- Location
- City of Johannesburg Metropolitan Municipality, Gauteng
- Workplace
- Hybrid
- Type
- Full-time
- Department
- Marketing
- Education
- Bachelor
- Closing date
- Today
- Source
- Vincere
Description
A leading organisation is seeking an Intermediate Cyber GRC Consultant to join its team on a six-month fixed-term contract. Based in Gauteng with a hybrid working model, this role offers an exciting opportunity to contribute to meaningful cybersecurity governance, risk and compliance initiatives while working across a range of client engagements.
Responsibilities:
- Deliver cybersecurity governance, risk and compliance advisory services.
- Conduct cyber risk, security and maturity assessments, identifying control gaps and recommending practical improvements.
- Develop and maintain information security policies, standards, procedures and guidelines.
- Support ISMS implementation and cybersecurity governance programmes.
- Conduct compliance and gap assessments against frameworks including ISO/IEC 27001, NIST Cybersecurity Framework and CIS Critical Security Controls.
- Support audit readiness, evidence gathering and remediation activities.
- Facilitate risk workshops, stakeholder interviews and governance engagements.
- Prepare professional reports, dashboards, presentations and executive summaries.
- Track remediation activities, project risks and deliverables across multiple engagements.
- Build strong client relationships and contribute to solution development and pre-sales activities.
Requirements:
The ideal candidate will have:
- 3–5 years' experience in cybersecurity, risk, compliance, audit or information security.
- A Bachelor's Degree, Diploma or equivalent qualification in Information Security, Information Technology, Computer Science, Risk Management, Information Systems or a related field.
- Proven experience in risk assessments, security reviews, policy development and control effectiveness evaluations.
- Strong knowledge of ISO/IEC 27001 and 27002, NIST Cybersecurity Framework and CIS Controls.
- Understanding of cyber risk management, enterprise risk management and third-party risk management.
- Knowledge of POPIA; GDPR knowledge will be advantageous.
- Strong reporting, documentation and stakeholder engagement skills.
- The ability to translate technical and regulatory requirements into clear, practical business recommendations.
- Certifications such as ISO/IEC 27001 Lead Implementer/Lead Auditor, CISA, CISM, CRISC, CISSP, Security+, CC or COBIT Foundation will be advantageous.
EE Disclaimer:
All positions will be filled in accordance with the company's Employment Equity plan. We encourage people with disabilities to apply.
Application Unsuccessful Disclaimer:
If you do not receive feedback within two weeks of your application, please consider it unsuccessful. Keep an eye on our website and other career sites for future opportunities.
REF: GC01
Skills
CybersecurityRisk ManagementComplianceGDPRCISSP