Business Information Security Officer

2 weeks ago


Johannesburg, Gauteng, South Africa Nedbank Full time

Requisition Details & Talent Acquisition Contact

  • REQ Tshego Semenya
    Cluster
  • Information Technology

Career Stream

  • It Risk

Leadership Pipeline

  • Manage Self: Expert

Position

  • Business Information Security Officer
    Job Purpose
  • The BISO must support the business cluster in the implementation and execution of the cyber resilience risk management framework that includes implementation of cyber risk assessments, strategy, cyber security programme, policies, standards, reporting of all clusterspecific cyber security programme elements and regulatory matters as it relates to cyber security

Responsibilities:

  • Build and maintain professional relationships by information sharing and professional networking within the bank.
  • Build and maintain internal stakeholder relationships through collaboration with stakeholders and regular communication via various media
  • Drive compliance to security policies and standards on cluster infrastructure.
  • Primary interface between the cluster and CISO office.
  • Represent business as an information security representative on the CSSC;
  • Ensure alignment and implementation of CRRMF in clusters.
  • Report of all cluster specific information security program elements;
  • Work closely together with all stakeholders.
  • Actively executes the cyber security programme elements and other information and cyber security plans developed by the business.
  • Assist the cluster with identification of critical assets ("crown jewels") and feeding that back into the business impact analysis and risk management processes.
  • Work with the business to develop processes and procedures to ensure information security policies and standards are integrated; and
  • Assist with third party supplier information and cyber security risk assessments and assurance
  • Assist business with incident management related to cyber and/or privacy incidents
  • Conclude cyber / privacy impact assessment on new business initiatives
  • Build and maintain professional relationships by information sharing and professional networking within the bank.
  • Build and maintain internal stakeholder relationships through collaboration with stakeholders and regular communication via various media
  • Drive compliance to security policies and standards on cluster infrastructure;
  • Primary interface between the cluster and CISO office.
  • Represent business as an information security representative on the CSSC;
  • Ensure alignment and implementation of CRRMF in clusters.
  • Report of all cluster specific information security program elements;
  • Work closely together with all stakeholders.
  • Actively executes the cyber security programme elements and other information and cyber security plans developed by the business.
  • Assist the cluster with identification of critical assets ("crown jewels") and feeding that back into the business impact analysis and risk management processes.
  • Work with the business to develop processes and procedures to ensure information security policies and standards are integrated; and
  • Assist with third party supplier information and cyber security risk assessments and assurance
  • Assist business with incident management related to cyber and/or privacy incidents
  • Conclude cyber / privacy impact assessment on new business initiatives
  • Minimum Experience Level years in Information Security Experience
  • Exposure in Risk Management Monitoring
  • Data Reporting Analytics experience

Essential Qualifications - NQF Level

  • Professional Qualifications/Honour's Degree

Preferred Qualification

  • Master's Degree in IT / Computer Science / Informatics


Preferred Certifications
  • Certified Information Security Manager (CISM)
  • Certified in Risk and Information Systems Control (CRISC)
  • Certified Information Systems Auditor (CISA)
  • Certified Information Systems Security Professional (CISSP)


Type of Exposure
  • Completed Reports and Achieved Budgets
  • Developed and Implemented Communications Strategy
  • Manage internal process
  • Managed Relationships
  • Managed Self
  • Designed Workforce Planning Solutions
  • Managed Transformation and Innovation
  • Provided Administrative Support
  • Provided Client Service
  • Supported Transformation, Change and continued Improvement

Technical / Professional Knowledge

  • Administrative procedures and systems
  • Banking knowledge
  • Data analysis
  • Governance, Risk and Controls
  • Microsoft Office
  • Principles of project management
  • Relevant regulatory knowledge
  • Relevant software and systems knowledge
  • Business writing skills
  • Information Security Threats and Attact vectors
  • Cluster Specific Operational Knowledge
  • System Development Life cycle(SDLC)
  • TCP/IP
  • Information Security terms and definitions
  • Basic computer concepts
  • Relevant Operating System
  • Information Security policies and procedures
  • Vendor Management Principles

