42 Security Audit jobs in South Africa
Senior Manager: Information Systems Audit (Cyber Security)
Posted 1 day ago
Job Viewed
Job Description
Requirement Review
Manage the effective and timeous cybersecurity audits of public sector Information Technology (IT) systems, thereby ensuring a service is provided to the people of South Africa in terms of relevant laws and regulations.
Implement the business unit’s strategic objectives by managing a portfolio of audits through the effective and efficient allocation of resources, management, stakeholder management and coordination of people to perform quality, effective and timely audits.
Roles and Responsibilities
Strategic Function
- Provide input into the strategic objectives to assist in establishing the strategic direction of the Business Unit (BU).
- Facilitate the implementation of the Business Unit and Specialised Audit Solutions (SAS) strategic plans in accordance with policies, procedures and legislation.
- Manage teams to ensure alignment to the vision, mission, strategic goals and values of the Auditor-General of South Africa (AGSA or Auditor-General)
- Provide feedback on implementation / achievement of strategic objectives to the relevant stakeholders
Strategic Leadership & Innovation
- Ensure the effective execution of cybersecurity audits
- Drive innovation, efficiency, and effectiveness in the cyber audit space.
- Identifying emerging risks, leveraging new audit techniques, and enhancing audit methodologies to strengthen the AGSA’s cybersecurity assurance.
Thought Leadership & Brand Building
- Key driver in positioning AGSA as a cybersecurity audit leader, both locally and internationally.
- Contribute in knowledge-sharing platforms, engage at all levels
- Collaborate with INTOSAI and other key stakeholders to shape the future of cybersecurity audit excellence.
Product Management
Manage Audits
-Lead, direct and coordinate portfolio of audits covering the three audit phases:
- Planning
- Execution
- Reporting
-Liaise with auditees in the provision of advice / recommendations, setting up meetings, etc
-Initiate and lead meetings with the audit team regarding the direction and progress on the audits
-Provide guidance to managers an assistance on audit related matters
-Ensure that all risks are addressed for the specific audit engagements, for example:
- Appointment of specialist staff
- Contract in and out
-Conduct audit team visits to:
- Review work
- Finalise the audit
- Conclude working papers
- Prepare audit report
- Attend meetings with the team and auditees
-Provide motivation talks and training on auditing matters to team members
-Engage with contracted out partners
-Project manage all projects to ensure timeous delivery on milestones and quality of delivery is met
-Perform functions as required by an engagement manager as spelled out in the ISA’s and the Auditor-General policies
-Prepare and take responsibility for presentations
-Report back to the audit steering committees and audit committees on the planning, execution and reporting of the audits
-Manage audits within the allocated time frame
-Manage audits in accordance with policies, procedures and legislation
Stakeholder Management
- Ensure clear understanding of auditees’ business requirements through efficient stakeholder engagement and that this is translated into clear deliverables.
- Build collaborative relationships with internal and external stakeholders.
- Liaise and interact with key stakeholders & management to share information, resolve challenges and make recommendations for improvements.
- Manage and report on stakeholder engagements.
- Promote the AGSA brand and reputation.
Participate in Business Unit Leader/Deputy Business Unit Leader Discussions
-Inform the Business Unit Leader and/or the Deputy Business Unit Leader on:
- Issues arising from audits
- Focus areas for auditing administration matters
- Financial issues
- Compliance concerns
- People and resourcing matters
Manage Internal Stakeholder Relationships:
- Engage with regularity audit on audit proceedings.
- Facilitate debriefing sessions with regularity audit on the previous year’s audits performed
- Engage with the team during the three audit phases (namely planning, execution and reporting)
- Communicate with the team on non-audit and strategic matters
- Liaise with colleagues within the BU
- Liaise with colleagues within the portfolio
Manage External Relationships:
- Engage regularly with the management of the auditee on audit proceedings
- Engage with audit firms regarding contracted out audits
- Participate in audit and steering committee meetings
- Attend Standing Committee on Public Accounts (SCOPA) and portfolio committee meetings by invitation
- Engage with prospective employees
People Management
-Implement the activities outlined on the BU People Plan.
