Information Security Specialist
2 weeks ago
Information Security Management System (ISMS) Specialist Information Security Management System (ISMS) Specialist is responsible for the end-to-end implementation, maintenance, and continuous improvement of the Information Security Management System (ISMS) in accordance with ISO/IEC 27001 standards. The incumbent will play a pivotal role in ensuring the confidentiality, integrity, and availability of our information assets, while also ensuring compliance with legal and regulatory requirements. Key Responsibilities ISMS Development and Implementation: Lead the design, implementation, and continuous improvement of an ISMS aligned with ISO/IEC 27001 and other relevant frameworks (e.g., NIST, POPIA, CIS, CSA etc.). Develop, implement, and maintain information security policies, procedures, and guidelines. Assess existing information security practices and recommend improvements. Ensure the organization's ISMS aligns with business needs, regulatory requirements, and industry best practices. Risk Assessment and Management: Perform risk assessments to identify potential security risks to the organization's information assets in alignment to ISO 31000. Develop risk treatment plans and assist in the implementation of risk mitigation strategies. Conduct ongoing risk assessments and audits to ensure the effectiveness of the ISMS. Compliance and Audits: Ensure compliance with ISO/IEC 27001 and other industry standards and regulations. Prepare the organization for certification audits and support the audit process. Coordinate with auditors and certification bodies. Maintain records and documentation to ensure traceability and compliance with ISMS requirements. Training and Awareness: Provide training to staff and management on information security best practices, policies, and compliance requirements. Promote a culture of information security awareness across the organization. Support the creation of an internal security awareness program. Incident Response and Management: Assist in the development and testing of incident response plans. Provide guidance and support in handling information security incidents. Ensure incidents are documented and reported in accordance with regulatory and contractual obligations & assist in post-incident analysis to determine the cause and recommend preventive actions. Define and monitor ISMS-related KPIs and metrics. Monitor and report on the performance of the ISMS, identifying areas for improvement. Monitor compliance with security policies and procedures. Lead regular internal audits to assess the effectiveness of the ISMS. Recommend and implement improvements based on audit findings, risk assessments, and evolving industry practices. Keep up-to-date with emerging threats, vulnerabilities, and regulatory changes. Vendor and Third-Party Risk Management: Assess and monitor third-party vendors and service providers for information security compliance. Assist in the integration of ISMS controls into third-party contracts and SLAs. Key Relationships: This role plays a critical role in managing and maintaining relationships with both internal and external stakeholders. These interactions are essential for ensuring the organization’s security posture is robust and aligned with its strategic objectives. Qualifications and Experience Bachelor’s Degree in information security, Computer Science, Information Technology, or a related field. Mandatory Requirement: ISO27001 Lead Implementer. Preferred: ISO27001 Lead Auditor, Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA). Robust combination of technical expertise, specialized knowledge, and strong leadership abilities. Intrinsic understanding of the ISMS statement of applicability. In-depth knowledge of information security frameworks such as ISO/IEC 27001, NIST, and CIS Controls. Familiarity with IT governance frameworks (e.g., COBIT, ITIL) and extensive experience in risk management, incident response, and compliance, particularly with South African regulations like POPIA and the Cybercrimes Act. Soft skills such as excellent communication, adaptability, attention to detail, and ethical judgment are also vital. Minimum of 7-10 years of experience in the field of information security, cybersecurity, or a related discipline, with at least 1-3 years in a managerial or leadership capacity. Proven experience leading ISO/IEC 27001 certification projects and certification maintenance. Experience working with ISO27001 certification bodies. Development of audit and ISMS remediation plans. Familiarity with data protection laws and industry regulations. Relevant professional certifications such as CISM, CRISC, or CISA. Knowledge of security tools, including Microsoft Sentinel, CyberReason, and Microsoft Defender. Skills and Competencies Strategic Thinking: Align security strategies with business objectives and anticipate future challenges. Technical Expertise: Knowledge of security frameworks, technologies, and tools with strong proficiency in threat analysis and mitigation. People Management: Strong leadership skills to build, manage, and effectively leverage external resources. Decision-Making and Judgment: High discretion in making critical security decisions, balancing immediate needs with long-term goals. Collaboration and Communication: Excellent interpersonal skills for engaging with both technical and non-technical stakeholders. Problem-Solving and Analytical Skills: Strong analytical abilities to assess and resolve complex security issues across organizational boundaries. Compliance and Regulatory Knowledge: In-depth understanding of relevant regulations and standards, ensuring ongoing compliance. Adaptability and Resilience: Ability to adapt to changing security landscapes and manage high-pressure situations. Ethical Integrity: Commitment to upholding the highest ethical standards in all security practices. Seniority level Mid-Senior level Employment type Full-time Job function Information Technology Industries Transportation, Logistics, Supply Chain and Storage #J-18808-Ljbffr
-
Information Security Manager
4 days ago
Midrand, Gauteng, South Africa Boardroom Appointments Full time R1 800 000 - R2 500 000 per yearInformation Security ManagerMinimum Requirements:A bachelors degree in Computer Science or Information Technology.Completed Cyber Security or an equivalent qualification.Professional certifications such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM) (Negotiable).3-5 years of experience in...
