- Location
- Cape Town
- Type
- Full-time
- Seniority
- Senior
- Closing date
- Today
- Source
- CareersPage
Description
Senior Cyber Prevent Specialist
Duration: 12 months
Location: Century City – Cape town
Role purpose:
The primary purpose of the role is to manage and support Cyber Prevent operations across companies products, services and technology environments under the direction and supervision of the Manager: Cyber Prevent. The role provides preventative cyber security assurance, identifies and manages material risks, supports control compliance and reporting, and coordinates assigned activities within strategic security programmes across business units and markets. In performing this role you will:
- Identify cyber security risks in new and changed products, services, applications and technology solutions, and define preventative controls to avoid, reduce or mitigate those risks;
- Review solution designs and control implementation to confirm that security requirements are embedded during design and build;
- Provide security assurance before go-live by validating that required controls are implemented, evidenced and aligned with companies security requirements and applicable laws;
- Assess cyber security risks arising from material changes to live products, services and technology environments, and track agreed remediation actions; and
- Ensure security risks, access, data, infrastructure and control obligations are addressed when products, services or technology components are decommissioned.
You will also support delivery of the Cyber Prevent strategy, control-maturity improvements and risk-reduction initiatives across assigned business units. This includes monitoring assigned activities against agreed outcomes, escalating material risks and blockers to the Manager: Cyber Prevent, and supporting the protection of Vodacom infrastructure, services and customer data from cyber threats. The role requires close collaboration with business, cyber security, Technology and IT stakeholders across Group and operating companies to help ensure preventative controls are consistently understood, implemented and evidenced across markets.
Key accountabilities and responsibilities:
- Manage Cyber Prevent operations, planning, prioritisation, delivery governance and performance across assigned business units and markets.
- Manage KRI data quality, reporting and automation under agreed governance, providing accurate management information, trend analysis and timely escalation of control weaknesses, risks and delivery blockers.
- Provide preventative cyber security assurance, guidance and decision support to strategic programmes, projects, products and services throughout the delivery lifecycle.
- Translate companies policies, standards and control requirements into practical requirements, guardrails, security patterns and acceptance criteria.
- Manage assigned cyber security assessment governance and quality-assurance activities, including planning, evidence review, recommendations, exceptions and remediation tracking, under the oversight of the Manager: Cyber Prevent.
- Identify material cyber security risks, agree proportionate treatment plans with accountable owners, and track remediation, exceptions and residual-risk acceptance to closure.
- Manage assigned CHARM compliance activities, control evidence, technology alignment and the tracking of control gaps and overdue actions under agreed oversight.
- Support DevSecOps security enablement by helping to embed preventative controls into agile delivery, engineering practices, CI/CD pipelines and developer tooling.
Core competencies, knowledge and experience:
- Three-year technical diploma or degree in Information Security, Computer Science, Engineering or a related discipline.
- Relevant industry certification. CISSP is strongly preferred; CCSP, OSCP, CISM, CISA or equivalent certifications will be considered. SABSA, TOGAF or other security architecture qualifications are advantageous.
- Minimum of five years' experience in a cyber security role, including responsibility for governance, risk, assurance or preventative security controls.
- Knowledge of recognised technology management and compliance frameworks, including ISO/IEC 27001, NIST CSF, ISF, PCI DSS, OWASP and SANS.
- Strong understanding of technology security risks, preventative controls, risk treatment and evidence-based assurance.
- Experience across at least three security domains, including security assessment and testing, software development security, governance and risk management, security architecture and engineering, network security, identity and access management, security operations or asset security.
- Experience managing or coordinating cyber security programmes, workstreams or control-improvement initiatives across multiple stakeholders or markets under defined governance and management oversight.
- Experience in KRI management, management reporting, data quality and workflow or reporting automation.
- Experience managing vendors, security deliverables, contractual dependencies and commercial performance.
- Provide technical subject-matter expertise, executive decision support and escalation management for complex or high-risk cyber security matters.
- Manage vendor engagement, security deliverables, commercial dependencies and contract performance with procurement, legal and accountable business owners.
- Partner with Security Architecture, Cyber Defence, Identity, Cloud Security, Technology Risk, Privacy, Audit and delivery teams to resolve cross-functional dependencies.
- Coordinate and support the Cyber Prevent community across markets, promoting consistent ways of working, knowledge sharing, capability uplift and adoption of common controls.
- Manage assigned deliverables and provide coordination support across strategic initiatives including AI security, Dynamic Trust, SD-WAN, PAM, DLP, IAM