-Manage team performance to drive productivity.
-Contribute to transformation/culture plans.
-Motivate, coach and mentor staff to ensure maximum productivity and development of the staff to their full potential.
-Participate in initiatives to attract talent.
-Contribute to effective administration of the BU training office.
-Cascade strategic organisational alignment messages and commitments.
-Implement relevant centre initiatives to bring about an inclusive culture, enhanced employee experience and employee well-being
-Analyse the business plan to determine the applicable deliverables and targets
-Determine and secure the human resource requirements to ensure that deliverables will be met in accordance with the expected targets
-Manage the staff performance evaluation system for the centre:
- Compile Individual Performance Contracts (IPC)’s and Performance Development Plans (PDP)’s
- Conduct coaching sessions to ensure staff member/s perform at the optimum level
- Conduct performance reviews in accordance with policies and procedures and take corrective action where necessary
- Conduct one-on-one sessions
- Participate in the talent management of the Business Unit to drive a high performance culture in accordance with the AGSA’s roles and responsibilities and competency framework
-Manage the development of staff and ensure each staff member has a Personal Development Plan
-Approve leave, timesheets, subsistence and travel (S&T) and cash advances
-Act as a champion on one of the five strategic goals of the business unit (value add, visibility with impact, viability and visions and values) to ensure that the Business Unit achieves its objectives:
- Provide feedback at the monthly senior management meeting
-Manage the centre’s resources (staff, Contract Work Contractors (CWC) and funding):
- Participate in meetings
- Provide direction and guidance to achieve a timely high quality product
- Develop the staff to optimum productivity levels
- Improve on client relations within the overall business processes captured in the Business Scorecard (BSC)
-Manage Human Resources in accordance with policies, procedures and legal requirements
-Complete Human Resource Management actions within the allocated time frames
Financial management and operational management
- Responsible for compiling the centre budget.
- Manage the centre budget, income and cost to ensure adherence to the required financial performance standards for the portfolio
- Manage debtor’s collection.
- Ensure compliance with internal processes and procedures
- Manage supply chain processes and other adhoc financial requests.
Other responsibilities (Applicable to All JD’s)
- Perform and/or manage other projects, tasks and assignments not stipulated on the Job description as and when required.
Monitor Information
- Track the following to gather and monitor the centre:
- Audits (Own and CWC)
- Stakeholder engagements
- Funding (income and expenditure)
- IPC’s
- HR/Culture Initiatives
- Balanced Scorecard Initiatives
- BU Initiatives
- Compliance matters (internal control)
Skills, Experience and Education
Formal Education
- Minimum qualification of National Qualifications Framework (NQF) Level 7 (i.e. 4 year Bachelor’s Degree / post graduate Diploma) e.g. B Com with specialisation in Auditing and/or Information Technology
- Certified Information Systems Auditor (CISA) or equivalent (e.g. a recognised IT auditing certification)
AND
At least one of the following:
- Offensive Security Certified Professional (OSCP) or equivalent (e.g. CEH)
- Certified Incident Handler (ECIH/ GCIH) or equivalent (e.g. CRIA)
Experience
- Minimum of 8 years’ experience post qualification with at least 4 years’ experience operating at a manager/middle management level.
- Extensive experience in managing cybersecurity and network security audits, with a strong understanding of networked environments that support various application hosting infrastructures, including Windows and Unix-based operating systems, as well as MSSQL and Oracle databases.
- Extensive experience in conducting cybersecurity maturity assessments, particularly within the Southern African context. This includes a strong ability to position insights and control recommendations for clients, guided by leading frameworks such as NIST CSF, ISO 27001/2, CIS, and COBIT.
NB: Please note that only shortlisted candidates will be contacted. Should you not hear from us within four weeks, kindly consider your application unsuccessful.
#J-18808-LjbffrInformation Security Engineer
Posted 1 day ago
Job Viewed
Job Description
A Security Engineer is a crucial member of an organization’s IT team, specializing in safeguarding digital assets and maintaining the security posture of the company. They work to design, implement, and manage security measures to protect against cyber threats, unauthorized access, and data breaches.
