Specialist: Cyber Secure By Design

1 week ago


Midrand, Gauteng, South Africa Vodafone Full time

Role purpose:


The primary purpose of the role is to work within a team of Secure by Design and Security Architecture specialists, in collaboration with the Privacy and Business Risk Teams to Perform Secure by Design Assessments against Vodacom policies and standards.


Your responsibilities will include:

Provide technology security assurance, guidance and support to high profile projects,
Ensure security is embedded in IT System and Network Infrastructure (Mobile, IS and Enterprise) across the Vodacom Group
Defining, implementing, and efficiently maintaining technology security controls and requirements
Ensure timely delivery of technology security assurance and support for projects, products and services.
Ensure compliance with Legal and Regulatory requirements
Support Technology Security awareness programs and educational efforts within the business unit to which you are asssigned
Provide accurate and timely reporting of technology security risks identified during secure by design assessments, project engagement and propose remediation and mitigation options in line with policy and good practice
Fulfil key customers' obligations and stakeholders' expectation
Ensure financial efficiency in Tech Security Solutions
Ensure compliance with the applicable legislative and regulatory interpretation and corporate risk appetite;
Engage with the stakeholders on compliance to control effectiveness and deficiencies in the design and operating effectiveness of information security controls, design and recommend opportunities for continuous improvement;
Manage and conduct formal information security risk analyses, reviews, tests, audits and/or self-assessments;
Design appropriate remedial actions for identified risks, drive remediation of findings and management of risks and exemptions;
Assist to compile a report of information security risks in an appropriate way for different audiences;
Develop, manage and maintain an information security incident management capability;
Collaborate with various key stakeholders, and provide information security advice to stakeholders

Technical / professional requirements:

3 year Technical Diploma/Degree in Information Security, Computer Science or Engineering
An industry certification. The CISSP is strongly preferred, however CCSP, OSCP, CISM, CISA or other relevant certifications will be considered. Security/IT Architecture qualifications such as SABSA, TOGAF etc and relevant security architecture experience will be an added advantage
Minimum of 3-5 years of experience in Cyber Security role

Knowledge of common information technology management / compliance frameworks such as ISO/IEC 27001, NIST CSF, ISF, PCI DSS, OWASP, SANS etc.

A deep understanding of Technology Security risks and mitigating solutions

A diverse security background with knowledge and experience in three or more of the Security Domains including: Security Assessment and Testing; Software Development Security; Security Governance and Risk Management; Security Architecture and Engineering; Communication and Network Security; Identity and Access Management; Security Operations; Asset Security.

Specialist experience in Either DevSecOps, Application Security, Security Architecture or Offensive Security will be an added advantage.

Core competencies, knowledge and experience:

Knowledge of operating systems such as Windows and Linux and how to secure them
Knowledge of and/ or experience in creating and managing DevSecOps pipelines practicing CSA, SAST, DAST, and Security as Code will be an added advantage

Be well-versed in at least one of the programming languages like Java, PHP, Python, Ruby, and Perl so as to collaborate competently with software engineering teams within the organization to identify and implement opportunities for improvement and automation in the CI/CD pipeline.

Knowledge of Cloud and container technologies such as AWS/GCP/Azure, Docker, Kubernetes, and how to implement developer tools such as GitHub and Dependency management will be an added advantage.

Knowledge of configuration management tools such as Chef, Puppet, and Ansible will be an added benefit.
Ability to work under time and resource pressure.
An ability and desire to collaborate and communicate with a broad set of stakeholders.
A customer-focused, responsive, and transparent attitude

Closing date for Applications
:30 April 2023.
The base location for this role is
Midrand, Vodacom Campus
The Company's approved Employment Equity Plan and Targets will be considered as part of the recruitment process. As an Equal Opportunities employer, we actively encourage and welcome people with various disabilities to apply.
Vodacom is committed to an organisational culture that recognises, appreciates and values diversity & inclusion.

  • Midrand, Gauteng, South Africa Vodafone Full time

    Role purpose:The primary purpose of the role is to work within a team of Secure by Design and Security Architecture specialists, in collaboration with the Privacy and Business Risk Teams to Perform Secure by Design Assessments against Vodacom policies and standards.In performing this role, you will:Identify potential cyber security risks for new products,...


  • Midrand, Gauteng, South Africa Vodafone Full time

    Role purpose:The primary purpose of the role is to work within a team of Secure by Design specialists, in collaboration with the Privacy and Business Risk Teams to Perform Secure by Design Assessments against Vodacom policies and standards. In performing this role you willIdentify potential cyber security risks for new products, services and operations and...


  • Midrand, Gauteng, South Africa Adcorp Holdings Full time

    SynopsisOur Client in the Telecommunications industry is hiring for a Cyber Security Specialist as an Independent Contractor for 12 months. This role will allow you to gain experience in working with one of the largest telecommunications companies in South Africa.HybridMidrand basedon the hunt for an experienced and highly skilled Cyber Security Senior...


  • Midrand, Gauteng, South Africa Vodafone Full time

    Role purpose:Cyber Defence is one of MPA's critical Cyber Security teams. The Cyber Defence team's mission is to deliver a highly effective end to end 24x7 Cyber Defence service. They are responsible for proactively identifying threats and vulnerabilities; detecting and mitigating cyber events; and managing cyber security incident responses to minimise...


  • Midrand, Gauteng, South Africa Vodafone Full time

    Role Purpose:The primary purpose of the role is to support Cyber GRC functions which are all interdependent and would require good teamwork.To ensure the best delivery, exposure and create backfill capability with succession planning, the role and function for a Cyber GRC specialist would require expertise in the following areas broadly covered...


