The Cybersecurity Assurance & Compliance Specialist is a key member of the Global IT Security team, responsible for leading the organization's governance, risk, and compliance (GRC) activities. This role ensures the organization maintains and advances its security posture through the management of critical certification programs (SOC 2 Type II, CMMC Level 2, ISO/IEC 27001) and by overseeing enterprise cyber risk management.
This position serves as the primary point of contact for external auditors, certification bodies, customers, and internal stakeholders, ensuring continuous audit readiness and compliance with all applicable regulatory and contractual requirements. The ideal candidate will be a strong communicator who can translate complex technical requirements into actionable business processes.
Compliance & Certification Management
Lead and coordinate all activities for SOC 2 Type II, CMMC Level 2, and ISO/IEC 27001 certifications, including audits and continuous improvement.
Maintain audit readiness programs, compliance roadmaps, and a clear framework mapping between standards (e.g., NIST 800-171, CIS Controls).
Manage evidence collection, control validation, and the tracking of audit findings and corrective actions through to completion.
Monitor changes in regulatory, customer, and industry frameworks that could impact compliance obligations.
Audit & Assurance Management
Act as the primary liaison to external auditors, assessors, and certification bodies.
Develop and maintain audit evidence repositories and supporting documentation.
Coordinate all auditor requests, including interviews, walkthroughs, and testing activities.
Perform internal compliance reviews and readiness assessments.
Establish and maintain policies, standards, and control documentation.
Track and report on compliance metrics to leadership.
Customer Security Assurance
Own the process for responding to customer cybersecurity due diligence requests, security questionnaires, and RFP security sections.
Maintain a knowledge base of approved security responses and supporting evidence.
Partner with cross-functional teams (Sales, Legal, Privacy, Infrastructure) to provide accurate and timely responses.
Participate in customer security discussions to articulate the organization’s security posture.
Support contract reviews related to cybersecurity requirements.
Cyber Risk Management
Manage and maintain the enterprise cybersecurity risk register.
Facilitate regular risk assessments across business processes, systems, applications, cloud environments, and third-party vendors.
Identify, assess, document, and prioritize cybersecurity risks using established methodologies.
Develop and maintain risk scoring frameworks and treatment plans.
Coordinate with risk owners to establish mitigation strategies and track remediation activities.
Prepare risk dashboards, reports, and presentations for leadership and governance committees.
Develop and maintain Key Risk Indicators (KRIs) to measure program effectiveness.
Governance & Security Program Support
Support the development and maintenance of information security policies, standards, and procedures.
Coordinate annual policy reviews and control effectiveness assessments.
Assist with third-party risk management and vendor security reviews.
Support security awareness and compliance training initiatives.
Contribute to the continuous improvement of the overall security program maturity.
Required Experience
Minimum 5 years of experience in cybersecurity, information security, IT audit, risk management, governance, or a related compliance role.
Minimum 3 years of direct experience supporting one or more of the following: SOC 2, ISO/IEC 27001, CMMC, NIST 800-171.
Proven experience managing compliance documentation, coordinating audits, and collecting evidence.
Demonstrated experience conducting risk assessments and maintaining risk registers.
Experience in responding to customer security questionnaires and assessments.
Technical & Software Skills
Proficient with Microsoft 365 suite (Teams, Word, Excel, PowerPoint, SharePoint).
Comfortable using GRC platforms, policy management tools, and other reporting/documentation software.
Ability to read and interpret business cases, project plans, risk reports, and technical documentation.
Strong analytical skills to prepare clear, concise written summaries and reports.
Preferred Education & Experience
Bachelor’s degree in Information Security, Cybersecurity, Information Technology, Risk Management, Business Administration, or a related discipline is preferred.
An equivalent combination of education, professional certification (e.g., CISSP, CISM, CRISC, CISA), and relevant experience may be considered.
Specialists in Civil, Structural, Mechanical Engineering, Information Technology, Mining, Manufacturing and Finance Careers! Hire Resolve is one of the larger and more agile South African recruitment companies that focus on placing professionals and skilled people in permanent employment and contract employment. We prefer and focus on working with top quality professionals and candidates in South Africa and Africa. Hire Resolve has successfully placed Engineering, Mining, IT, Manufacturing and Finance professionals with top firms across the Western Cape, Eastern Cape, KwaZulu Natal, Gauteng and in Africa. Hire Resolve has assisted candidates to find jobs at over 100 JSE listed companies of which many are global companies with offices and operations in South Africa and Africa. It is for this reason that we are well respected in the industries we operate in and in the recruitment industry.
You have successfully created your alert.
You will receive an email when a new job matching your criteria is posted.
Please check your email. It looks like you haven't verified your account yet. Here's what you're missing out on:
Didn't receive the link? Resend Verification Link