Disclaimer

_Please contact the Nedbank Recruiting Team at _
- **_Please con

  • Johannesburg, Gauteng, South Africa Nedbank Full time

    Job Purpose The BISO must support the business cluster in the implementation and execution of the cyber resilience risk management framework that includes implementation of cyber risk assessments, strategy, cyber security programme, policies, standards, reporting of all clusterspecific cyber security programme elements and regulatory matters as it relates to...


  • Johannesburg, Gauteng, South Africa WePlace Full time

    Gauteng, JHB - Northern Suburbs Market Related Annually Basic Salary We have an exciting opportunity as an Information Security Officer based at our client in the Commercial Banking sector which is located in Sandton.Role Description: The focus of the role will be to assess, identify and address the cyber and information security risks in the division. We...


  • Johannesburg, Gauteng, South Africa Telebest Full time

    Our client has an EE opportunity available for an Information Security Officer based in SelbyRequirements:7 years' experience in technology security or risk management roles of which should include:4 years in technology policy writing.4 years' experience in designing implementing and closing technology general control gaps.3 years' experience in directly...


  • Johannesburg, Gauteng, South Africa Telebest Full time

    Our client has an EE opportunity available for an Information Security Officer based in Selby.Requirements:7 years' experience in technology security or risk management roles of which should include:4 years in technology policy writing.4 years' experience in designing implementing and closing technology general control gaps.3 years' experience in directly...


  • Johannesburg, Gauteng, South Africa Integralis Full time

    As the Information Security Officer, you will be responsible for the information security vision, strategy, governance, management, processes and user education. The role also requires technical abilities to assist the team in improving the security posture.Purpose:Assist the management team in creating and executing the security strategy and updating the...


  • Johannesburg, Gauteng, South Africa Kontak Recruitment Full time

    Information Security Officer (JB4536) Remote, (Suitable for candidates in Gauteng Only) XXX-XXXX.00 to XXX-XXXX.00 Annually CTC Permanent A retailer operating in the travel retail sector is looking for a professional Information Security Officer. The ...Matric & Relevant tertiary qualificationOne or more of the below certifications would be...


  • Johannesburg, Gauteng, South Africa Elite Search and Selection Full time

    Gauteng, JHB - Northern Suburbs R R Monthly Cost To Company (Various Exco Team Benefits)ROLE: Chief Information Security OfficerLOCATION:Johannesburg - Sandton Area - Office BasedAre you an experienced and visionary IT professional with a passion for cybersecurity? Are you ready to take the reins and safeguard the digital ecosystem of a rapidly expanding...


  • Johannesburg, Gauteng, South Africa Kontak Recruitment Full time

    "Information Security Officer (JB4444) Remote, (Suitable for candidates in Gauteng Only) XXX-XXXX.00 to XXX-XXXX.00 Annually CTC Permanent A retailer operating in the travel retail sector is looking for a professional Information Security Offi...Matric & Relevant tertiary qualification One or more of the below certifications would be...


  • Johannesburg, Gauteng, South Africa Kontak Recruitment Full time

    "Information Security Officer (JB4444) Remote, (Suitable for candidates in Gauteng Only) XXX-XXXX.00 to XXX-XXXX.00 Annually CTC Permanent A retailer operating in the travel retail sector is looking for a professional Information Security Offi...Matric & Relevant tertiary qualification One or more of the below certifications would be advantageous: CISSP:...


  • Johannesburg, Gauteng, South Africa Kontak Recruitment Full time

    "Information Security Officer (JB4444) Remote, (Suitable for candidates in Gauteng Only) XXX-XXXX.00 to XXX-XXXX.00 Annually CTC Permanent A retailer operating in the travel retail sector is looking for a professional Information Security Offi...Matric & Relevant tertiary qualification One or more of the below certifications would be advantageous: CISSP:...


