Chief Information Security Officer
Role Overview
Empowering Africa’s tomorrow, together…one story at a time. With over 100 years of rich history and strongly positioned as a local bank with regional and international expertise, a career with our family offers the opportunity to be part of this exciting growth journey, to reset our future and shape our destiny as a proudly African group. Belonging at Absa Absa is committed to creating an inclusive workplace where everyone can thrive. We are an equal opportunity employer and welcome applications from suitably qualified individuals from diverse backgrounds. In support of our Diversity, Equity, Inclusion and Belonging (DEIB) commitments and Employment Equity objectives, preference may be given to candidates from underrepresented designated groups, including persons with disabilities. We encourage applicants who may require reasonable accommodation during the recruitment process to let us know so that appropriate support can be provided.
The Chief Information Security Officer (CISO) is accountable for establishing, leading and continuously enhancing Absa's enterprise cyber security and information security capability. The role is responsible for protecting the confidentiality, integrity and availability of the organisation's information assets, digital platforms, technology infrastructure and customer services. The CISO provides strategic leadership and executive oversight of cyber risk management, cyber defence, security operations, security engineering, cyber resilience, identity and access management, threat intelligence and regulatory compliance. As a member of the Information & Technology Office (ITO) Executive Committee, the CISO works closely with business and technology leaders to ensure security is embedded into business strategy, technology transformation and operational decision-making. The role provides assurance to the Board, Executive Management, regulators, customers and stakeholders that Absa maintains an effective cyber security posture aligned to regulatory requirements, industry best practice and the organisation's risk appetite. The CISO plays a critical role in enabling innovation and digital growth while ensuring appropriate protection against cyber threats, operational disruption, reputational damage and financial loss.
Strategic Cyber Security Leadership Define, maintain and execute Absa's enterprise-wide cyber security strategy and operating model. Develop a multi-year cyber security roadmap aligned to business objectives, technology transformation initiatives and regulatory requirements. Establish cyber security as a strategic business enabler that supports innovation, digital adoption and customer trust. Provide thought leadership on emerging cyber threats, industry trends and evolving regulatory requirements. Advise Executive Committees, Risk Committees and the Board on cyber security strategy, risk and resilience. Cyber Risk Management Establish and oversee the enterprise cyber risk management framework. Ensure cyber risks are identified, assessed, quantified, prioritised and managed in alignment with the organisation's risk appetite. Provide regular reporting on cyber risk exposure to executive management and governance forums. Embed cyber risk management practices into business processes, technology change programmes and strategic initiatives. Ensure effective management of third-party and supply chain cyber security risks. Security Operations and Cyber Defence Lead and continuously enhance the Security Operations Centre (SOC). Oversee cyber threat monitoring, threat hunting, detection and response capabilities. Ensure the effective identification, containment, investigation and remediation of cyber security incidents. Maintain executive oversight of cyber incident response processes and major cyber event management. Drive the adoption of intelligence-led cyber defence capabilities focused on proactive threat mitigation. Cyber Resilience Develop and maintain enterprise cyber resilience and recovery capabilities. Ensure appropriate cyber recovery strategies are implemented and regularly tested. Partner with technology, infrastructure and business stakeholders to strengthen operational resilience against cyber disruption. Maintain preparedness for significant cyber incidents through testing, simulation exercises and executive engagement. Ensure lessons learned from incidents and exercises are incorporated into continuous improvement initiatives. Security Architecture and Engineering Establish enterprise security architecture principles, standards and patterns. Ensure security controls are embedded within cloud, application, infrastructure and data environments. Drive secure-by-design and secure-by-default practices across technology delivery teams. Oversee the implementation and effectiveness of cyber security technologies and platforms. Ensure security requirements are integrated throughout the software development lifecycle. Identity and Access Management Establish and maintain enterprise identity and access management strategies. Ensure effective governance and control of privileged access. Drive the implementation of modern authentication, authorisation and identity security capabilities. Ensure access controls align to regulatory, operational and security requirements. Regulatory Compliance and Assurance Ensure compliance with all applicable cyber security regulations, industry standards and regulatory obligations. Maintain effective relationships with regulatory authorities on cyber security matters. Oversee independent security assessments, penetration testing, audits and capability reviews. Provide executive assurance regarding the effectiveness of security controls and overall cyber security posture. Ensure timely remediation of identified vulnerabilities, risks and control deficiencies. Security Culture and Awareness Develop and maintain a strong cyber security culture across the organisation. Promote accountability for cyber security at all levels of the business. Drive enterprise-wide security awareness and education programmes. Ensure employees understand their role in protecting information assets and customer data. Position cyber security as a shared organisational responsibility. Leadership and People Management Lead high-performing cyber security teams. Establish a culture of accountability, innovation, excellence and continuous improvement. Develop succession plans and talent strategies for critical cyber security roles. Build and maintain a diverse pipeline of cyber security skills and leadership capabilities. Foster strong collaboration across technology, risk, compliance and business functions. External Representation Represent Absa at industry forums, regulatory engagements and cyber security working groups. Build strategic relationships with industry peers, regulators, cyber security organisations and relevant external stakeholders. Position Absa as a recognised leader in cyber security and cyber resilience within the financial services sector.
Requirements
Education and Experience
- Required Essential Bachelor's degree in Information Technology, Computer Science, Cyber Security, Information Systems, Engineering or a related discipline. 15 years of progressive experience in cyber security, information security, technology risk or related fields. 8-10 years' leadership experience managing large-scale cyber security functions within a complex organisation.
- Demonstrated experience operating within highly regulated financial services or similarly regulated industries.
- Proven experience engaging executive committees, boards and regulators on cyber security and technology risk matters.
- Significant experience leading enterprise cyber transformation programmes.
- Preferred Postgraduate qualification in Technology, Cyber Security, Business Administration or a related field.
- MBA, MSc Information Security or equivalent advanced qualification.
Education
- Bachelor's Degree: Information Technology
Contact Absa Group Africa
Job Details
Ready to Apply?
Don't miss out on this opportunity. Apply now and take the next step in your career.
Apply Now