Skip to content
← Back to job listings

Senior Specialist - Data Protection and IAM.Technology Information

MTN EXTERNAL CAREER SITE · Remote, Gauteng, South Africa

IT - Network / Systems / DB AdminSenior LevelRemoteExternal listingfull-time3 days ago

About The Role

Mission/ Core purpose of the Job

This role reports into the MTN SA Hub that provides Information Security Services to the identified Spoke MTN Operating Companies (Opcos). The responsibilities of this role include designing, implementing and maintaining identity and access management (IAM) solutions and processes (based on Group Ref architecture) related to authorization, authentication, identity registry management, and identity lifecycle in the Spoke Opcos' data repositories. The role is also responsible for for providing data protection services to the Spoke Opcos. The Specialist will anticipate data security requirements and identify sound security controls for applications, systems and processes. All IT and Network environments of the supported Opcos are within scope of this role.

Context

  • The individual needs to be able to work in a highly pressured planning and operational environment
  • ISO 27001, OWASP, NIST, SANS and POPI
  • Fast changing, regulated business environment.
  • Security is managed cross functionality across Network and IT functions
  • Security policies and frameworks are driven from MTN Group
  • The Technology Security area has to deal with the rapid advancement of systems and technology within the following areas:

o OSS (Operational support systems)

o BSS (Business support systems) layers

o Various Network platforms enabling many Billing, VAS and ISP network functions

o Trends within the industry as being experienced and embraced internationally must be followed

o Deal with and environment that is highly regulated and legislated

o Operate in a scarce skills & highly specialised systems environment

o Outsourced partners and the driving of these through retaining in-house knowledge and supplying vendors fully fledged and detailed specifications and driving vendors in the fulfilment of these

o Requirement for single version of the truth drive across MTN South Africa

o High data volumes

Key Performance Areas: Core, essential responsibilities / outputs of the position (KPA's)

Key Deliverables - Ensure clear execution on below delivery from SA Hub Opco to allocated Spoke Opcos

  • Implement business processes and policies related to controlling access to data, protection strategies, architectures and implementation plans in alignment to Group Policy and Reference Architecture.
  • Work closely with Privacy teams of Spoke Opcos to ensure potential and real incidents of data leakage are resolved
  • Provide security guidance and review on business and technology solutions, model threats and risks as well as the controls necessary to mitigate them, on both an organisational and technical level – thinking like a malicious hacker, understanding and anticipating the moves and tactics that a hacker might use to attack MTN systems.
  • Implement policies and standards to protect data, applications, and the associated infrastructure that reside in a public cloud
  • Implement Data Leakage Prevention policies for Office 365 Data leakage prevention policies for OneDrive, Exchange online and SharePoint and integration with other platforms
  • Configure and implement Mobile Application/ Device management policies
  • Define local Opco security policies and standards for database protection
  • Implement information security controls to protect databases and stored data
  • Demonstrate architectures, methods and controls required to meet stringent compliance and audit requirements
  • Architect, engineer and support data security solutions from pre-deployment through deployment and post
  • Review plans to safeguard sensitive data against accidental or unauthorized modification, destruction, or disclosure and to meet emergency data processing needs
  • Proactively assess DLP safeguards across the DLP tool suite to identify potential risks and perform trend analysis
  • Provide technical support for a comprehensive risk management program identifying mission critical processes and systems; current and projected threats; and system vulnerabilities.
  • Administer and support data loss prevention solutions, creating and implementing Data Loss Prevention (DLP) rules that trigger on specific conditions to data attributes or data class.
  • Create Regular Expression rules that work against a wide range on premise and cloud-based solutions
  • Assist in identifying, assessing, and recommending security software, processes, and services to Senior Manager Security Managed Services based on business plans and security gaps, as appropriate.
  • Recognize and identify potential areas where existing data security policies, procedures, and controls require change, or where new ones need to be developed.
  • Maintains an awareness of industry trends and emerging risks, and proposes relevant company response.
  • Provide support to manage critical issues that may affect customers, including determining short-term solutions.
  • Complete status and statistical reports in assigned area as required
  • Provide support to Senior Manager Security Managed Services in partnering with legal, privacy and audit departments to ensure compliance with policy and regulatory requirements.
  • Lead the daily operations of Access Provisioning, aligning with best practice standards and information security policies and procedures.
  • Oversee the design, installation, configuration and support of IAM security technologies across the Spoke Opcos
  • Ensure that the security solutions and architectural designs utilize the IAM security components necessary to meet MTN and regulatory requirements
  • Define local Spoke Opco policies, standards, and procedures for remote access and remote access security with alignment to Group standards.
  • Assess and develop IAM roadmaps to improve the Opcos’ security posture by identifying security gaps to manage existing and emerging security risks
  • Lead efforts and participate in audits covering IAM services and technologies in the Opcos
  • Assist in executing upgrades to existing systems, communications and coordination of change with impacted departments, directly or through delegation
  • Activities that are not executable from the Hub Opco needs to be raised to the relevant stakeholder to ensure cyber security risks are addressed.
  • Build a strong relationship with Spoke Opco to ensure delivery.
  • Where there are challenges to perform tasks remotely, ensure the Spoke Opco execute actions that are in line with above mentioned activities.
  • Where there are challenges to execute actions remotely, the incumbent needs to resolve the challenges in a timely manner and inform the relevant stakeholders.

