97 Cyber Risk Management jobs in South Africa

Financial Crime Risk Assessment Specialist

Gauteng, Gauteng Findojobs South Africa

Posted today

Job Viewed

Tap Again To Close

Job Description

We are looking for a seasoned Financial Crime Risk Assessment Specialist to join our team of experts responsible for providing ongoing oversight of the compliance issues impacting the financial crime risk profile. The role includes active engagement with segments on non-compliance issues raised by assurance providers or identified through breaches in key risk indicators. In addition, the incumbent will coordinate and participate in the group’s response to quarterly regulatory returns, periodic inspections, and progress reports on remediation.

Evaluation and assessment

Coordinate (manage / direct / contribute to) requests for information, quarterly returns to the regulator, and self-assessment questionnaires or declarations.

  • Coordinate the group response to inspections by regulators, requesting information from segments, evaluating segment feedback, and submitting to regulators, including coordination of presentations.
  • Perform monthly Archer logs reviews and facilitate meetings with the respective segment compliance teams to ensure non-compliance issues are complete, accurate, and valid when logged on Archer. Review risk ratings, root causes, and action plans, and assess the adequacy of actions to close findings promptly.
  • Oversee attendance at key segment or business unit meetings.
Reporting

Coordinate submissions for regulatory reports, consolidate to create a group view, and evaluate segment feedback. Assist with the collation, preparation, and distribution of financial crime compliance management, governance, and assurance reports from the Group Financial Crime. Support the quarterly Prudential Authority returns for ML/TF/PF, extracting data from sources within FSR (e.g., AML Ops).

Assurance

Facilitate assessments and evaluate the controls' effectiveness. Track and follow up on corrective actions. Prepare high-risk themes for monitoring based on legislation, policies, standards, and guidance notes.

Customer

Manage and contribute to engagement with regulators, maintaining effective relationships across FirstRand’s financial crime centre of excellence and business unit compliance officers.

Other

Perform any other ad hoc tasks assigned by the Group Head of Financial Crime Compliance or the Group Financial Crime Compliance Manager.

Core competencies
  • Ambitious, driven, and resilient to change and challenges.
  • Strategic thinker with operational excellence skills.
  • Ability to multitask in a fast-paced environment managing multiple projects.
  • Excellent analytical, communication, interpersonal, and facilitation skills.
  • Strong planning, organizational, and project management skills.
  • Trustworthy with highly sensitive information and collaborative in stakeholder engagement.
  • Adaptable to workforce trends, including hybrid work models.
  • Ability to translate complex data into compelling narratives for senior leadership.
  • Agile mindset with a focus on quick delivery and continuous growth in technical and leadership skills.
Job Details

Applications will not be accepted after 16/08/2025. Please submit applications before the closing date. All appointments will align with FirstRand Group’s Employment Equity plan. The bank supports the recruitment and advancement of individuals with disabilities. Candidates may disclose disability information voluntarily; this will be kept confidential unless required by law.

#J-18808-Ljbffr
This advertiser has chosen not to accept applicants from your region.

Information Security Specialist

Johannesburg, Gauteng Kpmg-Southafrica

Posted today

Job Viewed

Tap Again To Close

Job Description

The KPMG Africa Information Security Specialist is responsible for ensuring the confidentiality, integrity, and availability of all systems across KPMG Africa offices (South Africa, Botswana, Mauritius, Mozambique, Namibia, Zambia, Zimbabwe, Nigeria, Ghana, Kenya, Uganda, Tanzania, and Rwanda). The role involves actively managing and monitoring information security systems to detect, respond to, and remediate security risks and threats across the infrastructure.

4. Position Specifications

Educational Requirements (minimum necessary to perform the job):

  • Professional / Tertiary qualification

Other Requirements:

Experience (minimum necessary):

Desired Qualifications and Experience:

  • 3-5 years' experience in Information Technology Support or Information Security, including Microsoft Azure
  • Industry-recognized certifications such as A+, N+, Security+, CySA+, and Cloud Security certifications like:

o Microsoft Certified: Security Operations Analyst Associate

o Microsoft Certified: Information Protection and Compliance Administrator Associate

o Microsoft Certified: Security, Compliance, and Identity Fundamentals

o Microsoft Certified: Identity & Access Management

o Microsoft Certified: Azure Security Engineer

  • Professional certifications such as CISM, CISSP, ECIH are preferred but not required
  • Strong knowledge of information security and cloud security concepts
  • Experience in identifying, analyzing, and reporting on security risks and incidents
  • Experience with security tools such as Qualys, Microsoft Defender Endpoint, Microsoft Sentinel, etc.
  • Ability to evaluate vulnerabilities, develop mitigation strategies, and implement remediation
  • Strong knowledge of operating systems, Microsoft Servers, Active Directory, and network protocols and technologies

