View all jobs

Chief Information Security Officer (CISO) (JB6195)

  • Sandton, Gauteng

Chief Information Security Officer (CISO) (JB6195)
Location: Sandton, Johannesburg
Salary: Market Related
Employment Type: Permanent

This is a senior executive opportunity with a technology-focused organisation operating in a fast-paced, security-driven environment. The business runs a 24/7 Security Operations Centre and serves clients with complex cybersecurity obligations, making security governance and operational resilience central to everything it does.

A rare seat at the executive table is open for a CISO who is as comfortable presenting to a board as they are challenging a technical team. This is not a figurehead role. The successful candidate will own the cybersecurity strategy end to end, drive ISO/IEC 27001 certification readiness, lead a round-the-clock SOC, and serve as the organisation's most credible voice on cyber risk. If you have spent years building the expertise to lead at this level, this is the role that matches it.

What's in it for you
Executive-level influence reporting directly to the CEO.
Ownership of a full cybersecurity function spanning strategy, governance, operations and compliance.
The opportunity to lead ISO/IEC 27001 certification from the front.
Oversight of a 24/7 Security Operations Centre with real operational weight behind the role.
A platform to mentor and grow cybersecurity, GRC and security operations teams.
Involvement in client-facing engagements, tenders and strategic security conversations.

Minimum Requirements
NQF Level 7 degree in Cybersecurity, Information Technology, Computer Science or Information Systems.
A minimum of 10 years' experience in cybersecurity.
At least 5 years in a senior cybersecurity leadership position.
Proven track record across security operations, governance, risk and compliance.
Strong working knowledge of ISO/IEC 27001, NIST, COBIT, CIS Controls and relevant data-protection requirements.
Demonstrated experience managing major incidents and engaging with executives, auditors and clients.
CISSP certification is required.
At least one of the following senior certifications is required: CISM, CRISC, CISA, or ISO/IEC 27001 Lead Implementer or Lead Auditor.
Strong commercial acumen, leadership capability and executive communication skills.

Key Responsibilities
Develop and execute the organisation's cybersecurity strategy and roadmap.
Advise the CEO and executive team on material cyber risks and strategic security decisions.
Lead information security governance, policies, risk management and compliance programmes.
Drive ISO/IEC 27001 implementation and certification readiness across the business.
Provide executive oversight of the 24/7 SOC and manage major security incidents.
Ensure effective incident response, vulnerability management and remediation processes are in place.
Oversee cloud, network, endpoint, application, identity and data security.
Review client security obligations, tenders, proposals and service commitments.
Lead cybersecurity audits and manage third-party risk and regulatory compliance.
Define and report on security KPIs, KRIs, incidents and control weaknesses to executive stakeholders.
Develop, mentor and grow the cybersecurity, GRC and security operations teams.
Escalate material risks and hold responsible teams accountable for remediation.

Keywords
CISO, Chief Information Security Officer, cybersecurity strategy, ISO/IEC 27001, CISSP, CISM, CRISC, CISA, SOC, Security Operations Centre, GRC, governance risk compliance, NIST, COBIT, CIS Controls, incident response, vulnerability management, cloud security, enterprise security architecture, cyber risk, Johannesburg

Please do not apply using scanned CVs; no supporting documentation is required at this point. This will be requested later.

Kontak Recruitment Disclaimer
Equal opportunity: All backgrounds are welcome, with no bias. All are considered based on requirements.
Job specifics: Requirements mirror advertisement, duties may adjust for client needs.
Fair process: Fair assessment, only shortlisted candidates contacted due to volume.
Privacy: Data processed as per Privacy Policy. By applying, you agree to data handling. We safeguard applicant info.
Candidate verification: Candidates selected by the client are verified. False info may disqualify or end employment with the client.
Offer clarity: The Advert is not a binding offer. Written offers based on pre-employment conditions.
No direct link: Advert is not tied to Kontak Recruitment. We assist in the employment process ONLY.
Applicant Responsibility: Upon applying, confirmation of receipt for a specific advert is given. If no confirmation is received, you must verify with Kontak Recruitment.