Business Information Security Officer

2 weeks ago


Bellville, South Africa Sanlam Full time

What will you do?
The Business Information Security Officer (BISO) is responsible for identifying and assessing the Information Security requirements of the business. The BISO in conjunction with the Business CIO, is responsible for the establishment and maintenance of an Information Security Management System (ISMS) and ensure that the appropriate Information Security controls are implemented, maintained and aligned with the Group Governance requirements (i.e. Policies, Standards, Procedures and Guidelines and Cyber Resilience Framework). The BISO is responsible for Security Awareness, Information Risk Management and translating risks and the effect thereof to Lines of Business to ensure informed risk assessment. Other responsibilities include: Participation in Group Information Security bodies and initiatives, logical access management, incident response, vulnerability management, IT audit coordination, ensuring new systems adhere to security policy and Providing management assurance regarding the Cyber and Information Security posture of the Business. What will make you successful in this role?
Establish and manage a Business Information Security Programme, effective participation in Group Information Security Programme (GISP) initiatives, Information Security Incident response and Cyber Crisis Management, Information Security Governance and assurance, Application (including cloud) and Infrastructure Security, and Cybersecurity Education, Training and Awareness.
The BISO will implement processes and controls as agreed with the CISO and the Business CIO. The BISO will be responsible for quality and cost effectiveness of delivery of information security services in the BU and will report on these metrics to the GISP.
Outputs
Regular feedback to Business Manco on Group-wide information security issues.
The BISO must have an action plan to implement these initiatives in the Business.
The BISO will report to the GISP Manager on new initiatives, plans and progress which will be discussed at the Cyber Steering Committee.
Review and improve existing IT and Information Risk assessment, reporting and management practices.
Up to date and complete Business IT and Information Security Risk register.
Documented Security risk management action plan. This must include relative priorities of agreed actions; Ownership of the actions; Agree timelines. Priorities will be aligned to Business and GISP priorities.
Up to date and complete Business Cloud register (if these services are used in the Business).
Review and respond to Policies, Standads, Procedures and Guidelines and Risk Acceptance requests within the agreed time.
Document processes and artefacts that prove that the relevant Governance and Assurance processes were implemented as designed.
Clear and timely communication to management and users regarding planned group awareness campaigns.
Risk assessment that identifies a requirement for additional awareness or targeted education, training and awareness interventions.
Maintenance of Business/ Cluster and alignment with the Group annual security education, training and awareness plan.
Documented Logical Access review schedule for Line of Business Applications, review results, facilitate resolution, progress report on resolution of issues that were identified during the reviews.
Provide management comment to the audit observations/ findings, that is specific as far as actions and due dates are concerned.
Track and follow up on audit finding commitments.
Report all cyber security incidents, or information security incidents (including privacy related incidents) where the compromise was through technology to the SGT CSIRT.
Be contactable or provide alternative contact details for Cybersecurity incidents that are identified by the SGT CSIRT.
Ensure appropriate actions are taken when policy breaches are identified in the Business.
Assist by facilitating engagement and communication with key stakeholders in the Cluster during a major incident.
Provide context on system and process criticality.
Produce Quarterly Group ISO Forum and GISP reports.
Provide input into requirements documents - ensure security roles; auditing; data protection (in transit and rest); monitoring etc. are defined in line with approved. Information Security policies and standards.
Ensure that Security 'gates' are a formal part of the SDLC/ Agile/ relevant solution development methodology.
Interventions and role-players must be clearly specified.
Active participation in Sanlam sanctioned industry bodies (e.g. ISF Live, ISACA).
Timeous escalation of new, high or escalating risks.
Facilitate workshops and risk documentation during Control Self Assessments, or Crown Jewel Risk Assessment processes.

**Qualifications**:
Grade 12
Bachelor’s degree in Information Technology, Commerce, Science, or Social Science (preferable).
In force Information Security Certifications such as CISM, CISSP, CCSP, CISA, ISO 27000 Lead Implementer/ Auditor. Experience and Knowl



  • Bellville, South Africa Progressive IT Resourcing Full time

    **What will you do?** The Business Information Security Officer (BISO) is responsible for identifying and assessing the information security requirements of the business. The BISO in conjunction with the Business CIO, is responsible for the establishment and maintenance of an Information Security Management System (ISMS) and ensure that the appropriate...


  • Bellville, South Africa Sanlam Full time

    **CAREER OPPORTUNITY** - Santam BITS has a career opportunity for a senior role of Business Information Security Officer (BISO) in the Business Information and Technology Services (BITS) department which will be based in the Western Cape or Gauteng. **KEY RESPONSIBILITIES** - Establish and manage a Santam Business Unit (SBU) Information Security...


  • Bellville, South Africa Sanlam Full time

    What will you do? The Business Information Security Officer (BISO) is responsible for identifying and assessing the information security requirements of the business. The BISO in conjunction with the Business CIO, is responsible for the establishment and maintenance of an Information Security Management System (ISMS) and ensure that the appropriate...


  • Bellville, Western Cape, South Africa Sanlam Full time

    Santam BITS has a career opportunity for a senior role of Business Information Security Officer (BISO) in the Business Information and Technology Services (BITS) department which will be based in the Western Cape or Gauteng.KEY RESPONSIBILITIESEstablish and manage a Santam Business Unit (SBU) Information Security Programme.Implement cybersecurity awareness...