Key Responsibilities:
Security Infrastructure Design:
- Design and implement security infrastructure, including firewalls, intrusion detection systems, and encryption protocols.
- Evaluate and recommend security products and technologies to enhance the organization’s security posture.
Incident Response and Monitoring:
- Monitor network traffic for suspicious activity and potential security breaches.
- Develop and maintain incident response plans and procedures to mitigate security incidents.
- Investigate security incidents, determine the root cause, and implement corrective actions.
Vulnerability Assessment and Penetration Testing:
- Conduct regular security assessments to identify vulnerabilities in systems and applications.
- Perform penetration tests to simulate cyberattacks and assess the organization’s readiness.
Access Control and Authentication:
- Manage user access controls and authentication mechanisms.
- Implement and maintain multi-factor authentication (MFA) solutions.
Security Policies and Compliance:
- Develop and enforce security policies, standards, and procedures.
- Ensure compliance with industry regulations (e.g., GDPR, HIPAA, PCI DSS) and best practices.
Security Awareness and Training:
- Conduct security awareness programs and training for employees.
- Keep the organization informed about emerging threats and security best practices.
Security Patch Management:
- Manage and coordinate the timely installation of security patches and updates.
- Maintain an inventory of software and hardware assets.
Encryption and Data Protection:
- Implement encryption mechanisms to protect sensitive data at rest and in transit.
- Ensure the confidentiality and integrity of data through encryption and access controls.
Qualifications:
- Bachelor’s degree in computer science, information security, or a related field (or equivalent experience).
- Relevant industry certifications such as Certified Information Systems Security Professional (CISSP), Certified Ethical Hacker (CEH), Certified Information Security Manager (CISM), or equivalent.
- Proven experience in information security roles, including network security, system security, or application security.
- Strong knowledge of security technologies, protocols, and tools.
- Understanding of risk management principles and methodologies.
- Proficiency in scripting and programming languages (e.g., Python, PowerShell) for automation and analysis.
- Familiarity with cloud security concepts (e.g., AWS, Azure, Google Cloud).
- Excellent problem-solving and analytical skills.
- Effective communication and teamwork abilities.
Preferred Skills:
- Experience with security information and event management (SIEM) systems.
- Knowledge of threat intelligence and threat hunting techniques.
- Experience with secure coding practices and application security assessments.
- Familiarity with network and web application firewalls.
- Understanding of security-related regulations and compliance standards.
- Security Engineers typically work in an office environment but may need to respond to security incidents outside regular business hours.
- The role may involve occasional travel to remote offices or data centers.
Security Engineers play a pivotal role in maintaining the confidentiality, integrity, and availability of an organization’s information assets. They are instrumental in protecting against cyber threats and ensuring compliance with industry regulations and security best practices.
#J-18808-LjbffrOfficer, Information Security
Posted 1 day ago
Job Viewed
Job Description
Company Description
Standard Bank Group is a leading Africa-focused financial services group and an innovative player on the global stage. We offer a variety of career-enhancing opportunities and the chance to work alongside talented, motivated professionals. Our clients range from individuals to businesses of all sizes, high net worth families, and large multinational corporates and institutions. We are passionate about creating growth in Africa, bringing meaningful value to our clients and communities, and creating a sense of purpose for our employees.
Job Description
To implement the Group Cyber Resilience strategy by securing platforms, ecosystems, and third-party integrations; protecting sensitive data, applications, and infrastructure from infiltration or misuse; guiding security capabilities in client segments and solutions. Facilitate security services ensuring policies, standards, and controls are embedded to prevent losses and ensure regulatory compliance. Educate employees about their InfoSec responsibilities.
- Alert responsible stakeholders of non-compliance with Cyber Resilience Policies and Standards, and collaborate on remediation plans and solutions.
- Assess information security maturity scores, guide implementation for awareness and prioritization, and monitor compliance with standards.
