The Head of Information Security (CISO) is accountable for Dis-Chem’s information security strategy, governance, risk management, and security operations. The role ensures the confidentiality, integrity, and availability of systems and data while enabling business growth and digital innovation. The CISO operates as both risk authority and business enabler, embedding security-by-design across platforms, vendors, and delivery teams.
Requirements
- Degree in Information Security, IT, or related field
- Masters in Cyber Security preferred
- Relevant InfoSec certifications
- 10+ years’ experience in senior security leadership
- Experience in regulated, large-scale enterprise environments
Responsibilities
Security strategy and governance
- Define, own, and continuously evolve the enterprise information security strategy aligned to business objectives and risk appetite
- Establish and enforce security policies, standards, and control frameworks across the organisation
- Govern enterprise security architecture, patterns, and platform guardrails in alignment with Enterprise Architecture
- Provide regular security posture, risk, and compliance reporting to executive leadership and Board-level forums
Security operations and resilience
- Oversee security operations, including threat monitoring, incident response, and forensic investigations
- Ensure effective detection, response, and recovery capabilities across all platforms and environments
- Partner with Technology Resilience to ensure business continuity, disaster recovery, and cyber resilience readiness
- Own relationships and performance of SOC/MDR providers and security tooling ecosystem
Risk and third-party security
- Own enterprise information security risk management, including identification, assessment, mitigation, and reporting
- Define and maintain the organisation’s cyber risk framework aligned to enterprise risk management
- Govern third-party and supply chain security risk, including supplier assurance and ongoing monitoring
- Lead engagement with internal and external audit, regulators, and compliance bodies
Data, Privacy, and Regulatory Compliance
- Ensure protection of sensitive data, including customer, patient, and operational data, in line with regulatory requirements (e.g. POPIA)
- Oversee data security, privacy controls, and secure use of data across platforms and integrations
- Ensure compliance with applicable laws, regulations, and industry standards
Competencies
- Deep expertise in cyber security, governance, and risk
- Strong executive communication and influence
- Ability to balance security rigor with business agility
- Lead, coach, and develop Tribes and Squad Leads and their teams
- Set performance expectations and conduct performance reviews
- Manage team capacity, workload allocation, and capability development
- Support recruitment, succession planning, and organisational design
Key Performance Indicators
- Reduction in high-severity security incidents
- Effectiveness of security controls and risk remediation
- Compliance with regulatory, audit, and policy requirements
- Security posture maturity and resilience readiness
- Stakeholder confidence in security governance
- Contribution to culture and leadership outcomes, measured through employee engagement, culture index improvements, and adherence to organisational values and leadership behaviours.
- Drive a security-first culture across the organisation through awareness, training, and leadership engagement
- Promote accountability for security across all levels of the organisation
- Embed secure-by-design and secure-by-default principles across technology and business teams