Information Security and Compliance Analyst New Cape Town SA
Full time
at stitch.money
in
Online
Posted on February 1, 2025
Job details
Information Security and Compliance Analyst
Cape Town SA About Stitch Stitch is a payments infrastructure company on a mission to make it easier for enterprise businesses to connect to the financial system and build better experiences for their customers. We are expanding the team to enable Stitch to broaden our product offering and extend our geographical footprint. Key Responsibilities- Guide and ensure compliance with card-based payment solutions and key management systems to protect transactions and CHD in accordance with PCI DSS and other security standards.
- Assist with the implementation and maintenance of the ISMS in accordance with ISO 27001 and other adopted security-related standards.
- Conduct risk assessments to identify vulnerabilities and ensure appropriate risk mitigation strategies are in place within the ISMS framework.
- Conduct information security due diligence on third-party vendors and provide recommendations to management.
- Complete vendor risk assessments submitted by clients and prospective clients.
- Assist with the development, updating, and enforcement of policies and procedures to sustain compliance with ISO 27001, PCI and other relevant information security standards and practices.
- Assist with the coordinate and manage of PCI, ISO 27001 and related audits, including internal and third-party assessments.
- Train and guide staff on information security practices and policies to foster a secure organisational culture.
- Monitor compliance with information security policies and procedures, reporting on performance against the standards to senior management.
- Create technical documentation and security guidelines for internal use to assist compliance with regulatory requirements.
- Stay abreast of new trends and changes in security regulations and standards to ensure continuous improvement of the ISMS.
- Bachelor’s degree in Information Technology, Cybersecurity, or related field.
- Relevant professional certifications (CISSP, CRISC, CISM, ISO 27001 Lead Auditor or Implementer, PCI ISA) are strongly preferred.
- A minimum of 3 years experience in information security management and compliance, focusing on ISO 27001, PCI DSS, PCI PIN and PCI P2PE.
- In-depth knowledge of information security standards and frameworks, particularly 27001, 22301, 27701, SOC2, POPIA, PCI and GDPR.
- Proven track record of assisting in running with PCI DSS, PCI PIN and PCI P2PE and ISO 27001 audit programmes.
- Strong understanding of cryptographic protocols, key management, and secure payment solutions.
- Ability to perform risk assessments, identify potential threats, and propose effective solutions.
- Excellent analytical, problem-solving, and organisational skills.
- Strong interpersonal and communication skills with the ability to engage effectively with technical and non-technical stakeholders.
- Willingness to stay current on emerging threats, technologies, and regulatory updates related to the payment industry and overall information security.
- Based in Cape Town or willing to relocate.
- Valid driver’s license required.
Employee Assistance Programmes
We care about the well-being of our team. Our Employee Assistance Programmes provide you with the necessary resources and support to not only excel in your job but also to thrive in your personal life. Whether it's counselling, advice, or support services, we're here to help every step of the way.Other notable benefits and perks
Celebrations for important life and work milestones Daily team lunches in the Cape Town office Bi-annual work retreats New starter dinners Frequent team and company events #J-18808-LjbffrApply safely
To stay safe in your job search, information on common scams and to get free expert advice, we recommend that you visit SAFERjobs, a non-profit, joint industry and law enforcement organization working to combat job scams.