Snr Information Security Officer

NI (National Instruments)South AfricaOn-siteFull-timeStaff, 8–12 yearsListed 6 hours ago

Apply now

About this role

About Us:

Network International is the largest Financial Technology company in Middle East and Africa. Payments is our core business where we provide services in more than 50 countries – UAE, Jordan, South Africa, Egypt are some of our key markets. Apart from payments, we provide services on Data and Insights, Lending, Insurance, Risk Solutions, etc. Our core customers are businesses at every scale and segment, though recently we are growing in direct-to-consumer card segment as well.

Our EVP's:

At Network International, we always stay ahead. In the fast-paced world of financial services, we thrive on innovation, agility, and purposeful collaboration. We invest first in our people, empowering you to make bold decisions, learn fast, and grow your expertise alongside industry leaders. Here, solving complex problems means more than using cutting-edge technology; it’s about creating meaningful value for our customers, together. We foster a culture where trust, accountability, and achievement go hand in hand—because success isn’t just a goal; it’s how we work, every day, as one team.

Job Description:

Support the Information security program, Provide oversight and execution of the organizational information security compliance and requirements program. Be accountable for 2 nd line of defense for the DPO Group in line with relevant Regulatory frameworks such as e.g. PCI-DSS, ISO 27001, POPIA and GDPR, as well as NI Group’s own security frameworks and strategic goals. You The successful candidate will also be responsible for implementing security processes and ensure that configuration standards and best practice Hygiene are applied, configured and maintained for the organization’s AWS and various other platforms, collaborating with development, DevOps, DevSecOps to deliver on the corporate security strategy, developing and implementing security solutions to accommodate variety of use-cases at scale.

Responsibilities:

▪ Manage and monitor implementation of technical cloud security controls (e.g. posture, threat response, monitoring etc)
▪ Monitor and plan for threats and incidents in the AWS environment
▪ Evaluate new or acquired cloud solutions, make recommendations on security best practices, and incorporate into cloud security strategy
▪ Responsible for delivery of all AWS security related projects in the region.
▪ Performs regular risk assessments of the AWS infrastructure
▪ Manage AWS Security Incidents end-to-end includes root cause analysis and reporting
▪ Assist with overall responsibility and ownership of the Information Security compliance to provide necessary consultancy and guidance to Group
▪ Bring an engineering approach to security compliance, governance and technical implementation.
▪ Monitor and manage security tooling and Incident response programs.
▪ Performs regular risk assessments of the Security posture and infrastructure
▪ Provide oversight regarding metrics on cloud incidents, alerts across the hybrid cloud environment
▪ Manage Security Incidents end-to-end includes root cause analysis and reporting
▪ Continuously develop and improve the security and data privacy posture and framework to meet industry best practice, regulation and frameworks.
▪ Co-ordinate all information security-related audits such as PCI DSS, ISO 27001,NIST CSF and ISAE 3402/SOC2 in terms of Service Organization Controls.
▪ Assist to Manage ongoing compliance of Information Security standards in coordination with various departments that are impacted.
▪ Own PCI/DSS assurance processes across the group.
▪ Plan and collate key metrics that will provide a realistic view of the compliance state of the IT environment of PayFast, DPO and NI to all stakeholders.
▪ Assist to manage the Information Security compliance program to ensure that staff are trained with regards to their security and data privacy obligations.
▪ Apply practical knowledge and under minimal supervision manage security projects using project management methodologies (e.g., Agile, Waterfall).
▪ Understand and support SOC team with advanced threat hunting and analysis using tools like Security Information and Event Management (SIEM) systems, network traffic analysis tools and endpoint detection and response (EDR) solutions.
▪ Experience with security incident response tools and frameworks (e.g., MITRE ATT&CK) to investigate and respond to security incidents.
▪ Strong knowledge of security technologies, such as secure web gateways, identity and access management (IAM) systems, and security information and event management (SIEM) platforms.
▪ Familiarity with cloud security concepts and experience with cloud security tools and services (e.g., AWS Security Hub, Azure Security Center).
▪ Understanding of secure software development lifecycle (SDLC) practices and tools with ability to perform secure code reviews.
▪ Knowledge of regulatory requirements and compliance frameworks (e.g., GDPR, PCI DSS) and experience with compliance assessments and audits.
▪ Strong communication and leadership skills to collaborate with cross-functional teams and provide technical guidance.
▪ Ability to conduct security risk assessments and develop risk mitigation strategies.
▪ Stay updated on emerging security technologies, threats, and industry best practices through continuous learning and professional development.

Network International is an equal opportunity employer. We welcome and encourage applications from candidates of all backgrounds, nationalities, and experience levels. We are committed to creating an inclusive workplace where innovation, diversity, and performance thrive.