- Collaborate with feature teams, product owners, architecture, IT, vendors, and other stakeholders to investigate risk controls.
- Work with threat intelligence, cybersecurity, security engineering, and other risk functions to develop and maintain a holistic security strategy and remediation plans.
- Communicate and raise awareness of policies within business, technology, and risk communities.
Qualifications
- Degree in Business, Commerce, Information Technology, or Risk Management (minimum)
- Post Graduate Degree in Business, Commerce, or Information Technology (preferred)
Experience Required: Cyber Security
- 5-7 years in an information security or audit role within banking or financial services. Experience with multi-vendor, outsourced, and multi-system IT environments.
- 5-7 years of knowledge and experience with implementing and managing information security policies and frameworks in a corporate environment. Management experience with diverse teams.
- 5-7 years of strong IT understanding, insights into digital and platform operating models, and current cybersecurity trends and solutions.
Behavioural Competencies:
- Adopting Practical Approaches
- Articulating Information
- Checking Things
- Directing People
- Examining Information
Technical Competencies:
- Benefits Management
- Information Security
- Internal & External IT Environment
- IT Risk Management
- Knowledge of Banking & Financial Services
Information Security Officer
Posted 1 day ago
Job Viewed
Job Description
A highgrowth fintech backed by global investors is building worldclass payment infrastructure across Africa. The company helps global brands succeed in South Africa by reducing payment friction increasing reliability and ensuring regulatory compliance.
Their clients include leading enterprises and globally recognised brands. With scale and security at the heart of their mission theyre shaping how the world does business on the continent.
Role Overview
As the Information Security Officer you will lead the companys information security function as it grows its enterprise and global client base. Youll design and implement fitforpurpose security strategies that support compliance protect data and enable innovation in a fastpaced environment.
Reporting to the VP of Engineering this crossfunctional role supports engineering compliance operations and leadership teams.
Key Responsibilities
- Own and maintain the information security roadmap and risk register
- Implement security policies across infrastructure applications and endpoints
- Support teams in embedding securitybydesign into the SDLC
- Lead compliance audits and assessments (e.g. PCIDSS ISO 27001 SOC 2)
- Coordinate vulnerability assessments penetration testing and risk modelling
- Develop and maintain incident response procedures
- Promote security awareness across the organisation
- Manage internal IT security needs (cloud MDM Google Workspace password policies)
- Support client security reviews and enterprise procurement processes
- Stay informed on relevant threats and regulatory changes
Challenges Youll Tackle
Ideal Candidate Profile
Required Experience :
Unclear Seniority
Key Skills
International Development,Information Systems,Community,Information Technology Sales,Corporate Recruitment
Employment Type : Contract
Experience : years
Vacancy : 1
#J-18808-LjbffrInformation Security Officer
Posted 1 day ago
Job Viewed
Job Description
South Africa
Apply Now and Redefine Digital Payments with Us!
Why EFT Corporation
At EFT Corporation, we don’t just enable payments, we empower possibilities. With over 26 years of experience, we’re Africa’s leading payment solutions provider, working with over 100 financial institutions to deliver cutting-edge technology that drives financial inclusion and transforms lives. Operating in dynamic markets across Africa and beyond, our team of 300+ experts spans Mauritius, Ghana, Kenya, South Africa, Zambia, Zimbabwe, and India. We’re on a mission to shape the future of payments across the continent through innovation, collaboration, and a shared vision of progress.
Why You'll Love Working Here:
- Purpose-Driven Culture : Make an impact in transforming lives through secure and innovative payment solutions.
- Global Collaboration : Work alongside diverse, talented teams from across the globe.
- Continuous Growth : Expand your skills with mentorship, knowledge sharing, and cutting-edge technologies.
- Inclusive Environment : We value and celebrate diversity, fostering a workplace where everyone thrives.
Your Role
- As an Information Security Officer , your job purpose is to be held accountable in respect to assisting the Senior Security and Infrastructure Engineer and the Senior DevOps Engineers in the following:
- Assisting in maintaining the safety and security of the organisation’s systems and network database to prevent unauthorized access and avoid data breaches.
