Chief Information Security Officer (Ciso)

Chief Information Security Officer (Ciso)
Company:

Council For Scientific And Industrial Research (Csir)


Details of the offer

The Council for Scientific and Industrial Research (CSIR) is a leading scientific and technology research organisation that researches, develops, localises and diffuses technologies to accelerate socio-economic prosperity in South Africa. The organisation's work contributes to industrial development and supports a capable state. The CSIR has a vacancy for a Chief Information Security Officer (CISO) based in Pretoria.About The JobThe CSIR has a vacancy for a Chief Information Security Officer (CISO) who will be responsible for leading the Information Security Office and maintaining a comprehensive CSIR-wide information security programme to ensure that all CSIR information assets are adequately protected against current/future and internal/external threats. Tasked with developing and implementing policies, standards, procedures, and oversight of information security in the CSIR, ensuring the organisation can identify various security concerns, gaps and remedial actions to guarantee security of operations. Works with executive management to determine acceptable levels of IT risk for the organisation.Key ResponsibilitiesLeadershipDevelop, review and drive implementation of information security policy, strategy and short (annual)- and long-range operational plans in order to ensure secure operations across the CSIR;Maintain a comprehensive, CSIR-wide information security programme;Oversee ISO and Cybersecurity Centre of Innovation managers and teams, allocating resources to ensure that staff deliver secure and robust IT solutions to the CSIR's requirements;Manage and develop staff to ensure high calibre personnel who achieve performance objectives in support of the CSIR mission and vision as they pertain to information security;Conduct performance management contracting and reviews for all staff at the recommended periods, for the purpose of managing and improving service delivery.Information SecurityProvide leadership and vision for information security at the CSIR;Provide managerial oversight in the development and implementation of an information security programme, ensuring the programme is continuously updated in alignment with the changing threat landscape;Determine projects and priorities for all CSIR information security issues;Direct the dissemination of CSIR information security policies;Oversee development of an effective information security incident response plan and determine metrics to measure effectiveness;Lead the response to information security incidents and act as the primary control point in the case of any significant information security incidents;Define vulnerability management programme and oversee the planning and execution of vulnerability audits, penetration testing, or forensic IT audits and investigations, ensuring the results improve CSIR's information security through developing metrics to prove its effectiveness;Oversee development of CSIR-wide information security training and awareness programme;Oversee the development and implementation of all necessary information security controls;Understand and interact with RDI divisions and support functions across the CSIR (through risk management or other committees) to ensure the consistent application of policies and standards across all technology projects, systems, and services;Advise the CSIR regarding internal or external information security threats to allow CSIR to focus efforts and allocate budget for their mitigation;Provide technical guidance on information security products and technical controls to the CSIR business as a whole;Manage the information security team to proactively analyse, and directly respond to internal and external threats to information infrastructure and minimise/mitigate risk;Conduct risk assessments in alignment with the CSIR Risk Management Process;Ensure security controls in place support compliance to national data and protection of information regulations;Build formal relationships with third parties, vendors and industry as well as threat intelligence feed providers and establish forums for information exchange;Stay abreast of changing technologies, developing threats, including cybersecurity risks, and regulatory changes affecting the CSIR's information security, and respond accordingly;Understand and examine the impact of new technologies on the CSIR's information security, establishing processes to review the implementation of new technologies to ensure security compliance.Financial ManagementDevelop and manage the Information Security Office budget;Manage information security assets;Ensure cost effective service delivery;Ensure compliance with financial legislative requirements.Qualifications, Skills And ExperienceA Bachelor's degree in Information Technology (IT), Computer Science, Information Systems, Computer Engineering, or related field with at least eight years experience in ICT services, of which five years should be in a management role;Must also have five years relevant experience managing Information Security and risk, particularly in large organisations or projects;A proven track record in:Business continuity, disaster recovery, risk management, vulnerability assessments and incident management;Defining information security architecture;Negotiating with vendors and service providers;People management, including performance management;Project management;Budgeting and cost models and management;Strategic planning;Operational planning and implementation;Resource planning and optimisation;Understanding industry standards and regulations;Communication and engagement with senior executives;Influencing stakeholder acceptance of appropriate Information Security improvements and corrective action.Knowledge of and competence in the provision of Information Security services including:Knowledge of national and international information security standards and regulations;Working knowledge of protocols that deal with intrusion detection, intrusion prevention, and firewalls;Knowledge of techniques for ethical hacking and threat modelling;Knowledge of relevant IT security related hardware, software, and vendor solutions;Overall understanding of the operating systems used within CSIR and the scripting programming languages used by the ICT and ISO teams;Knowledge of common information security management frameworks;Supervisory and incident management skills;Ability to balance the long-term and short-term implications of individual decisions;Ability to remain neutral towards technology, vendor and product choices, as well as to be more interested in results than in personal preferences;Knowledge of continuous improvement processes, process control and enhancement;Financial, planning and strategic management skills;Policy development and administration skills.Must be in possession of a Security clearance certificate or be prepared to undergo clearance.Closing date: 23 September 2024PLEASE NOTE THAT FEEDBACK WILL BE GIVEN TO SHORTLISTED CANDIDATES ONLY.For more info, please email us at ******. Please do not send your application to this mailbox, it is only for inquiries.The CSIR is an equal opportunity employer. As such, it is committed to the Employment Equity Act and will through the filling of this vacancy, give preference to candidates from designated groups in terms of the Employment Equity Act. By applying for this position at the CSIR, the applicant understands, and agrees that the CSIR may solicit a credit and criminal report from registered credit bureau and/or South African Police Services (in relation to positions that require trust and honesty and/or entail the handling of cash or finances), and may also verify the applicant's educational qualification and employment history. The CSIR reserves the right to remove the advertisement at any time before the stated closing date and it further reserves the right not to appoint if a suitable candidate is not identified.
#J-18808-Ljbffr

Requirements

Chief Information Security Officer (Ciso)
Company:

Council For Scientific And Industrial Research (Csir)


Intermediate – Senior Javascript Engineer

Requirements:Proficiency in software engineering fundamentals and a commitment to clean code and best practices.Ability to architect and structure projects w...


From Tumaini Consulting - Gauteng

Published a month ago

Full Stack Engineer - Front End Focused

Season Share is a Sports Ticketing Technology Software ProviderWe are looking for a Senior full-stack JavaScript developer interested in developing products ...


From Season Share, Inc. - Gauteng

Published a month ago

Java Developer (Jav)

DVT is a leading global custom software development and data engineering company, and we're looking for talented individuals to join our dynamic team! Here, ...


From Dvt - Gauteng

Published a month ago

Senior Network Engineer (Jhb)

We Want YouAre you ready to take your career to the next level with BET Software? We're searching for a talented Senior Network Engineer to join our dynamic ...


From Betsoftware - Gauteng

Published a month ago

Built at: 2024-09-21T17:02:39.939Z