Head: Information Security & GRC

Development Bank of Southern Africa DBSA · Johannesburg, Gauteng

Stop applying one at a time.

JobAlertsZA auto-applies to South African jobs like this one for you, overnight. Upload your CV once — we do the applying.

Start free — we apply for you →

Job Description

  • The Head: Information Security & GRC provides enterprise-wide leadership for the Bank's ICT environment, information and systems security, cyber resilience, technology risk, governance, compliance and assurance. The role is accountable for establishing and maintaining a secure, resilient, compliant and business-aligned technology environment across infrastructure, cloud, applications, data, identity, third-party platforms and emerging technologies. The incumbent develops and executes integrated ICT and information security strategies, policies, standards, controls and operating models aligned to the Bank's mandate, business strategy, risk appetite, regulatory obligations and recognised frameworks such as ISO/IEC 27001, NIST Cybersecurity Framework, COBIT, ITIL, POPIA and King V. The role enables secure digital transformation, strengthens operational resilience, provides executive and board-level reporting on technology and cyber risk, and embeds a culture of security, accountability, service excellence, innovation and continuous improvement across the organisation.

Key Responsibilities KEY PERFORMANCE AREAS

Strategic Delivery

  • Develop and execute a comprehensive ICT, information security, and GRC strategy aligned to the organisation's overall business objectives and long-term vision.
  • Identify strategic priorities and deliverables for Information / Security, and GRC based on the overall Bank strategy, ensuring alignment with organisational priorities.
  • Own the enterprise ICT and security operating model, ensuring clear accountability for infrastructure, systems security, cloud security, identity and access management, data protection, resilience and GRC outcomes.
  • Translate strategic priorities into clear digitalisation goals, initiatives, milestones, and measurable outcomes.
  • Develop both long-term and short-term digitalisation strategies and implementation plans aligned to approved budgets and resource frameworks.
  • Drive enterprise-wide adoption of digital solutions through structured communication and stakeholder engagement internally and externally.
  • Lead the communication of the strategy to all stakeholders internally and externally.
  • Drive ICT and cybersecurity as strategic business enablers by aligning technology and security initiatives with business objectives, digital transformation priorities, and enterprise risk management outcomes.

Governance and Compliance

  • Establish and enforce information security policies, standards, and procedures.
  • Maintain compliance with South African and international regulations e.g.., POPIA, GDPR, ISO/IEC 27001.
  • Conduct regular policy reviews and updates in line with regulatory changes.
  • Liaise with legal, risk, compliance and audit teams to manage regulatory risks and compliance obligations.
  • Promote cyber risk ownership across business units by embedding cybersecurity risk management into business processes and decision-making.
  • Maintain an integrated technology, cyber and compliance control framework, including control ownership, testing, evidence management, remediation tracking and assurance reporting.
  • Facilitate and drive appropriate, reasonable technical and organisational measures are implemented and evidenced to protect personal information, critical systems and sensitive business information.

Cyber Security Operations

  • Oversee the Security Operations Centre SOC and ensure effective threat monitoring and response.
  • Manage incident response plans and lead investigations into security breaches.
  • Implement and maintain security technologies e.g.., SIEM, DLP, firewalls, endpoint protection.
  • Conduct regular vulnerability assessments and simulationpenetration testing.
  • Leverage AI, automation, and advanced analytics to improve threat detection, monitoring, incident response, and security operations effectiveness.
  • Drive the adoption of modern cybersecurity practices, including Zero Trust Architecture, cloud security governance, and continuous threat exposure management.

Third-Party Risk Management

  • Develop and implement a third-party risk management framework.
  • Conduct due diligence and risk assessments for new and existing vendors.
  • Monitor third-party compliance with security requirements and SLAs.
  • Maintain a centralised third-party risk register and reporting mechanism.
  • Ensure third-party engagements do not compromise the organisation's security, data, or operational integrity.

Reporting and Governance

  • Establish and enforces robust governance frameworks and reporting mechanisms to ensure transparency, compliance, and effective decision-making across all operations.
  • Provide timely and accurate reporting of key performance indicators, risks, and progress against strategic objectives to relevant internal and external bodies.
  • Prepare for and lead internal and external security audits.
  • Maintain audit trails and documentation for compliance purposes.
  • Report on security posture, incidents, and risk metrics to executive leadership and the board.
  • Implement corrective actions and track remediation progress.

Stakeholder Engagement

  • Build and maintains strong, collaborative relationships with key internal and external stakeholders, including leadership, government entities, commercial banks, development partners, and community representatives, to drive shared objectives.
  • Navigate complex stakeholder landscapes, influencing outcomes and fostering consensus to achieve strategic goals.
  • Collaborate with enterprise architecture, infrastructure and solution delivery teams to ensure security-by-design principles are incorporated into technology and digital solutions

People Management

  • Lead, mentor, and develop a high-performing team, fostering a culture of collaboration, accountability, and continuous learning to maximise individual and collective potential.
  • Drive talent development initiatives, including coaching, performance management, and career pathing, to build and retain a skilled and motivated team.
  • Attract, retain, and develop talent and ensure succession planning and sufficient capacity and capability in all critical functions, supporting diversity strategies and initiatives as well.
  • Promote DBSA values and a culture of high performance through implementing performance management in line with the planned strategic objectives, goals, quality standards and agreed key performance measures using sound performance management principles.
  • Contribute to building synergies & cooperation across functions in the DBSA.
  • Promote cybersecurity and AI literacy across the organisation through awareness, behavioral change, and capability-building programmes.

Security and Digital Transformation

  • Foster a culture of security awareness and ensuring that third-party engagements do not compromise the organisation's security or operational integrity.
  • Ensure that information and cyber security capabilities, controls, and governance frameworks effectively support and enable digital transformation initiatives, while protecting DBSA's information assets and technology environment.
  • Foster a mindset of innovation, identifying opportunities to adopt emerging technologies and best practices to modernise processes and deliver impactful solutions.

Key Measurements of Outputs

  • Percentage reduction and prevention in security incidents.
  • Percentage of critical systems compliant with approved security baselines, patching thresholds and resilience requirements.
  • Successful adherence to compliance & audit performance.
  • Improvement of security awareness & training impact of employees.
  • Advancement in the organisation's cybersecurity maturity model score.
  • Percentage of critical assets covered by key security controls.
  • Number of open critical/high-risk findings identified in third-party assessments.
  • Number of security incidents originating from or involving third parties.
  • Reduction in material cyber risk exposure.
  • Board and executive repo
Auto-apply to this jobView original posting ↗
Head: Information Security & GRC at Development Bank of Southern Africa DBSA — Johannesburg, Gauteng · JobAlertsZA