Principal Specialist Cyber Security Grc

3 weeks ago


Midrand, South Africa Vodafone Full time

**Role purpose**:
Defining Cyber Governance, Risk & Compliance to:
To lead the ongoing evaluation of security policies, and relevant standards and support the continuous improvement of the security governance program.
To ensure that comprehensive Information Security Risk management programs are established.
Ensure the alignment of Information Security Risk management with the enterprise risk management framework.
To lead in the risk management of cyber security risks while collaborating with other departments to identify, recommend, develop, implement, and support a risk-informed decision and action framework.
To provide Management with assurance covering controls across the Business environments that there are adequately designed and operating effectively.
To support Management during audits as well as implement and track Management audit actions to closure.
Assist in the management and rollout of cyber-Training & Awareness initiatives.
Provide Management with status update reports as well as insight reporting.

**Your responsibilities will include**:
Take a proactive approach to ongoing evaluation of cyber security policies to ensure security policy adherence.
Promote awareness of security policies, training, and the governance strategy amongst all levels of the organization to ensure sound security governance is reflected across the organization.
Maintain and further develop the Cyber Risk Management Program.
Actively manage risks on the Cyber Risk Register from intake to resolution.
Communicate risk assessment findings with key stakeholders to develop and monitor risk remediation plans.
Develop cyber risk portfolios to provide a more holistic view of teams’ risks.
Conduct regular compliance assessments with the Business to ensure that current and emerging risks are being monitored and managed.
Proactive Control design and implementation guidance provided to the Business.
Process and Control Compliance Monitoring and Reporting.
Cyber audit SPOC to the business with guidance on all audit submissions.
Cyber audit report reviews and guidance to Management on the recommended actions.
Tracking and monitoring of audit remediation action implementation.
Deploying cyber security awareness training collateral with innovative approaches.
Design of status reports as well as insight reporting as and when required by Management.
Lead reporting development with the use of automation and reporting tools to generate Cyber Risk metrics, i.e. KPI, KRI’s, KGI’s (KSI).

**Ideally you should possess the following**:
Matric/Grade 12 is essential.
Degree\Relevant tertiary qualification in Information technology and Minimum of 8 + years of experience in a Tech Security role where you meet business deliverables.
8+ years experience in cyber governance, risk, controls, and compliance management in a technology environment.
8+ years experience in IT Audit and Assurance management in a Cyber or technology environment.
Knowledge of common information technology management/compliance frameworks such as ISO/IEC 27001, SOC 2, SOX, ITIL, COBIT, and NIST.
Knowledge of legal, regulatory, and privacy requirements, such as Personally Identifiable Information (PII) Protection and Payment Card Industry (PCI)/Data Security Standard.
High-level understanding and Knowledge of Cloud Risk, Compliance, and Assurance.
Proven experience managing and operating multiple security programs, projects, and initiatives.
An ability to think strategically and drive change.
A deep understanding of Tech Security risks and mitigating solutions.
GSM Network Infrastructure.
Diverse security background with knowledge in several areas including layered security architecture; internet protocols; firewalls; VPN technologies, IDS/IPS, network access control and network segmentation, anti-malware and spam technologies; risk and vulnerability assessments, and compliance.
Security concepts related to DNS, routing, authentication, VPN, proxy services, and DDOS mitigation technologies.
Windows, UNIX, and Linux operating systems.
Web Security & Encryption.
Strong organizational skills and an entrepreneurial drive with a history of recruiting and developing high-performing teams.
Ability to build and manage a highly motivated and innovative technical team.
Ability to work under time and resource pressure.
An ability and desire to communicate and work with a broad set of stakeholders.
A customer-focused, responsive, and transparent attitude.
Grasping technical concepts rapidly and the ability to articulate these concepts to technical and non-technical audiences.
Skilled in communicating with all levels of management.

Desired:
An industry certification e.g. ISO 27001 Lead practitioner, CGEIT, CRISC, CISA, CISM, and CISSP is strongly preferred.

**Closing date for Applications: 03 March 2023.**

The base location for this role is **Midrand, Vodacom Campus.**

The Company’s approved Employment Equity Plan and Targets will be considered as part of the recruitment process



  • Midrand, South Africa Vodafone Full time

    **Role Purpose**: The primary purpose of the role is to support Cyber GRC functions which are all interdependent and would require good teamwork. To ensure the best delivery, exposure and create backfill capability with succession planning, the role and function for a Cyber GRC specialist would require expertise in the following areas broadly covered...


  • Midrand, South Africa TalentCru Full time

    Our company in the telecommunication industry is seeking an experienced and highly skilled Cyber Security Principal Lead or Specialist to oversee our cyber security strategies and initiatives within the financial services, insurance, and lending sector. The ideal candidate should have a deep understanding of cyber security practices and trends and possess...


  • Midrand, South Africa TalentCru Full time

    Our company in the telecommunication industry is seeking an experienced and highly skilled Cyber Security Principal Lead or Specialist to oversee our cyber security strategies and initiatives within the financial services, insurance, and lending sector. The ideal candidate should have a deep understanding of cyber security practices and trends and possess...


  • Midrand, South Africa Adzuna ZA B C2 Full time

    Our company in the telecommunication industry is seeking an experienced and highly skilled Cyber Security Principal Lead or Specialist to oversee our cyber security strategies and initiatives within the financial services, insurance, and lending sector. The ideal candidate should have a deep understanding of cyber security practices and trends and possess...


  • Midrand, South Africa TalentCru Full time

    Our Client in the Telecommunications industry is hiring for a Cyber Security Specialist as an Independent Contractor for 12 months. This role will allow you to gain experience in working with one of the largest telecommunications companies in South Africa. The ideal candidate to come from or worked with clients in the  : Financial Services /...