5. Core Competencies:

  • Attention to detail and accurate documentation
  • Analytical skills to interpret information
  • Ability to work independently and in a team
  • Organizational and prioritization skills under pressure

6. Key Responsibilities & KPIs

Main Responsibilities:

  • Monitoring incident response channels
  • Executing the Information Security Incident Management Process and escalating high-priority issues
  • Tracking and escalating open incidents
  • Producing weekly and quarterly reports for the CISO on incident status and trends

Security Systems Configuration and Management:

  • Daily monitoring of security systems to ensure proper functioning
  • Configuration and management of security tools such as vulnerability, privileged access, and log management systems
  • Reconciliation of assets to ensure coverage of security systems
  • Reporting and issue resolution support for operational teams

Patch Management Monitoring:

  • Monitoring patch management performance and identifying risks
  • Addressing challenges to compliance

Threat and Event Monitoring:

  • Detecting and escalating security threats and events

Vulnerability Management:

  • Monitoring vulnerabilities daily
  • Monthly asset reconciliation
  • Managing vulnerability remediation with owners
  • Supporting penetration testing activities

Supporting NITSO projects and other initiatives as required.

#J-18808-Ljbffr
This advertiser has chosen not to accept applicants from your region.

Information Security Officer

EFT Corp.

Posted 5 days ago

Job Viewed

Tap Again To Close

Job Description

workfromhome

Please select a reason for contacting us* I want to enquire about your services Other

What is your role in your organisation

What is your desired timeframe for the project to go live?

In which region(s) do you plan to offer your product/solution?

What are you interested in?

How did you find out about us?

I accept Terms and Conditions

I would like to receive EFT Corporation News and Updates

Thank you! Your submission has been received!

Oops! Something went wrong while submitting the form.

At EFT Corporation, success starts with people. Our team of 290+ professionals works across the United Kingdom, South Africa, Zambia, Ghana, Kenya, Mauritius, Zimbabwe, and India, bringing together deep local knowledge and shared ambition.With over 25 years of experience, we partner with more than 100 financial institutions to deliver secure, modern payment solutions that improve access and make everyday transactions easier. We're building the future of payments through smart technology, strong partnerships, and a clear focus on progress.

