- Location
- Johannesburg, South Africa
- Workplace
- Remote, Hybrid
- Type
- Full-time
- Department
- Security
- Education
- Master
- Closing date
- Today
- Source
- Workday
Description
TransUnion's Job Applicant Privacy Notice
Team Overview
At TransUnion, a leader in information and risk management services, we are committed to protecting the integrity, confidentiality, and availability of the information entrusted to us. As cyber threats continue to evolve, we are seeking an Information Security Analyst to strengthen our security operations, governance, risk management, compliance, and assurance capabilities. This role will become a key contributor to our Information Security program, supporting both operational security initiatives and regulatory obligations across the organisation. This is a hybrid position and involves regular performance of job responsibilities virtually as well as in-person at an assigned TU office location for a minimum of two days a week.
Role Overview And Core Responsibilities
Responsibilities
Security Operations (SOC)
- Support incident response activities including identification, analysis, containment, eradication, recovery, and lessons learned.
- Develop and improve detection use cases, alerting mechanisms, playbooks, runbooks, and operational procedures.
- Collaborate with internal technology teams and external security service providers during security incidents.
- Maintain awareness of emerging cyber threats, vulnerabilities, attack techniques, and industry trends.
Vulnerability Management
- Assist in day-to-day vulnerability management activities across servers, endpoints, applications, databases, and network infrastructure.
- Perform vulnerability assessments and coordinate remediation activities with technology, application, and infrastructure teams.
- Track vulnerabilities through resolution and provide management reporting on remediation performance and compliance.
- Assist in maintaining vulnerability management standards and reporting against defined remediation SLAs.
Governance, Risk & Compliance (GRC)
- Support the continued operation, maintenance, and improvement of the Information Security Management System (ISMS).
- Assist with ISO 27001 and SOC 2 certification, surveillance audits, recertification audits, and control reviews.
- Support internal and external audits through evidence collection, compliance validation, and remediation tracking.
- Assist with enterprise security risk assessments and risk treatment activities.
- Support compliance with ISO 27001, ISO 27002, CIS Controls, regulatory requirements, and internal policies.
- Track audit findings, corrective actions, and compliance initiatives.
Identity Security
- Support identity governance initiatives, including:
- Privileged Access Management (PAM)
- Role-Based Access Control (RBAC)
- Multi-Factor Authentication (MFA)
- Access reviews and certification processes
- Participate in security assessments of new technologies, systems, and services.
Security Awareness & Training
- Support security awareness programmes, phishing simulations, and employee education initiatives.
- Promote a strong security culture across the organisation.
- Assist business stakeholders in understanding security risks and control requirements.
- Contribute to awareness campaigns, security communications, and policy adoption initiatives.
Reporting & Metrics
- Produce security dashboards, reports, and key performance indicators (KPIs).
- Report on:
- Security incidents
- Vulnerability management
- Risk management
- ISO 27001 compliance
- Audit findings
- Third-party risk
- Security operations effectiveness
- Support management reporting and governance forums through meaningful security metrics and analysis.
- Drive improvements in security reporting through automation and continuous enhancement initiatives.
Required Knowledge And Experiences
Minimum Qualifications
- Degree or Diploma in Information Security, Computer Science, Information Technology, Engineering, or related field.
- Relevant cybersecurity certifications will be advantageous.
Experience
- 3–5 years' experience in Information Security, Cyber Security, Security Operations, Infrastructure, Cloud Security, or Technology Risk.
- Experience supporting ISO 27001 and SOC 2 implementation, maintenance, or certification activities.
- Experience with incident response and security event investigation.
- Experience with vulnerability management and remediation tracking.
- Experience conducting security assessments, audits, or compliance activities.
- Experience working with cloud technologies and security controls.
- Experience in Identity and Access Management principles.
- Experience with Application security principles and OWASP Top 10.
Professional Competencies
- Strong analytical and investigative skills.
- Excellent written and verbal communication skills.
- Ability to engage effectively with both technical and non-technical stakeholders.
- Strong attention to detail and problem-solving capability.
- Ability to manage multiple priorities in a fast-paced environment.
- Strong stakeholder management and relationship-building skills.
- Pragmatic and business-focused approach to security.
- High degree of integrity, accountability, and professionalism.
- Self-motivated with a continuous improvement mindset.
For positions based in South Africa, preference will be given to suitably qualified candidates from designated groups in line with the company’s Employment Equity plan and targets.
If you do not hear from TransUnion within three weeks of applying, please consider your application unsuccessful.
TransUnion Overview:
At TransUnion, our Workforce for Good is built on purpose, impact, and opportunity. We empower our people to grow, innovate, and make a meaningful difference for our communities and customers all while being supported to thrive both professionally and personally. With a strong focus on flexibility, wellbeing, and collaboration, you’ll work with exceptional people across the globe, pioneering products, and cutting‑edge technology that truly matters.
At TransUnion Africa, you’ll join a purpose‑driven organisation that invests in its people through competitive rewards, comprehensive benefits, and meaningful career development. We offer permanent work‑from‑home flexibility, wellbeing support for you and your family, and access to global exposure and accredited learning so you can grow your career while maintaining balance.
TransUnion Job Title
Analyst, Cybersecurity