- Maintaining the organisation’s systems and networks.
- Assisting in overseeing the entire software development process, from planning and development to deployment and maintenance.
- This role requires expertise in both software development and operations, as well as an understanding of the DevOps methodology.
- This includes CI/CD, Infrastructure management (AWS), Automation, Monitoring, logging and metrics, Collaboration and Security.
- The role also requires a significant focus on PCI compliance and support and collaboration with the Security and Infrastructure team is required.
- You will be responsible for owning the Futurex HSM and Thales HSM device management which includes:
- Yearly Key management/replacement ceremonies.
- PCI compliance as it relates to the HSM.
- Assisting with new security compliance:
- ISO27001.
- PCI+PIN.
What You’ll Do Maintain Operational Systems, Networks and Security:
- Facilitate annual PCI audits.
- Linux Operating systems are security patched in a timely manner. If patching will affect customers, arrange with operations support, and follow the correct change control process.
- Maintain Elastic SIEM.
- Respond to and investigate SIEM alerts.
- Respond to operational system alerts and/or operational queries across the entire technology stack (Production and QA system issues, infrastructure issues, Databaseissues, Network issues, Security and Firewall issues and any 3rd party or customer integration issues) as they occur.
- Manage / Deploy system tooling that may be beneficial to the business.
- Research, POC and deploy new open source or when applicable closed source tooling that is beneficial to the business systems or processes. This can be in supporting Applications, Monitoring, Logging, SIEM, AI/machine Learning, Fraud Detection, Operational Support applications, Authentication systems, BI / Data Analytics, networks, Security or compliance.
- Create ad hoc Python scripts / Applications to perform various repetitive tasks.
- Ensure that AWS environments and services are architectured and configured in a secure and redundant manner including all security services from AWS.
- Maintain AWS services including but not limited to: VPC, EC2, ECS, ECS Fargate, ECR, Guard Duty, Cloudwatch, Cloudtrail, Security groups, VPC Routing, Site to Site VPNs, Application Load balancers / network load balancers, Web application firewalls,etc.
- Architect, support and maintain connectivity between 3rd parties, Banking partners, integrators and on prem datacentres.
- Ensure best practice security measures are implemented.
- Ensure best practices regarding system isolation and scope reduction.
- Provide support to field engineers on HSMs and key management.
- Maintain internal HSMs and key management procedures.
- Provide support to the product and SLDC teams – this includes consulting on design, finding compliant solutions for customer issues, and filling out cyber risk assessments for customers or tenders.
- Maintain/Improve (PC14) PCI.
- Stretch: ISO 27001.
- GDPR.
- Ensure Security, Infrastructure & Procedures (with supporting team) are comprehensive and kept up to date.Security Tooling:
- Ensure SSO, Intrusion detection, SIEM, Antivirus, Patch Management and PGP are implanted as per the polices.
- Stimulation / adoption of user-driven security culture (give security a brand within the org and educate).
- To increase efficiency and reduce errors for both security and infrastructure management.
- To reduce costs (optimize) without sacrificing performance and security.
- Ensure that weekly vulnerability scans results are tracked, and vulnerabilities are remediated within set severity timeframes weekly.
- Review all daily and weekly BAU PCI Items for signoff monthly.
- Ensure weekly Internal and External Scans were completed.
- Perform data analysis reporting monthly.
- Maintain a strong security posture within the card holder environment.
- Work with 3rd party to ensure PCI Certification Audit is completed and passed on time.
- Review Security Commitment to third parties.
- Bachelor’s degree in Computer Science or related field.
- 3 years’ relevant experience.
- Experience within the payment / banking sector.
- Experience working with PCI Audits / Security in DevOps, Linux, Mysql, Cloud (AWS).
- Network experience (particularly cloud based / virtual).
- PCI Audits / Security / Processes.
- Linux, Mysql, and Cloud (AWS).
- Experience with automation tools like CloudFormation, Ansible, Puppet, Chef, etc.
- CI/CD tooling eg. Bitbucket pipelines, Jenkins, etc.
