Government EntityTransnet SOC Ltd
    LocationDurban, KwaZulu-Natal
    Reference Numberreq5835
    Centre / LocationDurban Central
    Closing DateSeptember 18, 2026
    Source and Applicationtransnettalentportal.csod.com

    Operating Division: Transnet Pipelines

    Employee Group: Permanent

    Department: ICT

    Grade: E

    Position Purpose: The position holder must lead the design and provide assurance to the CIO on the sustainability of IT general controls, information and technology risks, security of information assets and regulatory compliance (i.e., King IV, etc.) COBIT. The position holder must advocate Information Security, IT risk and compliance to the relevant laws and regulations, to Transnet employees as well as to senior management, to ensure risks relating to the above are mitigated. (e.g., reputational, and non-compliance). The position focuses on the provision of leadership and direction in the area of IT Risk, Information Security, IT Governance, and IT Compliance across TPL. The role develops and implements a comprehensive, enterprise-wide Information Security, Governance, Risk and Compliance (ISGRC) strategy aligned to TPL’s business objectives, industry best practice and applicable regulations/standards (COBIT, ITIL, ISO/IEC 27001). Accountable for TPL-wide cyber incident response: establishing, maintaining and leading the emergency response plan for cyber breaches, coordinating multi-disciplinary teams during incidents, and ensuring rapid containment, recovery and post-incident improvement. Drives a culture of information security awareness through targeted training, campaigns and leadership engagement across all levels of the organisation.

    Competencies: Knowledge required: Sound knowledge of ITIL and COBIT frameworks; understanding of governance frameworks for ICT and King IV; knowledge of IT laws and regulatory obligations. Sound understanding of governance frameworks for ICT. Sound knowledge of IT laws. Understanding of KING IV. Knowledge of software and hardware technologies - the individual should be familiar with a wide range of applications, operating systems, server applications and tools. Network and server security, including firewalls, VPN, IDS/IPS, anti-virus, patch management, vulnerability management. Business applications including SAP. Domain structures, user authentication, and digital signatures and PKI. Intranet, Extranet, Internet, eCommerce, EDI links with parties within and outside of the organization. Process Control/SCADA/PLC environments would be considered an advantage Common information security management frameworks, such as International Standards Organization (ISO) 17799/27001, the IT Infrastructure Library (ITIL) and Control Objectives for Information and Related Technology (CobiT) frameworks. Knowledge of security issues, techniques, and implications across all of the key platforms within the TPL environment, including: o Microsoft Windows Server and Desktop, o Microsoft SQL Server, SharePoint, o UNIX (AIX) o Oracle, o MaxDB, o VPN and remote access technologies, o CISCO networking platforms, o Palo Alto firewall technology, o Data leakage prevention, o Cryptography, o BCM/DRP, o Access Control, o Wireless Security, o Ethical hacking skills, o Application Security, o IT Risk Assessments.

    Equity Statement: Preference will be given to suitably qualified Applicants who are members of the designated groups in line with the Employment Equity Plan and Targets of the Organisation/Operating Division.

    Disclaimer: If you have not heard from Transnet within 90 days, please consider your application as unsuccessful.

    Requirements

    Qualifications & Experience: Related B-degree / B.Tech / Advanced Diploma (NQF 7) in Computer Science/IT/IS (or other degree + IT/IS diploma) with minimum 8 years’ relevant experience, including ?3 years at managerial level, in any of: IT/ICT Risk Management, Audit, Compliance, Governance, Information Security. OR: Relevant National Higher Diploma (NQF 6) + 10 years’ relevant experience with ?5 years managerial/specialist experience in the above domains. Further qualifications preferred: o Certified Information Systems Security Professional (CISSP) o Information Systems Security Architecture Professional (CISSP-ISSAP) o Certified Information Security Manager (CISM) o Certified in Risk and Information Systems Controls (CRISC) o Certified Information Systems Auditor (CISA) o Certified in the Governance of Enterprise IT (CGEIT) o SAP Certified Technology Professional – System Security with SAP NetWeaver (SAP Global Certification) Further professional memberships preferred: o International Information Systems Security Certification Consortium (ISC2) o Information Systems Audit and Control Association (ISACA) Standard Job Requirements Driver’s license code 08 Travel as required and approved

