Hiring.Camp

Information Security & Compliance Officer

Herotel

·

Apr 23, 2026

Location
Plattekloof, ZA
Type
Full-time
Department
Legal
Source
Breezy HR

Description

Are you passionate about cybersecurity, threat detection, and protecting critical business systems? Join our IT team as an Information Security & Compliance Officer in Plattekloof and take ownership of safeguarding Herotel’s digital environment across our national footprint.

The key purpose of this role is to drive the operational delivery of our information security programme, ensuring strong cyber defence, regulatory compliance, and risk management while actively monitoring, detecting, and responding to security threats in real time.

What you’ll do:

  • Monitor systems, networks, and security dashboards for suspicious activity, anomalies, and emerging threats
  • Investigate, triage, and respond to security incidents and escalations in real time, including root cause analysis and documentation
  • Maintain and manage endpoint protection platforms, SIEM systems, and broader security tooling
  • Develop, implement, and maintain incident response plans to ensure effective handling of security events
  • Lead real-time incident management to minimise business impact and ensure service continuity
  • Conduct regular vulnerability scans and security assessments across infrastructure and applications
  • Support and execute annual penetration testing activities and track remediation actions
  • Collaborate with IT and infrastructure teams to remediate vulnerabilities and strengthen system security
  • Review, harden, and continuously improve server, network, and cloud security configurations
  • Support security architecture improvements across on-premise and cloud environments (Azure, AWS, GCP)
  • Maintain and enforce POPIA compliance policies, procedures, and governance frameworks
  • Manage POPIA-related requests, incidents, data subject access requests, and breach notifications
  • Support the Information Officer in meeting POPIA statutory obligations and regulatory engagements
  • Conduct data protection impact assessments for new systems, vendors, and integrations
  • Maintain security risk registers, incident logs, and vulnerability tracking documentation
  • Monitor access and authentication logs for suspicious or unauthorised activity
  • Ensure ongoing alignment with IT governance and security best practices

What you’ll need:

  • 5–7 years’ hands-on experience in cybersecurity, information security, or IT security engineering roles
  • Strong experience in security monitoring, incident response, and vulnerability management
  • Proven experience working with SIEM systems, SOC tooling, and endpoint protection platforms
  • Solid understanding of IT governance, risk management, and compliance frameworks
  • Practical experience with POPIA compliance and data protection requirements
  • Exposure to cloud environments such as Azure, AWS, or GCP and associated security controls
  • Strong understanding of networking fundamentals (TCP/IP, DNS, DHCP) and Windows environments
  • Experience with Entra ID / Azure AD and identity and access management principles
  • Familiarity with threat frameworks such as MITRE ATT&CK
  • Knowledge of firewall management, security architecture, and defensive security principles
  • Scripting ability (BASH or Python) advantageous
  • ISP or telecoms environment experience advantageous
  • Strong analytical and problem-solving skills with attention to detail
  • Ability to manage multiple priorities in a fast-paced, high-availability environment
  • Strong communication skills and ability to engage across technical and non-technical teams
  • Relevant degree or diploma in IT, Computer Science, Cybersecurity, or related field
  • Certifications advantageous (e.g. CISM, CISSP, CEH, CompTIA Security+, ISO 27001 Lead Implementer/Auditor)

What we offer:

  • Exposure to a dynamic workplace
  • A chance to grow your skills through our internal academy
  • A friendly, team-driven environment
  • Group Risk Benefits
  • Medical Benefits
  • Health and Lifestyle Programmes

Important Disclaimer:

  • Please ensure that the information you provide in your application is true, accurate, and correct.
  • Preference will be given to candidates from Designated Groups, as defined by the Employment Equity Act and in line with Herotel’s Employment Equity Plan.
  • By submitting an application, you consent to the processing of your personal information in accordance with POPIA for recruitment purposes. For more details on how we handle personal information, please refer to our Privacy Policy on our website.
  • If you do not hear from us within 14 days, please consider your application unsuccessful.

Skills

PythonAWSAzureGCPCybersecurityPenetration TestingSIEMSOCTCP/IPRisk ManagementComplianceISO 27001CISSPCompTIA

Similar Jobs

30

Information Security

Caci · 229 HANOVER MD, United States of America · Onsite

1 month ago

Information Security Engineer

Trupanion · Seattle, WA, United States · Hybrid

Today

Information Security Engineer

ALKU - Apply Today! · Andover, MA +1 · Remote, Hybrid

Today

Senior Information Security, Risk & Compliance Specialist

Geotab · z. Canada Job Post Template +1

Today

Dir Chief Information Security Architect

Integris Health · Oklahoma City, OK, United States, US · Hybrid

Today

Information Security Architect

Airship · Remote - U.S. +1 · Remote

Today

Manager - Information Security

Mayo Clinic · Rochester, MN, United States, US

Today

Information Security Governance Specialist

Frontify · Sankt Gallen Metropolitan Area · Hybrid

Today

Information Security Governance Specialist

Frontify · London Area · Hybrid

Today

T2021 - Information Security Engineer

ASRC Federal · Seaside, CA, USA

Yesterday

Senior Information Security Operations Analyst

Mastercard · Pune, India

Yesterday

Information Security Officer – Global Banking & Markets (GBAM)

Bank Of America · Washington, United States of America +2 · Onsite

Yesterday

SVP, Chief Information Security Officer

Attainfinance · , US · Remote

Yesterday

Director, Information Security

Brocku · Main Campus (Employees), Canada

Yesterday

Information Security Engineer II

Candescent · SQ - Belgrade - Office, Serbia

Yesterday

Information Security Engineer I

Candescent · SQ - Belgrade - Office, Serbia

Yesterday

Lead Information Security Analyst

Conmed · Largo, FL, United States of America +1 · Remote

Yesterday

Information Security Engineer II

Candescent · SQ - Belgrade - Office, Serbia

Yesterday

Information Security Engineer I

Candescent · SQ - Belgrade - Office, Serbia

Yesterday

Information Security Analyst III

Arrow · IN-KA-Bangalore, India (SKAV Seethalakshmi) GESC · Hybrid

Yesterday

Lead Engineer, Information Security

Lowe's · Lowe's Charlotte Technology Hub 3505, United States of America

Yesterday

Information Security Officer – Global Banking & Markets (GBAM)

Bank Of America · Washington, United States of America +2 · Onsite

Yesterday

Lead DLP Data Integration and Automation Information Security Engineer

Wells Fargo · 102462-AZ-B Building, Chandler Campus, United States of America +2

Yesterday

Sr. Information Security Consultant (AppSec Enablement and Insights)

Truist · Atlanta GA - 303 Peachtree Center Avenue - Garden Offices, United States of America +2

Yesterday

Junior Information Security Officer

Nngroup · The Hague - Haagse Poort - Low Rise, Netherlands · Hybrid

Yesterday

Information Security Officer

Audif1 · Hinwil, Zürich

Yesterday

Technology Chief Information Security Officer (Tech CISO)

Ing · HBP (Amsterdam - Haarlerbergpark), Netherlands

Yesterday

Sr. Information Security Analyst

Cadence Design · NOIDA 02, India

Yesterday

Lead Information Security Engineer - Cyber Ops(Cloud Security)

Svb · IND - KA - Bangalore - Outer Ring Road, India · Hybrid

Yesterday

Lead Information Security Engineer - IAM

Svb · IND - KA - Bangalore - Outer Ring Road, India · Hybrid

Yesterday