IT Security Manager (Hybrid)
Job description
Our client in Port Elizabeth is seeking an experienced IT Security Manager to lead and strengthen its information security governance, risk, and compliance initiatives across a global business environment. This role will be responsible for ensuring that security frameworks, policies, and risk management processes are effectively implemented and continuously improved.
Responsibilities
Lead the development, implementation, and continuous improvement of information security policies, standards, and governance practices while ensuring security requirements are embedded within business operations and strategic initiatives. Oversee the identification, assessment, monitoring, and mitigation of information security risks, maintaining risk registers and ensuring remediation activities are effectively managed and reported.
Coordinate security audits, assessments, and compliance initiatives, managing findings, corrective actions, reporting processes, and adherence to regulatory, contractual, and industry requirements. Drive security awareness programs and provide ongoing guidance to employees, management, and stakeholders to strengthen the organisation's overall security culture.
Support third-party security risk management activities by conducting vendor security reviews, monitoring identified risks, and coordinating appropriate remediation efforts. Manage and support security programs, strategic initiatives, reporting activities, and continuous improvement efforts while serving as a central point of coordination for governance, risk, compliance, and security assurance matters.
Participate in strategic security projects, business continuity and disaster recovery governance activities, policy reviews, security reporting, stakeholder engagement initiatives, and the evaluation of emerging security risks and industry trends.
Requirements
5+ years of experience in information security, cybersecurity, risk management, governance, compliance, audit, or a related field. Bachelor's degree in Information Security, Cybersecurity, Information Technology, Risk Management, Business Administration, or a related field is preferred. Strong understanding of information security principles, governance practices, and risk management processes.
Experience coordinating security audits, assessments, findings, and remediation activities. Experience developing, maintaining, or supporting security policies, standards, procedures, and awareness programs. Experience with security frameworks and standards such as ISO 27001, NIST Cybersecurity Framework, SOC 2, CIS Controls, or equivalent.
Experience with third-party security risk management. Professional certification such as CISSP, CISM, CRISC, CGRC, ISO 27001 Lead Implementer, or equivalent.