Submitting more applications increases your chances of landing a job.

Here’s how busy the average job seeker was last month:

Opportunities viewed

Applications submitted

Keep exploring and applying to maximize your chances!

Looking for employers with a proven track record of hiring women?

Click here to explore opportunities now!
We Value Your Feedback

You are invited to participate in a survey designed to help researchers understand how best to match workers to the types of jobs they are searching for

Would You Be Likely to Participate?

If selected, we will contact you via email with further instructions and details about your participation.

You will receive a $7 payout for answering the survey.


User unblocked successfully
Jabu Mtembu, Manager: Information Security Policy and Standards

Jabu Mtembu

Manager: Information Security Policy and Standards·MTN

South Africa

Bachelor's degree, BUSINESS INFORMATICS

Work experience

Total years of experience: 18 years, 1 months

Manager: Information Security Policy and Standards

August 2023 - Present

MTN

Johannesburg, South Africa

August 2023 - Present

I am a passionate information security specialist with a unique blend of expertise across proactive
cybersecurity (information security), reactive digital forensics (including mobile forensics), and
Governance, Risk, and Compliance (GRC), enabling me to approach security challenges with both
strategic insight and technical precision. I hold a BCom degree in Business Informatics and various
industry certifications. Currently, I am employed as the Manager of Information Security Policy and
Standards at MTN within the GRC function.

My core responsibility is to manage and oversee the Information Security Policies and Standards
within the MTN group. I also support other MTN operating companies in adopting compliance
documents. Additionally, I assist with reviewing weekly reports, committee reports (Risk and Audit),
and the CTIO report. I act as a liaison and contact for security auditing purposes.
Furthermore, I provide yearly training on the application of the NIST Framework and support MTN
InfoSec teams in various jurisdictions to conduct NIST risk-based assessments. I prepare packs for
two committees: the Information Security Forum (ISF) and the Technical Security Governance
Council (TSGC). I record minutes, action items, and follow up on them on a monthly basis. I also
assist with compiling Risk Acceptances and have been assigned as project manager for the following
projects: Ransomware Framework, Compliance Dashboard, and Governance Framework.

In my GRC role at MTN, which spans all jurisdictions (18 countries) under the group umbrella, I work
closely with the Privacy team, Information Security Heads, Audit, and Risk and Compliance teams.
This experience has exposed me to the company's operations at all levels, providing me with access
to senior stakeholders.

Company industry:
Telecommunications

Business Information Security Officer

August 2017 - July 2023

Nedbank

Johannesburg, South Africa

August 2017 - July 2023

I served as one of the primary contacts between non-client facing clusters and the Chief Information
Security Officer (CISO). In this role, I ensured the alignment and implementation of the cyber
resilience framework (FFIEC). I also conducted extensive third-party privacy and cybersecurity risk
assessments, which included reviewing security standards on Master Service Agreements (MSAs)
where necessary.

Another focus area was the daily monitoring of the Data Loss Prevention (DLP) dashboard. I assisted
clusters in identifying critical assets from a confidentiality perspective (referred to as "Crown Jewels")
and integrating this information into the business impact analysis and risk management processes.
Additionally, I was involved in social engineering awareness training, helping users to better identify
red flags and report phishing emails, vishing, and smishing attempts. On a monthly basis, I extracted,
analyzed, and reported on critical information security matters, presenting these findings at various
cluster Executive Risk and Information Security committees.

Company industry:
Banking

Manager: Computer Forensics

October 2014 - January 2017

Ernst and Young (EY)

Johannesburg, South Africa

October 2014 - January 2017

Before joining Nedbank, I was a Manager in the Digital Forensics specialist division at Ernst and
Young, PwC, and Exactech. My role involved acquiring, preserving, and recovering digital evidence,
including mobile phones, and preparing detailed reports. I conducted numerous Anton Piller orders
with the assistance of the South African Police Service, law attorneys, and sheriffs. Additionally, I
sought new business opportunities through networking and trained over 15 computer forensics
consultants.

