Dis-Chem Pharmacies has an opportunity available for an Information Security Operations (SecOps) to Lead day-to-day security monitoring, detection, and response activities across Dis-Chem’s technology environment. Oversees operation of endpoint, network, and perimeter security tools, and manages outsourced SOC/MSSP partners providing 24/7 monitoring. Coordinates incident handling, containment, and recovery in partnership with Technology Resilience and Infrastructure teams. Ensures consistent application of CISO policies, security engineering standards, and “shift-left” practices across platform squads. Builds execution capability in a small, high-dependency environment with heavy reliance on external vendors
Requirements
- Degree in Information Security, IT, Risk Management, or related field, or 7 + years' experience in similar role
- 5+ years’ experience in IT security or vendor risk management, preferably in a multi-vendor environment
- Exposure to outsourced service models, SOC/MDR providers, and cloud-hosted solutions.
Responsibilities
Security Operations & Monitoring
- Lead daily operation of core security tools (endpoint protection, email security, network monitoring, SIEM/SOC integrations)
- Manage outsourced SOC/MSSP providers, ensuring effective alert triage, escalation, and 24/7 coverage
- Review critical alerts and prioritize response actions; coordinate with platform squads and IT ops to address vulnerabilities and misconfigurations
- Ensure logging, monitoring, and detection coverage across applications, infrastructure, cloud, and retail environments
Incident Management & Response
- Oversee end-to-end cyber incident handling (analysis, containment, recovery) with CISO, Infrastructure, Technology Resilience, and external vendors
- Maintain incident runbooks and ensure readiness for security events affecting stores, IT platforms, digital engagement, and data systems
- Conduct post-incident reviews and drive follow-up actions to reduce recurrence.
Security Engineering & Execution
- Implement and enforce secure configuration baselines for infrastructure, networks, endpoints, and cloud workloads
- Support rollout of security guardrails and “secure-by-design” patterns within development and integration squads
- Guide security champions within squads and provide practical coaching on controls, tooling, and remediation steps
- Partner with Enterprise Architecture to validate technical designs against CISO standards
Competencies
Domain Expertise
- Strong understanding of third-party risk, vendor security controls, and security assessment methods
- Knowledge of risk domains relevant to retail pharmacy (hosting, data protection, resilience, availability, integrations)
- Familiarity with regulatory and contractual security requirements.
Leadership & Commercial Acumen
- Ability to influence vendors and internal stakeholders toward secure-by-design decisions
- Strong negotiation and communication skills to articulate risks and required mitigations.
Key Performance Indicators
- Vendors assessed and risk-rated before onboarding
- Remediation closure rate for vendor findings
- Contribution to culture, accountability, engagement, and continuous improvement
- Reduction in vendor-related incidents or outages
- Quality and completeness of vendor risk documentation
- Stakeholder satisfaction with vendor risk process
ONLY SUCCESSFUL APPLICANTS WILL BE CONTACTED. IF YOU HAVEN`T BEEN CONTACTED WITHIN TWO WEEKS AFTER THE CLOSING DATE, CONSIDER YOUR APPLICATION AS UNSUCCESSFUL.
Dis-Chem Pharmacies is an equal opportunity employer. Dis-Chem’s approved Employment Equity Plan and Targets will be considered as part of the recruitment process aligned to Dis-Chem’s Employment Equity & Transformation Strategy. Dis-Chem actively supports the recruitment of People with Disabilities.