Summary
Overview
Work History
Education
Skills
Certification
Accomplishments
Languages
Work Availability
Timeline
References
Certified Certifications
Projects
Hobbies and Interests
References
Certified Certifications
Projects
Hobbies and Interests
References
Certified Certifications
Projects
Hobbies and Interests
References
Certified Certifications
Projects
Hobbies and Interests
References
Generic
Clifford Mathebula

Clifford Mathebula

Summary

Dynamic and results-driven Cybersecurity professional with over five years of
experience in the financial banking sector, currently serving as Business
Information Security Officer (BISO). Holding a BSc in Information Technology and
advancing toward an Honours degree in Computing, I bring a strong blend of
technical expertise, strategic oversight, and business alignment in cybersecurity.
Recognized through multiple accolades, including Nedbank Top Achiever (2022), Outstanding Performance (2024), Significant Development (2024), Outstanding Team Performance (2024), Nedbank Achiever (2025), BISO Team of the year (2025). I have a proven track record of excellence in delivering robust information security
strategies, third-party risk management, compliance frameworks, and incident
response capabilities. My skillset spans across data privacy, IT risk, cyber and
privacy risk assessments, data loss prevention, Cyber management information
systems, data analysis and the development of executive-level dashboards and
Power BI reports to support informed decision-making. I am motivated to
contribute to the growth and success of progressive organizations by leveraging
my diverse expertise, strong interpersonal skills, and commitment to excellence.

Overview

6
6
years of professional experience
2
2
Certificate

Work History

Business Information Security Officer (BISO)

Nedbank CIB
07.2024 - Current
  • Act as the strategic interface between business and cybersecurity, ensuring alignment with the Cyber Resilience Risk Management Framework (CRRMF) and enterprise security standards.
  • Provide cyber risk oversight by monitoring Key Risk Indicators (KRIs), identifying threshold breaches, and driving timely remediation across the cluster.
  • Lead third-party cyber and privacy risk management, including supplier tiering, assessments, assurance reviews, and remediation tracking.
  • Protect critical (“crown jewel”) assets through ongoing monitoring, assurance activities, and integration with access governance controls.
  • Oversee Data Loss Prevention (DLP) across endpoint, network, and cloud environments, including incident investigation and risk mitigation.
  • Drive cyber resilience and awareness through targeted training, phishing simulations, and risk-focused security campaigns.
  • Develop, maintain, and enhance cyber risk dashboards (TPRM, DLP, SSL certificates, IT KRIs) to support executive reporting and decision-making.
  • Deliver executive-level cyber reporting using dashboards, metrics, and governance forums to support informed, risk-based decision-making.
  • Maintain strong engagement with the CISO, Information Security, Compliance, IT, BCP & DR Risk, IDAG, and business stakeholders.
  • Provide trusted advisory support on cyber risk, secure data sharing, access governance, audit remediation, and policy compliance.
  • Support incident response activities, including phishing incidents, cyber breach investigations, and ensuring timely escalation and resolution.
  • Review and maintain cybersecurity policies, frameworks, standards, and guidelines to ensure ongoing compliance and relevance.
  • Complete and support Due Diligence Questionnaires (DDQs) and RFP responses for clients, ensuring alignment with organisational controls and standards.

Information Security Risk Analyst

Nedbank - RBB
04.2022 - 07.2024
  • Conduct objective and risk based assessments on existing and new systems and technologies, and communicate findings to all stakeholders within the information system.
  • Provide input to mitigation of Cyber Resilience risk which could impact the protection of personal information.
  • Ensure authorized transfers of sensitive data are appropriately protected.
  • Detecting and preventing sensitive data loss events as well as avoiding high risk routes or file sharing site.
  • Analyse and Monitor data to minimize operational risk and ensure governance in the achievement of business needs.
  • Analyse data sets to identify trends and gaps, escalate exceptions and recommend corrective measures to mitigate potential risks and ensure appropriate risk profile for the relevant business units.
  • Develop and Monitor risk related reports to ensure business units and management understand and take appropriate action on inherent risks and understand the impact of the decisions made to mitigate the risk.
  • Educate stakeholders on risk trends, Systems updates and legislative requirements to mitigate risk.
  • Third-Party Risk Management