Creativities (improvement/innovation inherent)

  • Implement and enhance security disciplines
  • Investigate and research best practices in Endpoint, Application and Network Security and related disciplines with a view to leveraging for MTN
  • Reduce complexity and streamline processes with a view to optimize technologies and reduce operational costs
  • Input and leadership in analytical thinking for MTN
  • Influence management decision making in security related aspects
  • Pro-active
  • Champion of quality and doing things right the first time
  • Sharing of knowledge and security skills

Budgets

  • Assist with management of departmental budgets in line with business objectives and facilitate forecasting
  • Manage project initiative budgets in line with business objectives
  • Drive initiatives that will ensure that the “cost of operations” are reduced, in line with a least cost operating strategy stemming from the business drivers.
  • Assist Spoke Opcos with contract negotiations

Vulnerabilities (control span)

  • Large amount of workload
  • Operational teams commitments to other projects
  • Complexity of the environment and the need to implement security changes in a phased manner to minimize impact
  • Vendor Applications not being able to meet the security standards

Role Dependencies

  • MTN SA Technology Security
  • MTN Group Security
  • MTN SA’s IT operations and applications
  • Network division
  • MTN Spoke Opco
  • MTN Policies

Responsibility towards

  • Key external stakeholders: External contractors & partners
  • Key internal stakeholders:
  • o Opco Information Security Head/ CIO/ CTO/ CTIO
  • o Business Verticals in MTN
  • o Hub Opco InfoSec team
  • o Spoke Opco InfoSec Team
  • o Spoke Opco IT Operations Team
  • o Hub Opco IT Operations Team

Independent thought and Judgment

  • Alignment to department strategy and assist in setting objectives for the department
  • Assist in management of budgets through viewing ones system landscape innovatively and prioritising work
  • Implement efficiencies in systems and processes
  • Determine SLAs with “internal clients” as well as external outsourced suppliers.
  • Exercise the mandate, subject only to budget and legal constraints
  • Implement change on a discretionary basis as presented by the GM
  • Implementation of action plans and activities
  • System, process and procedure fine-tuning / development to achieve business objectives
  • All decisions made to be aligned to MTN SA strategic & Business plan.
  • Exploration of the market and global trends to recommend future direction in terms of business architecture and information needs
  • Lateral thought to recommend system development requirements to align with Business Plan strategy.
  • Decision-making that is effective and responsible for profit and business sustainability and growth and within parameters of budget and business plan
  • Security incident response

Authorities

  • Budget
  • Recommendations on systems strategies, technologies, frameworks and policies
  • Implementation of appropriate security standards and security settings
  • Acceptance testing signoff on Vendor work
  • Analysis of capacity trends and impacts on service thereby planning for future requirements