  • Johannesburg, Gauteng, South Africa Kontak Recruitment Full time

    "Information Security Officer (JB4444) Remote, (Suitable for candidates in Gauteng Only) XXX-XXXX.00 to XXX-XXXX.00 Annually CTC Permanent A retailer operating in the travel retail sector is looking for a professional Information Security Offi...Matric & Relevant tertiary qualification One or more of the below certifications would be advantageous: CISSP:...


  • Johannesburg, Gauteng, South Africa Standard Bank Of South Africa Limited Full time

    Business Segment: Business & Commercial Banking Location: ZA, GP, Johannesburg, Simmonds Street 5 To implement the Group Cyber Resilience strategy securing platforms ecosystems 3rd party integration protecting sensitive data, applications and supporting infrastructure from infiltration or misuse guiding security capabilities in client segment and solutions....


  • Johannesburg, Gauteng, South Africa Security Bank & Trust Co. Full time

    Johannesburg: Information Security Officer (Remote)EDUCATION &EXPERIENCE:Matric & Relevant tertiary qualification.One or more of the below certifications would be advantageous:CISSP:Certified Information Systems Security ProfessionalCISA:Certified Information Systems AuditorCISM:Certified Information Security Manager KPAs 5 years experience in Cyber...


  • Johannesburg, Gauteng, South Africa Security Bank & Trust Co. Full time

    Johannesburg: Information Security Officer (Remote)EDUCATION &EXPERIENCE:Matric & Relevant tertiary qualification.One or more of the below certifications would be advantageous:CISSP:Certified Information Systems Security ProfessionalCISA:Certified Information Systems AuditorCISM:Certified Information Security Manager KPAs 5 years experience in Cyber...


  • Johannesburg, Gauteng, South Africa F & G Sourcing Specialist Full time

    Our Security Services client is seeking a skilled, professional Information Security Officer to join their team in Johannesburg.Salary: R R77 000 per MonthBenefits:The CTC consist of the following:Employer contributes 100% towards Medical aid (CTC) Employer contributes 100% towards Provident Fund Performance bonus: not guaranteed based on the performance of...


  • Johannesburg, Gauteng, South Africa Sanlam Full time

    Who are we?Sanlam Developing Markets [SDM] (a wholly-owned subsidiary of Sanlam Life Limited) is one of the top financial services providers in the South African entry-level and emerging middle market. It aims to understand the unique requirements of clients and offers a wide range of simple and affordable financial solutions that cover needs such as funeral...


  • Johannesburg, Gauteng, South Africa Recruitment Matters Africa Full time

    Our client is looking for a Data Protection/Information Security Officer to join their team.The Director Data Protection & Compliance Programs is responsible to ensure departments in SSA Countries adhere to the company's Data Protection/Privacy standards and to the IT Infrastructure and Service Management standards, i.e. Information Security.Compliance will...


  • Johannesburg, Gauteng, South Africa Hera Group Full time

    Are you a visionary leader with a passion for cybersecurity and a proven track record of driving security initiatives? Hera Group, a prominent company operating across Africa, is seeking an accomplished Chief Information Security Officer (CISO) to steer our cybersecurity strategies and ensure digital resilience.About Us:Hera Group is a trailblazing force in...


  • Johannesburg, Gauteng, South Africa FirstRand Full time

    About us, purpose, experience and qualificationsabout us:- make a promise- be deeply invested- value our differences- build trust, not territory- have courage- always do the right thingpurpose: To address the risk management of the FNB information security environment and the definition and maintenance of information security policy; To contain our...


  • Johannesburg, Gauteng, South Africa ABC Worldwide Full time

    Information Security Manager will be responsible for implementing and monitoring IT security strategies for all platforms across IT function with organization. He will provide assistance to manage the risk to the platform assigned and will ensure business alignment, effective governance, system and infrastructure availability, integrity and...