Why You'll Love Working Here:
  • Career Development: We invest in your future by providing continuous learning, mentorship, and growth opportunities.
  • Work-Life Balance: We support flexible work arrangements and wellness programs to ensure you can thrive both professionally and personally.
  • Impact-Driven Work: Be part of a company driving innovation and transforming financial services across Africa.
  • Diversity, Equity & Inclusion Commitment: Be part of a workplace where everyone feels valued and appreciated
Your Role
  • As an Information Security Officer , your job purpose is to be held accountable in respect to assisting the Senior Security and Infrastructure Engineer and the Senior DevOps Engineers in the following:
    • Assisting in maintaining the safety and security of the organisation’s systems and network database to prevent unauthorized access and avoid data breaches.
    • Maintaining the organisation’s systems and networks.
    • Assisting in overseeing the entire software development process, from planning and development to deployment and maintenance.
    • This role requires expertise in both software development and operations, as well as an understanding of the DevOps methodology.
    • This includes CI/CD, Infrastructure management (AWS), Automation, Monitoring, logging and metrics, Collaboration and Security.
    • The role also requires a significant focus on PCI compliance and support and collaboration with the Security and Infrastructure team is required.
  • You will be responsible for owning the Futurex HSM and Thales HSM device management which includes:
    • Yearly Key management/replacement ceremonies.
    • PCI compliance as it relates to the HSM.
  • Assisting with new security compliance:
    • ISO27001.
    • PCI+PIN.
What You’ll Do Maintain Operational Systems, Networks and Security:
  • Facilitate annual PCI audits.
  • Linux Operating systems are security patched in a timely manner. If patching will affect customers, arrange with operations support, and follow the correct change control process.
  • Maintain Elastic SIEM.
  • Respond to and investigate SIEM alerts.
  • Respond to operational system alerts and/or operational queries across the entire technology stack (Production and QA system issues, infrastructure issues, Databaseissues, Network issues, Security and Firewall issues and any 3rd party or customer integration issues) as they occur.
  • Manage / Deploy system tooling that may be beneficial to the business.
  • Research, POC and deploy new open source or when applicable closed source tooling that is beneficial to the business systems or processes. This can be in supporting Applications, Monitoring, Logging, SIEM, AI/machine Learning, Fraud Detection, Operational Support applications, Authentication systems, BI / Data Analytics, networks, Security or compliance.
  • Create ad hoc Python scripts / Applications to perform various repetitive tasks.
  • Ensure that AWS environments and services are architectured and configured in a secure and redundant manner including all security services from AWS.
  • Maintain AWS services including but not limited to: VPC, EC2, ECS, ECS Fargate, ECR, Guard Duty, Cloudwatch, Cloudtrail, Security groups, VPC Routing, Site to Site VPNs, Application Load balancers / network load balancers, Web application firewalls,etc.
  • Architect, support and maintain connectivity between 3rd parties, Banking partners, integrators and on prem datacentres.
  • Ensure best practice security measures are implemented.
  • Ensure best practices regarding system isolation and scope reduction.
  • Provide support to field engineers on HSMs and key management.
  • Maintain internal HSMs and key management procedures.
  • Provide support to the product and SLDC teams – this includes consulting on design, finding compliant solutions for customer issues, and filling out cyber risk assessments for customers or tenders.
Regulatory Compliance:
  • Maintain/Improve (PC14) PCI.
  • GDPR.
  • Ensure Security, Infrastructure & Procedures (with supporting team) are comprehensive and kept up to date.Security Tooling:
  • Ensure SSO, Intrusion detection, SIEM, Antivirus, Patch Management and PGP are implanted as per the polices.
  • Stimulation / adoption of user-driven security culture (give security a brand within the org and educate).
Automation:
  • To increase efficiency and reduce errors for both security and infrastructure management.
  • To reduce costs (optimize) without sacrificing performance and security.
Perform Security Activities & Reporting:
  • Ensure that weekly vulnerability scans results are tracked, and vulnerabilities are remediated within set severity timeframes weekly.
  • Review all daily and weekly BAU PCI Items for signoff monthly.
  • Ensure weekly Internal and External Scans were completed.
  • Perform data analysis reporting monthly.
  • Maintain a strong security posture within the card holder environment.
  • Work with 3rd party to ensure PCI Certification Audit is completed and passed on time.
  • Review Security Commitment to third parties.
What We’re Looking For Qualification & Experience:
  • Bachelor’s degree in Computer Science or related field.
  • 3 years’ relevant experience.
  • Experience within the payment / banking sector.
  • Experience working with PCI Audits / Security in DevOps, Linux, Mysql, Cloud (AWS).
  • Network experience (particularly cloud based / virtual).
Skills & Knowledge Required:
  • PCI Audits / Security / Processes.
  • Linux, Mysql, and Cloud (AWS).
  • Experience with automation tools like CloudFormation, Ansible, Puppet, Chef, etc.
  • Cloud knowledge, specifically AWS.
  • Logging Frameworks: ELK stack, cloudwatch, etc.
  • Monitoring and Alerting Framework: Zabbix, Nagios, etc.
Personal Attributes:
  • Ability to learn new technologies at pace.
  • Problem solving.
  • Ability to work within a high stress & flux environment.
  • Ability to foster & cultivate relationships with internal & external stakeholders.
  • Ability to work autonomously as well as part of a team.
  • Assertiveness – communicating feelings and beliefs; being non-offensive.
  • Detail & deadline oriented.
  • Analytical & critical thinking.
  • Celebrate Your Special Day: Enjoy a dedicated day off to celebrate your birthday.
  • Wellbeing Matters: Maintain a healthy work-life balance with up to 3 days of wellbeing leave annually.
  • Family Comes First: Support your loved ones when it matters most with up to 20 days of family responsibility leave.
Our Values
  • Empowerment
    We trust our team to lead, make decisions, and drive outcomes.
  • Financial Inclusion for All
    We build payment solutions that broaden access and support diversity.
  • Technology with Purpose
    We design tech that simplifies and improves every transaction.
  • Customer-Centric
    Our customers are at the heart of everything we do.

Join EFTCorporation and help shape simpler, more inclusive payments for millions across Africa.

Ready to make your mark? Apply Now

EFT Corporation is an Equal Opportunity Employer. Diversity drives our success, and we welcome passionate individuals from all walks of life to join our team.

EFT Corporation does not accept unsolicited resumes from search firms/recruiters. EFT Corporation will not pay any fees to search firms/recruiters if a search firm/recruiter submits a candidate unless an agreement has been entered into concerning the specific open position(s). Search firms/recruiters offering resumes to EFT Corporation on an unsolicited basis shall be deemed to accept this condition, regardless of any other provision to the contrary.

