We’re recruiting for the position of Cyber Security Specialist (Cyber Prevent). The primary purpose of the role is to manage and support Cyber Prevent operations across the company’s products, services and technology environments under the direction and supervision of the Manager: Cyber Prevent. The role provides preventative cyber security assurance, identifies and manages material risks, supports control compliance and reporting, and coordinates assigned activities within strategic security programmes across business units and markets. (12 month contract role based in Cape Town).
Duties and Responsibilities:
- Identifying cyber security risks in new and changed products, services, applications and technology solutions, and defining preventative controls to avoid, reduce or mitigate those risks
- Reviewing solution designs and control implementation to confirm that security requirements are embedded during design and build
- Providing security assurance before go-live by validating that required controls are implemented, evidenced and aligned with organisational security requirements and applicable laws
- Assessing cyber security risks arising from material changes to live products, services and technology environments, and tracking agreed remediation actions
- Ensuring security risks, access, data, infrastructure and control obligations are addressed when products, services or technology components are decommissioned
- Supporting delivery of the Cyber Prevent strategy, control-maturity improvements and risk-reduction initiatives across assigned business units
- Monitoring assigned activities against agreed outcomes, escalating material risks and blockers to the Manager: Cyber Prevent, and supporting the protection of infrastructure, services and customer data from cyber threats
- Collaborating closely with business, cyber security, Technology and IT stakeholders across the Group and operating companies to help ensure preventative controls are consistently understood, implemented and evidenced across markets
- Managing Cyber Prevent operations, planning, prioritisation, delivery governance and performance across assigned business units and markets
- Managing KRI data quality, reporting and automation under agreed governance, providing accurate management information, trend analysis and timely escalation of control weaknesses, risks and delivery blockers
- Providing preventative cyber security assurance, guidance and decision support to strategic programmes, projects, products and services throughout the delivery lifecycle
- Translating organisational policies, standards and control requirements into practical requirements, guardrails, security patterns and acceptance criteria
- Managing assigned cyber security assessment governance and quality-assurance activities, including planning, evidence review, recommendations, exceptions and remediation tracking, under the oversight of the Manager: Cyber Prevent
- Identifying material cyber security risks, agreeing proportionate treatment plans with accountable owners, and tracking remediation, exceptions and residual-risk acceptance to closure
- Managing assigned CHARM compliance activities, control evidence, technology alignment and the tracking of control gaps and overdue actions under agreed oversight
- Supporting DevSecOps security enablement by helping to embed preventative controls into agile delivery, engineering practices, CI/CD pipelines and developer tooling
- Providing technical subject-matter expertise, executive decision support and escalation management for complex or high-risk cyber security matters
- Managing vendor engagement, security deliverables, commercial dependencies and contract performance with procurement, legal and accountable business owners
- Partnering with Security Architecture, Cyber Defence, Identity, Cloud Security, Technology Risk, Privacy, Audit and delivery teams to resolve cross-functional dependencies
- Co-ordinating and supporting the Cyber Prevent community across markets, promoting consistent ways of working, knowledge sharing, capability uplift and adoption of common controls
- Managing assigned deliverables and providing co-ordination support across strategic initiatives including AI security, Dynamic Trust, SD-WAN, PAM, DLP, IAM and cloud security
- Contributing to control-maturity improvements, automation and reusable security guidance to improve consistency, delivery speed and visibility of preventative security outcomes
- Providing peer support, quality input and knowledge sharing to Cyber Prevent specialist resources, with guidance from the Manager: Cyber Prevent and without direct line-management responsibility
- Delivering the agreed Cyber Prevent operational plan, milestones and control-improvement outcomes within approved timelines
- Issuing KRI reports within agreed reporting cycles, with complete, accurate and validated data
- Reducing manual reporting effort through agreed automation initiatives and improved data-quality controls
- Completing cyber security assessments within agreed service levels, with material findings escalated and remediation actions tracked to closure
- Supporting CHARM controls with current evidence, with control gaps and overdue actions reduced against agreed targets
- Escalating and managing material cyber security risks, audit findings, exceptions and mitigation plans within agreed governance timelines
- Delivering strategic programmes, vendor deliverables and cross-market initiatives against agreed scope, milestones, dependencies and outcomes
Minimum Requirements:
- Three-year technical diploma or degree in Information Security, Computer Science, Engineering or a related discipline
- Relevant industry certification – CISSP is strongly preferred; CCSP, OSCP, CISM, CISA or equivalent certifications will be considered
- SABSA, TOGAF or other security architecture qualifications are advantageous
- Minimum of five years’ experience in a cyber security role, including responsibility for governance, risk, assurance or preventative security controls
- Knowledge of recognised technology management and compliance frameworks, including ISO/IEC 27001, NIST CSF, ISF, PCI DSS, OWASP and SANS
- Strong understanding of technology security risks, preventative controls, risk treatment and evidence-based assurance
- Experience across at least three security domains, including security assessment and testing, software development security, governance and risk management, security architecture and engineering, network security, identity and access management, security operations or asset security
- Experience managing or coordinating cyber security programmes, workstreams or control-improvement initiatives across multiple stakeholders or markets under defined governance and management oversight
- Experience in KRI management, management reporting, data quality and workflow or reporting automation
- Experience managing vendors, security deliverables, contractual dependencies and commercial performance
- Strong executive stakeholder management, written communication, presentation and escalation-management capability
- Knowledge of Windows and Linux security, cloud and container technologies such as AWS, GCP, Azure, Docker and Kubernetes, and developer tooling such as GitHub and dependency-management platforms
- Ability to deliver under time, resource and operational pressure while maintaining quality and governance discipline
- Ability to influence and collaborate across technical, business, market and executive stakeholders without relying on direct authority
- Customer-focused, responsive, transparent and outcome-driven approach
