About the role
From the employer’s listing · Leroy Merlin · posted 1 June 2026
<p><strong>Role Purpose</strong></p><p>The successful candidate will play a critical role in protecting the organisation’s systems, data, and infrastructure by designing, implementing, and maintaining robust security controls. The role combines strong technical cybersecurity capability with deep knowledge of compliance and regulatory frameworks to ensure the organisation remains secure, resilient, and audit-ready. You will work closely with infrastructure, cloud, application, risk, and audit teams to embed security across all layers of the technology environment while actively identifying and mitigating threats.</p><p></p><p><strong>Key Responsibilities</strong></p><ul><li><p><span>Design, implement, and maintain cybersecurity controls across on-premise, cloud, and hybrid environments</span></p></li><li><p><span>Manage and optimise security technologies including SIEM, EDR, firewalls, IDS/IPS, endpoint protection, and vulnerability management tools</span></p></li><li><p><span>Monitor security environments for threats, anomalies, and suspicious activity, ensuring timely detection and response</span></p></li><li><p><span>Lead investigation and response to security incidents, including root cause analysis and remediation actions</span></p></li><li><p><span>Perform regular vulnerability scanning and coordinate penetration testing activities with internal and external parties</span></p></li><li><p><span>Ensure secure configuration and hardening of servers, networks, endpoints, and cloud workloads</span></p></li><li><p><span>Support secure architecture design for new systems, applications, and infrastructure projects</span></p></li><li><p><span>Apply security-by-design principles across all technology implementations and changes</span></p></li><li><p><span>Ensure compliance with relevant security and regulatory frameworks including ISO 27001, NIST, CIS Controls, POPIA, GDPR, and internal governance standards</span></p></li><li><p><span>Support internal and external audits by preparing evidence, addressing findings, and tracking remediation activities</span></p></li><li><p><span>Maintain and improve cybersecurity policies, procedures, and standards</span></p></li><li><p><span>Conduct risk assessments and support enterprise risk management processes</span></p></li><li><p><span>Produce regular security reports, dashboards, and risk summaries for technical and executive stakeholders</span></p></li><li><p><
