Thank you! Your submission has been received!

Oops! Something went wrong while submitting the form.

#J-18808-Ljbffr
This advertiser has chosen not to accept applicants from your region.

Information Security Architect

Johannesburg, Gauteng InfyStrat

Posted 14 days ago

Job Viewed

Tap Again To Close

Job Description

Job title: Information Security Architect

Contract duration: Start with 6 months

First preference: EEE candidates

Location: JHB

The Head of Security Architecture for the organization is responsible for designing, implementing, and maintaining robust security architectures that protect sensitive data in compliance with regulations such as POPIA, GDPR. This role is critical in safeguarding the confidentiality, integrity, and availability of electronic health records (EHR), patient and employee information, medical devices, and cloud-based healthcare services. The role will focus on designing and developing security architecture that aligns business and corporate security strategy. The role will collaboratively direct Security Architects, IT, and Engineers to design and build security controls and solutions compliant with approved enterprise architecture frameworks and standards across business and digital.

Key Responsibilities:

  • Design and develop complex and comprehensive security architectures for our systems, applications, and infrastructure, considering both current and future needs.
  • Collaborates with stakeholders, including developers, engineers, and project managers, to integrate security requirements into the system design and development lifecycle.
  • Provides guidance and expertise in secure coding practices, network security, identity and access management, data protection, and other security domains.
  • Model threats and risks, designing the controls necessary to mitigate them, on both an organizational and technical level – thinking like an attacker, understanding and anticipating the moves and tactics that a hacker might use to attack systems.
  • Follow the architecture analysis process, which consists of research, validation, and evaluation of all new initiatives, with phase gate reviews presented to all stakeholders during key forums, including current trends such as AI and LLMS.
  • Evaluates and selects security technologies, tools, and frameworks to support the organization’s security.
  • Define portfolio vision and reusable security patterns aligned with the EA strategy.
  • Lead architecture reviews for high-risk projects, driving recommendations to resolution.
  • Advise on security controls for hybrid and cloud platforms, balancing usability, cost, and compliance.
  • Defines and applies security policies, standards, and procedures to ensure compliance with industry regulations and best practices.
  • Leads incident response activities, including identification, containment, eradication, and recovery, in coordination with the incident response team.
  • Experience with Cloud Security platform vendors and technologies such as Azure and AWS.
  • Manage security architects and mentor engineers, developers, and vendors.

What will you bring?

  • Risk-based decision-making - expert in ISO 27001 / NIST / CIS controls, able to quantify and articulate risk, then select proportionate, cost-effective controls.
  • Pen-testing & threat-modelling - scoping, overseeing, and translating results into enforceable patterns and backlog items.
  • Influential communication - proven ability to engage C-suite and delivery stakeholders alike, adapting style to gain agreement and drive secure-by-design culture.
  • Teamwork and Energy – work across different functional and business teams with effective collaboration.
  • Technical depth - hands-on knowledge of cloud security, IAM, container & API security, network segmentation, encryption, and DevSecOps toolchains; capable of explaining the exploitability of complex vulnerabilities. Zero trust design thinking.
  • Mentoring & governance - experience in line-managing or coaching security architects/engineers and running architecture assurance or design-review boards.
  • Secure-system design leadership - demonstrable track record creating or validating architectures for large-scale, high-risk services using recognised frameworks (SABSA, TOGAF).

Requirements / Skills and Competence

  • Tertiary qualification in Computer Science, Engineering, or related field (preferred)
  • Minimum of 5-10 years of experience in Security Architecture.
  • CISSP, CISA, CISM, or other relevant security-related designation(s) preferred.
  • Certifications in CISSP-ISSAP, TOGAF, or SABSA, cloud architecture (Microsoft, AWS, GCP)
  • Experience in identifying gaps in existing architectures.
  • Understanding of security infrastructure in Public and Private Cloud, e.g., virtual network infrastructure, hybrid IaaS/PaaS/SaaS solutions.
  • Experience in designing security architectures to mitigate threats and sound knowledge of security strategies and technologies.
  • Direct the Project and Security teams with the guidance to build policies, standards, risks, and controls frameworks supporting operational requirements for the business.
  • Good experience in security architecture design in Cloud and on-prem.
  • Design and implementation of IOT, endpoint protection, and secure IAM.
  • Understanding of authentication and authorisation technologies (SAML, LDAP, PKI, etc.) and other IAM technologies
  • Understanding of the implementation, operation, and maintenance of SIEM, boundary protection technologies (firewalls, mail gateways), Antivirus, and AD security products
  • Knowledge of web application architectures and threat modelling.
#J-18808-Ljbffr
This advertiser has chosen not to accept applicants from your region.