- Scripting languages: Bash, Python, etc.
- Cloud knowledge, specifically AWS.
- Containerisation: Docker, Kubernetes, AWS ECS, etc.
- Logging Frameworks: ELK stack, cloudwatch, etc.
- Cloud-based virtual networking eg VPC, subnets, ALB, NLB, WAF, Peering, Transit Gateways, VPN gateways, etc.
- SIEM experience – Elastic, Splunk, etc.
- Monitoring and Alerting Framework: Zabbix, Nagios, etc.
- Ability to learn new technologies at pace.
- Problem solving.
- Ability to work within a high stress & flux environment.
- Ability to foster & cultivate relationships with internal & external stakeholders.
- Ability to work autonomously as well as part of a team.
- Assertiveness – communicating feelings and beliefs; being non-offensive.
- Detail & deadline oriented.
- Analytical & critical thinking.
Our Values
- Purposeful Impact : Every action drives meaningful change.
- Client-Centric Excellence : We succeed when our clients do.
- Integrity : Doing the right thing, always.
- Teamwork : Together, we achieve the extraordinary.
Why Now?
Be part of a pioneering force in digital payments, leading transformative projects across continents. At EFT Corporation, you’re not just joining a company—you’re joining a movement.
Ready to redefine the future of payments with us?
Apply now and let’s create the extraordinary together!
EFT Corporation is an Equal Opportunity Employer. Diversity drives our success, and we welcome passionate individuals from all walks of life to join our team.
EFT Corporation does not accept unsolicited resumes from search firms/recruiters. EFT Corporation will not pay any fees to search firms/recruiters if a search firm/recruiter submits a candidate unless an agreement has been entered into concerning the specific open position(s). Search firms/recruiters offering resumes to EFT Corporation on an unsolicited basis shall be deemed to accept this condition, regardless of any other provision to the contrary.
#J-18808-LjbffrInformation Security Architect
Posted 1 day ago
Job Viewed
Job Description
Job title: Information Security Architect
Contract duration: Start with 6 months
First preference: EEE candidates
Location: JHB
The Head of Security Architecture for the organization is responsible for designing, implementing, and maintaining robust security architectures that protect sensitive data in compliance with regulations such as POPIA, GDPR. This role is critical in safeguarding the confidentiality, integrity, and availability of electronic health records (EHR), patient and employee information, medical devices, and cloud-based healthcare services. The role will focus on designing and developing security architecture that aligns business and corporate security strategy. The role will collaboratively direct Security Architects, IT, and Engineers to design and build security controls and solutions compliant with approved enterprise architecture frameworks and standards across business and digital.
Key Responsibilities:
- Design and develop complex and comprehensive security architectures for our systems, applications, and infrastructure, considering both current and future needs.
- Collaborates with stakeholders, including developers, engineers, and project managers, to integrate security requirements into the system design and development lifecycle.
- Provides guidance and expertise in secure coding practices, network security, identity and access management, data protection, and other security domains.
- Model threats and risks, designing the controls necessary to mitigate them, on both an organizational and technical level – thinking like an attacker, understanding and anticipating the moves and tactics that a hacker might use to attack systems.
- Follow the architecture analysis process, which consists of research, validation, and evaluation of all new initiatives, with phase gate reviews presented to all stakeholders during key forums, including current trends such as AI and LLMS.
- Evaluates and selects security technologies, tools, and frameworks to support the organization’s security.
- Define portfolio vision and reusable security patterns aligned with the EA strategy.
- Lead architecture reviews for high-risk projects, driving recommendations to resolution.
- Advise on security controls for hybrid and cloud platforms, balancing usability, cost, and compliance.
- Defines and applies security policies, standards, and procedures to ensure compliance with industry regulations and best practices.
- Leads incident response activities, including identification, containment, eradication, and recovery, in coordination with the incident response team.
- Experience with Cloud Security platform vendors and technologies such as Azure and AWS.
- Manage security architects and mentor engineers, developers, and vendors.
What will you bring?
