Information Security Analyst
Summary
Monitors and resolves IT security issues across hotels and business units, ensuring system uptime and compliance with security standards like PCI DSS, GDPR/POPI. Manages incident response, patching, and cloud security (Azure) while supporting 24/7 operations and third-party vendors.
Position Detail
Overall Purpose of the Job
Supports the IT functionality of all business units and hotels by providing all internal users with secure solutions to their IT needs. Troubleshoots security issues and identifies security trends so as to ensure ongoing up time of systems. Provides insights into future security trends.
Education (Formal Qualification Required)
Minimum
Grade 12.
National Diploma: IT.
N+.
MCSA: Windows 10 and above.
ITIL Foundations v4.
Security +.
Microsoft 365: Modern Desktop Administrator Associate.
Computer literacy is essential particularly with proficiency in Microsoft Office Suite.
Advantageous
CEH.
Legal Requirements (e.g. Driver’s License, etc.)
Valid driver’s license.
Experience (Minimum Experience Required - Number of years)
Minimum
Incumbent must have at least 4 years' experience in Incident Response, Intrusion Prevention, Cyber Security Techniques, Advanced Server, Advanced Network Support WAN and LAN, Operating Systems, Advanced Azure Support and Virtualisation.
Advantageous
IT experience in hospitality or related industry.
People
May hire new employees when authorised to do so up to the level of Information Systems Support Officer (Security).
Is required to issue verbal/written warnings when necessary and in the event of company policy having been violated. After consultation with the Divisional Director: IT | Group IT Manager and the Divisional Director: HR | Group HR Manager, may terminate contracts of employment, where necessary and in the event of company policy having been gravely violated.
Finance
The job requires the handling of money and the authorisation to dispense and deposit company funds and is therefore subject to a fraud and credit check.
Occasional Duties
Carry out any duties as may be requested by the Divisional Director: IT and in line with expertise and role.
Special Conditions
May be required to work on a standby basis after hours, as per rotation schedule.
May be required to be available 24/7 for emergencies.
Own transport.
This job requires prolonged sitting, maintaining a static posture, performing repetitive movements, undertaking manual handling that may involve awkward postures, managing visual strain, and coping with exposure to psychosocial and cognitive stressors.
Competencies (Knowledge, Skills and Behavioural Attributes)
Knowledge
- Penetration testing
- Active Directory
- Scripting
- Azure Cloud and Hybrid
- Email Security and Spam Filters
- Data handling and Encryption
- Voice
- Networks – routing and switching
- Virtualisation
- Antivirus and EDR
- Patch management
- Immutable Backups
- Secure Certificates
- Vulnerability Assessment
Skills
- Time management
- Verbal and written communication
- Troubleshooting/problem solving
- Relationship management
- Cognitive (Memory/Insight/ Conceptualisation)
- Planning
- Clerical (documentation)
- Attention to detail
- Critical and creative thinking
- Learning agility
Behavioural Attributes
- Customer centric
- Perseverance
- Self-starter
- Collaborative
- Stress tolerant and resilient
- Results orientated
- Accountable
Position Requirements
Detailed Description / Output
- Finds and supplies secure solutions to issues in an effective and efficient manner.
- Contributes necessary information for budgets.
- Contributes to cost savings drive by the division.
- Monitors and reports on the entire estate to ensure everything is secured correctly by attending to:
- Awareness Training
- PCIDSS Assessments
- GDPR/POPI Assessments
- Penetration Testing
- Vulnerability and Patch Management
- Incident Response
- Configures and maintains all deployed hardware to the required security standards considering the current functionality of the hardware and the capacity of the hardware measured against the needs of the business.
- Maintains software deployed on the hardware and networks. This includes operating systems and various other operational tools (such as backup tools, monitoring tools and security tools) and business and core CLH systems.
- Ensure that the WAN and LAN are correctly secured
- Builds and maintains relationship with 3rd party suppliers.
- Manages escalations.
- Maintains security on all software applications and hardware devices and assists with the deployment of new or existing systems.
- Attends to security incidents.
- Monitors the strict adheres of the IT team and users to IT security requirements.
- Administers the change management process in a manner that ensures changes or new implementations do not affect business efficiency and continuity.
- Devises and maintains the necessary DR policies, plans and procedures.
- Manages the applicable DR solutions in place.
- Tests DR solutions, processes and procedures and reports on these, as well as on all other DR related activities.
- Develops, implements and maintains IT security policies and procedures.
- Be on the lookout for and be aware of any enhancements that could improve the security of the group’s infrastructure and to communicate such to the group.
- Maintains any differentiation, should it exist or be required, between the brands in relation to the applicable hardware/software authorised for use in those brands.
- Provides support to first line technicians on the more technical software, hardware, network and security related queries and resolve these within the agreed Service Level Agreements (SLAs).
- Provides incident management, problem management, event management, availability management, asset and configuration management and capacity management.
- Supports projects related to the deployment or upgrade of IT hardware, networks and software.
- Assists with testing of new and existing systems prior to deployment.
- Provides 24/7 support to the business to eliminate any system down time.
- Communicates effectively and timeously with different business units, suppliers and CLH IT.
- Builds and maintains relationships with key stakeholders which includes the different business units, suppliers, CLH IT and 3rd party vendors.
- Participates in personal development activities to learn/enhance skillset.
- Participates in and manages ITs human resources function in accordance with the company’s human resource policies.
- Conducts/participates all legislative and operational training in line with group requirements and/or training department directives.
- Achieves and maintains good working relationships and cooperation with IT employees and company colleagues.
- In liaison with the training department of the HR division, provides users accessing core business applications with sufficient training and reference material in line with CLH policies and standard operating procedures.