Information Security Consultant

Cape Town, Western Cape iLaunch (Pty) Ltd

Posted 20 days ago

Job Viewed

Tap Again To Close

Job Description

Job Description

Our client, a leading financial services firm, is seeking an Information Security Consultant to join their team on a permanent basis.

Responsibilities
  • Security Auditing
  • Responsible for Security tools monitoring
  • Network experience (TCP/IP, Firewalls, IPS, NAC)
  • Operating System management and Hardening
  • Anti-Virus System management and Configuration
  • Logical Access Management
  • Vulnerability Management
Minimum Requirements
  • Matric and an Information Technology diploma or degree qualification
  • 4+ years experience in the field
Package & Remuneration

Salary: Market Related

#J-18808-Ljbffr
This advertiser has chosen not to accept applicants from your region.

Information security officer

New
EFT Corp.

Posted today

Job Viewed

Tap Again To Close

Job Description

permanent
Please select a reason for contacting us* I want to enquire about your services Other What is your role in your organisation What is your desired timeframe for the project to go live? In which region(s) do you plan to offer your product/solution? What are you interested in? How did you find out about us? I accept Terms and Conditions I would like to receive EFT Corporation News and Updates Thank you! Your submission has been received! Oops! Something went wrong while submitting the form. At EFT Corporation, success starts with people. Our team of 290+ professionals works across the United Kingdom, South Africa, Zambia, Ghana, Kenya, Mauritius, Zimbabwe, and India, bringing together deep local knowledge and shared ambition. With over 25 years of experience, we partner with more than 100 financial institutions to deliver secure, modern payment solutions that improve access and make everyday transactions easier. We're building the future of payments through smart technology, strong partnerships, and a clear focus on progress. Why You'll Love Working Here: Career Development: We invest in your future by providing continuous learning, mentorship, and growth opportunities. Work-Life Balance: We support flexible work arrangements and wellness programs to ensure you can thrive both professionally and personally. Impact-Driven Work: Be part of a company driving innovation and transforming financial services across Africa. Diversity, Equity & Inclusion Commitment: Be part of a workplace where everyone feels valued and appreciated Your Role As an Information Security Officer , your job purpose is to be held accountable in respect to assisting the Senior Security and Infrastructure Engineer and the Senior Dev Ops Engineers in the following:Assisting in maintaining the safety and security of the organisation’s systems and network database to prevent unauthorized access and avoid data breaches. Maintaining the organisation’s systems and networks. Assisting in overseeing the entire software development process, from planning and development to deployment and maintenance. This role requires expertise in both software development and operations, as well as an understanding of the Dev Ops methodology. This includes CI/CD, Infrastructure management (AWS), Automation, Monitoring, logging and metrics, Collaboration and Security. The role also requires a significant focus on PCI compliance and support and collaboration with the Security and Infrastructure team is required. You will be responsible for owning the Futurex HSM and Thales HSM device management which includes:Yearly Key management/replacement ceremonies. PCI compliance as it relates to the HSM. Assisting with new security compliance:ISO27001. PCI+PIN. What You’ll Do Maintain Operational Systems, Networks and Security: Facilitate annual PCI audits. Linux Operating systems are security patched in a timely manner. If patching will affect customers, arrange with operations support, and follow the correct change control process. Maintain Elastic SIEM. Respond to and investigate SIEM alerts. Respond to operational system alerts and/or operational queries across the entire technology stack (Production and QA system issues, infrastructure issues, Databaseissues, Network issues, Security and Firewall issues and any 3rd party or customer integration issues) as they occur. Manage / Deploy system tooling that may be beneficial to the business. Research, POC and deploy new open source or when applicable closed source tooling that is beneficial to the business systems or processes. This can be in supporting Applications, Monitoring, Logging, SIEM, AI/machine Learning, Fraud Detection, Operational Support applications, Authentication systems, BI / Data Analytics, networks, Security or compliance. Create ad