Specialist - Cyber Security Grc

1 week ago


Midrand, Gauteng, South Africa Vodafone Full time

Role Purpose:


The primary purpose of the role is to support Cyber GRC functions which are all interdependent and would require good teamwork.

To ensure the best delivery, exposure and create backfill capability with succession planning, the role and function for a Cyber GRC specialist would require expertise in the following areas broadly covered below:

Governance
Cyber Security Training, Awareness and Education
Cyber Security Document Management & Compliance
Risk and Risk Management
Cyber Security Risk and Risk Management
Reporting & Data Analytics
Compliance and Assurance
Cyber Security Baseline (CSB)
Audits and Assurance


You will also be required to drive the delivery of Cyber Security strategy and maturity improvement or risk reduction initiatives into the business unit(s) to which you will be assigned, monitor progress against agreed targets with the objective of safeguarding Vodacom Infrastructure and customer data from Cyber threat actors.

This role will involve working with the respective Business units, Cyber and IT stakeholders in Vodacom South Africa to drive out Cyber Security baseline requirements - Some of these responsibilities may extend to collaboration with Group Cyber Security and other operating companies to ensure that cyber security controls are consistently applied across markets.


Your responsibilities will include:

Governance
Cyber Security Training, Awareness and Education
Responsible for the various components of security awareness, training and education covering which could include the following:
Cyber Security Training and Awareness planning, executing, tracking, and reporting.
Provide bespoke training for high profile staff based on their potential risk of being attacked (HR, IT, Senior Executives, Executive Pa's.
Deliver Cyber Security inductions for all new joiners.

Deliver presentations to senior management on results of Cyber Security awareness campaigns, pain points, lessons learned and actions going forward for improvement.

Execute routine phishing simulations to assess the posture of staffs reporting and click rates.
Identify high risk users through phishing simulations and provide workshops to lower their risks.
Roll out Cyber Security training for all staff based on current trending global topics.
Provide executive reports to Vodafone regarding the Cyber Security programme.
Research common attack vectors and ways to spot them to reduce the risk
Provide security communications based on risks identified within the organisation.
Main point of contact for Cyber Security Training and Awareness.

Cyber Security Document Management & Compliance
Responsible for the various components of governance covering cyber policies, standards, processes and procedures which could include the following:
Implementation and guide policy compliance across Vodacom SA.
Review of Vodafone Security Policies, Processes and Standards against Vodacom SA for non-conformances.
Identify gaps in policies and provide input to improve them.
Communicate changes to policies to the organisation and the impact of the changes.
ISO9001 Coordinator for the department to ensure the Quality Management System is maintained.

Risk and Risk Management
Cyber Security Risk and Risk Management
Responsible for the risk management process and actions related to the various cyber security governing controls which will cover aspects like:

Risk reviews processes with partner departments to ensure good security practices are up to date as per industry standards and have applied Security by Design.

Identifying and registering new risks with the implementation and integration of new systems.

Technical / Professional Qualifications:

3-year Technical Diploma/Degree in Information Security, Computer Science or Engineering
Diploma or bachelor's degree in Computer Science, Information Systems, Systems Analysis, or another related field
Minimum of - 8 years of experience in Tech Security role where you meet business deliverables.

Core competencies, knowledge, and experience:


Knowledge of common information technology management / compliance frameworks such as ISO/IEC 27001, SOC 2, SOX, ITIL, COBIT, and NIST.

Knowledge of legal, regulatory and privacy requirements, such as Personally Identifiable Information (PII) Protection and Payment Card Industry (PCI)/Data Security Standard.

Proven experience managing and operating multiple security programs, projects, and initiatives.
An ability to think strategically and drive change.
A deep understanding of Technology Security risks and mitigating solutions.

A diverse security background with knowledge in several areas including layered security architecture; internet protocols; firewalls; VPN technologies, IDS/IPS, network access control and network segmentation, anti-malware and spam technologies; risk and vulnerability assessments, and compliance.

Security concepts related to DNS, routing, authentication, VPN, proxy services and DDOS mitigation technologies.
Windo

  • Midrand, Gauteng, South Africa Vodafone Full time

    Role purpose:Defining Cyber Governance, Risk & Compliance to:To lead the ongoing evaluation of security policies, and relevant standards and support the continuous improvement of the security governance program.To ensure that comprehensive Information Security Risk management programs are established.Ensure the alignment of Information Security Risk...


  • Midrand, Gauteng, South Africa Adcorp Holdings Full time

    SynopsisOur Client in the Telecommunications industry is hiring for a Cyber Security Specialist as an Independent Contractor for 12 months. This role will allow you to gain experience in working with one of the largest telecommunications companies in South Africa.HybridMidrand basedon the hunt for an experienced and highly skilled Cyber Security Senior...


  • Midrand, Gauteng, South Africa Vodafone Full time

    Role purpose:Cyber Defence is one of MPA's critical Cyber Security teams. The Cyber Defence team's mission is to deliver a highly effective end to end 24x7 Cyber Defence service. They are responsible for proactively identifying threats and vulnerabilities; detecting and mitigating cyber events; and managing cyber security incident responses to minimise...


  • Midrand, Gauteng, South Africa Vodafone Full time

    Role purpose:The primary purpose of the role is to work within a team of Secure by Design and Security Architecture specialists, in collaboration with the Privacy and Business Risk Teams to Perform Secure by Design Assessments against Vodacom policies and standards.In performing this role, you will:Identify potential cyber security risks for new products,...


  • Midrand, Gauteng, South Africa Vodafone Full time

    Role purpose:The primary purpose of the role is to work within a team of Secure by Design specialists, in collaboration with the Privacy and Business Risk Teams to Perform Secure by Design Assessments against Vodacom policies and standards. In performing this role you willIdentify potential cyber security risks for new products, services and operations and...


