaC scanning
• Understanding of secrets management using AWS Secrets Manager, Azure Key Vault, or GCP Secrets Manager
• Familiarity with Thales and AWS KMS/HSM for key management
Other Tools & Platforms
• Knowledge of SailPoint for identity governance
• Experience with CyCognito for external attack surface management
• Familiarity with Imperva for WAF, DDoS, and botnet protection
• Exposure to ProofPoint and MS Office365 Message Security for email security
• Use of 1Password for credential management
• Awareness of Netwrix for password policy enforcement
- Degree or equivalent qualifications and experience in Computer Science, Information Technology, Data or a related field Technical & Security Experience
- Experience with automated and manual methods for evaluating security controls in both on-prem and cloud environments
- Experience in monitoring and reporting on security flaws and supporting related remediation activities
- Familiarity with change management processes in technology environments Risk, Controls & Compliance
- Contribute to accurate statistical reporting on the market’s IT security posture
- Ensure first line of defence (1LoD) ownership of non-compliance issues, exception justifications, mitigation controls, and risk documentation
- Ensure accuracy and timely completion of control testing and remediations
- Collaborate with Security Partners, RISOs and other governance functions to drive remediation of identified security deficiencies
- Ability to compile management reports and presentations on technical risks, controls, and deficiencies Communication & Collaboration
- Strong ability to communicate complex information clearly and effectively
- Good collaboration, relationship-building, and interpersonal skills
- Act as primary liaison with internal, local and regional stakeholders, ensuring quality engagements and clear progress updates
Our uniqueness is that we celebrate yours. Experian's culture and people are important differentiators. We take our people agenda very seriously and focus on what matters; DEI, work/life balance, development, authenticity, collaboration, wellness, reward & recognition, volunteering. the list goes on. Experian's people first approach is award-winning; World's Best Workplaces 2024 (Fortune Top 25), Great Place To Work in 24 countries, and Glassdoor Best Places to Work 2024 to name a few. Check out Experian Life on social or our Careers Site to understand why.
Experian is proud to be an Equal Opportunity and Affirmative Action employer. Innovation is an important part of Experian's DNA and practices, and our diverse workforce drives our success. Everyone can succeed at Experian and bring their whole self to work, irrespective of their gender, ethnicity, religion, colour, sexuality, physical ability or age. If you have a disability or special need that requires accommodation, please let us know at the earliest opportunity.
Experian Careers - Creating a better tomorrow together
Find out what its like to work for Experian by clicking here
- Seniority level Not Applicable
- Employment type Full-time
- Job function Information Technology
Referrals increase your chances of interviewing at Experian by 2x
Sign in to set job alerts for “Application Security Analyst” roles.We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.
#J-18808-LjbffrApplication and security management analyst
Posted today
Job Viewed
Job Description
Information Security Management System (ISMS) Specialist
Posted 24 days ago
Job Viewed
Job Description
Join to apply for the Information Security Management System (ISMS) Specialist role at Vector Logistics
Information Security Management System (ISMS) SpecialistJoin to apply for the Information Security Management System (ISMS) Specialist role at Vector Logistics
Overview
We are a Supply Chain and Sales & Merchandising partner adding value to your business through a fully integrated, temperature-controlled network in Southern Africa.
Permanent
Midrand
Overview
We are a Supply Chain and Sales & Merchandising partner adding value to your business through a fully integrated, temperature-controlled network in Southern Africa.
But we are also more than that. We are people serving people. While we boast the best in tech and infrastructure, our people are our greatest resource. With our skilled, curious, can-do people at the forefront, our assets become your assets, our service your solutions.
Vector’s vehicle fleet includes a food industry first in ‘multi-temperature’ vehicles enabling the company to service business across frozen, chilled and ambient temperature zones on a single delivery.
Job Purpose
Information Security Management System (ISMS) Specialist is responsible for the end-to-end implementation, maintenance, and continuous improvement of the Information Security Management System (ISMS) in accordance with ISO/IEC 27001 standards. The incumbent will play a pivotal role in ensuring the confidentiality, integrity, and availability of our information assets, while also ensuring compliance with legal and regulatory requirements.
