Business Information Security Officer (BISO)
ZAR 420K-560K (estimate) Senior-level Full Time
Tasks
- Address vulnerabilities from penetration tests red team and scans
- Conduct logical access reviews
- Coordinate cyber crisis management
- Document governance and assurance evidence
- Engage stakeholders during major incidents
- Ensure workstation network and server integration security
- Escalate cybersecurity risks
- Establish information security programme
- Facilitate control self assessments and risk documentation
- Handle policy breach actions
- Implement cybersecurity awareness campaigns
- Implement security controls and processes
- Integrate security gates into SDLC
- Maintain cloud technology outsourcing and third party register
- Maintain configuration register of assets and licenses
- Maintain information security risk assessment and reporting
- Maintain security risk management action plan
- Manage information security incident response
- Participate in information security governance initiatives
- Perform root cause analysis and implement long-term fixes
- Produce ISO forum and GISP reports
- Provide information security governance and assurance
- Report cybersecurity incidents to CSIRT
- Review and respond to risk acceptance requests
- Review and respond to security audit findings
- Serve as primary contact for CSIRT incidents
- Update information security risk register
Perks/Benefits
- N/A
Skills/Tech-stack
Access reviews | Agile | Asset Management | Assurance | CSIRT | Cause analysis | Cloud Security | Configuration Management | Control Self-Assessment | Crisis management | Crown Jewel Risk Assessment | Cyber crisis management | Cybersecurity | Cybersecurity Awareness | Governance | Incident Response | Information security | License Management | Logical Access | Logical Access Reviews | Penetration Testing | Red Teaming | Risk Assessment | Risk Management | Risk register | Root Cause Analysis | Root cause | SDLC | Security Audits | Security Risk | Security Risk Register | Security risk assessment | Self-assessment | Third-Party Risk | Third-party risk management | Vulnerability scanning
Related jobs
-
Information Security Engineer ZAR 360K-480KAccess Control | CIS Controls | Cause analysis | Cloud Security | Data GovernanceAnnual leave | Cycle to work scheme | Family leave | Gym membership discounts | Life assuranceMid-level Full TimeNewcastle1d ago
-
Information Security Compliance Administrator ZAR 280K-300KBusiness Continuity | Data Protection | ISO 14001 | ISO 22301 | ISO 27001Flexible work | Life insurance | Pension scheme | Private health insurance | Remote workEntry-level Full TimeCape Town1d ago