hoc Python scripts / Applications to perform various repetitive tasks. Ensure that AWS environments and services are architectured and configured in a secure and redundant manner including all security services from AWS. Maintain AWS services including but not limited to: VPC, EC2, ECS, ECS Fargate, ECR, Guard Duty, Cloudwatch, Cloudtrail, Security groups, VPC Routing, Site to Site VPNs, Application Load balancers / network load balancers, Web application firewalls,etc. Architect, support and maintain connectivity between 3rd parties, Banking partners, integrators and on prem datacentres. Ensure best practice security measures are implemented. Ensure best practices regarding system isolation and scope reduction. Provide support to field engineers on HSMs and key management. Maintain internal HSMs and key management procedures. Provide support to the product and SLDC teams – this includes consulting on design, finding compliant solutions for customer issues, and filling out cyber risk assessments for customers or tenders. Regulatory Compliance: Maintain/Improve (PC14) PCI. GDPR. Ensure Security, Infrastructure & Procedures (with supporting team) are comprehensive and kept up to date.Security Tooling: Ensure SSO, Intrusion detection, SIEM, Antivirus, Patch Management and PGP are implanted as per the polices. Stimulation / adoption of user-driven security culture (give security a brand within the org and educate). Automation: To increase efficiency and reduce errors for both security and infrastructure management. To reduce costs (optimize) without sacrificing performance and security. Perform Security Activities & Reporting: Ensure that weekly vulnerability scans results are tracked, and vulnerabilities are remediated within set severity timeframes weekly. Review all daily and weekly BAU PCI Items for signoff monthly. Ensure weekly Internal and External Scans were completed. Perform data analysis reporting monthly. Maintain a strong security posture within the card holder environment. Work with 3rd party to ensure PCI Certification Audit is completed and passed on time. Review Security Commitment to third parties. What We’re Looking For Qualification & Experience: Bachelor’s degree in Computer Science or related field. 3 years’ relevant experience. Experience within the payment / banking sector. Experience working with PCI Audits / Security in Dev Ops, Linux, Mysql, Cloud (AWS). Network experience (particularly cloud based / virtual). Skills & Knowledge Required: PCI Audits / Security / Processes. Linux, Mysql, and Cloud (AWS). Experience with automation tools like Cloud Formation, Ansible, Puppet, Chef, etc. Cloud knowledge, specifically AWS. Logging Frameworks: ELK stack, cloudwatch, etc. Monitoring and Alerting Framework: Zabbix, Nagios, etc. Personal Attributes: Ability to learn new technologies at pace. Problem solving. Ability to work within a high stress & flux environment. Ability to foster & cultivate relationships with internal & external stakeholders. Ability to work autonomously as well as part of a team. Assertiveness – communicating feelings and beliefs; being non-offensive. Detail & deadline oriented. Analytical & critical thinking. Celebrate Your Special Day: Enjoy a dedicated day off to celebrate your birthday. Wellbeing Matters: Maintain a healthy work-life balance with up to 3 days of wellbeing leave annually. Family Comes First: Support your loved ones when it matters most with up to 20 days of family responsibility leave. Our Values Empowerment We trust our team to lead, make decisions, and drive outcomes. Financial Inclusion for All We build payment solutions that broaden access and support diversity. Technology with Purpose We design tech that simplifies and improves every transaction. Customer-Centric Our customers are at the heart of everything we do. Join EFTCorporation and help shape simpler, more inclusive payments for millions across Africa.Ready to make your mark? Apply Now EFT Corporation is an Equal Opportunity Employer. Diversity drives our success, and we welcome passionate individuals from all walks of life to join our team.EFT Corporation does not accept unsolicited resumes from search firms/recruiters. EFT Corporation will not pay any fees to search firms/recruiters if a search firm/recruiter submits a candidate unless an agreement has been entered into concerning the specific open position(s). Search firms/recruiters offering resumes to EFT Corporation on an unsolicited basis shall be deemed to accept this condition, regardless of any other provision to the contrary. Thank you! Your submission has been received! Oops! Something went wrong while submitting the form. #J-18808-Ljbffr
This advertiser has chosen not to accept applicants from your region.