  • Midrand, Gauteng, South Africa Vodafone Full time

    Role purpose:The primary purpose of the role is to work within a team of Secure by Design and Security Architecture professionals, in collaboration with the Privacy and Business Risk Teams to Perform Secure by Design Assessments against Vodacom policies and standards. In performing this role you willIdentify potential cyber security risks for new products,...


  • Midrand, Gauteng, South Africa Vodafone Full time

    Role purpose:The Manager - Cybersecurity Prevent will coordinate the team, tools, processes and operations of the Cyber Security Prevent Team responsible for managing, optimizing and deploying Cybersecurity solutions and capabilities to safeguard the information assets and reduce the Cybersecurity risk for M-Pesa Africa and its customers. The role holder...


  • Midrand, Gauteng, South Africa Vodafone Full time

    Role purpose:The primary purpose of the role is to work within a team of Secure by Design and Security Architecture specialists, in collaboration with the Privacy and Business Risk Teams to Perform Secure by Design Assessments against Vodacom policies and standards.Your responsibilities will include:Provide technology security assurance, guidance and support...


  • Midrand, Gauteng, South Africa Nexio Full time

    ROLE REQUIREMENT To increase security threat detection capability and defence effectiveness in the Security Assessment Team, and SOC Team in their engagements with customers. Provides support for Nexio Offensive Security capabilities for the Security Assessment Team, and SOC Team for customers' engagements. Direct impact on business resilience and...


  • Midrand, Gauteng, South Africa Vodafone Full time

    Role purpose:Your responsibilities will include:Provide supervisory technology security assurance, guidance, and support to the Vodacom Group.Assure that security is embedded in IT systems and Network Infrastructure (Mobile, IS, and Enterprise) across the Vodacom Group.Defining, implementing, and efficiently maintaining technology security controls and...

  • SAP Grc Consultant

    1 week ago


    Midrand, Gauteng, South Africa Full Circle Resourcing Full time

    Our client requires the services of a Software Engineer (Advanced) Midrand/Menlyn/Rosslyn/Home Office rotation.- Amazing brand with innovative technology:Excellent teams in Global team collaboration:- High work-life balance with Flexible hours:Agile working environmentPOSITION:Until December 2026EXPERIENCE:4-6 Years related working experience.COMMENCEMENT:As...


  • Midrand, Gauteng, South Africa SACAA Full time

    PURPOSE OF THE JOBThe South African Civil Aviation Authority (SACAA) has an exciting opportunity in our Aviation Security department.We are looking for a talented individual with the relevant skills and experience who will:- develop and manage an Aviation Security Risk Management System.- develop and monitor Cyber Security Governance Framework, incorporating...


  • Midrand, Gauteng, South Africa Sabenza IT Full time

    SAP Authorizations Specialist Authorizations/ Security/ GRC, Technical - SAPMenlyn - Gauteng - South Africa, Midrand - Gauteng - South Africa, Rosslyn - Gauteng - South AfricaAre you ready to drive your career to the next level? Our client is seeking a talented and experienced SAP Authorizations Specialist to join their dynamic team. As a global leader in...


  • Midrand, Gauteng, South Africa Vodafone Full time

    Role purpose:The primary purpose of the role is to work within a team of Secure by Design and Security Architecture professionals, in collaboration with the Privacy and Business Risk Teams to Perform Secure by Design Assessments against Vodacom policies and standards.In performing this role you will:Identify potential cyber security risks for new products,...


  • Midrand, Gauteng, South Africa Vodafone Full time

    Role purpose:Your responsibilities will include:The incumbent will direct, develop, implement and maintain a comprehensive Vodacom-wide vulnerability management strategy.Defining, implementing and efficiently maintaining technology security controls and requirementsEnsure timely delivery of technology security vulnerability reports and support for...


  • Midrand, Gauteng, South Africa Vodafone Full time

    Role purpose:The Specialist Demand and Delivery will provide project delivery support to cyber security-driven programs within the Vodacom South Africa operations. The post holder will support delivery activity whilst providing direction and guidance to the delivery team to ensure a successful outcome of projects using an Agile methodology. You will need to...


  • Midrand, Gauteng, South Africa Vodafone Full time

    Role purpose:The Senior Specialist: Internal Audit, Tech is responsible for executing Technology and Integrated audits and ad hoc management requests across the Vodacom Group footprint in support of strengthening the control environment. The audit work must be performed in line with the Vodacom Internal Audit methodology and professional standards. Following...


  • Midrand, Gauteng, South Africa DBSA Full time

    The purpose of this role is to perform information security responsibilities such as developing, coordinating and implementing policies, standards, and procedures to safeguard the bank's information systems and data. Ensuring that information security policy is aligned with the bank's business strategy & benchmarked with best practice.Strategic Focus:Define...


  • Midrand, Gauteng, South Africa Nexio Full time

    ROLE PURPOSEAs part of the Customer-facing Nexio SOC team, the Specialist: Cybersecurity Analyst plays a critical role in monitoring, detecting, and responding to cybersecurity incidents within a Security Operations Center. The Cybersecurity Analyst utilizes incident handling methodologies to validate security events, assess severity levels, and provide...


  • Midrand, Gauteng, South Africa Nexio Full time

    ROLE PURPOSETheSenior Security Operations Lead is responsible for customers' SLA management and service delivery by all Security Delivery Teams across all Nexio customers. The Senior Security Operations Lead plans, coordinates, and directs all daily operational activities of the Security Services Teams show in the organogram.The Senior Security Operations...