  • Bellville, Western Cape, South Africa Sanlam Full time

    Santam is looking for a Business Information Risk Officer to join its Business Information and Technology Services (BITS) department. As a senior role, this position will be based in the Western Cape or Gauteng.Responsibilities:Develop and implement a comprehensive information security programme to protect Santam's business operations and assets.Work closely...


  • Bellville, South Africa University of the Western Cape Full time

    **A.** **Information Security Governance** i. Establish, communicate and maintain information security policies, standards, procedures and other documentation that support information security, ii. Facilitate the development of an information security strategy aligned with the University’s IT governance model and its strategic goals and objectives, iii....


  • Bellville, Western Cape, South Africa Sanlam Full time

    Santam seeks an experienced Information Security Expert to join its Business Information and Technology Services (BITS) department. As a senior role, this position will be based in the Western Cape or Gauteng.Key Responsibilities:Establish and manage a Santam Business Unit (SBU) Information Security Programme to ensure effective risk management and...


  • Bellville, South Africa Sanlam Full time

    Who are we? Sanlam Group Technology is responsible for the provision of a digitally enabled technology service as a group COE, drive business and transformation and provide group-wide digital and data architecture. We operate the various technology platforms and shared services, ensure Cyber and Information Security resilience, and act as technology...


  • Bellville, South Africa Sanlam Full time

    **What will you do?** - Assisting, performing and reporting on key information security activities such as: - Reporting and follow ups with regards to Anti-Malware, Anti-Virus, Security patching of all IT related hardware/software. - Investigate and resolve logical access incidents. - Provide afterhours & weekend support as part of project involvement and...


  • Bellville, South Africa Sanlam Full time

    Who are we? Sanlam Group Technology is responsible for the provision of a digitally enabled technology service as a group COE, drive business and transformation and provide group-wide digital and data architecture. We operate the various technology platforms and shared services, ensure Cyber and Information Security resilience, and act as technology...


  • Bellville, South Africa Sanlam Full time

    What will you do? Responsible for providing operational information technology security support to ensure that the organisation is not compromised in any way. Conducts necessary housekeeping as required. What will make you successful in this role? **Logical Access Administration**: Service new requests to create, adjust and remove users and access on the...


  • Bellville, South Africa Sanlam Full time

    Who are we? Sanlam Group Technology is responsible for the provision of a digitally enabled technology service as a group COE, drive business and transformation and provide group-wide digital and data architecture. We operate the various technology platforms and shared services, ensure Cyber and Information Security resilience, and act as technology...


  • Bellville, South Africa Progressive IT Resourcing Full time

    Responsible for providing operational information technology security support to ensure that the organization is not compromised in any way. **Permanent, Cape Town based** **Role Responsibilities** **Logical Access Administration**: Service new requests to create, adjust and remove users and access on the following environments: - Microsoft Active...


  • Bellville, Western Cape, South Africa Kontak Recruitment Full time

    Chief Information Officer (JB5139)Bellville, Cape TownSalary: NegotiablePermanentSeeking an experienced Chief Information Officer (CIO) to drive strategic IT initiatives and enhance business operations through technology in the insurance industry.Reporting directly to the CEO, this role requires a visionary leader with strong technical acumen and strategic...


  • Bellville, South Africa Xone Integrated Security (Pty) Ltd. Full time

    Xone Intergrated Security is seeking to employ a qualified and skilled Security supervisor for one of our sites located in the bellville/Durbanville area Registered PSIRA Grade A Clear Criminal Record Minimum 5 years Access control / Security experience. Minimum 2 years CCTV control room experience Minimum 2 years Supervisory / management experience /...


  • Bellville, South Africa Tafelberg Furniture Stores Full time

    **SECURITY/CUSTOMER CARE OFFICER** We are currently seeking to employ a Security/Customer Care Officer for our Bellville branch. - Meeting customers at the door - Checking invoices and scanning out products before customer leaves the store - Directing customers to correct salesperson - Patrolling of grounds/shop floor - Conducting searches - Opening and...


  • Bellville, South Africa Tafelberg Furniture Stores Full time

    **SECURITY/CUSTOMER CARE OFFICER** We are currently seeking to employ a Security/Customer Care Officer for our Bellville branch. - Meeting customers at the door - Checking invoices and scanning out products before customer leaves the store - Directing customers to correct salesperson - Patrolling of grounds/shop floor - Conducting searches - Opening and...


  • Bellville, South Africa Sanlam Full time

    Who are we? Sanlam Group Technology is responsible for the provision of a digitally enabled technology service as a group COE, drive business and transformation and provide group-wide digital and data architecture. We operate the various technology platforms and shared services, ensure Cyber and Information Security resilience, and act as technology...


  • Bellville, South Africa Tafelberg Furniture Stores Full time

    **SECURITY/CUSTOMER CARE OFFICER** We are currently seeking to employ a Security/Customer Care Officer for our branches across the Northern Suburbs. - Meeting customers at the door - Checking invoices and scanning out products before customer leaves the store - Directing customers to correct salesperson - Patrolling of grounds/shop floor - Conducting...


  • Bellville, South Africa Tafelberg Furniture Stores Full time

    **SECURITY/CUSTOMER CARE OFFICER** We are currently seeking to employ a Security/Customer Care Officer for our Bellville branch. - Meeting customers at the door - Checking invoices and scanning out products before customer leaves the store - Directing customers to correct salesperson - Patrolling of grounds/shop floor - Conducting searches - Opening and...