Head IT Security

3 weeks ago


Johannesburg, South Africa Network Contracting Full time

**HEAD: IT SECURITY, GOVERNANCE, RISK & COMPLIANCE**
The Head of IT Security and GRC is responsible for overseeing the organisation's information security program and ensuring compliance with governance, risk management, and regulatory requirements. This senior leadership role will develop and implement a comprehensive security strategy, manage a team of IT security and GRC professionals, and work closely with various departments to minimize risks and protect the organisation from potential security threats. The Head of IT Security and GRC will also be responsible for driving a security-aware culture and maintaining a strong governance framework throughout the organisation.

**Key performance areas / Key responsibilities**:

- Security Strategy and Governance: Develop and maintain a comprehensive IT security and GRC strategy, aligned with the organisation's goals and objectives, ensuring a strong governance framework is in place.
- Policy and Compliance Management: Establish, review, and enforce IT security and GRC policies, procedures, and standards, ensuring they comply with industry best practices and regulatory requirements.
- Risk Assessment and Management: Regularly assess, identify, and prioritize potential security risks and vulnerabilities, implementing appropriate risk mitigation measures and controls.
- Incident Response and Management: Lead the organisation's incident response team, ensuring efficient detection, containment, and resolution of security incidents, as well as conducting post-incident analysis to improve response strategies.
- Security Awareness and Training: Promote a security-aware culture within the organisation through continuous education, training, and awareness programs for employees at all levels.
- Performance Monitoring and Reporting: Regularly monitor and evaluate the effectiveness of the IT security and GRC programs, providing reports to senior leadership on progress, risks, and areas of improvement.
- Vendor and Third-Party Management: Ensure that external vendors, partners, and service providers comply with the organisation's security policies, standards, and regulatory requirements.
- Audit and Assessment: Oversee IT security and GRC audits, vulnerability assessments, and penetration testing, ensuring timely remediation of identified issues and compliance with relevant regulations.
- Budget and Resource Management: Manage the budget and resources for the IT Security and GRC department, ensuring effective allocation and utilization to support the organisation's security goals.
- Continuous Improvement and ownership: Keep abreast of emerging security trends, platforms, technologies, and threats, and make recommendations for improving the organisation's security posture and GRC framework.
- Gap Identification and Solution Implementation: Proactively identify gaps in the organisation's IT security and GRC framework by conducting thorough assessments and research. Evaluate, select, and implement appropriate solutions to mitigate these gaps, ensuring seamless integration and ongoing maintenance to strengthen the organisation's security posture and compliance efforts.
- Ownership and Accountability: Assume full ownership and accountability for the organisation's IT security and GRC programs, ensuring that all initiatives are executed effectively and in accordance with established policies, procedures, and standards. Act as the primary point of contact for all IT security and GRC-related matters, demonstrating a strong commitment to protecting the organisation's digital assets, infrastructure, and information while maintaining compliance with regulatory requirements.
- Team Management and Leadership: Lead, mentor, and develop a high-performing team of IT security and GRC professionals, fostering a culture of collaboration and excellence.

Able to effectively communicate at various levels
- Likely to engage often with the following individuals/ groups:

- Chief Information Officer
- Executives
- Departmental Heads
- Other key external stakeholders

**EDUCATION**:
**MINIMUM QUALIFICATIONS**
- Bachelors degree in computer science, Information Technology, or a related field

**DESIRED/ PREFERRED REQUIREMENTS**
- Masters Degree
- CISSP, CISM, CISA

**MINIMUM REQUIREMENTS**
- A minimum of 10 years of experience in information security, with at least 5 years in a management/leadership role.
- A minimum of 7 years of experience in a technical or specialist information security role.

**INDUSTRY EXPERIENCE**
- Financial industry preferred
- Exposure to it Strategic Planning and Implementation
- Sourcing and managing suppliers

**DESIRED/ PREFERRED REQUIREMENTS**
- In-depth knowledge of IT security principles, best practices, and industry standards, including experience with regulatory compliance (e.g., POPIA, GDPR, HIPAA, ISO 27001).
- Demonstrated ability to manage a team of IT security professionals, and effectively collaborate with stakeholders at all levels of the organisation.
-


  • Head of Security

    4 weeks ago


    Johannesburg, South Africa Elite Search and Selection Full time

    Gauteng, JHB - Northern Suburbs - R 1 000 000 - R 1 200 000 Annually Cost To Company- Role: The Head of Security (HoS) Location: Illovo A leading and innovative telco is looking for a Head of Security who will be responsible for establishing and maintaining their organisation's information security program. The HoS will be a Cybersecurity expert, entrusted...

  • Head of Security

    2 weeks ago


    Johannesburg, Gauteng, South Africa Elite Search and Selection Full time

    Gauteng, JHB - Northern Suburbs R R Annually Cost To Company Role: The Head of Security (HoS)Location: IllovoA leading and innovative telco is looking for a Head of Security who will be responsible for establishing and maintaining their organisation's information security program. The HoS will be a Cybersecurity expert, entrusted with safeguarding sensitive...


  • Johannesburg, Gauteng, South Africa Job Masters Full time

    Head of Critical Services, Security, Risk or National Security - National and Across Border Vehicle Recovery Operations AA/EE JHB North Minimum requirements:Post Graduate Degree in Operations Management or Business Management (Management Development Programme will be advantageous)Around 8 years of operational management experience gained within the private...