Key Responsibilities
ISMS Development And Implementation
- Lead the design, implementation, and continuous improvement of an ISMS aligned with ISO/IEC 27001 and other relevant frameworks (e.g., NIST, POPIA, CIS, CSA etc.).
- Develop, implement, and maintain information security policies, procedures, and guidelines.
- Assess existing information security practices and recommend improvements.
- Ensure the organization's ISMS aligns with business needs, regulatory requirements, and industry best practices.
- Perform risk assessments to identify potential security risks to the organization's information assets in alignment to ISO 31000.
- Develop risk treatment plans and assist in the implementation of risk mitigation strategies.
- Conduct ongoing risk assessments and audits to ensure the effectiveness of the ISMS.
- Ensure compliance with ISO/IEC 27001 and other industry standards and regulations.
- Prepare the organization for certification audits and support the audit process.
- Coordinate with auditors and certification bodies.
- Maintain records and documentation to ensure traceability and compliance with ISMS requirements.
- Provide training to staff and management on information security best practices, policies, and compliance requirements.
- Promote a culture of information security awareness across the organization.
- Support the creation of an internal security awareness program.
- Assist in the development and testing of incident response plans.
- Provide guidance and support in handling information security incidents.
- Ensure incidents are documented and reported in accordance with regulatory and contractual obligations & assist in post-incident analysis to determine the cause and recommend preventive actions.
- Define and monitor ISMS-related KPIs and metrics.
- Monitor and report on the performance of the ISMS, identifying areas for improvement.
- Monitor compliance with security policies and procedures.
- Lead regular internal audits to assess the effectiveness of the ISMS.
- Recommend and implement improvements based on audit findings, risk assessments, and evolving industry practices.
- Keep up-to-date with emerging threats, vulnerabilities, and regulatory changes.
- Assess and monitor third-party vendors and service providers for information security compliance.
- Assist in the integration of ISMS controls into third-party contracts and SLAs.
Key Relationship 1
- This role plays a critical role in managing and maintaining relationships with both internal and external stakeholders.
- These interactions are essential for ensuring the organization’s security posture is robust and aligned with its strategic objectives.
Qualifications, Skills and Experience Required for the Job
- Bachelor’s Degree: A bachelor’s degree in information security, Computer Science, Information Technology, or a related field is required.
- Mandatory Requirement: ISO27001 Lead Implementer Preferrable: ISO27001 Lead Auditor, Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA)
- The ISMS Specialist role demands a robust combination of technical expertise, specialized knowledge, and strong leadership abilities. The ideal candidate must have an intrinsic understanding of the ISMS statement of applicability.
- The ideal candidate should possess in-depth knowledge of information security frameworks such as ISO/IEC 27001, NIST, and CIS Controls. Familiarity with IT governance frameworks (e.g., COBIT, ITIL)., and have extensive experience in risk management, incident response, and compliance, particularly with South African regulations like POPIA and the Cybercrimes Act.
- Soft skills such as excellent communication, adaptability, attention to detail, and ethical judgment are also vital, enabling the Information Security Compliance Specialist to convey complex security concepts, adapt to evolving threats, and uphold the highest standards of security and privacy within the organization. Experience in BIA, BCM, DR.Include experience in vulnerability management, patching, JML.
- Minimum of 7-10 years of experience in the field of information security, cybersecurity, or a related discipline, with at least 1-3 years in a managerial or leadership capacity. This experience should include hands-on management of security frameworks such as ISO/IEC 27001 and NIST, as well as significant exposure to risk management, incident response, and compliance with industry regulations.
- Proven experience of leading ISO/IEC 27001 certification projects and certification maintenance.
- Experience in working with ISO27001 certification bodies.
- Development of audit and ISMS remediation plans.
- Familiarity with data protection laws and industry regulations.
- Relevant professional certifications such as CISM, CRISC, or CISA, which validate their expertise in key areas of information security. Knowledge of security tools, including Microsoft Sentinel, CyberReason, and Microsoft Defender, is essential for managing the organization’s security posture effectively.
