Senior Specialist Data Security - Midrand, South Africa - Vodafone

Vodafone
Vodafone
Verified Company
Midrand, South Africa

2 days ago

Thabo Mthembu

Posted by:

Thabo Mthembu

beBee Recruiter


Description

Role purpose:


Your responsibilities will include:

Provide supervisory technology security operations and support to high profile projects,
Ensure security is embedded in IT System and Network Infrastructure (Mobile, IS and Enterprise) across the Vodacom Group
Support Cyber Incident Response actions.
Defining, implementing and efficiently maintaining technology security controls and requirements
Ensure timely delivery of technology security assurance and support for projects
Ensure compliance with Legal and Regulatory requirements
Provide SME input to Technology Security Policy requirements and procedures
Provide accurate and timely reporting of technology security risks identified during project engagement and propose remediation and mitigation options
Fulfil key customers' obligations and stakeholders' expectation
Participate in creation and execution of technology security strategy
Ensure financial efficiency in Tech Security Solutions
The role requires the individual to monitor information security governance, risk, and compliance by Vodacom Corporate IT, Mobile and Enterprise Business domains
Ensure alignment of information security governance with the Vodacom's business objectives, the information security strategy, plans and controls
Ensure compliance with the applicable legislative and regulatory interpretation and corporate risk appetite;
Lead, develop, manage and maintain the Vodacom-wide information security governance deliverables lifecycle including compliance measurement, deviations and exemptions;
Engage with the stakeholders on compliance to control effectiveness and deficiencies in the design and operating effectiveness of information security controls, design and recommend opportunities for continuous improvement;
Interpret and manage the controls and capabilities required for Vodacom to establish and comply with an information security management system in alignment with information security international best practice and/or industry standard(s);
Manage and conduct formal information security risk analyses, reviews, tests, audits and/or self-assessments;
Design appropriate remedial actions for identified risks, drive remediation of findings and management of risks and exemptions;
Participate in IT general controls and compliance testing activities and/or audits;
Lead, develop and maintain a comprehensive and effective Vodacom information security risk, threat and vulnerability management capability that effectively anticipates the latest threat and vulnerabilities for Vodacom, as well as assesses and reduces information security risk to within the corporate risk appetite
Report information security risks in an appropriate way for different audiences;
Lead, drive and manage information security investigations and incident management;
Develop, manage and maintain an information security incident management capability;
Develop, measure and manage Vodacom measurements to assess the effectiveness of this program, and drive continuous improvement;
Collaborate with various key stakeholders, and provide information security advice to stakeholders

Diploma or Bachelor's Degree in Computer Science, Information Systems, Systems Analysis, or other related field
Minimum of 5+ years of experience in Tech Security role where you meet business deliverables

Knowledge of common information technology management / compliance frameworks such as ISO/IEC 27001, SOC 2, SOX, ITIL, COBIT, and NIST.

Knowledge of legal, regulatory and privacy requirements, such as Personally Identifiable Information (PII) Protection and Payment Card Industry (PCI)/Data Security Standard.

Experience supporting DLP, WAF, EDR and other solutions.
Cyber Incident Response
Previous or current workings with Microsoft Security Technologies will be beneficial.

A diverse security background with knowledge in several areas including: layered security architecture; internet protocols; firewalls; VPN technologies, IDS/IPS, network access control and network segmentation, anti-malware and spam technologies; risk and vulnerability assessments, and compliance.

Security concepts related to DNS, routing, authentication, VPN, proxy services and DDOS mitigation technologies.
Windows, UNIX and Linux operating systems
Practices and methods of enterprise architecture and security architecture
Network security architecture development and definition
Web Security & Encryption
Ability to build and manage highly motivated and innovated technical team
Ability to work under time and resource pressure
An ability and desire to communicate and work with a broad set of stakeholders
A customer-focused, responsive, and transparent attitude
An industry certification within Cyber Security.

Closing date for Applications
:22 May 2023
The base location for this role is,
Midrand, Vodacom Campus
The Company's approved Employment Equity Plan and Targets will be considered as part of the recruitment process. As an Equal Opportunities employer, we

More jobs from Vodafone