  • Johannesburg, Gauteng, South Africa Job Masters Full time

    Head of Critical Services, Security, Risk or National Security - National and Across Border Vehicle Recovery Operations AA/EE JHB North Minimum requirements:Post Graduate Degree in Operations Management or Business Management (Management Development Programme will be advantageous)Around 8 years of operational management experience gained within the private...


  • Johannesburg, South Africa Energy at Work Projects Full time

    Head of IT Security and GRC is responsible for overseeing the organisation's information security program and ensuring compliance with governance, risk management, and regulatory requirements. This senior leadership role will develop and implement a comprehensive security strategy, manage a team of IT security and GRC professionals, and work closely with...


  • Johannesburg, Gauteng, South Africa Recru-it Full time

    Key Roles and Responsibilities:Determine who requires access to which information & Plan, coordinate, and implement information security programs.Help protect against Web threats that facilitate cyber-crime like malware, phishing, viruses, denial-of service attacks, and hacking.Ensure you know and follow the incident and change processes, Perform Problem...


  • Johannesburg, Gauteng, South Africa Energy at Work Projects Full time

    Head of IT Security and GRC is responsible for overseeing the organisation's information security program and ensuring compliance with governance, risk management, and regulatory requirements. This senior leadership role will develop and implement a comprehensive security strategy, manage a team of IT security and GRC professionals, and work closely with...


  • Johannesburg, South Africa Absa Bank Limited Full time

    Bring your possibility to life! Define your career with us - With over 100 years of rich history and strongly positioned as a local bank with regional and international expertise, a career with our family offers the opportunity to be part of this exciting growth journey, to reset our future and shape our destiny as a proudly African group.Job Summary The...

  • Cloud Security Manager

    2 months ago


    Johannesburg, South Africa IT Ridge Technologies Full time

    The main purpose of this position is to manage the Cloud Security Section within the Cyber Security Operations (CSO) Division and act as a liaison to the Business Solutions and Technology Department (BSTD) and business stakeholders to enable execution against cloud and emerging technology security controls and standards, across the Group. **Detailed...


  • Johannesburg, South Africa My It Crew Full time

    **This is an in-office position.** Ready to get off the IT machine and come be part of a team where you are more than a cog in the wheel? My IT Crew is the place where everyone gets a voice and new ideas are welcomed. Sound like this could be your new home? Keep reading. My IT Crew has been a leader in the Managed Service provider space since 2016. We...


  • Johannesburg, South Africa South African Bankers Services Company Pty Ltd Full time

    **Job Description**: BankservAfrica form part of the South African National Payments System and are a trusted partner of the financial industry, including banking institutions, and therefore require that employees adhere to unwavering standards of honesty and transparency in performing their duties. **PURPOSE** The main purpose of the Head Facilities and...


  • Johannesburg, Gauteng, South Africa Numata Business IT Full time

    Service Desk Engineers provide IT end-user support on variouscomponents of an IT environment, including but not limited to, hardwaresupport, software support and network support. Being the first point of contactfor clients, you are expected to be professional, helpful, and to provideassistance with a sense of urgency, regardless of the level of incident....


  • Johannesburg, South Africa Absa Bank Limited Full time

    Bring your possibility to life! Define your career with us - With over 100 years of rich history and strongly positioned as a local bank with regional and international expertise, a career with our family offers the opportunity to be part of this exciting growth journey, to reset our future and shape our destiny as a proudly African group.Job Summary An...


  • Johannesburg, South Africa IT Ridge Technologies Full time

    **Detailed Description** - Contribute to the compilation of divisional operational plans and take responsibility for the implementation as well as the monitoring thereof. - Manage and direct the development and maintenance of the secure Software Development Life Cycle procedures and standards based on the environment and manage the implementation thereof,...


  • Johannesburg, South Africa IT Ridge Technologies Full time

    **Detailed description** - Contribute to the compilation of divisional operational plans and take responsibility for the implementation as well as the monitoring thereof - Manage and direct the development and maintenance of the secure Software Development Life Cycle procedures and standards based on the environment and manage the implementation thereof,...


  • Johannesburg, Gauteng, South Africa IT Ridge Technologies Full time

    Detailed description Contribute to the compilation of divisional operational plans and take responsibility for the implementation as well as the monitoring thereof Manage and direct the development and maintenance of the secure Software Development Life Cycle procedures and standards based on the environment and manage the implementation thereof, ensuring...


  • Johannesburg, Gauteng, South Africa Telebest Full time

    Requirements:8 years' working in Cyber Security of which:5 years has been managing security operations and teams.3 years has been managing IT Security supplier performanceExpert knowledge of Information Security tools and techniques, IT Governance standards and methodologies, Information Security legislation and regulations and software development...

  • Security Manager

    4 weeks ago


    Johannesburg, South Africa Ericsson Full time

    **About this opportunity!** We are looking for a Security Manager who will be responsible for managing security risks and activities for Ericsson in countries under Customer Unit (CU) across South Africa, Nigeria, Ghana, Cameroon & Congo Brazzaville. The CU security manager reports to the Head of Security Operations, MMEA and supports, and liaises closely...


  • Johannesburg, Gauteng, South Africa Telebest Full time

    Requirements:8 years' working in Cyber Security of which:5 years has been managing security operations and teams.3 years has been managing IT Security supplier performanceExpert knowledge of Information Security tools and techniques, IT Governance standards and methodologies, Information Security legislation and regulations and software development...


  • Johannesburg, South Africa Telebest Full time

    Requirements:8 years' working in Cyber Security of which:5 years has been managing security operations and teams.3 years has been managing IT Security supplier performanceExpert knowledge of Information Security tools and techniques, IT Governance standards and methodologies, Information Security legislation and regulations and software development...