- Strategic Thinking: Ability to align security strategies with business objectives and anticipate future challenges.
- Technical Expertise: Knowledge of security frameworks, technologies, and tools, with strong proficiency in threat analysis and mitigation.
- People Management: Strong leadership skills to build, manage, and effectively leverage external resources.
- Decision-Making and Judgment: High discretion in making critical security decisions, balancing immediate needs with long-term goals.
- Collaboration and Communication: Excellent interpersonal skills for engaging with both technical and non-technical stakeholders and building strong relationships.
- Problem-Solving and Analytical Skills: Strong analytical abilities to assess and resolve complex security issues across organizational boundaries.
- Compliance and Regulatory Knowledge: In-depth understanding of relevant regulations and standards, ensuring ongoing compliance.
- Adaptability and Resilience: Ability to adapt to changing security landscapes and manage high-pressure situations.
- Ethical Integrity: Commitment to upholding the highest ethical standards in all security practices
- Seniority level Mid-Senior level
- Employment type Full-time
- Job function Information Technology
- Industries Transportation, Logistics, Supply Chain and Storage
Referrals increase your chances of interviewing at Vector Logistics by 2x
Sign in to set job alerts for “Information Security Specialist” roles.Johannesburg, Gauteng, South Africa 2 days ago
Johannesburg, Gauteng, South Africa 1 week ago
Johannesburg Metropolitan Area 3 days ago
Johannesburg, Gauteng, South Africa 1 month ago
Randburg, Gauteng, South Africa 4 days ago
Johannesburg, Gauteng, South Africa 1 week ago
Randburg, Gauteng, South Africa 5 days ago
Senior Manager: Information Systems Audit (Cyber Security)Pretoria, Gauteng, South Africa 2 weeks ago
Johannesburg Metropolitan Area 3 days ago
Centurion, Gauteng, South Africa 4 days ago
Johannesburg, Gauteng, South Africa 1 day ago
Johannesburg, Gauteng, South Africa 6 days ago
Johannesburg, Gauteng, South Africa 5 days ago
We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.
#J-18808-LjbffrInformation Security Management System (ISMS) Specialist
Posted 24 days ago
Job Viewed
Job Description
Information Security Management System (ISMS) Specialist
Permanent
Midrand
Overview
We are a Supply Chain and Sales & Merchandising partner adding value to your business through a fully integrated, temperature-controlled network in Southern Africa.
But we are also more than that. We are people serving people. While we boast the best in tech and infrastructure, our people are our greatest resource. With our skilled, curious, can-do people at the forefront, our assets become your assets, our service your solutions.
Vector’s vehicle fleet includes a food industry first in ‘multi-temperature’ vehicles enabling the company to service business across frozen, chilled and ambient temperature zones on a single delivery.
Job Purpose
Information Security Management System (ISMS) Specialist isresponsible for the end-to-end implementation, maintenance, and continuousimprovement of the Information Security Management System (ISMS) in accordancewith ISO/IEC 27001 standards. The incumbent will play a pivotal role inensuring the confidentiality, integrity, and availability of our informationassets, while also ensuring compliance with legal and regulatory requirements.
Key Responsibilities
ISMS Development and Implementation:
- Lead the design, implementation, and continuous improvement of an ISMS aligned with ISO/IEC 27001 and other relevant frameworks (e.g., NIST, POPIA, CIS, CSA etc.).
- Develop, implement, and maintain information security policies, procedures, and guidelines.
- Assess existing information security practices and recommend improvements.
- Ensure the organization's ISMS aligns with business needs, regulatory requirements, and industry best practices.
Risk Assessment and Management:
- Perform risk assessments to identify potential security risks to the organization's information assets in alignment to ISO 31000.
- Develop risk treatment plans and assist in the implementation of risk mitigation strategies.
- Conduct ongoing risk assessments and audits to ensure the effectiveness of the ISMS.
Compliance and Audits:
- Ensure compliance with ISO/IEC 27001 and other industry standards and regulations.