Information security consultant

New
Cape Town, Western Cape ILaunch

Posted today

Job Viewed

Tap Again To Close

Job Description

permanent
Job Description Our client, a leading financial services firm, is seeking an Information Security Consultant to join their team on a permanent basis. Responsibilities Security Auditing Responsible for Security tools monitoring Network experience (TCP/IP, Firewalls, IPS, NAC) Operating System management and Hardening Anti-Virus System management and Configuration Logical Access Management Vulnerability Management Minimum Requirements Matric and an Information Technology diploma or degree qualification 4+ years experience in the field Package & Remuneration Salary: Market Related #J-18808-Ljbffr
This advertiser has chosen not to accept applicants from your region.
Be The First To Know

About the latest Cyber risk management Jobs in South Africa !

Information security consultant

Cape Town, Western Cape ILaunch

Posted today

Job Viewed

Tap Again To Close

Job Description

permanent
Job Description Our client, a leading financial services firm, is seeking an Information Security Consultant to join their team on a permanent basis. Responsibilities Security Auditing Responsible for Security tools monitoring Network experience (TCP/IP, Firewalls, IPS, NAC) Operating System management and Hardening Anti-Virus System management and Configuration Logical Access Management Vulnerability Management Minimum Requirements Matric and an Information Technology diploma or degree qualification 4+ years experience in the field Package & Remuneration Salary: Market Related #J-18808-Ljbffr
This advertiser has chosen not to accept applicants from your region.

Information security architect

Johannesburg, Gauteng InfyStrat

Posted today

Job Viewed

Tap Again To Close

Job Description

permanent
Job title: Information Security Architect Contract duration: Start with 6 months First preference: EEE candidates Location: JHB The Head of Security Architecture for the organization is responsible for designing, implementing, and maintaining robust security architectures that protect sensitive data in compliance with regulations such as POPIA, GDPR. This role is critical in safeguarding the confidentiality, integrity, and availability of electronic health records (EHR), patient and employee information, medical devices, and cloud-based healthcare services. The role will focus on designing and developing security architecture that aligns business and corporate security strategy. The role will collaboratively direct Security Architects, IT, and Engineers to design and build security controls and solutions compliant with approved enterprise architecture frameworks and standards across business and digital. Key Responsibilities: Design and develop complex and comprehensive security architectures for our systems, applications, and infrastructure, considering both current and future needs. Collaborates with stakeholders, including developers, engineers, and project managers, to integrate security requirements into the system design and development lifecycle. Provides guidance and expertise in secure coding practices, network security, identity and access management, data protection, and other security domains. Model threats and risks, designing the controls necessary to mitigate them, on both an organizational and technical level – thinking like an attacker, understanding and anticipating the moves and tactics that a hacker might use to attack systems. Follow the architecture analysis process, which consists of research, validation, and evaluation of all new initiatives, with phase gate reviews presented to all stakeholders during key forums, including current trends such as AI and LLMS. Evaluates and selects security technologies, tools, and frameworks to support the organization’s security. Define portfolio vision and reusable security patterns aligned with the EA strategy. Lead architecture reviews for high-risk projects, driving recommendations to resolution. Advise on security controls for hybrid and cloud platforms, balancing usability, cost, and compliance. Defines and applies security policies, standards, and procedures to ensure compliance with industry regulations and best practices. Leads incident response activities, including identification, containment, eradication, and recovery, in coordination with the incident response team. Experience with Cloud Security platform vendors and technologies such as Azure and AWS. Manage security architects and mentor engineers, developers, and vendors. What will you bring? Risk-based decision-making - expert in ISO 27001 / NIST / CIS controls, able to quantify and articulate risk, then select proportionate, cost-effective controls. Pen-testing & threat-modelling - scoping, overseeing, and translating results into enforceable patterns and backlog items. Influential communication - proven ability to engage C-suite and delivery stakeholders alike, adapting style to gain agreement and drive secure-by-design culture. Teamwork and Energy – work across different functional and business teams with effective collaboration. Technical depth - hands-on knowledge of cloud security, IAM, container & API security, network segmentation, encryption, and Dev Sec Ops toolchains; capable of explaining the exploitability of complex vulnerabilities. Zero trust design thinking. Mentoring & governance - experience in line-managing or coaching security architects/engineers and running architecture assurance or design-review boards. Secure-system design leadership - demonstrable track record creating or validating architectures for large-scale, high-risk services using recognised frameworks (SABSA, TOGAF). Requirements / Skills and Competence Tertiary qualification in Computer Science, Engineering, or related field (preferred) Minimum of 5-10 years of experience in Security Architecture. CISSP, CISA, CISM, or other relevant security-related designation(s) preferred. Certifications in CISSP-ISSAP, TOGAF, or SABSA, cloud architecture (Microsoft, AWS, GCP) Experience in identifying gaps in existing architectures. Understanding of security infrastructure in Public and Private Cloud, e.g., virtual network infrastructure, hybrid Iaa S/Paa S/Saa S solutions. Experience in designing security architectures to mitigate threats and sound knowledge of security strategies and technologies. Direct the Project and Security teams with the guidance to build policies, standards, risks, and controls frameworks supporting operational requirements for the business. Good experience in security architecture design in Cloud and on-prem. Design and implementation of IOT, endpoint protection, and secure IAM. Understanding of authentication and authorisation technologies (SAML, LDAP, PKI, etc.) and other IAM technologies Understanding of the implementation, operation, and maintenance of SIEM, boundary protection technologies (firewalls, mail gateways), Antivirus, and AD security products Knowledge of web application architectures and threat modelling. #J-18808-Ljbffr
This advertiser has chosen not to accept applicants from your region.