I have consulted in both the private and public sectors across all nine South African provinces and
14 African countries. I also assisted international EY and PwC teams from China, the UK, the USA,
and Australia. As an expert witness, I testified in the Kimberly High Court and various internal
disciplinary matters. I have experience in basic data analysis using SQL, ACL, and Excel, and have
assisted in non-IT/Cyber Forensics investigations, including double payments to suppliers,
nepotism, asset verification, and ghost employees.

Company industry:
Accounting

Assistant Manager: Computer Forensics

November 2011 - September 2014

PricewaterhouseCoopers

Pretoria, South Africa

November 2011 - September 2014

Before joining Nedbank, I was a Manager in the Digital Forensics specialist division at Ernst and
Young, PwC, and Exactech. My role involved acquiring, preserving, and recovering digital evidence,
including mobile phones, and preparing detailed reports. I conducted numerous Anton Piller orders
with the assistance of the South African Police Service, law attorneys, and sheriffs. Additionally, I
sought new business opportunities through networking and trained over 15 computer forensics
consultants.

I have consulted in both the private and public sectors across all nine South African provinces and
14 African countries. I also assisted international EY and PwC teams from China, the UK, the USA,
and Australia. As an expert witness, I testified in the Kimberly High Court and various internal
disciplinary matters. I have experience in basic data analysis using SQL, ACL, and Excel, and have
assisted in non-IT/Cyber Forensics investigations, including double payments to suppliers,
nepotism, asset verification, and ghost employees.

Company industry:
Business Consultancy Services

Senior Associate: Computer Forensics

November 2007 - October 2011

Exactech

Johannesburg, South Africa

November 2007 - October 2011

Before joining Nedbank, I was a Manager in the Digital Forensics specialist division at Ernst and
Young, PwC, and Exactech. My role involved acquiring, preserving, and recovering digital evidence,
including mobile phones, and preparing detailed reports. I conducted numerous Anton Piller orders
with the assistance of the South African Police Service, law attorneys, and sheriffs. Additionally, I
sought new business opportunities through networking and trained over 15 computer forensics
consultants.

I have consulted in both the private and public sectors across all nine South African provinces and
14 African countries. I also assisted international EY and PwC teams from China, the UK, the USA,
and Australia. As an expert witness, I testified in the Kimberly High Court and various internal
disciplinary matters. I have experience in basic data analysis using SQL, ACL, and Excel, and have
assisted in non-IT/Cyber Forensics investigations, including double payments to suppliers,
nepotism, asset verification, and ghost employees.

Company industry:
Business Consultancy Services

Education

UNIVERSITY OF SOUTH AFRICA

October 2022

October 2022

Bachelor's degree, BUSINESS INFORMATICS

South Africa

Skills

ACCESS CONTROL LIST
Intermediate
ACCESS CONTROL LIST
Intermediate
ANGULAR REACTIVE FORMS
Intermediate
ANGULAR REACTIVE FORMS
Intermediate
BUSINESS INFORMATION SYSTEM
Intermediate
BUSINESS INFORMATION SYSTEM
Intermediate
COMPUTER LITERACY
Intermediate
COMPUTER LITERACY
Intermediate
CORPORATE GOVERNANCE
Intermediate
CORPORATE GOVERNANCE
Intermediate
CYBER SECURITY
Intermediate
CYBER SECURITY
Intermediate
DIGITAL FORENSICS
Intermediate
DIGITAL FORENSICS
Intermediate
INFORMATION SECURITY MANAGEMENT
Intermediate
INFORMATION SECURITY MANAGEMENT
Intermediate
RELATIONAL DATABASE MANAGEMENT SYSTEMS
Intermediate
RELATIONAL DATABASE MANAGEMENT SYSTEMS
Intermediate
REPORT WRITING
Intermediate
REPORT WRITING
Intermediate

Languages

English

Beginner

Afrikaans

Beginner

Training and Certifications

Certifications
Advanced Report writing ACL (Audit Control Language)
Microsoft SQL Server 2014
National Certificate for Estimating
Computer Forensics