Job title: IT Chief Security Officer
Reporting to:
Salary: To be discussed
Hours: Permanent, Full Time
Location: Midrand, Johannesburg, South Africa
Purpose of the position
The Chief Security Officer is a leadership role responsible for
developing, planning and managing an enterprise-wide information
security and risk management strategy across the organization.The role is to provide vision and leadership for developing and supporting security initiatives.The Chief Security Officer directs the planning and implementation
of enterprise IT security systems and access, data- and cybersecurity,
business operation, and defenses against security breaches and
vulnerability issues.This individual is responsible for auditing existing systems, .
Responsibilities & Duties
Responsibility 1: Information Security Strategy
Define and evangelize the organizational Information Security Strategy and Plan, including the security Architecture. Participate as a member of the senior management team in governance processes of the organization’s security strategies. Develop and communicate security strategies and plans to executive team, staff, partners, customers, and stakeholders.
Responsibility 2: Policies & Compliance
Develop, implement, maintain, and oversee enforcement of policies,
procedures, and associated plans for system security administration,
data security, cyber security and user system access based on
industry-standard best practices. Recommend and implement changes in security policies and practices in accordance with changes in legislation.Collaborate with Business Leaders, CIO, and human resources to
establish and maintain a system for ensuring that security and privacy
policies are met.
Responsibility 3: Analysis and Advisory
Regularly test and analyze the organization’s Information Security
systems in order to inform that planning process, including electronic
discovery and digital forensic investigations. Assess the organization’s infrastructure and data to identify
vulnerabilities caused by weaknesses or flaws in software and hardware
that could expose the infrastructure to a security breach.Evaluates security trends, evolving threats, risks and vulnerabilities and applies tools to mitigate risk as necessary.Evaluate the effectiveness of existing security measures, such as
firewalls, password policies and intrusion-detection systems. They make
recommendations to improve security based on their assessments and
knowledge of current and emerging threats.Identify security risks in the business application systems and remedy where possible.Lead strategic security planning to achieve business goals by
prioritizing defense initiatives and coordinating the evaluation,
deployment, and management of current and future security technologies.Define and communicate corporate plans, procedures, policies, and
standards for the organization for acquiring, implementing, and
operating new security systems, equipment, software, and other
technologiesWork closely with IT department on corporate technology development
to fully secure information, computer, network, and processing systems.Provide relevant input into the design and implementation of
disaster recovery and business continuity plans, procedures, audits, and
enhancements
Responsibility 5: Awareness and Culture
Evangelize and foster an organizational culture of Information Security.Act as advocate and primary liaison for the company’s security
vision via regular written and in-person communications with the
company’s executives, department heads, and end users.Develop and promote an Information Security Training and Awareness campaign
Responsibility 6: Operational Management
Manage the administration of all computer security systems and their
corresponding or associated software, including firewalls, intrusion
detection systems, cryptography systems, and anti-virus software.Manage the administration of the facility’s security systems and
their corresponding equipment or software, including data, access and
cybersecurity equipment and systems.Creatively and independently provide resolution to security problems in a cost-effective manner.Promote and oversee strategic security relationships between
internal resources and external entities, including government, vendors,
and partner organizations
Responsibility 7: General Managerial duties
Develop, track, and control the security services annual operating
and capital budgets for purchasing, staffing, and operations. Provide
input to the organizational budgeting process.Where necessary, supervise recruitment, development, retention, and
organization of security staff in accordance with corporate budgetary
objectives and personnel policies.Ensure a motivated, engaged and competent Information Security team.Manage own continuous growth and education
Academic & Trades Qualifications
Essential Qualifications
Completed three-year tertiary qualification at NQF level 7Security Certifications, including: CEH, CISA, CISSPA
Desirable Qualifications
Work Experience & Skills
Essential Experience
minimum of 10 years of experience in Financial Services5 to 10 years of experience managing and/or directing an IT and/or
security operation in a banking environment, of at least 5 year managing
teams of specialistsProven experience in planning, organizing, and developing IT security and facility security system technologiesExperience in planning and executing security policies and standards developmentSubstantial exposure to data processing, hardware platforms,
enterprise software applications, and outsourced systems, including Data
Warehousing.Experience with systems design and development from business requirements analysis through to day-to-day managementExcellent understanding of project management principlesDemonstrated ability to apply IT in solving security problems.Experience in Stakeholder Management, including vendor management and related SLA management
Desirable Experience
Minimum of 10 years of experience in Financial Services, ideally within leadership rolesCOBIT and or ITIL Certification
Personal Qualities & Behavioral traits
Essential Competencies & Skills
Behavioral Competencies
Excellent written and oral communication skills.Ability to present ideas in business-friendly and user-friendly language.Superior analytical, evaluative, and problem-solving abilities.Excellent interpersonal skills.Strong negotiating skills.Persuasion skills.Conflict Resolution skills.Proven leadership ability, and proven track record to attract and retain talented individualsAbility to motivate in a team-oriented, collaborative environmentAbility to set and manage priorities judiciouslyExceptionally self-motivated and directedKeen attention to detail and strong analytical abilityExceptionally self-motivated and directedExceptional service orientationProbity and Integrity.
Technical Skills:
Excellent knowledge of technology environments, including information security, building security, and defense solutions.Good understanding of key information security technologies and methodologies.Excellent knowledge of cybersecurity for online transactional
systems and the risks involved, as well as knowledge of key defense
areas and capabilities required.
Our client is one of the leading medical insurance groups, and has
released very strong results this year, with its share price rising to
record highs. The culture strongly encourages innovation,
entrepreneurship, and self-leadership. There are strong career
opportunities arising within the multitude of business units in the
company, and in the group. This is a high profile job, which provides
exposure to the medical insurance business and senior management in the
units, with opportunities arising from there.
Should you not receive feedback within 2 weeks of applying, please
accept that you did not qualify for this position. Email responses to Email Address or Email Address