Cybersecurity Assurance and Compliance Specialist
Our client in Port Elizabeth is seeking an experienced IT Security Manager to lead and strengthen its information security governance, risk, and compliance initiatives across a global business environment. This role will be responsible for ensuring that security frameworks, policies, and risk management processes are effectively implemented and continuously improved.
Responsibilities:
- Lead the development, implementation, and continuous improvement of information security policies, standards, and governance practices while ensuring security requirements are embedded within business operations and strategic initiatives.
- Oversee the identification, assessment, monitoring, and mitigation of information security risks, maintaining risk registers and ensuring remediation activities are effectively managed and reported.
- Coordinate security audits, assessments, and compliance initiatives, managing findings, corrective actions, reporting processes, and adherence to regulatory, contractual, and industry requirements.
- Drive security awareness programs and provide ongoing guidance to employees, management, and stakeholders to strengthen the organisation's overall security culture.
- Support third-party security risk management activities by conducting vendor security reviews, monitoring identified risks, and coordinating appropriate remediation efforts.
- Manage and support security programs, strategic initiatives, reporting activities, and continuous improvement efforts while serving as a central point of coordination for governance, risk, compliance, and security assurance matters.
- Participate in strategic security projects, business continuity and disaster recovery governance activities, policy reviews, security reporting, stakeholder engagement initiatives, and the evaluation of emerging security risks and industry trends.
Requirements
- 5+ years of experience in information security, cybersecurity, risk management, governance, compliance, audit, or a related field.
- Bachelor's degree in Information Security, Cybersecurity, Information Technology, Risk Management, Business Administration, or a related field is preferred.
- Strong understanding of information security principles, governance practices, and risk management processes.
- Experience coordinating security audits, assessments, findings, and remediation activities.
- Experience developing, maintaining, or supporting security policies, standards, procedures, and awareness programs.
- Experience with security frameworks and standards such as ISO 27001, NIST Cybersecurity Framework, SOC 2, CIS Controls, or equivalent.
- Experience with third-party security risk management.
- Professional certification such as CISSP, CISM, CRISC, CGRC, ISO 27001 Lead Implementer, or equivalent.