Summary
Overview
Work History
Education
Skills
Certification
Accomplishments
Languages
Work Availability
Timeline
Certified Certifications
Projects
Hobbies and Interests
References
Certified Certifications
Projects
Hobbies and Interests
References
Generic
Clifford Mathebula

Clifford Mathebula

Johannesburg, Midrand

Summary

I am a highly motivated, dedicated, ambitious, and goal-oriented Cybersecurity scientist with strong interpersonal skills. I hold a BSc. in Information Technology, with over Five years of Cyber-Security experience in the Financial Banking Industry. My current role comprises of extensive skills such as Information Security Strategy, Third Party Risk Management, Compliance, Security Awareness, Incident Response, Analysis, Data and Privacy, Cyber Management Information System, Data Loss Prevention, Cyber and Privacy Risk Assessments, IT Risk, Power BI report developments, etc. Through my dedication and hard working I was recognised and won a Nedbank Top Achiever 2022 and later again recognised as Nedbank Achiever 2025. I am eager to expanding my skillset and motivated to contribute to the growth and success of a progressive organization by leveraging my diverse skillset, knowledge, experience, strong interpersonal skills and commitment to excellence.

Overview

6
6
years of professional experience
2
2
Certificate

Work History

Business Information Security Officer (BISO)

Nedbank CIB
07.2024 - Current
  • Act as the strategic interface between business and cybersecurity, ensuring alignment with the Cyber Resilience Risk Management Framework (CRRMF) and enterprise security standards.
  • Provide cyber risk oversight by monitoring Key Risk Indicators (KRIs), identifying threshold breaches, and driving timely remediation across the cluster.
  • Lead third-party cyber and privacy risk management, including supplier tiering, assessments, assurance reviews, and remediation tracking.
  • Protect critical (“crown jewel”) assets through ongoing monitoring, assurance activities, and integration with access governance controls.
  • Oversee Data Loss Prevention (DLP) across endpoint, network, and cloud environments, including incident investigation and risk mitigation.
  • Drive cyber resilience and awareness through targeted training, phishing simulations, and risk-focused security campaigns.
  • Develop, maintain, and enhance cyber risk dashboards (TPRM, DLP, SSL certificates, IT KRIs) to support executive reporting and decision-making.
  • Deliver executive-level cyber reporting using dashboards, metrics, and governance forums to support informed, risk-based decision-making.
  • Maintain strong engagement with the CISO, Information Security, Compliance, IT, BCP & DR Risk, IDAG, and business stakeholders.
  • Provide trusted advisory support on cyber risk, secure data sharing, access governance, audit remediation, and policy compliance.
  • Support incident response activities, including phishing incidents, cyber breach investigations, and ensuring timely escalation and resolution.
  • Review and maintain cybersecurity policies, frameworks, standards, and guidelines to ensure ongoing compliance and relevance.
  • Complete and support Due Diligence Questionnaires (DDQs) and RFP responses for clients, ensuring alignment with organisational controls and standards.

Information Security Risk Analyst

Nedbank - RBB
04.2022 - 07.2024
  • Conduct objective and risk base assessments on existing and new systems and technologies, and communicate findings to all stakeholders within the information system.
  • Provide input to mitigation of Cyber Resilience risk which could impact the protection of personal information.
  • Ensure authorized transfers of sensitive data are appropriately protected.
  • Detecting and preventing sensitive data loss events as well as avoiding high risk routes or file sharing site.
  • Analyse and Monitor data to minimize operational risk and ensure governance in the archievement of business needs.
  • Analyse data sets to identify trends and gaps, escalate exceptions and recommend corrective measures to mitigate potential risks and ensure appropriate risk profile for the relevant business units.
  • Develop and Monitor risk related reports to ensure business units and management understand and take appropriate action on inherent risks and understands the impact of the decisions made to mitigate the risk.
  • Educate stakeholders on risks trends, Systems updates and legislative requirements to mitigate risk.
  • Third-Party Risk Management