  • Midrand, Gauteng, South Africa Vodafone Full time

    Role purpose:The primary purpose of the role is to work within a team of Secure by Design and Security Architecture professionals, in collaboration with the Privacy and Business Risk Teams to Perform Secure by Design Assessments against Vodacom policies and standards. In performing this role you willIdentify potential cyber security risks for new products,...


  • Midrand, Gauteng, South Africa Vodafone Full time

    Role purpose:Defining Cyber Governance, Risk & Compliance to:To lead the ongoing evaluation of security policies, and relevant standards and support the continuous improvement of the security governance program.To ensure that comprehensive Information Security Risk management programs are established.Ensure the alignment of Information Security Risk...


  • Midrand, Gauteng, South Africa Vodafone Full time

    Role purpose:The Manager - Cybersecurity Prevent will coordinate the team, tools, processes and operations of the Cyber Security Prevent Team responsible for managing, optimizing and deploying Cybersecurity solutions and capabilities to safeguard the information assets and reduce the Cybersecurity risk for M-Pesa Africa and its customers. The role holder...


  • Midrand, Gauteng, South Africa Vodafone Full time

    Role purpose:Your responsibilities will include:Provide supervisory technology security assurance, guidance, and support to the Vodacom Group.Assure that security is embedded in IT systems and Network Infrastructure (Mobile, IS, and Enterprise) across the Vodacom Group.Defining, implementing, and efficiently maintaining technology security controls and...


  • Midrand, Gauteng, South Africa Vodafone Full time

    Role purpose:The primary purpose of the role is to work within a team of Secure by Design and Security Architecture professionals, in collaboration with the Privacy and Business Risk Teams to Perform Secure by Design Assessments against Vodacom policies and standards.In performing this role you will:Identify potential cyber security risks for new products,...


  • Midrand, Gauteng, South Africa Nexio Full time

    ROLE REQUIREMENT To increase security threat detection capability and defence effectiveness in the Security Assessment Team, and SOC Team in their engagements with customers. Provides support for Nexio Offensive Security capabilities for the Security Assessment Team, and SOC Team for customers' engagements. Direct impact on business resilience and...


  • Midrand, Gauteng, South Africa SACAA Full time

    PURPOSE OF THE JOBThe South African Civil Aviation Authority (SACAA) has an exciting opportunity in our Aviation Security department.We are looking for a talented individual with the relevant skills and experience who will:- develop and manage an Aviation Security Risk Management System.- develop and monitor Cyber Security Governance Framework, incorporating...


  • Midrand, Gauteng, South Africa Vodafone Full time

    Role purpose:Your responsibilities will include:The incumbent will direct, develop, implement and maintain a comprehensive Vodacom-wide vulnerability management strategy.Defining, implementing and efficiently maintaining technology security controls and requirementsEnsure timely delivery of technology security vulnerability reports and support for...


  • Midrand, Gauteng, South Africa Open Source (Pty) Ltd Full time

    Essential Skills: Cisco ASA, Fortinet Firewall /IPS, Cisco FirePower, Cisco FMC, Tipping Point, Tufin UNIX/Linux. Cyber Security understanding, Troubleshooting skills, wireshark / tcpdump capture / analysis Linux administration, scripting Monitoring & Alerting Virtualization Experience with Cisco & HP Azure Cloud Experience Secured SD-WAN Networks...


  • Midrand, Gauteng, South Africa DBSA Full time

    The purpose of this role is to perform information security responsibilities such as developing, coordinating and implementing policies, standards, and procedures to safeguard the bank's information systems and data. Ensuring that information security policy is aligned with the bank's business strategy & benchmarked with best practice.Strategic Focus:Define...


  • Midrand, Gauteng, South Africa Vodafone Full time

    Role purpose:The PAM Specialist is responsible for ensuring that the PAM product is implemented and rolled out throughout the Vodacom group. This role is responsible for all the checkpoints during the delivery lifecycle of PAM support, maintenance and rollout. This role is responsible for managing the product and the associated projects that impact the use...


  • Midrand, Gauteng, South Africa Vodafone Full time

    Role purpose:The Specialist Demand and Delivery will provide project delivery support to cyber security-driven programs within the Vodacom South Africa operations. The post holder will support delivery activity whilst providing direction and guidance to the delivery team to ensure a successful outcome of projects using an Agile methodology. You will need to...


  • Midrand, Gauteng, South Africa Vodafone Full time

    Role purpose:The Senior Specialist: Internal Audit, Tech is responsible for executing Technology and Integrated audits and ad hoc management requests across the Vodacom Group footprint in support of strengthening the control environment. The audit work must be performed in line with the Vodacom Internal Audit methodology and professional standards. Following...


  • Midrand, Gauteng, South Africa Nexio Full time

    ROLE PURPOSEAs part of the Customer-facing Nexio SOC team, the Specialist: Cybersecurity Analyst plays a critical role in monitoring, detecting, and responding to cybersecurity incidents within a Security Operations Center. The Cybersecurity Analyst utilizes incident handling methodologies to validate security events, assess severity levels, and provide...


  • Midrand, Gauteng, South Africa Nexio Full time

    ROLE PURPOSETheSenior Security Operations Lead is responsible for customers' SLA management and service delivery by all Security Delivery Teams across all Nexio customers. The Senior Security Operations Lead plans, coordinates, and directs all daily operational activities of the Security Services Teams show in the organogram.The Senior Security Operations...