Minimum Requirements

Education

  • Minimum of 3 years tertiary qualification (degree/ national diploma) in Information Technology/ Engineering
  • CISSP/CEH/ CGEIT certification (one of)
  • Business analysis/architecture qualifications
  • Other qualifications (ITIL, TMF, COBIT) advantage

Experience

  • Minimum of 5+ years of relevant work experience in Information Security
  • Experience in managing and implementing large scale security projects
  • Advanced working understanding of the information and technology environment of a bank or telecom company
  • Understanding emerging markets advantageous
  • Worked across diverse cultures and geographies
  • Pan Africa multi-cultural experience is advantageous

Functional Knowledge

  • Strong knowledge of data protection software and hardware solutions, including transparent solutions [SQL, Oracle TDE]
  • Knowledge of data security mechanisms with an understanding of cryptographic techniques and protocols. This can include symmetric and asymmetric encryption algorithms [AES, RSA], hashing algorithms [SHA/HMAC] and data in transit protection protocols [TLS/IPSec].
  • Knowledge of data security standards
  • Experience implementing solutions beyond analysis/assessment that meet requisite compliance.
  • Experience in a technical customer-facing consulting or advisory role.
  • Experience implementing data security solutions for applications [Java, .net, web services] and databases [Oracle, MS-SQL].
  • Basic knowledge of DLP solutions
  • Fluent in English and overall business acumen
  • Ability to express complex technical security control concepts passionately and effectively
  • Ability to work well with people from different disciplines and countries with varying degrees of technical experience.
  • Ability to communicate effectively when dealing with business customers and suppliers.
  • Knowledge of national and international regulatory compliances and frameworks such as NIST-CSF, ISO-27000, POPI, GDPR, PCI, etc.

Competencies

Head - Big Picture Focus (20)

  • Strategy Implementers - Ensures execution of strategies through creating and implementing tactical plans for others to follow
  • Decisive Problem Solver - Has the mental agility to identify business challenges and explore effective solutions through effective influencing
  • Best Practice Value Creator - Encourages commercial innovation and continuous improvement for systems, processes, products and service offerings

Heart – Emotionally Intelligent (30)

  • Culture and Change Champion - Role models ethical practices by living the MTN values and vital behaviours for others to follow
  • Guiding People Manager - Is self-aware and guides team capability development through opportunity creation for realising potential
  • Relationship Builder - Builds relationships across the business in order to influence decision-makers and build team credibility

Hands – Results Focused (40)

  • Results Achiever - Produces sustainable divisional results through ethical practices
  • Operationally Astute - Sets priorities, plans, organizes and co-ordinates the work of others

General working conditions

  • Target driven and cyclic in nature
  • Long, irregular hours and tight deadlines during peak periods
  • Working in busy open plan environment
  • Stressful, Non routine
  • Tied in with legal responsibilities
  • Laptop
  • Standby
  • Dial in facility
  • Mobile phone
  • Full-time engagement online/ telephonic with In-country teams of the Spoke Opcos
  • Must be willing to travel outside of country to Spoke Opcos if required

KPA Quality Standards

  • Security settings deployed – alignment to MTN security standards and best practices
  • Number of server and application systems to which the security standards are deployed
  • Degree of impact to systems and users while deploying standards
  • Security settings deployed counter MTN risks, e.g. theft of intellectual property, information leakage
  • Speed with which security settings are deployed
  • Implementation of security event monitoring in the server environment that strikes a balance between security events that are relevant and important vs. minimizing false positives
  • Completeness and accuracy of documentation
  • Sustainability of processes implemented
  • Expenditure within budget
  • Quality of source data in terms of completeness, accuracy and timeliness
  • Meeting agreed SLA’s with customers
  • Objectives of area met
  • Collaboration with all key stakeholders
  • Drives short term actions consistent with long term goals.
  • User/customer satisfaction/feedback
  • Capex and Opex vs budget
  • Project Metrics (In time, cost + quality)
  • Systems availability
  • Timely delivery of information to internal customers (reporting, dashboards etc)
  • High levels of automation of data processing and reporting
  • Incorporation of new technologies
  • Alignment to MTN Strategy

This is an external listing. JobSpring does not represent or verify the employer. Report this listing