    Duties

    IT GOVERNANCE, RISK & COMPLIANCE 1. Governance/Strategy Develop and maintain an ISGRC strategy that aligns to organisational goals and regulatory requirements; translate strategy into multi-year roadmaps and annual plans. Establish and maintain governance frameworks that ensure accountability, transparency and integrity of security and compliance initiatives across TPL. Review current and proposed information systems for compliance with the organisation's obligations (including legislation, regulatory, contractual, and agreed standards/policies) and adherence to overall strategy. Provide advice to those accountable for governance to correct compliance issues. Define KPIs/metrics for ISGRC effectiveness (e.g., audit closure, vulnerability SLAs, phishing risk, MTTR); report to executive committees and relevant governance forums. 2. Risk Management Conduct regular, formal risk assessments across information assets; define and implement risk mitigation strategies and track closure to tolerance levels set by executive management. Maintain the IT risk register within the approved risk management system. Carry out risk assessment within a defined functional or technical area of business. Use consistent processes for identifying potential risk events, quantifying and documenting the probability of occurrence and the impact on the business. Refer to domain experts for guidance on specialised areas of risk, such as architecture and environment. Co-ordinate the development of countermeasures and contingency plans. Research and advise on risks related to new and existing technologies. Third-party/vendor security risk management: define due-diligence processes, assess supplier risks and ensure contractual controls and ongoing monitoring. 3. Manage Regulatory and Internal Compliance Manage the organisation’s IT regulatory universe. Carry out regulatory and compliance risk assessment of relevant ICT laws and regulations. Use consistent processes for identifying potential regulatory and legal risk events, quantifying and documenting the probability of occurrence and the impact on the business. Refer to domain experts for guidance on specialised areas of regulatory and legal risk, such as legal and regulatory compliance. Co-ordinate the development of compliance control plans. Manage the IT audit function by liaising with internal and external audit Provide a consulting service to TPL IT functional areas on compliance matters (regulatory universe, compliance control plans), risk framework, and IT policies. Ensure adherence to standards where appropriate (for e.g., ITIL, COBIT, ISO, etc.) Prepare and submit compliance and assurance reports to regulatory bodies and auditors, evidencing conformity with applicable standards/frameworks. 4. Manage Business Continuity and Disaster Recovery Implement and contribute to the development of a continuity management plan. Coordinate the assessment of risks to the availability, integrity and confidentiality of systems that support critical business processes. Coordinate the planning, designing, and testing of maintenance procedures and contingency plans. Lead and manage the organisation’s IT BCM and DR strategy INFORMATION SECURITY 1. Information and Cyber Security Strategy Define, present, and promote an information security policy for approval by the senior management of the organisation. Own (not just implement) the development, review and continuous improvement of security policies, procedures and standards; ensure enforcement across the environment. Apply relevant standards, best practices and legal requirements for information security. 2. Manage Information Security Evaluate security management measures and indicators and decides if compliant to information security policy. Investigate and instigate remedial measures to address any security breaches. Provide guidance in defining access rights and privileges. Investigate security breaches in accordance with established procedures and recommend required actions and support/follow up to ensure these are implemented. Serve as a security expert in application development, database design, network, and/or platform (operating systems) efforts, helping project teams comply with enterprise and IT security policies, industry regulations, and best practices. Research and advocate new technologies, architectures, and security products that will support security requirements for the enterprise and its customers. Work with the IT team to ensure adequate security solutions are in place throughout all IT systems and platforms. Establish relationships with key external information security bodies to stay abreast with information security matters in industry and how these could impact the organisation. 3. Implement SIEM (Security Information & Event Management) Contribute to the development of policies, standards, processes, and guidelines for the SIEM solution. Analyse and prioritise security incidents in line with the security incidents management policy. Investigate and instigate remedial measures to address any security incidents. 4. Manage Threat Protection Coordinate and manage the planning of penetration tests. Deliver objective insights into the existence of vulnerabilities, the effectiveness of defences and mitigating controls - both those already in place and those planned for future implementation. Take responsibility for integrity of testing activities and coordinates the execution of these activities. Provide authoritative advice and guidance on the planning and execution of vulnerability tests. Define and communicates the test strategy. Manage all test processes and contribute to corporate security testing standards. 5. Manage data/information security which includes data loss prevention and encryption Provide advice and guidance on security strategies to manage identified risks and ensure adoption and adherence to standards. Obtain and act on vulnerability information and conduct security risk assessments, business impact analysis and accreditation on complex information systems. Investigate major breaches of security and recommends appropriate control improvements. Contribute to development of information security policy, standards and guidelines 6. Manage Identity, Access, and User Authentication Ensure that access privileges to the organisation’s information technology assets and resources (including networks, systems, applications, computers and mobile devices) based on the principles of need to know (users or resources are granted access to systems that are necessary to fulfil their roles and responsibilities) and least privilege ( users or resources are provided with the minimum privileges necessary to fulfil their roles and responsibilities). 7. Manage network security Maintain security administration processes and check that all requests for support are dealt with according to agreed procedures. Provide guidance in defining access rights and privileges. Investigate security breaches in accordance with established procedures and recommend required actions and support/follow up to ensure these are implemented. 8. Manage Data Centre, Server, and Storage Security Review operational metrics of IT systems and environments and take appropriate action to ensure corrective and proactive maintenance to support the requirement to protect and secure business information. Create reports and proposals for improvement and contribute to the planning and implementation of new installations and scheduled maintenance and changes within the system. Review operational procedures from an information security perspective, and provide technical expertise and appropriate information to the senior management. 9. Manage end user device security Implement information security policy Monitor compliance to approved end user device configuration standards Ensure end-user computing device applications and multimedia capabilities are not used to breach privacy and confidentiality according to the Acceptable Use Policy Minimize security risks associated with end-user computing devices by ensuring that all such equipment is encrypted, password protected, and physically secured, minimizing the threat of loss or theft of the device itself and any confidential data contained therein. 10. Implement and maintain a robust incident response plan, including playbooks, roles, communications and post-incident reviews; coordinate response to incidents and breaches. 11. Evaluate and recommend security technologies, tools and services to enhance TPL’s security posture; lead associated business cases. 12. Lead security awareness programme design and roll-out (campaigns, simulations, training). 13. Cross-functional collaboration with Legal, Compliance, HR, OT/SCADA, BCM and enterprise risk to ensure alignment of security, compliance and business continuity with business objectives. 14. Manage the budget allocated for information security, governance and risk initiatives, ensuring value realisation and cost optimisation.

    Source / Circular Reference

    transnettalentportal.csod.com