Manager: ISGRC
Posted Updated
The position holder must lead the design and provide assurance to the CIO on the sustainability of IT general controls, information and technology risks, security of information assets and regulatory compliance (i.e., King IV, etc.) COBIT. The position holder must advocate Information Security, IT risk and compliance to the relevant laws and regulations, to Transnet employees as well as to senior management, to ensure risks relating to the above are mitigated. (e.g., reputational, and non-compliance). The position focuses on the provision of leadership and direction in the area of IT Risk, Information Security, IT Governance, and IT Compliance across TPL. The role develops and implements a comprehensive, enterprise-wide Information Security, Governance, Risk and Compliance (ISGRC) strategy aligned to TPL’s business objectives, industry best practice and applicable regulations/standards (COBIT, ITIL, ISO/IEC 27001). Accountable for TPL-wide cyber incident response: establishing, maintaining and leading the emergency response plan for cyber breaches, coordinating multi-disciplinary teams during incidents, and ensuring rapid containment, recovery and post-incident improvement. Drives a culture of information security awareness through targeted training, campaigns and leadership engagement across all levels of the organisation.