Information Security Lead.
Location: Fourways, Johannesburg (Magaliessig Office).
Type: Full-time.
Closing Date: 19 September 2025.
About the Company
Interfile is South Africa’s leading Electronic Bill Presentment & Payment (EBPP) fintech, delivering large-scale digital solutions for banks, corporates, and government. With a strong focus on innovation and modern architectures, the company provides a collaborative workspace that includes a Vitality-certified gym, canteen, and relaxation areas.
Role Purpose
The Information Security Lead will be responsible for strengthening and maintaining security across on-premise and cloud environments, covering hardware, networks, and data centres.
The role involves driving vulnerability remediation (through automation and manual interventions), ensuring compliance with POPIA, and implementing/upgrading security standards (ISO 27001/27002, NIST CSF 2.0). The successful candidate will also oversee risk management, incident response, and help embed a security-first culture across the business.
Key Responsibilities
Security Assessments: Conduct infrastructure, application, and data environment assessments; manage SAST/DAST tools; track and resolve vulnerabilities.
Monitoring & Reporting: Develop security dashboards and reports, set KPIs, and ensure accountability across teams.
Automation & CI/CD: Design automated controls, integrate security into CI/CD pipelines.
Compliance: Align with POPIA and data protection regulations; support audits and compliance reporting.
Frameworks: Implement and align security practices with ISO 27001/27002, NIST CSF 2.0.
Risk Management: Maintain a risk register and work with business units to mitigate risks.
Incident Response: Develop response plans, lead breach investigations, and oversee post-incident reviews.
Awareness & Training: Deliver training programs and promote a security-first culture.
Vendor Security: Assess risks tied to third parties and ensure SLAs include proper security clauses.
Architecture: Participate in solution reviews and advise on secure design patterns.
Requirements
Bachelor’s degree in Information Security, Computer Science, or similar.
At least one recognized security certification (CISSP, CISM, CEH, CompTIA Security+, ISO 27001 Lead Implementer, etc.).
5+ years of experience in information security roles.
Proven expertise across infrastructure, applications, and data environments.
Hands-on experience with SAST/DAST tools (SonarQube, OWASP ZAP, Burp Suite).
Strong vulnerability management and automation skills (Python, PowerShell, CI/CD).
Knowledge of POPIA and other data protection laws.
Experience with frameworks like NIST CSF and ISO 27001/27002.
Ability to communicate risks and solutions to non-technical audiences.
Preferred Skills
Advanced or multiple security certifications.
Proactive, detail-oriented, and collaborative approach.
Passion for security, compliance, and continuous improvement.
Why Join Harris (Parent Company)
Stable, financially strong company (part of Canada’s largest software group, CSI).
Professional growth and personal development opportunities.
Casual, supportive work environment with comprehensive benefits.
Award-winning company culture and commitment to diversity and inclusion.
Equal Opportunity
Harris values diversity and encourages applications from candidates of all backgrounds, without discrimination.