Cyber Risk Administrator

Nedbank - RBB
08.2021 - 03.2022
  • Ensure authorized transfers of sensitive data are appropriately protected.
  • Detecting and preventing sensitive data loss events as well as avoiding high-risk routes or file sharing sites.
  • Analyse data sets to identify trends and gaps, escalate exceptions, and recommend corrective measures to mitigate potential risks and ensure appropriate risk profile for the relevant business units.
  • Develop and monitor risk related reports to ensure business units and management understand and take appropriate action on inherent risks and understand the impact of the decisions made to mitigate the risk.
  • Educate stakeholders on risk trends, systems updates, and legislative requirements to mitigate risk.

Cybersecurity BankSeta Internship

Altron Bytes People's Solutions
03.2021 - 03.2022
  • Enrolled in the BankSeta Internship (hosted by Nedbank) through Altron, which offers the opportunity to gain one year's work experience and international certifications in CompTIA Cloud+, Security+, and Certified Ethical Hacker (CEH), as well as Pen-Testing upon successful examination.

IT Practical Work Internship

Phalaborwa Foundation
Phalaborwa
06.2019 - 07.2019
  • As part of my school's practical work exposure program, I was hosted by a non-profit organization in my town, where I gained valuable insights into a real-life work environment.
  • During my internship, I acquired hands-on experience with various tasks, including building a desktop PC from components and participating in the rollout of multiple e-learning computer laboratories with 60 workstations.
  • I was part of a team that installed and configured Microsoft Windows Servers 2016, updated and configured e-learning components, and performed post-installation testing and troubleshooting.
  • Additionally, I worked on installing and configuring digital signage for internal marketing and information displays, designing content for these displays, and capturing and interpreting data for a total cost of ownership analysis for a large IT contract.
  • I also attended an IT operational planning meeting and a strategic IT Steering Committee meeting, further broadening my understanding of IT operations and strategic planning.
  • A non-profit organization in my town, where I gained valuable insights into a real-life work environment.

Education

B.Sc. Honours degree in Computing - Computer Science and Information Systems

University of South Africa
Johannesburg, GP
2027

Certificate of Higher Education - Banking (FinTech and Risk Management)

NoviaOne Group
Johannesburg, GP
2024

Certificate of Higher Education - Risk Management

Free State University
Free State
07.2024

Bachelor of Science - Information Technology

North-West University
Potchefstroom, NW
2021

Skills

  • Analytical skills
  • Cyber risk management
  • Third-party risk assessment
  • Data loss prevention
  • Risk analysis
  • Stakeholder engagement
  • Risk reporting
  • Compliance assurance
  • Cyber resilience training
  • Trend analysis
  • Problem solving
  • Effective communication
  • Written and verbal communication
  • Data analysis
  • Adaptability
  • Collaboration
  • Communication
  • Critical thinking
  • Decision-making
  • Interpersonal communication
  • Leadership
  • Microsoft Office
  • Problem-solving
  • Teamwork
  • Power BI
  • DAX
  • Computer
  • Research skills
  • Python
  • C
  • C#
  • HTML and CSS
  • Risk Management
  • Self-motivation
  • Critical-thinking
  • Encryption technologies knowledge
  • Cybersecurity legislation familiarity
  • Network security awareness
  • Cybersecurity
  • Analytical-thinking
  • Technical report writing
  • Vulnerability analysis
  • Vendor relationship management
  • Stress resilience
  • Reporting and presentation
  • Risk assessment proficiency
  • Data privacy understanding
  • Data interpretation

