Principal Specialist Cyber Security Grc

1 week ago


Midrand, Gauteng, South Africa Vodafone Full time

Role purpose:

Defining Cyber Governance, Risk & Compliance to:

To lead the ongoing evaluation of security policies, and relevant standards and support the continuous improvement of the security governance program.

To ensure that comprehensive Information Security Risk management programs are established.
Ensure the alignment of Information Security Risk management with the enterprise risk management framework.

To lead in the risk management of cyber security risks while collaborating with other departments to identify, recommend, develop, implement, and support a risk-informed decision and action framework.

To provide Management with assurance covering controls across the Business environments that there are adequately designed and operating effectively.
To support Management during audits as well as implement and track Management audit actions to closure.
Assist in the management and rollout of cyber-Training & Awareness initiatives.
Provide Management with status update reports as well as insight reporting.

Your responsibilities will include:

Take a proactive approach to ongoing evaluation of cyber security policies to ensure security policy adherence.

Promote awareness of security policies, training, and the governance strategy amongst all levels of the organization to ensure sound security governance is reflected across the organization.

Maintain and further develop the Cyber Risk Management Program.
Actively manage risks on the Cyber Risk Register from intake to resolution.
Communicate risk assessment findings with key stakeholders to develop and monitor risk remediation plans.
Develop cyber risk portfolios to provide a more holistic view of teams' risks.
Conduct regular compliance assessments with the Business to ensure that current and emerging risks are being monitored and managed.
Proactive Control design and implementation guidance provided to the Business.
Process and Control Compliance Monitoring and Reporting.
Cyber audit SPOC to the business with guidance on all audit submissions.
Cyber audit report reviews and guidance to Management on the recommended actions.
Tracking and monitoring of audit remediation action implementation.
Deploying cyber security awareness training collateral with innovative approaches.
Design of status reports as well as insight reporting as and when required by Management.
Lead reporting development with the use of automation and reporting tools to generate Cyber Risk metrics, i.e. KPI, KRI's, KGI's (KSI).

Ideally you should possess the following:
Matric/Grade 12 is essential.

Degree\Relevant tertiary qualification in Information technology and Minimum of 8 + years of experience in a Tech Security role where you meet business deliverables.

8+ years experience in cyber governance, risk, controls, and compliance management in a technology environment.
8+ years experience in IT Audit and Assurance management in a Cyber or technology environment.
Knowledge of common information technology management/compliance frameworks such as ISO/IEC 27001, SOC 2, SOX, ITIL, COBIT, and NIST.

Knowledge of legal, regulatory, and privacy requirements, such as Personally Identifiable Information (PII) Protection and Payment Card Industry (PCI)/Data Security Standard.

High-level understanding and Knowledge of Cloud Risk, Compliance, and Assurance.
Proven experience managing and operating multiple security programs, projects, and initiatives.
An ability to think strategically and drive change.
A deep understanding of Tech Security risks and mitigating solutions.
GSM Network Infrastructure.

Diverse security background with knowledge in several areas including layered security architecture; internet protocols; firewalls; VPN technologies, IDS/IPS, network access control and network segmentation, anti-malware and spam technologies; risk and vulnerability assessments, and compliance.

Security concepts related to DNS, routing, authentication, VPN, proxy services, and DDOS mitigation technologies.
Windows, UNIX, and Linux operating systems.
Web Security & Encryption.
Strong organizational skills and an entrepreneurial drive with a history of recruiting and developing high-performing teams.
Ability to build and manage a highly motivated and innovative technical team.
Ability to work under time and resource pressure.
An ability and desire to communicate and work with a broad set of stakeholders.
A customer-focused, responsive, and transparent attitude.
Grasping technical concepts rapidly and the ability to articulate these concepts to technical and non-technical audiences.
Skilled in communicating with all levels of management.

Desired:
An industry certification e.g. ISO 27001 Lead practitioner, CGEIT, CRISC, CISA, CISM, and CISSP is strongly preferred.

Closing date for Applications: 03 March 2023.
The base location for this role is
Midrand, Vodacom Campus.
The Company's approved Employment Equity Plan and Targets will be considered as part of the recruitment process

  • Midrand, Gauteng, South Africa Vodafone Full time

    Role Purpose:The primary purpose of the role is to support Cyber GRC functions which are all interdependent and would require good teamwork.To ensure the best delivery, exposure and create backfill capability with succession planning, the role and function for a Cyber GRC specialist would require expertise in the following areas broadly covered...


  • Midrand, Gauteng, South Africa Adcorp Holdings Full time

    SynopsisOur Client in the Telecommunications industry is hiring for a Cyber Security Specialist as an Independent Contractor for 12 months. This role will allow you to gain experience in working with one of the largest telecommunications companies in South Africa.HybridMidrand basedon the hunt for an experienced and highly skilled Cyber Security Senior...


  • Midrand, Gauteng, South Africa Vodafone Full time

    Role purpose:Cyber Defence is one of MPA's critical Cyber Security teams. The Cyber Defence team's mission is to deliver a highly effective end to end 24x7 Cyber Defence service. They are responsible for proactively identifying threats and vulnerabilities; detecting and mitigating cyber events; and managing cyber security incident responses to minimise...


  • Midrand, Gauteng, South Africa Nexio Full time

    ROLE REQUIREMENT To increase security threat detection capability and defence effectiveness in the Security Assessment Team, and SOC Team in their engagements with customers. Provides support for Nexio Offensive Security capabilities for the Security Assessment Team, and SOC Team for customers' engagements. Direct impact on business resilience and...