- Risk-based decision-making - expert in ISO 27001 / NIST / CIS controls, able to quantify and articulate risk, then select proportionate, cost-effective controls.
- Pen-testing & threat-modelling - scoping, overseeing, and translating results into enforceable patterns and backlog items.
- Influential communication - proven ability to engage C-suite and delivery stakeholders alike, adapting style to gain agreement and drive secure-by-design culture.
- Teamwork and Energy – work across different functional and business teams with effective collaboration.
- Technical depth - hands-on knowledge of cloud security, IAM, container & API security, network segmentation, encryption, and DevSecOps toolchains; capable of explaining the exploitability of complex vulnerabilities. Zero trust design thinking.
- Mentoring & governance - experience in line-managing or coaching security architects/engineers and running architecture assurance or design-review boards.
- Secure-system design leadership - demonstrable track record creating or validating architectures for large-scale, high-risk services using recognised frameworks (SABSA, TOGAF).
Requirements / Skills and Competence
- Tertiary qualification in Computer Science, Engineering, or related field (preferred)
- Minimum of 5-10 years of experience in Security Architecture.
- CISSP, CISA, CISM, or other relevant security-related designation(s) preferred.
- Certifications in CISSP-ISSAP, TOGAF, or SABSA, cloud architecture (Microsoft, AWS, GCP)
- Experience in identifying gaps in existing architectures.
- Understanding of security infrastructure in Public and Private Cloud, e.g., virtual network infrastructure, hybrid IaaS/PaaS/SaaS solutions.
- Experience in designing security architectures to mitigate threats and sound knowledge of security strategies and technologies.
- Direct the Project and Security teams with the guidance to build policies, standards, risks, and controls frameworks supporting operational requirements for the business.
- Good experience in security architecture design in Cloud and on-prem.
- Design and implementation of IOT, endpoint protection, and secure IAM.
- Understanding of authentication and authorisation technologies (SAML, LDAP, PKI, etc.) and other IAM technologies
- Understanding of the implementation, operation, and maintenance of SIEM, boundary protection technologies (firewalls, mail gateways), Antivirus, and AD security products
- Knowledge of web application architectures and threat modelling.
Information Security Specialist
Posted 1 day ago
Job Viewed
Job Description
The KPMG Africa Information Security Specialist is responsible for ensuring the confidentiality, integrity, and availability of all systems across KPMG Africa offices (South Africa, Botswana, Mauritius, Mozambique, Namibia, Zambia, Zimbabwe, Nigeria, Ghana, Kenya, Uganda, Tanzania, and Rwanda). The role involves actively managing and monitoring information security systems to detect, respond to, and remediate security risks and threats across the infrastructure.
4. Position Specifications
Educational Requirements (minimum necessary to perform the job):
- Professional / Tertiary qualification
Other Requirements:
Experience (minimum necessary):
Desired Qualifications and Experience:
- 3-5 years' experience in Information Technology Support or Information Security, including Microsoft Azure
- Industry-recognized certifications such as A+, N+, Security+, CySA+, and Cloud Security certifications like:
o Microsoft Certified: Security Operations Analyst Associate
o Microsoft Certified: Information Protection and Compliance Administrator Associate
o Microsoft Certified: Security, Compliance, and Identity Fundamentals
o Microsoft Certified: Identity & Access Management
o Microsoft Certified: Azure Security Engineer
- Professional certifications such as CISM, CISSP, ECIH are preferred but not required
- Strong knowledge of information security and cloud security concepts
- Experience in identifying, analyzing, and reporting on security risks and incidents
- Experience with security tools such as Qualys, Microsoft Defender Endpoint, Microsoft Sentinel, etc.