Certification

  • ISF South Africa Chapter Autumn Meeting 2026
  • Key National and Global Issues Impacting Investment, Banking, and Economic Growth, Nedbank (2025)
  • Ethics in Digital and AI, Nedbank (2025)
  • Artificial Intelligence for Cybersecurity, LinkedIn Learning - 2025
  • Cybers Criss Management with NIST Cybersecurity Framework (CSF) 2.0, LinkedIn Learning - 2025
  • Project Management Foundation, LinkedIn Learning - 2025
  • Cybersecurity Career: Become a Business Information Security Officer (BISO), LinkedIn Learning - 2024
  • Cyber Risk Management, Nedbank (2024)
  • ISF South Africa Chapter Autumn Meeting 2024
  • Network Firewall - Multiple Requirements, A Common Approach, BrightTALK (2023)
  • Cyber Risk Management, Nedbank (2023)
  • CISM Cert Prep (2022): 4 Incident Management, LinkedIn Learning
  • CISM Cert Prep (2022): 3 Information Security Program, LinkedIn Learning
  • CISM Cert Prep (2022): 2 Information Security Risk Management, LinkedIn Learning
  • CISM Cert Prep (2022): 1 Information Security Governance, LinkedIn Learning
  • ISF South Africa Chapter Autumn Meeting 2022
  • Digital 2021, ISF WORLD CONGRESS, ISF ATTENDANCE
  • Leadership Training Course, Metric (Grade 12)

Accomplishments

  • Nedbank Achiever 2025 Award, Formal recognition and winner for Nedbank Achievers.
  • Outstanding Performance 2024, Certificate of achievement for outstanding performance at Nedbank CIB Ops Risk Team
  • Significant Development 2024, Certificate of achievement for individual significant development at Nedbank CIB Ops Risk Team.
  • Outstanding Team Performance 2024, Certificate of achievement for best and outstanding team performance at Nedbank CIB Ops Risk Team
  • SHARK TANK WINNER 2024, DISRUPTIVE TECHNOLOGY AND FINTECH RISK MANAGEMENT, NoviaONE GROUP in the Final Project Assignment.
  • Nedbank Top Achiever 2022 Award, Formal recognition and winner for Nedbank Top Achievers.
  • Nedbank RBB Achiever 2022, Formal recognition at Nedbank RBB ERM team.

Languages

Xitsonga
Proficient
C2
English
Advanced
C1
Sepedi
Beginner
A1
IsiZulu
Elementary
A2

Work Availability

monday
tuesday
wednesday
thursday
friday
saturday
sunday
morning
afternoon
evening
swipe to browse

Timeline

Business Information Security Officer (BISO)

Nedbank CIB
07.2024 - Current

Information Security Risk Analyst

Nedbank - RBB
04.2022 - 07.2024

Cyber Risk Administrator

Nedbank - RBB
08.2021 - 03.2022

Cybersecurity BankSeta Internship

Altron Bytes People's Solutions
03.2021 - 03.2022

IT Practical Work Internship

Phalaborwa Foundation
06.2019 - 07.2019

B.Sc. Honours degree in Computing - Computer Science and Information Systems

University of South Africa

Certificate of Higher Education - Banking (FinTech and Risk Management)

NoviaOne Group

Certificate of Higher Education - Risk Management

Free State University

Bachelor of Science - Information Technology

North-West University

Certified Certifications

  • EC-Council Certified Ethical Hecker (CEH), Expired in 2024
  • CompTIA Security +, Expired in 2024

