Dixie Recruitment has always been known for its strength in Executive Search and Management Placements. In 2020 during COVID, a time of absolute uncertainty, we started Career Talk, a career guidance platform for graduates. It really was about adding value to our graduate community, and we had the time. Business Support Placements was also a COVID baby, a di...
The primary focus of this role is Cyber Assurance and validation of cybersecurity controls, with the Group framework largely based on CIS Controls v8.
You will review business self-assessments, validate supporting evidence, challenge unsupported or overstated responses and ensure cybersecurity risk and maturity reporting is accurate.
This is not a technical remediation role. You will not be responsible for fixing the issues; you need to be technically capable of understanding the controls, asking the right questions and determining whether they are genuinely effective.
Key Responsibilities
Conduct cybersecurity assurance assessments across multiple businesses.
Review and validate business self-assessments and supporting evidence.
Assess the effectiveness of cybersecurity controls.
Challenge inaccurate or unsupported compliance claims.
Identify control gaps, risks and weaknesses.
Apply practical knowledge of CIS Controls v8.
Maintain and assess cybersecurity risk information and risk registers.
Produce portfolio-level risk, maturity and assurance reporting.
Engage with technical and non-technical stakeholders across multiple businesses.
Support third-party risk, security governance and acquisition-related assurance activities.
Requirements
3–5+ years' experience in Cyber GRC, Cyber Assurance, Information Security, IT/Internal Audit, Risk Management or a related field.
Proven experience conducting cybersecurity audits, assurance reviews or control assessments.
Strong practical understanding of CIS Controls v8.
Strong technical understanding of cybersecurity controls and technologies.
Experience reviewing evidence and validating whether controls are genuinely operating.
Ability to challenge stakeholders constructively and investigate responses where required.
Experience with cyber risk assessments and/or risk registers.
Strong analytical, reporting and stakeholder management skills.
Ability to work independently across multiple business units.
Advantageous
Experience in a global, multi-business or decentralised environment.
Knowledge of NIST CSF and/or ISO 27001.
Experience with Microsoft 365, Azure, Entra ID or cloud security.
GDPR, POPIA or other international regulatory knowledge.
Third-party risk management experience.
Relevant certifications such as CISA, CRISC, CISSP, CGRC or ISC2 CC.
Dual passport / international travel capability.
Ability and willingness to travel internationally when required.
The Ideal Candidate
We are looking for someone who can look beyond the answer on the audit questionnaire.
20 Initiatives to Boost Employee EngagementAre you struggling with improving employee engagement at work? This article covers everything from better communication to building a strong workplace culture.
30 Common Interview Mistakes to AvoidThis piece examines 30 of the most common mistakes applicants make at interviews, so you know how to better avoid them.