- Prepare the organization for certification audits and support the audit process.
- Coordinate with auditors and certification bodies.
- Maintain records and documentation to ensure traceability and compliance with ISMS requirements.
Training and Awareness:
- Provide training to staff and management on information security best practices, policies, and compliance requirements.
- Promote a culture of information security awareness across the organization.
- Support the creation of an internal security awareness program.
Incident Response and Management:
- Assist in the development and testing of incident response plans.
- Provide guidance and support in handling information security incidents.
- Ensure incidents are documented and reported in accordance with regulatory and contractual obligations & assist in post-incident analysis to determine the cause and recommend preventive actions.
Continuous Improvement:
- Define and monitor ISMS-related KPIs and metrics.
- Monitor and report on the performance of the ISMS, identifying areas for improvement.
- Monitor compliance with security policies and procedures.
- Lead regular internal audits to assess the effectiveness of the ISMS.
- Recommend and implement improvements based on audit findings, risk assessments, and evolving industry practices.
- Keep up-to-date with emerging threats, vulnerabilities, and regulatory changes.
Vendor and Third-Party Risk Management:
- Assess and monitor third-party vendors and service providers for information security compliance.
- Assist in the integration of ISMS controls intothird-party contracts and SLAs.
Key Relationships
Key Relationship 1
- This role plays a critical role in managing and maintaining relationships with both internal and external stakeholders.
- These interactions are essential for ensuringthe organization’s security posture is robust and aligned with its strategicobjectives.
Qualifications, Skills and Experience Required for the Job
Qualifications and Experience
- Bachelor’s Degree: A bachelor’s degree in information security, Computer Science, Information Technology, or a related field is required.
- Mandatory Requirement: ISO27001 Lead Implementer
Preferrable:ISO27001 Lead Auditor, Certified Information Security Manager (CISM), CertifiedInformation Systems Auditor (CISA)
- The ISMS Specialist role demands a robust combination of technical expertise, specialized knowledge, and strong leadership abilities. The ideal candidate must have an intrinsic understanding of the ISMS statement of applicability.
- The ideal candidate should possess in-depth knowledge of information security frameworks such as ISO/IEC 27001, NIST, and CIS Controls. Familiarity with IT governance frameworks (e.g., COBIT, ITIL)., and have extensive experience in risk management, incident response, and compliance, particularly with South African regulations like POPIA and the Cybercrimes Act.
- Soft skills such as excellent communication, adaptability, attention to detail, and ethical judgment are also vital, enabling the Information Security Compliance Specialist to convey complex security concepts, adapt to evolving threats, and uphold the highest standards of security and privacy within the organization. Experience in BIA, BCM, DR.Include experience in vulnerability management, patching, JML.
- Minimum of 7-10 years of experience in the field of information security, cybersecurity, or a related discipline, with at least 1-3 years in a managerial or leadership capacity. This experience should include hands-on management of security frameworks such as ISO/IEC 27001 and NIST, as well as significant exposure to risk management, incident response, and compliance with industry regulations.
- Proven experience of leading ISO/IEC 27001 certification projects and certification maintenance.
- Experience in working with ISO27001 certification bodies.
- Development of audit and ISMS remediation plans.
- Familiarity with data protection laws and industry regulations.
- Relevant professional certifications such as CISM, CRISC, or CISA, which validate their expertise in key areas of information security. Knowledge of security tools, including Microsoft Sentinel, CyberReason, and Microsoft Defender, is essential for managing the organization’s security posture effectively.
Skills and Competencies
- Strategic Thinking: Ability to align security strategies with business objectives and anticipate future challenges.
- Technical Expertise: Knowledge of security frameworks, technologies, and tools, with strong proficiency in threat analysis and mitigation.
- People Management: Strong leadership skills to build, manage, and effectively leverage external resources.
- Decision-Making and Judgment: High discretion in making critical security decisions, balancing immediate needs with long-term goals.
- Collaboration and Communication: Excellent interpersonal skills for engaging with both technical and non-technical stakeholders and building strong relationships.