Projects

  • A dynamic Power BI dashboard was developed to track and manage third-party vendors within a cluster. The dashboard enables efficient monitoring and remediation of high-risk, non-compliant vendors by tracking supplier security profiles, contracts, and cybersecurity and privacy risk assessments. This facilitates proactive risk management and informed decision-making
  • A Power BI dashboard was developed to monitor data egress via email, providing real-time insights into sensitive information leaving the organization. The dashboard highlights risk trends, areas of concern, and business unit breakdown analysis, enabling swift identification and mitigation of potential data breaches. Its real-time updates and efficient design facilitate proactive data loss prevention and enhanced security oversight
  • A Cyber Management Information System Power BI dashboard developed to track and monitor the remediation of non-compliant Cyber Key Risk Indicators (KRIs) and policy acknowledgments. The dashboard provides insights at both cluster and business unit levels, enabling effective management and mitigation of cyber risks
    SSL
  • A Power BI dashboard developed to track expiring SSL certificates, providing key details such as expiration dates and the number of days remaining. This dashboard enables proactive renewal of certificates, helping to prevent potential security issues and downtime
  • Throughout my university journey, I worked on various projects that helped me develop a range of technical skills. (1) One of my notable projects was the development of a client interactive responsive website using C# and SQL for database management. (2) I also collaborated on a group project to design and develop a hotel management system using the software development life cycle, which included system analysis, design, and development. (3) Another group project involved building a network system with three interconnected subnetworks using CISCO packet tracer. Additionally, (4) I created a web-based text classification program using Node.js for backend API, MongoDB for database, and HTML, CSS, and EJS for front-end development. (5) I also designed and developed a personal portfolio website using ReactJs, HTML, and CSS. These projects not only improved my programming skills but also exposed me to cloud-based technologies such as Heroku, AWS, Azure, and IBM. I learned new technologies like Node.js, HTML, CSS, EJS, JavaScript, ReactJs, and API development. Furthermore, working on these projects taught me the importance of collaboration and teamwork, including effective communication and problem-solving skills, even in remote online settings using platforms like Zoom and Microsoft Teams during the COVID-19 pandemic

Hobbies and Interests

  • Artificial Intelligence
  • Emerging Technology
  • Reading
  • Music
  • TV Shows / Series
  • Sports
  • Information Security
  • Mathematics

References

  • Available upon request

Certified Certifications

  • EC-Council Certified Ethical Hecker (CEH), Expired in 2024
  • CompTIA Security +, Expired in 2024

Projects

  • A dynamic Power BI dashboard was developed to track and manage third-party vendors within a cluster. The dashboard enables efficient monitoring and remediation of high-risk, non-compliant vendors by tracking supplier security profiles, contracts, and cybersecurity and privacy risk assessments. This facilitates proactive risk management and informed decision-making
  • A Power BI dashboard was developed to monitor data egress via email, providing real-time insights into sensitive information leaving the organization. The dashboard highlights risk trends, areas of concern, and business unit breakdown analysis, enabling swift identification and mitigation of potential data breaches. Its real-time updates and efficient design facilitate proactive data loss prevention and enhanced security oversight
  • A Cyber Management Information System Power BI dashboard developed to track and monitor the remediation of non-compliant Cyber Key Risk Indicators (KRIs) and policy acknowledgments. The dashboard provides insights at both cluster and business unit levels, enabling effective management and mitigation of cyber risks
    SSL
  • A Power BI dashboard developed to track expiring SSL certificates, providing key details such as expiration dates and the number of days remaining. This dashboard enables proactive renewal of certificates, helping to prevent potential security issues and downtime
  • Throughout my university journey, I worked on various projects that helped me develop a range of technical skills. (1) One of my notable projects was the development of a client interactive responsive website using C# and SQL for database management. (2) I also collaborated on a group project to design and develop a hotel management system using the software development life cycle, which included system analysis, design, and development. (3) Another group project involved building a network system with three interconnected subnetworks using CISCO packet tracer. Additionally, (4) I created a web-based text classification program using Node.js for backend API, MongoDB for database, and HTML, CSS, and EJS for front-end development. (5) I also designed and developed a personal portfolio website using ReactJs, HTML, and CSS. These projects not only improved my programming skills but also exposed me to cloud-based technologies such as Heroku, AWS, Azure, and IBM. I learned new technologies like Node.js, HTML, CSS, EJS, JavaScript, ReactJs, and API development. Furthermore, working on these projects taught me the importance of collaboration and teamwork, including effective communication and problem-solving skills, even in remote online settings using platforms like Zoom and Microsoft Teams during the COVID-19 pandemic

Hobbies and Interests

  • Artificial Intelligence
  • Emerging Technology
  • Reading
  • Music
  • TV Shows / Series
  • Sports
  • Information Security
  • Mathematics

References

  • Available upon request
Clifford Mathebula