433,960open jobs
15,178companies
61,739added this week
Browse all
Salary
$38k – $88k per year (Estimated)
Location
Remote/Hybrid (Johannesburg, Durban, South Africa)
Seniority
Senior · 6+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Old Mutual Limited is a major pan-African financial services group headquartered in Cape Town, South Africa, with origins dating back to 1845. The company provides a broad range of retail and corporate financial solutions, including life and short-term insurance, asset management, personal loans, and digital banking across more than 10 countries in Africa and Asia. Operating as a publicly traded enterprise listed on multiple stock exchanges - including the Johannesburg Stock Exchange - it stands as one of the largest and most established financial institutions on the African continent.

Let's Write Africa's Story Together!

Old Mutual is a firm believer in the African opportunity and our diverse talent reflects this.

Job Description

We are looking for an experienced Information Security Officer to drive the delivery of the organisation’s cybersecurity strategy across assigned business units.

The successful candidate will translate strategic priorities, security policies, regulatory obligations and risk requirements into practical initiatives and sustainable controls that strengthen cyber resilience across applications, infrastructure, cloud, data, third parties and digital services.

The role will lead and coordinate the execution of security improvement roadmaps, ensuring that strategic commitments are converted into measurable delivery outcomes. Key priorities include embedding secure-by-design practices, improving control effectiveness, reducing material security exposures, supporting incident preparedness and recovery, and strengthening the ability of critical business services to anticipate, withstand, respond to and recover from cyber disruption. Working closely with business leaders, technology teams, architects, risk functions and the group information security office, the Information Security Officer will remove delivery barriers, influence investment and risk decisions, track resilience outcomes and drive continual improvement in security maturity

Group Technology & Transformation | IT Governance Risk & Compliance

Governance

  • Develop and maintain Information Security and IT Risk Policies, supporting controls catalogue and related standards across the group to manage / mitigate associated risks.

  • Manage the capability maturity assessments of various IS and IT capabilities per the frameworks adopted (NIST, COBIT, ITIL) bi-annually drive ownership of the improvement plan to achieve agreed targets and to manage associated risks.

  • Analyze outcomes and information to create meaningful insights, to influence focus and budget decisions where input is required.

  • Provide feedback to senior leadership teams (Steering committees, IT leadership forums).

  • Develops and embeds reporting structures per the Information Security and IT management requirements, aligning with Old Mutual Risk and Compliance Governance structures, for risk aggregation and concentration of Old Mutual’s risk exposures.

  • Manage and review various requests and submissions of information to group-wide cyber insurers to determine the best premium for the organisation.

  • Educate and inform employees about our practices and standards.

Regulatory

  • Ensure that the relevant legislative and regulatory requirements are implemented and enforced in the organisation based on risk appetite, risk tolerance, and capability maturity levels (e.g., Cybercrimes Act, draft joint standard: Cybersecurity and Cyber Resilience, draft joint standard: IT Risk Management).

  • Manage and review various requests and submissions of information to the regulator / provide commentary on draft standards issued by the regulator prior to government approval.

Compliance

  • Ensure compliance with Old Mutual’s Information Security and IT requirements set out in policies, the controls catalogue, related standards, regulatory requirements, and industry guidelines.

  • Achieve agreed policy compliance targets for the Information Security and IT risk policies.

Leadership

  • Collaborate / partner with various stakeholders at different levels across the organization (IT, Audit, Business Units, Project teams, etc.) to obtain buy-in, ensure alignment, and achieve deliverables.

  • Lead a team of professionals and third-party service providers to achieve the agreed objectives per Old Mutual’s values, timelines, and budget.

  • Recommended or support optimisation/efficiency / enhancement opportunities aligned to the IT strategy, e.g., automation.

Business Unit Security Strategy Embedment and Oversight

  • Champion and drive the execution of the information and cybersecurity strategy within assigned business units, ensuring alignment to group security objectives, business priorities, and segment-specific risk requirements.

  • Act as the primary security interface between assigned business units and the CISO office, providing trusted advice, challenge, and coordination on security priorities, risks, and decisions.

  • Participate in design reviews and identify potential mitigation strategies for security risks.

  • Analyze business impact and exposure based on emerging security threats.

  • Support the strategic planning and tactical execution of information security initiatives and controls within assigned business units to improve resilience, compliance, and risk management outcomes.

  • Work closely with architects, functional area specialists, and security staff to ensure adequate security solutions are in place throughout all IT systems and platforms to mitigate identified risks sufficiently, and to meet business objectives and regulatory requirements.

  • Facilitates and coordinates the integration of the business-related security risk requirements into the broader governance structures by initiating relevant discussions and ensuring the evidencing of key risk-related decisions.

  • Tracks and reports risk management trends, opportunities, and remediation monthly and provides updates to the Security team

  • Create and maintain reporting, problem resolution, and other tasks necessary for continuous improvement and evolution of services.

  • Manage stakeholders at all levels within assigned business units, building strong relationships and promoting a security-aware culture that gives the business confidence that material information security risks are identified, understood, and addressed.