  • Midrand, South Africa TalentCru Full time

    Our Client in the Telecommunications industry is hiring for a Cyber Security Specialist as an Independent Contractor for 12 months. This role will allow you to gain experience in working with one of the largest telecommunications companies in South Africa.The ideal candidate to come from or worked with clients in the  : Financial Services /...


  • Midrand, South Africa Adzuna ZA B C2 Full time

    Our Client in the Telecommunications industry is hiring for a Cyber Security Specialist as an Independent Contractor for 12 months. This role will allow you to gain experience in working with one of the largest telecommunications companies in South Africa.The ideal candidate to come from or worked with clients in the : Financial Services /...


  • Midrand, South Africa A 1L Realization (Pty) Ltd Full time

    Desirable:An industry certification e.g. ISO 27001 Lead practitioner, DEVSECOPS, CCSP CGEIT, CRISC, CISA, CISM and CISSP is strongly preferred. Requirements:Degree\Relevant tertiary qualification in Information technology and Minimum of 8 + years of experience in Cyber Security role where you meet business deliverables. At least 8+ years experience in cyber...


  • Midrand, South Africa Adzuna ZA B C2 Full time

    Desirable:An industry certification e.g. ISO 27001 Lead practitioner, DEVSECOPS, CCSP CGEIT, CRISC, CISA, CISM and CISSP is strongly preferred.Requirements:Degree\Relevant tertiary qualification in Information technology and Minimum of 8 + years of experience in Cyber Security role where you meet business deliverables.At least 8+ years experience in cyber...


  • Midrand, South Africa A 1L Realization (Pty) Ltd Full time

    Desirable:An industry certification e.g. ISO 27001 Lead practitioner, DEVSECOPS, CCSP CGEIT, CRISC, CISA, CISM and CISSP is strongly preferred.Requirements:Degree\Relevant tertiary qualification in Information technology and Minimum of 8 + years of experience in Cyber Security role where you meet business deliverables.At least 8+ years experience in cyber...


  • Midrand, South Africa Nexio Full time

    **ROLE REQUIREMENT** - To increase security threat detection capability and defence effectiveness in the Security Assessment Team, and SOC Team in their engagements with customers. - Provides support for Nexio Offensive Security capabilities for the Security Assessment Team, and SOC Team for customers’ engagements. - Direct impact on business resilience...


  • Midrand, South Africa Vodafone Full time

    **Role purpose**: Cyber Defence is one of MPA’s critical Cyber Security teams. The Cyber Defence team’s mission is to deliver a highly effective end to end 24x7 Cyber Defence service. They are responsible for proactively identifying threats and vulnerabilities; detecting and mitigating cyber events; and managing cyber security incident responses to...


  • Midrand, South Africa Vodafone Full time

    **Role purpose**: Principal Specialist - Cyber Security Operations will provide the leadership to resources across Vodacom Group ensuring cyber security operations is proactively managed and implemented across all entities. Partner with other Cyber Security stake holders to align goals and priorities with security platforms/feeds, processes and intelligence...


  • Midrand, South Africa Vodafone Full time

    **Role purpose**: The primary purpose of the role is to work within a team of Secure by Design and Security Architecture specialists, in collaboration with the Privacy and Business Risk Teams to Perform Secure by Design Assessments against Vodacom policies and standards. **In performing this **role,** you will**: Identify potential cyber security risks for...


  • Midrand, South Africa Vodafone Full time

    **Role purpose**: The primary purpose of the role is to work within a team of Secure by Design and Security Architecture professionals, in collaboration with the Privacy and Business Risk Teams to Perform Secure by Design Assessments against Vodacom policies and standards. In performing this role you will Identify potential cyber security risks for new...


  • Midrand, South Africa Network Contracting Full time

    **Role Purpose**: The purpose of the role is to manage and lead the Technology Security Cyber Security Baseline Assurance. To further provide security assurance, guidance and support to high profile projects according to company defined policies and requirements, best practice and local/international standards (PCI, SOX, ISO27001, GDPR, POPIA and Cyber Crime...


  • Midrand, South Africa Vodafone Full time

    **Role purpose**: Cyber Defence is one of MPA’s critical Cyber Security teams. The Cyber Defence team’s mission is to deliver a highly effective end-to-end 24x7 Cyber Defence service. They are responsible for proactively identifying threats and vulnerabilities; detecting and mitigating cyber events, and managing cyber security incident responses to...


  • Midrand, South Africa Vodafone Full time

    **Role purpose**: The primary purpose of the role is to work within a team of Secure by Design and Security Architecture specialists, in collaboration with the Privacy and Business Risk Teams to Perform Secure by Design Assessments against Vodacom policies and standards. **Your responsibilities will include**: Provide technology security assurance, guidance...


  • Midrand, South Africa Vodafone Full time

    **Role purpose**: **Your responsibilities will include**: Provide supervisory technology security assurance, guidance, and support to the Vodacom Group. Assure that security is embedded in IT systems and Network Infrastructure (Mobile, IS, and Enterprise) across the Vodacom Group. Defining, implementing, and efficiently maintaining technology security...


  • Midrand, South Africa Gijima Holdings Full time

    EXPERIENCE: + 10 years experience in IT industry + 5 years experience in Technical Information Security positions Alignment and experience with good practices essential (CoBIT, ISO17799 or equivalent) Understanding of network protocols, cryptography, operating systems, and security tools is essential The ability to analyze data, identify patterns, and draw...