- Problem-Solving and Analytical Skills: Strong analytical abilities to assess and resolve complex security issues across organizational boundaries.
- Compliance and Regulatory Knowledge: In-depth understanding of relevant regulations and standards, ensuring ongoing compliance.
- Adaptability and Resilience: Ability to adapt to changing security landscapes and manage high-pressure situations.
- Ethical Integrity: Commitment to upholding thehighest ethical standards in all security practices
We look forward to hearing from you!
#J-18808-LjbffrBe The First To Know
About the latest Certified protection professional Jobs in South Africa !
Information security management system (isms) specialist
Posted today
Job Viewed
Job Description
Information security management system (isms) specialist
Posted today
Job Viewed
Job Description
Security Risk Management Specialist
Posted 4 days ago
Job Viewed
Job Description
Canonical is recruiting a Security Risk Management Specialist in Cape Town, Western Cape, South Africa.
What you will doIn security risk management we harness industry best practices and drive innovation in security risk assessments and modelling. The security risk management team owns the strategy and practices for identifying, tracking, and reducing Canonical's security risk across the organisation. You will help establish and execute a broad strategic vision for the security risk program and will work cross-functionally with teams across Canonical. The team contributes ideas for Canonical product security, improving the resilience and robustness of Ubuntu customers and users subject to cyber attacks. The team also collaborates with our Organisational Learning and Development team to develop playbooks and facilitate security training.
- Define Canonical's security risk management standards and playbooks
- Analyse and improve Canonical's security risk practices
- Evaluate, select and implement new security requirements, tools and practices
- Grow the presence and thought leadership of Canonical security risk management practice
- Develop Canonical security risk learning and development materials
- Work with Security leadership to present information and influence change
- Participate in developing key risk indicators, provide inputs to the development of key control indicators, and key performance indicators for various programs
- Apply statistical models to risk frameworks (such as FAIR, sensitivity analysis, and others)
- Participate in risk management, decision-making, and collaborative discussions
- Lead quantified risk assessments and understand the value of qualitative data for improvements to quality and engineering processes
- Interpret internal or external cyber security risk analyses in business terms and recommend a responsible course of action
- Develop templates and materials to help with self-service risk management actions
- Monitor and identify opportunities to improve the effectiveness of risk management processes
- Launch campaigns to perform security assessments and help mitigate security risks across the company
- Build evaluation methods and performance indicators to measure efficiency of security functions and capabilities
- An exceptional academic track record
- Undergraduate degree in Computer Science or STEM, or a compelling narrative about your alternative path
- Drive and a track record of going above-and-beyond expectations
- Deep personal motivation to be at the forefront of technology security
- Leadership and management ability
- Excellent business English writing and presentation skills
- Problem-solver with excellent communication skills, a deep technical understanding of security assessments and risk management
- Expertise in threat modelling and risk management frameworks
- Broad knowledge of how to operationalize the management of security risk
- Experience in Secure Development Lifecycle and Security by Design methodology
- Distributed work environment with twice-yearly team sprints in person
- Personal learning and development budget of USD 2,000 per year
- Annual compensation review
- Recognition rewards
- Annual holiday leave
- Maternity and paternity leave
- Employee Assistance Programme
- Opportunity to travel to new locations to meet colleagues
- Priority Pass, and travel upgrades for long haul company events
Canonical is a pioneering tech firm at the forefront of the global move to open source. As the company that publishes Ubuntu, one of the most important open source projects and the platform for AI, IoT and the cloud, we are changing the world on a daily basis. We recruit on a global basis and set a very high standard for people joining the company. We expect excellence — in order to succeed, we need to be the best at what we do. Canonical has been a remote-first company since its inception in 2004. Working here is a step into the future, and will challenge you to think differently, work smarter, learn new skills, and raise your game.
Canonical is an equal opportunity employer.
We are proud to foster a workplace free from discrimination. Diversity of experience, perspectives, and background create a better work environment and better products. Whatever your identity, we will give your application fair consideration.
Job details- Seniority level: Entry level
- Employment type: Full-time
- Job function: Finance and Sales
- Industries: Software Development