Officer, Information Security ( ISO)

Johannesburg, Gauteng Standard Bank Group

Posted today

Job Viewed

Tap Again To Close

Job Description

Company Description

Standard Bank Group is a leading Africa-focused financial services group and an innovative player on the global stage. We offer a variety of career-enhancing opportunities and the chance to work alongside some of the sector’s most talented, motivated professionals. Our clients range from individuals to businesses of all sizes, high net worth families, and large multinational corporates and institutions. We are passionate about creating growth in Africa, bringing true, meaningful value to our clients and communities, and creating a sense of purpose for our employees.

Job Description

To implement the Group Cyber Resilience strategy by securing platform ecosystems, third-party integrations, and protecting sensitive data, applications, and infrastructure from infiltration or misuse. Guide security capabilities in client segments and solutions. Facilitate security services ensuring policies, standards, and controls are embedded to prevent reputational, financial, or other losses and ensure regulatory compliance. Educate employees about their InfoSec responsibilities.

Qualifications
  • A Degree in Business, Commerce, Information Technology, or Risk Management.
Experience Required
  • 5-7 years experience in an information security or audit role within the banking and/or financial services sector. Experience working in a multi-vendor, outsourced, and multi-system IT environment.
  • 5-7 years of good working knowledge and experience with the implementation and management of information security policies and frameworks within a corporate environment. Management experience working with individuals and teams from diverse cultures.
  • 5-7 years of strong IT understanding, gaining insight into digital and platform operating models, cybersecurity trends, and solutions.
Additional Information Behavioral Competencies
  • Adopting Practical Approaches
  • Articulating Information
  • Checking Things
  • Directing People
  • Examining Information
  • Exploring Possibilities
  • Interpreting Data
  • Making Decisions
  • Providing Insights
  • Pursuing Goals
  • Showing Composure
  • Upholding Standards
Technical Competencies
  • Benefits Management
  • Information Security
  • Internal & External IT Environment
  • IT Risk Management
  • Knowledge of Banking & Financial Services
  • Stakeholder Management (IT)
#J-18808-Ljbffr
This advertiser has chosen not to accept applicants from your region.
 

Nearby Locations

Other Jobs Near Me

Industry

  1. request_quote Accounting
  2. work Administrative
  3. eco Agriculture Forestry
  4. smart_toy AI & Emerging Technologies
  5. school Apprenticeships & Trainee
  6. apartment Architecture
  7. palette Arts & Entertainment
  8. directions_car Automotive
  9. flight_takeoff Aviation
  10. account_balance Banking & Finance
  11. local_florist Beauty & Wellness
  12. restaurant Catering
  13. volunteer_activism Charity & Voluntary
  14. science Chemical Engineering
  15. child_friendly Childcare
  16. foundation Civil Engineering
  17. clean_hands Cleaning & Sanitation
  18. diversity_3 Community & Social Care
  19. construction Construction
  20. brush Creative & Digital
  21. currency_bitcoin Crypto & Blockchain
  22. support_agent Customer Service & Helpdesk
  23. medical_services Dental
  24. medical_services Driving & Transport
  25. medical_services E Commerce & Social Media
  26. school Education & Teaching
  27. electrical_services Electrical Engineering
  28. bolt Energy
  29. local_mall Fmcg
  30. gavel Government & Non Profit
  31. emoji_events Graduate
  32. health_and_safety Healthcare
  33. beach_access Hospitality & Tourism
  34. groups Human Resources
  35. precision_manufacturing Industrial Engineering
  36. security Information Security
  37. handyman Installation & Maintenance
  38. policy Insurance
  39. code IT & Software
  40. gavel Legal
  41. sports_soccer Leisure & Sports
  42. inventory_2 Logistics & Warehousing
  43. supervisor_account Management
  44. supervisor_account Management Consultancy
  45. supervisor_account Manufacturing & Production
  46. campaign Marketing
  47. build Mechanical Engineering
  48. perm_media Media & PR
  49. local_hospital Medical
  50. local_hospital Military & Public Safety
  51. local_hospital Mining
  52. medical_services Nursing
  53. local_gas_station Oil & Gas
  54. biotech Pharmaceutical
  55. checklist_rtl Project Management
  56. shopping_bag Purchasing
  57. home_work Real Estate
  58. person_search Recruitment Consultancy
  59. store Retail
  60. point_of_sale Sales
  61. science Scientific Research & Development
  62. wifi Telecoms
  63. psychology Therapy
  64. pets Veterinary
View All Cyber Risk Management Jobs