-
Information Security Manager
4 days ago
Midrand, Gauteng, South Africa Boardroom Appointments Full time R1 200 000 - R2 400 000 per yearInformation Security ManagerResponsibilitiesStrategic Leadership & GovernanceDevelop and maintain The Companys enterprise-wide cybersecurity strategy aligned with business objectives and regulatory requirements.Establish and enforce security governance frameworks, policies, and standards.Ensure alignment with the NIST Cybersecurity Framework (Identify,...
-
Cyber Security Specialist
1 week ago
Midrand, South Africa Optimal Growth Technologies Full timeSpecialist Cyber Security (Governance, Risk and Compliance) Location: Midrand Duration: 12 months Key Accountabilities and Decision Continually review and update security policies, standards, and guidelines in response to the ever-changing cyber threats in coordination with Enterprise Risk Management team. Core competencies, knowledge and experience:...
-
Principal Specialist Cyber Security
2 weeks ago
Midrand, South Africa Cell C Full timePrincipal Cyber Security Specialist At Cell C, we are not just a telecommunications company; we are a people‑centric, consumer‑focused organization committed to delivering exceptional experiences to our customers. In line with our dedication to customer‑centricity, we are seeking a seasoned professional Principal Specialist: Cyber Security to join our...
-
Cyber Security Specialist
1 week ago
Midrand, Gauteng, South Africa Optimal Growth Technologies Full time R1 200 000 - R2 400 000 per yearSpecialist Cyber Security (Governance, Risk and Compliance) Location: Midrand Duration: 12 months Key Accountabilities and Decision Continually review and update security policies, standards, and guidelines in response to the ever-changing cyber threats in coordination with Enterprise Risk Management team. Core competencies, knowledge and experience:...
-
Cyber Security Specialist
4 days ago
Midrand, Gauteng, South Africa Optimal Growth Technologies Full time R600 000 - R1 200 000 per yearSpecialist Cyber Security (Governance, Risk and Compliance)Location: MidrandDuration: 12 months Key Accountabilities and Decision Continually review and update security policies, standards, and guidelines in response to the ever-changing cyber threats in coordination with Enterprise Risk Management team. Core competencies, knowledge and experience:...
-
Midrand, South Africa PSG Konsult Ltd. Full time**Designation**: - Information Security Manager | Waterfall, Midrand, Gauteng | Permanent **Category**: - Information Technology **Job Level**: - Professionally qualified and experienced specialists and mid-management **Posted by**: - PSG Financial Services **Posted on**: - 03 Oct 2025 **Reference Number**: - POS08450 **Closing date**: -...
-
Cyber Security Specialist
4 weeks ago
Midrand, South Africa Optimal Growth Technologies Full timeCyber Security Specialist (Governance, Risk & Compliance) Job Openings Cyber Security Specialist (Governance, Risk & Compliance) About the job Cyber Security Specialist (Governance, Risk & Compliance) Specialist Cyber Security (Governance, Risk and Compliance) Duration: 12 months Key Accountabilities and Decision Continually review and update security...
-
Specialist – Cyber Security Assurance
1 week ago
Midrand, South Africa A 1 L Full timeOur client in the telecommunications sector is looking for a Specialist Cyber Security Assurance on a contract duration of 12 months. Key Skills and Qualifications Experience : Minimum of 3 years in penetration testing or ethical hacking. Certifications : Strongly preferred certifications like OSCP (Offensive Security Certified Professional) CEH (Certified...
-
Cyber Security Specialist
4 weeks ago
Midrand, South Africa Optimal Growth Technologies Full timeCyber Security Specialist (Governance, Risk & Compliance) Job Openings Cyber Security Specialist (Governance, Risk & Compliance) About the job Cyber Security Specialist (Governance, Risk & Compliance) Specialist Cyber Security (Governance, Risk and Compliance) Duration: 12 months Key Accountabilities and Decision Continually review and update security...