- Location
- Johannesburg
- Type
- Full-time
- Department
- Human Resources
- Seniority
- Lead
- Closing date
- Today
- Source
- CareersPage
Description
Lead, Continuous Threat Exposure Management
Contract duration: 12 months
Location: Midrand
Role Purpose
Lead the establishment, operation and continuous improvement of companies Continuous Threat Exposure Management capability. The role is accountable for providing a unified, risk-based view of cyber exposure across critical business services, infrastructure, telecommunications platforms, cloud environments, applications, APIs, identities, data, AI systems and approved third parties.
The role will drive the complete exposure lifecycle, from discovery and prioritisation through remediation, validation, exception management and executive reporting, with success
measured by verified risk reduction rather than vulnerability volumes.
Key Accountabilities
- Define and maintain the exposure-management strategy, operating model, roadmap, governance framework, standards and performance measures.
- Establish continuous discovery and reconciliation of assets and exposures against authoritative inventories.
- Integrate and correlate findings from vulnerability management, attack-surface management, cloud, identity, application-security testing, penetration testing, threat intelligence, incidents, audits and control-assurance activities.
- Prioritise exposures using business criticality, customer impact, internet exposure,reachability, attack paths, privilege, known exploitation, threat intelligence, CVSS, CISA KEV and EPSS, rather than technical severity alone.
- Maintain a single governed exposure backlog with accountable owners, required actions, target dates, dependencies, exceptions, evidence and audit trails.
- Coordinate remediation across infrastructure, network, cloud, application, identity, supplier, business and market teams.
- Lead urgent escalation and coordinated response for actively exploited vulnerabilities, credible zero-days, exposed privileged paths and critical control failures.
- Establish independent, evidence-based validation of remediation and ensure exposures are reopened where validation fails or evidence is insufficient.
- Govern time-bound risk acceptances, compensating controls and escalation of overdue exposures, ownership gaps and remediation blockers.
- Provide operational and executive reporting on exposure coverage, critical attack paths, ageing, remediation performance, exceptions, recurring issues and verified risk reduction.
- Manage exposure-management tooling, integrations, data quality, automation and supporting service-provider performance.
- Convert recurring exposure themes into systemic control improvements, architecture changes, security testing, supplier actions or problem-management initiatives.
- Coverage of priority business services and critical technology assets
- Reduction in critical attack paths and known-exploited exposures
- Remediation performance against approved targets
- Reduction in overdue, recurring and reopened exposures
- Percentage of material exposures with accountable owners
- Quality and timeliness of risk acceptances
- Successful independent validation of exposure closure
- Demonstrable and sustained reduction in residual cyber risk
- Relevant degree or equivalent experience in cybersecurity, technology, engineering or risk management.
- Significant experience leading vulnerability management, exposure management, cyber-risk reduction, security testing or a related enterprise security capability.
- Strong knowledge of infrastructure, cloud, identity, application, API, network and telecommunications security.
- Experience coordinating remediation across complex technology and business environments.
- Strong understanding of attack-path analysis, threat-informed prioritisation, security assurance and exception governance.
- Experience managing executive reporting, governance forums, senior stakeholders and service providers.
- Relevant certification such as CISSP, CISM, CRISC, CCSP, OSCP or GIAC is advantageous.
- Knowledge of NIST CSF 2.0, MITRE ATT&CK, CISA KEV and FIRST EPSS is advantageous.
Experience and Qualifications
Key Competencies
Strategic leadership, business-focused risk judgement, stakeholder influence, executive communication, analytical decision-making, delivery discipline, constructive challenge and the ability to coordinate action during urgent cyber exposure events.