Business Information Security Officer

18 hours ago


Tygervalley, South Africa Sanlam Full time

**Who are we?**

Glacier by Sanlam brings together leading experts and respected financial services companies to meet clients’ investment needs. We deliver focused investment services through specialist teams, partner with acclaimed financial intermediaries and pride ourselves on our superior products and solutions and high quality service. We offer a comprehensive range of investment solutions, designed to assist in the creation and preservation of wealth. Our offering encompasses local investments, including fixed term investments and investments with guarantees, international investments, retirement saving solutions, and retirement income solutions. While each solution has its own distinct purpose, they all share the world-class quality and commitment that have come to distinguish Glacier.

**What will you do?**
- The Business Information Security Officer (BISO) is responsible for identifying and assessing the cyber and information security requirements of the business. The BISO (with endorsement from the Glacier CIO and Head of IT Operations is responsible for the establishment and maintenance of an Information Security Management System (ISMS) and ensure that the appropriate cyber and information security controls are implemented, maintained and aligned with the Group governance requirements (i.e. PSPGs and Group Cyber Resilience Framework).
- Key Outcomes
- The following outcomes will be expected to be achieved by the BISO:
- Establish and manage a Glacier Information Security Programme
- Implement cybersecurity awareness campaigns.
- Participate in Group Information Security Programme (GISP) initiatives.
- Information Security Governance and assurance
- Document processes and artefacts that prove that the relevant governance and assurance processes were implemented as designed.
- Information Security Incident response and Cyber Crisis Management
- Application (including cloud) and Infrastructure Security, and Cybersecurity Education, Training and Awareness
- The BISO will implement processes and controls as agreed with the Group CISO, GISP and the Business CIO.
- The BISO will be responsible for quality and cost effectiveness of delivery of information security services in the BU and will report on these metrics to the GISP.
- Provide regular feedback to Glacier Manco on Group-wide information security issues.
- The BISO will report to the GISP Manager on new initiatives, plans and progress which will be discussed at the Group Cyber Sub-Committee.
- Review and improve existing IT and Information Risk assessment, reporting and management practices.
- Update the Glacier IT and Information Security Risk register.
- Document security risk management action plan. This must include relative priorities of agreed actions; ownership of the actions; agree timelines. Priorities will be aligned to Glacier and GISP priorities. The BISO must have an action plan to implement these initiatives in Glacier.
- Up to date and complete Glacier cloud technology outsourcing and third-party register (where applicable)
- Review and respond to PSPG and risk acceptance requests within the agreed time.
- What will you do - continued- Clear and timely communication to management and users regarding planned group awareness campaigns. Risk assessment that identifies a requirement for additional awareness or targeted education, training, and awareness interventions.
- Alignment with the Group annual security education, training and awareness plan.
- Document logical access review schedule for Line of Business Applications, review results, facilitate resolution, progress report on resolution of issues that were identified during the reviews.
- Review and respond to all security related audit findings.
- Report all cyber security incidents, or information security incidents (including privacy related incidents) where the compromise was through technology to the SGT CSIRT.
- Be a primary contact for cybersecurity incidents that are identified by the SGT CSIRT
- Ensure appropriate actions are taken when policy breaches are identified in the BU.
- Assist by facilitating engagement and communication with key stakeholders in the Cluster during a major incident.
- Produce Quarterly Group ISO Forum and GISP reports.
- Ensure that security 'gates' are a formal part of the SDLC/ Agile/ relevant solution development methodology.
- Interventions and role-players must be clearly specified.
- Active participation in Sanlam sanctioned industry bodies (e.g. ISF Live, ISACA, FS-ISAC)
- Timeous escalation of new, high or escalating cybersecurity risks.
- Facilitate workshops and risk documentation during Control Self Assessments, or Crown Jewel Risk Assessment processes.
- Find & provide root cause analysis and implement permanent and/or long term fixes for cyber related incidents
- Strong understanding of integration between Workstations and Network/Servers.
- Installations and monitoring of devices using automated tools (e.g. SCCM) & scripting
-



  • Tygervalley, South Africa PSG Insure Full time

    **Job description**: This role requires knowledge of Short-term Insurance processes, business analysis experience in an IT context, and a strong technical background including integrations. The role is responsible for overseeing the Business and System Analysis, Helpdesk (Internal and External), Testing and Infrastructure, and Desktop support functions. In...


  • Tygervalley, South Africa PSG Konsult Full time

    **Head of Information Systems - (Western National Insurance)** This role requires knowledge of Short-term Insurance processes, business analysis experience in an IT context and a strong technical background including integrations. The role is responsible for overseeing the Business and System Analysis, Helpdesk (Internal and External), Testing and...

  • Compliance Officer

    18 hours ago


    Tygervalley, South Africa Sanlam Full time

    Who we are? Sanlam Investments Group is one of South Africa’s largest investment management companies. We have a performance history spanning over 100 years, and offer a range of investment and financial planning solutions to protect and grow the long-term wealth of our clients. **We take particular pride in**: - Sanlam’s longevity and innovation -...


  • Tygervalley, South Africa Sanlam Full time

    Who are we? The Sanlam Retail Affluent business (SRA) is dedicated to empower South Africans in the middle - and upper-income segments to be financially confident, secure and prosperous. With deep client understanding and a focus on excellence in technology, client and intermediary experiences, SRA delivers financial solutions including comprehensive...

  • Compliance Officer I

    2 weeks ago


    Tygervalley, South Africa Sanlam Full time

    **Who we are?** Sanlam Investments Group is one of South Africa’s largest investment management companies. We have a performance history spanning over 100 years, and offer a range of investment and financial planning solutions to protect and grow the long-term wealth of our clients. We take particular pride in: - **Sanlam’s longevity and...


  • Tygervalley, South Africa Sanlam Full time

    **Who are we?** Glacier by Sanlam brings together leading experts and respected financial services companies to meet clients’ investment needs. We deliver focused investment services through specialist teams, partner with acclaimed financial intermediaries and pride ourselves on our superior products and solutions and high quality service. We offer a...


  • Tygervalley, South Africa Sanlam Full time

    Who are we? Glacier by Sanlam brings together leading experts and respected financial services companies to meet clients’ investment needs. We deliver focused investment services through specialist teams, partner with acclaimed financial intermediaries and pride ourselves on our superior products and solutions and high quality service. We offer a...


  • Tygervalley, South Africa Sanlam Full time

    **Who we are?** **Sanlam Investment Group** The Sanlam Investment Group is uniquely equipped and positioned to deliver on its purpose of empowering generations to be financially confident, secure and prosperous. Through our vast in-house expertise and strategic partner networks, we can access all asset classes across the globe, private and public, actively...


  • Tygervalley, South Africa Sanlam Full time

    Who are we? Glacier by Sanlam brings together leading experts and respected financial services companies to meet clients’ investment needs. We deliver focused investment services through specialist teams, partner with acclaimed financial intermediaries and pride ourselves on our superior products and solutions and high quality service. We offer a...


  • Tygervalley, South Africa Sanlam Full time

    **Who are we?** Glacier by Sanlam brings together leading experts and respected financial services companies to meet clients’ investment needs. We deliver focused investment services through specialist teams, partner with acclaimed financial intermediaries and pride ourselves on our superior products and solutions and high quality service. We offer a...