
Security Testing & GRC Specialist (Pen Tester + Governance, Risk & Compliance)
- Johannesburg, Gauteng
- Permanent
- Full-time
- Conduct penetration testing, ethical hacking, and vulnerability assessments using industry-standard tools (e.g., BurpSuite, OWASP ZAP, Metasploit, etc.).
- Identify, document, and report security vulnerabilities, providing remediation guidance to development and operations teams.
- Develop and maintain GRC frameworks, policies, and procedures in line with industry standards (ISO 27001, NIST, GDPR, POPIA, etc.).
- Support risk assessments, audits, and compliance initiatives.
- Act as a bridge between technical security testing and compliance-driven governance activities.
- Provide security awareness and compliance training as needed.
- Proven experience as a penetration tester, ethical hacker, or security engineer.
- Familiarity with GRC frameworks, regulatory compliance, and audit processes.
- Strong knowledge of application, cloud, and infrastructure security.
- Excellent communication and reporting skills to both technical and non-technical stakeholders.
- Client-Centric Mindset
- Demonstrates a strong commitment to understanding and delivering value to clients.
- Builds trust-based relationships and adapts communication style to diverse client environments.
- Collaborative Leadership
- Leads by example and fosters a culture of collaboration, knowledge sharing, and mutual respect.
- Comfortable mentoring junior team members and contributing to a psychologically safe team environment.
- Adaptability Growth Orientation
- Thrives in dynamic, fast-paced environments and embraces change as an opportunity.
- Actively seeks feedback and continuously looks for ways to improve personally and professionally.
- Integrity Accountability
- Upholds high ethical standards and takes ownership of outcomes.
- Transparent in communication and dependable in delivering on commitments.
- Innovation Problem Solving
- Brings a proactive, solution-oriented mindset to complex challenges.
- Encourages experimentation and is open to new technologies, methodologies, and ideas.
- Communication Influence
- Communicates clearly and persuasively with both technical and non-technical stakeholders.
- Able to influence decision-making at senior levels through data, insight, and credibility.
- Alignment with Company Values
- Embodies the core values of our organization (e.g., excellence, inclusion, curiosity, impact).
- Acts as a cultural ambassador both internally and in client-facing engagements.
- Initial contract position
- Location: Johannesburg – hybrid way of work
- Level: Senior
ExecutivePlacements.com