Jobs

Cybersecurity Assurance and Compliance Specialist

Hire Resolve

Eastern Cape Mid-Senior Posted 25 Aug 2026 Closes in 36 days

Overview

The Cybersecurity Assurance & Compliance Specialist is a key member of the Global IT Security team, responsible for leading the organization's governance, risk, and compliance (GRC) activities. This role ensures the organization maintains and advances its security posture through the management of critical certification programs and by overseeing enterprise cyber risk management.

Requirements

  • Minimum 5 years of experience in cybersecurity, information security, IT audit, risk management, governance, or a related compliance role.
  • Minimum 3 years of direct experience supporting one or more of the following: SOC 2, ISO/IEC 27001, CMMC, NIST 800-171.
  • Proven experience managing compliance documentation, coordinating audits, and collecting evidence.
  • Demonstrated experience conducting risk assessments and maintaining risk registers.
  • Experience in responding to customer security questionnaires and assessments.
  • Proficient with Microsoft 365 suite (Teams, Word, Excel, PowerPoint, SharePoint).
  • Comfortable using GRC platforms, policy management tools, and other reporting/documentation software.
  • Ability to read and interpret business cases, project plans, risk reports, and technical documentation.
  • Strong analytical skills to prepare clear, concise written summaries and reports.

Responsibilities

  • Lead and coordinate all activities for SOC 2 Type II, CMMC Level 2, and ISO/IEC 27001 certifications.
  • Maintain audit readiness programs, compliance roadmaps, and a clear framework mapping between standards.
  • Manage evidence collection, control validation, and the tracking of audit findings and corrective actions.
  • Monitor changes in regulatory, customer, and industry frameworks that could impact compliance obligations.
  • Act as the primary liaison to external auditors, assessors, and certification bodies.
  • Develop and maintain audit evidence repositories and supporting documentation.
  • Coordinate all auditor requests, including interviews, walkthroughs, and testing activities.
  • Perform internal compliance reviews and readiness assessments.
  • Establish and maintain policies, standards, and control documentation.
  • Track and report on compliance metrics to leadership.
  • Own the process for responding to customer cybersecurity due diligence requests.
  • Maintain a knowledge base of approved security responses and supporting evidence.
  • Partner with cross-functional teams to provide accurate and timely responses.
  • Manage and maintain the enterprise cybersecurity risk register.
  • Facilitate regular risk assessments across business processes, systems, applications, cloud environments, and third-party vendors.
  • Identify, assess, document, and prioritize cybersecurity risks using established methodologies.
  • Develop and maintain risk scoring frameworks and treatment plans.
  • Prepare risk dashboards, reports, and presentations for leadership and governance committees.
  • Support the development and maintenance of information security policies, standards, and procedures.
  • Assist with third-party risk management and vendor security reviews.
  • Support security awareness and compliance training initiatives.

How to apply

Verify before you apply SpanSam summarises opportunities for easier discovery. Always confirm the closing date, eligibility requirements and submission instructions on the original source before sending personal information or documents.

Apply on source site

About this listing: SpanSam is an opportunity discovery service and is not the hiring employer unless explicitly stated. Application decisions and source-listing changes are controlled by the employer or institution.