- Ability to evaluate vulnerabilities, develop mitigation strategies, and implement remediation
- Strong knowledge of operating systems, Microsoft Servers, Active Directory, and network protocols and technologies
5. Core Competencies:
- Attention to detail and accurate documentation
- Analytical skills to interpret information
- Ability to work independently and in a team
- Organizational and prioritization skills under pressure
6. Key Responsibilities & KPIs
Main Responsibilities:
- Monitoring incident response channels
- Executing the Information Security Incident Management Process and escalating high-priority issues
- Tracking and escalating open incidents
- Producing weekly and quarterly reports for the CISO on incident status and trends
Security Systems Configuration and Management:
- Daily monitoring of security systems to ensure proper functioning
- Configuration and management of security tools such as vulnerability, privileged access, and log management systems
- Reconciliation of assets to ensure coverage of security systems
- Reporting and issue resolution support for operational teams
Patch Management Monitoring:
- Monitoring patch management performance and identifying risks
- Addressing challenges to compliance
Threat and Event Monitoring:
- Detecting and escalating security threats and events
Vulnerability Management:
- Monitoring vulnerabilities daily
- Monthly asset reconciliation
- Managing vulnerability remediation with owners
- Supporting penetration testing activities
Supporting NITSO projects and other initiatives as required.
#J-18808-LjbffrBe The First To Know
About the latest Security audit Jobs in South Africa !
Information Security Officer
Posted 1 day ago
Job Viewed
Job Description
Job Purpose
Responsible for the installation, configuration, monitoring, and administration of information security systems for the Municipality.
Key Responsibility Areas
- Maintain, control, and operate the server and application security systems and infrastructure.
- Implement IT security systems and fault management support procedures for assigned systems.
- Monitor IT systems.
- Analyze logs to proactively enhance the Municipality's security posture.
- Monitor the security posture of IT systems, advise on weaknesses, and recommend improvements.
Competencies
- Advice and Guidance
- Operations
- User Support
- Business and IS&T Planning
- Interpersonal Relationships
- Communication
- Action and Outcome Orientation
- Resilience
- Cognitive Ability
- Learning Orientation
Essential Requirements
- Diploma (NQF Level 6) in an ICT-related field and an Information Security certificate.
- Valid motor vehicle driving license.
- 3 years relevant experience.
Preferred Requirements
- Degree (NQF Level 7) in an ICT-related field and an Information Security certificate.
- 4 years relevant experience.
Information Security Analyst
Posted 1 day ago
Job Viewed
Job Description
Managed Talent Solutions client in the mining sector is looking for a Information Security Analyst on a 12 month fixed term contract. Must have +6 years experience in conducting risk assessments that rely on outside penetration testing support and application of common Information Security Frameworks such as the ISO27000 series, SANS20, NIST and the ISF control framework.
POSITION INFO : Requirements :
- An undergraduate or postgraduate qualification in computer science, business informatics, / technology or equivalent Â
- Professional certifications and experience in Information Security from industry standard security frameworks : ISACA, BCS, CIPP, ITIL, Crest, ISC2, COMPTIA and key security vendors including Microsoft, Crowdstrike, Qualys, IBM.
- Must have experience in appliocation of Information Security frameworks such as the ISO27000 series, SANS20, NIST and the ISF control framework
- Conducting risk assessments that rely on outside penetration testing support
- Information security training and awareness concepts and delivery
- Incident response and crisis management concepts experience
 Key responsibilities :
- Support and monitor cybersecurity initiatives and controls in the region
- Collaborate with regional IT and security teams to implement security measures and protocols
- Conduct security assessments and risk analyses for regional assets and systems
- Facilitate security awareness training for regional employees
- Respond to and investigate security incidents in the region
- Stay updated with regional cybersecurity regulations and compliance requirements
Security Analyst • Johannesburg, South Africa
#J-18808-LjbffrInformation Security Consultant
Posted 7 days ago
Job Viewed
Job Description
Our client, a leading financial services firm, is seeking an Information Security Consultant to join their team on a permanent basis.
Responsibilities- Security Auditing
- Responsible for Security tools monitoring
- Network experience (TCP/IP, Firewalls, IPS, NAC)
- Operating System management and Hardening
- Anti-Virus System management and Configuration
- Logical Access Management
- Vulnerability Management
- Matric and an Information Technology diploma or degree qualification
- 4+ years experience in the field
Salary: Market Related
#J-18808-Ljbffr