Job Description
Location:
Cape Town |
Work Type:
Hybrid |
Job ID:
J107223
About our client:
Our client is a global investment advisory firm focusing on long-term value creation through investment strategies. They work with a diverse group of institutional partners and pride themselves on their collaborative, sustainable, inclusive culture and performance. You are welcome to go into the office daily or to take advantage of their hybrid in-office / remote benefit. This company places significant investment in employee wellness, their benefits which are on top of generous basic salaries, are industry leading in their generosity. Our client is large, offering fantastic career development opportunities but also very dynamic, they track as many metrics as possible in order to continuously improve - they spare no expense on the tools to do so. Automation, AI and R&D are pillars of their business framework which ensures you should never be at risk of falling behind or getting stuck working with old legacy software. Culturally they are very cosmopolitan and diverse, you will be working with the best globally.
What you will be doing:
Design and maintain an Information Security Program aligned with industry standards like ISO 27001, SOC 2, and NIST.
Establish enterprise-wide security policies and ensure adherence to global privacy regulations such as GDPR, CCPA, and POPIA.
Serve as the Data Protection Officer (DPO) and lead all incident response efforts, from investigation through containment.
Partner with IT, Engineering, HR, and Legal teams to integrate security requirements.
Conduct regular risk assessments, maintain a central risk register, and execute prioritised gap analysis and remediation plans.
Drive and maintain compliance with critical certifications and frameworks, including ISO 27001, SOC 2, and NIST.
Oversee the implementation of essential security controls, such as firewalls, encryption, intrusion detection, and identity management.
Monitor emerging threats to provide proactive security recommendations, manage InfoSec projects, and offer guidance on cloud architecture and secure development (SDLC).
What our client is looking for:
A relevant tertiary qualification would be beneficial (Computer Science, Information Security, etc.).
A relevant certification would be ideal (e.g., Certified Information Systems Security Professional (CISSP) or Certified Information Security Manager (CISM).
6+ years of relevant experience in information security management, preferably within software development or enterprise environments.
Proven track record in delivering complex security programs and managing certification processes (ISO/SOC 2/NIST).
Experience in security incident management, root cause analysis, and disaster recovery planning.
Requirements
Information Security, CISSP, CISM, Risk Management, ISO 27001, SOC 2, NIST, GDPR, CCPA, POPIA, Incident Response, DPO, Cloud Security, SDLC, Compliance, Cybersecurity, InfoSec Management