- Location
- Plattekloof, ZA
- Type
- Full-time
- Department
- Legal
- Experience
- 3+ years
- Source
- Breezy HR
Description
Are you a detail oriented governance and compliance specialist with a passion for information security? Join our Information Systems team as an IT Governance, Risk & Compliance Officer in Plattekloof, where you'll lead Herotel's ISO 27001 certification programme and own our POPIA compliance obligations.
This role is perfect for someone who thrives on structure, documentation and stakeholder engagement, and who wants to build a governance function from the ground up within a fast growing telecommunications business.
What you'll do:
- Lead Herotel's ISO 27001 certification programme, including ISMS scoping, gap and risk assessments, and maintaining the Statement of Applicability
- Develop, maintain and drive adoption of the information security policy suite
- Maintain the information security risk register and risk treatment plan, tracking remediation with control owners
- Plan and execute the ISMS internal audit programme, coordinate management reviews and maintain ISMS records and evidence
- Manage the certification body relationship, including Stage 1 and Stage 2 audits, findings closure and ongoing surveillance audit readiness
- Coordinate implementation of Annex A controls together with the Cybersecurity Engineer and IT teams
- Own POPIA compliance, developing, maintaining and enforcing policies and procedures aligned with legislative requirements
- Manage and respond to POPIA related requests and incidents, including data subject access requests, complaints and data breach notifications
- Serve as Herotel's Deputy Information Officer under POPIA
- Conduct data protection impact assessments for new systems, processes and third party integrations that handle personal information
- Run the security awareness and training programme, tracking completion and driving adoption across the organisation
- Conduct third party and vendor security and privacy risk assessments, reviewing vendor agreements for security and compliance obligations
- Produce the monthly compliance dashboard covering ISMS status, audit findings, POPIA metrics and awareness training
What you'll need:
- Diploma or Degree in Information Technology, Information Security, Audit, Law or a related field
- 3 to 5 years experience in information security governance, risk and compliance, ISMS, or privacy roles
- Hands on experience implementing or operating an ISO 27001 ISMS
- Working knowledge of POPIA and its practical application in a South African operating context
- Proven policy authorship, with experience driving policy adoption and security awareness training
- Experience with risk assessment methodologies and maintaining risk registers and treatment plans
- Exposure to third party and vendor risk assessment
- Sufficient understanding of security technologies such as SIEM, endpoint protection and vulnerability management to define and audit controls
- Strong written communication, documentation and stakeholder engagement skills
- ISO 27001 Lead Implementer certification is strongly preferred, or willingness to obtain it within the first six months
- Participation in certification or surveillance audits is advantageous
- Desirable certifications include ISO 27001 Lead Auditor, CISM, CISA, CRISC, CIPP or CIPM
What we offer:
- Exposure to a dynamic workplace
- A chance to grow your skills through our internal academy
- A friendly, team driven environment
- Group Risk Benefits
- Medical Benefits
- Health and Lifestyle Programmes
Important Disclaimer:
- Please ensure that the information you provide in your application is true, accurate, and correct.
- Preference will be given to candidates from Designated Groups, as defined by the Employment Equity Act and in line with Herotel's Employment Equity Plan.
- By submitting an application, you consent to the processing of your personal information in accordance with POPIA for recruitment purposes. For more details on how we handle personal information, please refer to our Privacy Policy on our website.
- If you do not hear from us within 14 days, please consider your application unsuccessful.