Principal Specialist:cyber Security-vfs - Johannesburg, South Africa - Vodafone

Vodafone
Vodafone
Verified Company
Johannesburg, South Africa

1 week ago

Thabo Mthembu

Posted by:

Thabo Mthembu

beBee Recruiter


Description

Role purpose:


Your responsibilities will include:

Take a proactive approach to ongoing evaluation of cyber security policies to ensure security policy adherence related to VFS and DLS
Support/assist with the development and management of the 3-to-5-year Cyber Security Strategy across the DLS and VFS entity.
Achieve and maintain and target Cyber Security Maturity level for VFS and DLS
Build relevant Business Cases for key initiatives and existing planned cyber programmes.
Design, Develop and Implement a Security Programme for VFS and DLS
No or per target Internal Audit findings related to VFS and DLS for Cyber Security
Ensure a Cyber Security Incident Response Practice is in place across the VFS and DLS entity.

Promote awareness of security policies, training, and the governance strategy amongst all levels of VFS and DLS to ensure sound security governance is reflected across the entity.

Actively manage risks on the Cyber Risk Register from intake to resolution
Communicate risk assessment findings with key stakeholders to develop and monitor risk remediation plans.
Conduct regular compliance assessments with the Business to ensure that current and emerging risks are being monitored and managed.
Proactive Control design and implementation guidance provided to the Business.
Process and Control Compliance Monitoring and Reporting
Management on the recommended actions
Tracking and monitoring of audit remediation action implementation
Design of status reports as well as insight reporting as and when required by Management.
Lead reporting development with the use of automation and reporting tools to generate Cyber Risk metrics, i.e. KPI's, KRI's
To provide Management with assurance covering controls across the Business environments that there are adequately designed and operating effectively.
To support Management during audits as well as implement and track Management audit actions to closure
Provide Management with status update reports as well as insight reporting across all VFS and DLS BUs


Degree\Relevant tertiary qualification in Information technology and Minimum of 8 + years of experience in Cyber Security role where you meet business deliverables.

At least 8+ years' experience in cyber governance, risk, controls, and compliance management in a technology environment
8+ years' of experience in IT Audit and Assurance management in a Cyber or technology environment

Knowledge of common information technology management / compliance frameworks such as ISO/IEC 27001, SOC 2, SOX, ITIL, COBIT, and NIST.


Desire
An industry certification e.g. ISO 27001 Lead practitioner, DEVSECOPS, CCSP CGEIT, CRISC, CISA, CISM and CISSP is strongly preferred.


Knowledge of legal, regulatory and privacy requirements, such as Personally Identifiable Information (PII) Protection and Payment Card Industry (PCI)/Data Security Standard.

High level understanding and Knowledge of Cloud Risk, Compliance and Assurance
Proven experience managing and operating multiple security programs, projects, and initiatives and related security tooling
An ability to think strategically and drive change
A deep understanding of Tech Security risks and mitigating solutions

A diverse security background with knowledge in several areas including layered security architecture; internet protocols; firewalls; VPN technologies, IDS/IPS, network access control and network segmentation, anti-malware and spam technologies; risk and vulnerability assessments, and compliance.

Security concepts related to DNS, routing, authentication, VPN, proxy services and DDOS mitigation technologies
Windows, UNIX and Linux operating systems
Web Application Security & Encryption
Strong organizational skills and an entrepreneurial drive with a history of recruiting and developing high-performing teams
Ability to build and manage highly motivated and innovated technical/extended team
Ability to work under time and resource pressure
An ability and desire to communicate and work with a broad set of stakeholders
A customer-focused, responsive, and transparent attitude
Grasping of technical concepts rapidly and the ability to articulate these concepts to technical and non-technical audiences
Skilled in communicating with all levels of management.

Closing date for Applications
: 21 June 2023
The base location for this role is,
Midrand, Vodacom Campus
The Company's approved Employment Equity Plan and Targets will be considered as part of the recruitment process. As an Equal Opportunities employer, we actively encourage and welcome people with various disabilities to apply.
Vodacom is committed to an organisational culture that recognises, appreciates and values diversity & inclusion.

More jobs from Vodafone