  • Midrand, Gauteng, South Africa Vodafone Full time

    Role purpose:The primary purpose of the role is to work within a team of Secure by Design and Security Architecture specialists, in collaboration with the Privacy and Business Risk Teams to Perform Secure by Design Assessments against Vodacom policies and standards.In performing this role, you will:Identify potential cyber security risks for new products,...


  • Midrand, Gauteng, South Africa Vodafone Full time

    Role purpose:The primary purpose of the role is to work within a team of Secure by Design specialists, in collaboration with the Privacy and Business Risk Teams to Perform Secure by Design Assessments against Vodacom policies and standards. In performing this role you willIdentify potential cyber security risks for new products, services and operations and...


  • Midrand, Gauteng, South Africa Vodafone Full time

    Role purpose:The primary purpose of the role is to work within a team of Secure by Design and Security Architecture professionals, in collaboration with the Privacy and Business Risk Teams to Perform Secure by Design Assessments against Vodacom policies and standards. In performing this role you willIdentify potential cyber security risks for new products,...


  • Midrand, Gauteng, South Africa Vodafone Full time

    Role purpose:The Manager - Cybersecurity Prevent will coordinate the team, tools, processes and operations of the Cyber Security Prevent Team responsible for managing, optimizing and deploying Cybersecurity solutions and capabilities to safeguard the information assets and reduce the Cybersecurity risk for M-Pesa Africa and its customers. The role holder...


  • Midrand, Gauteng, South Africa Vodafone Full time

    Role purpose:The primary purpose of the role is to work within a team of Secure by Design and Security Architecture specialists, in collaboration with the Privacy and Business Risk Teams to Perform Secure by Design Assessments against Vodacom policies and standards.Your responsibilities will include:Provide technology security assurance, guidance and support...


  • Midrand, Gauteng, South Africa Vodafone Full time

    Role purpose:Your responsibilities will include:Provide supervisory technology security assurance, guidance, and support to the Vodacom Group.Assure that security is embedded in IT systems and Network Infrastructure (Mobile, IS, and Enterprise) across the Vodacom Group.Defining, implementing, and efficiently maintaining technology security controls and...

  • SAP Grc Consultant

    1 week ago


    Midrand, Gauteng, South Africa Full Circle Resourcing Full time

    Our client requires the services of a Software Engineer (Advanced) Midrand/Menlyn/Rosslyn/Home Office rotation.- Amazing brand with innovative technology:Excellent teams in Global team collaboration:- High work-life balance with Flexible hours:Agile working environmentPOSITION:Until December 2026EXPERIENCE:4-6 Years related working experience.COMMENCEMENT:As...


  • Midrand, Gauteng, South Africa SACAA Full time

    PURPOSE OF THE JOBThe South African Civil Aviation Authority (SACAA) has an exciting opportunity in our Aviation Security department.We are looking for a talented individual with the relevant skills and experience who will:- develop and manage an Aviation Security Risk Management System.- develop and monitor Cyber Security Governance Framework, incorporating...


  • Midrand, Gauteng, South Africa Sabenza IT Full time

    SAP Authorizations Specialist Authorizations/ Security/ GRC, Technical - SAPMenlyn - Gauteng - South Africa, Midrand - Gauteng - South Africa, Rosslyn - Gauteng - South AfricaAre you ready to drive your career to the next level? Our client is seeking a talented and experienced SAP Authorizations Specialist to join their dynamic team. As a global leader in...


  • Midrand, Gauteng, South Africa Vodafone Full time

    Role purpose:The primary purpose of the role is to work within a team of Secure by Design and Security Architecture professionals, in collaboration with the Privacy and Business Risk Teams to Perform Secure by Design Assessments against Vodacom policies and standards.In performing this role you will:Identify potential cyber security risks for new products,...


  • Midrand, Gauteng, South Africa Vodafone Full time

    Role purpose:Your responsibilities will include:The incumbent will direct, develop, implement and maintain a comprehensive Vodacom-wide vulnerability management strategy.Defining, implementing and efficiently maintaining technology security controls and requirementsEnsure timely delivery of technology security vulnerability reports and support for...


  • Midrand, Gauteng, South Africa Fempower Personnel Full time

    Our client has an exciting opportunity for a Principal Project Preparation Specialist to lead Project Preparation Teams to prepare projects in order to develop the organization's investment pipeline in priority sectors in South Africa, SADC Region and selected African Countries in line with the approved Project Preparation Strategy. The incumbent of this...


  • Midrand, Gauteng, South Africa Vodafone Full time

    Role purpose:The Specialist Demand and Delivery will provide project delivery support to cyber security-driven programs within the Vodacom South Africa operations. The post holder will support delivery activity whilst providing direction and guidance to the delivery team to ensure a successful outcome of projects using an Agile methodology. You will need to...


  • Midrand, Gauteng, South Africa Vodafone Full time

    Role purpose:The Senior Specialist: Internal Audit, Tech is responsible for executing Technology and Integrated audits and ad hoc management requests across the Vodacom Group footprint in support of strengthening the control environment. The audit work must be performed in line with the Vodacom Internal Audit methodology and professional standards. Following...


  • Midrand, Gauteng, South Africa DBSA Full time

    The purpose of this role is to perform information security responsibilities such as developing, coordinating and implementing policies, standards, and procedures to safeguard the bank's information systems and data. Ensuring that information security policy is aligned with the bank's business strategy & benchmarked with best practice.Strategic Focus:Define...


  • Midrand, Gauteng, South Africa Nexio Full time

    ROLE PURPOSETheSenior Security Operations Lead is responsible for customers' SLA management and service delivery by all Security Delivery Teams across all Nexio customers. The Senior Security Operations Lead plans, coordinates, and directs all daily operational activities of the Security Services Teams show in the organogram.The Senior Security Operations...