Qualifications, Experience and Skills

  • Relevant tertiary qualification (Degree / Honours) in Information Security, Cybersecurity, Information Technology, or a related discipline.

  • 6-8 years’ experience in information security, cybersecurity, or IT and Cyber risk, with demonstrated experience in delivering security programmes, remediation initiatives, or resilience improvements across complex environments

  • Strong knowledge of frameworks such as NIST CSF, ISO/IEC 27001 and COBIT, together with the ability to translate strategy into prioritised roadmaps, measurable outcomes and executive reporting, is essential.

  • Experience in financial services, cyber resilience, cloud security, third-party risk, incident preparedness and security assurance will be advantageous

  • Relevant certifications such as CISSP, CISM, CRISC or CISA are preferred.

  • Working understanding of cloud services and best practices.

  • Cloud Certifications an advantage: AWS Cloud Practitioner, AWS Certified Security - Specialty or related.

  • Agile training and knowledge of Agile Frameworks.

  • Strong analytical & problem-solving skills and facilitation, negotiation, conflict resolution skills.

  • Experience in analyzing security and assurance reports: Penetration Testing Reports, Vulnerability Scans, SOC 2 Type 2 Reports, etc.

  • Excellent written & oral communication and networking skills

  • A motivated self-starter, capable of working on own initiative with a high level of integrity.

  • A resourceful, proactive, and confident communicator ensuring adequate quality and timely deliverables.

  • Ability to work professionally and constructively as a leader and team member providing advice and consultancy.

Skills

Action Planning, Analytics Software, Budget Management, Computer Literacy, Data Analysis, Database Reporting, Data Compilation, Data Controls, Data Interpretations, Evaluating Information, Management Reporting, Numerical Aptitude, Report Review, Solution Analysis

Competencies

Business InsightCourageDecision QualityEnsures AccountabilityFinancial AcumenInstills TrustManages ComplexityOptimizes Work Processes

Education

NQF Level 9 - Masters

Closing Date

24 September 2026 , 23:59

The appointment will be made from the designated group in line with the Employment Equity Plan of Old Mutual South Africa and the specific business unit in question.

The Old Mutual Story!

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
433,960 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Johannesburg
$32k – $79k per year (Estimated) • Equity • In office • 7+ years exp • Bachelor's Degree • Johannesburg • Cape Town
Python
Databases
Apache Kafka
AI/ML
Fine-tuning
LLM Guardrails
DevOps
Terraform
Helm
AWS CDK
CloudFormation
Datadog
GitOps
AWS
Kubernetes
Platform Engineering
SLI/SLO/SLA
Apply
Data Engineer 2 1 hour ago
$18k – $42k per year (Estimated) • In office • Full-Time • 2+ years exp • Bachelor's Degree • Bengaluru
Python
SQL
Python
pySpark
Databases
Databricks
Delta Lake
AI/ML
Spark
Airflow
DevOps
GCP
Azure
CI/CD
AWS
Analytics
ETL/ELT
SSIS
Azure Data Factory
Apply
GTM Public Sector 1 hour ago
$73k – $175k per year (Estimated) • In office • Full-Time • 7+ years exp
AI/ML
AI Agents
DevOps
Azure
AWS
Cybersecurity
FedRAMP
Apply
$29k – $68k per year (Estimated) • In office • Full-Time • 5+ years exp • Navi Mumbai • Bengaluru • Hyderabad
DevOps
AWS
Apply
$20k – $47k per year (Estimated) • In office • Full-Time • 5+ years exp • Nagpur • Bengaluru • Jaipur
DevOps
AWS
Incident Management
Apply
Equity • In office • Full-Time • Cape Town
Apply
$32k – $79k per year (Estimated) • Equity • In office • 7+ years exp • Bachelor's Degree • Johannesburg • Cape Town
Python
Databases
Apache Kafka
AI/ML
Fine-tuning
LLM Guardrails
DevOps
Terraform
Helm
AWS CDK
CloudFormation
Datadog
GitOps
AWS
Kubernetes
Platform Engineering
SLI/SLO/SLA
Apply
Training Manager 1 hour ago
In office • Full-Time • Accra
Apply
$13k – $33k per year (Estimated) • Equity • In office • Gqeberha
Apply
$36k – $94k per year (Estimated) • Equity • Remote/Hybrid • Full-Time • 10+ years exp • Bachelor's Degree • Johannesburg
Apply
$20k – $47k per year (Estimated) • In office • Full-Time • Johannesburg
Apply
$21k – $60k per year (Estimated) • In office • Full-Time • Johannesburg
Apply
$43k – $95k per year (Estimated) • In office • Full-Time • 12+ years exp • Johannesburg
Apply
$24k – $69k per year (Estimated) • Equity • In office • Full-Time • Johannesburg
Apply
Junior Underwriter 1 day ago
$15k – $35k per year (Estimated) • Equity • In office • Full-Time • 3+ years exp • Johannesburg
Analytics
Microsoft Excel
Management
Outlook
Apply
See all jobs
This is one of many
433,960 more open roles from verified company boards, updated every day.