Cyber Risk Administrator

Nedbank - RBB
08.2021 - 03.2022
  • Ensure authorized transfers of sensitive data are appropriately protected.
  • Detecting and preventing sensitive data loss events as well as avoiding high-risk routes or file sharing sites.
  • Analyse data sets to identify trends and gaps, escalate exceptions, and recommend corrective measures to mitigate potential risks and ensure appropriate risk profile for the relevant business units.
  • Develop and monitor risk related reports to ensure business units and management understand and take appropriate action on inherent risks and understand the impact of the decisions made to mitigate the risk.
  • Educate stakeholders on risk trends, systems updates, and legislative requirements to mitigate risk.

Cybersecurity BankSeta Internship

Altron Bytes People's Solutions
03.2021 - 03.2022
  • Enrolled in the BankSeta Internship (hosted by Nedbank) through Altron, which offers the opportunity to gain one year's work experience and international certifications in CompTIA Cloud+, Security+, and Certified Ethical Hacker (CEH), as well as Pen-Testing upon successful examination.

IT Practical Work Internship

Phalaborwa Foundation
Phalaborwa
06.2019 - 07.2019
  • During my internship, I acquired hands-on experience with various tasks, including building a desktop PC from components and participating in the rollout of multiple e-learning computer laboratories with 60 workstations.
  • Collaborated with a team to install and configure Microsoft Windows Servers 2016, update and configure e-learning components, and perform post-installation testing and troubleshooting.
  • Installed and configured digital signage for internal marketing and information displays, designed content, and captured data for total cost of ownership analysis on large IT contract.
  • I also attended an IT operational planning meeting and a strategic IT Steering Committee meeting, further broadening my understanding of IT operations and strategic planning.
  • Participated in school's practical work exposure programme at non-profit organisation, gaining insights into real-life work environment and operations.
  • Collaborated with local non-profit organisation to observe and understand daily operations and workplace dynamics.

Education

B.Sc. Honours degree in Computing - Computer Science and Information Systems

University of South Africa
Johannesburg, GP
2027

Certificate of Higher Education - Banking (Disruptive Technology and FinTech Risk Management)

NoviaOne Group
Johannesburg, GP
2024

Certificate of Higher Education - Risk Management

Free State University
Free State
07.2024

Bachelor of Science - Information Technology

North-West University
Potchefstroom, NW
2021

Skills

  • Cybersecurity risk management
  • Data loss prevention
  • Risk analysis
  • Risk Management
  • Third-party assessment
  • Risk reporting
  • Trend analysis
  • Data analysis
  • Data interpretation
  • Encryption technologies knowledge
  • Python
  • Java
  • C
  • C#
  • HTML and CSS
  • Power BI
  • DAX
  • Analytical thinking
  • Critical thinking
  • Problem solving
  • Decision-making
  • Stakeholder engagement
  • Reporting and presentation
  • Report writing
  • Interpersonal communication
  • Communication
  • Written communication
  • Leadership
  • Adaptability
  • Analytical-thinking
  • Critical-thinking
  • Microsoft Office
  • Reporting and presentation
  • Risk proficiency
  • Data interpretation

Certification

  • ISF Africa Conference 2026
  • ITWeb Security Summit 2026
  • ISF South Africa Chapter Autumn Meeting 2026
  • Key National and Global Issues Impacting Investment, Banking, and Economic Growth, Nedbank (2025)
  • Ethics in Digital and AI, Nedbank (2025)
  • Artificial Intelligence for Cybersecurity, LinkedIn Learning - 2025
  • Cyber Crises Management with NIST Cybersecurity Framework (CSF) 2.0, LinkedIn Learning - 2025
  • Project Management Foundation, LinkedIn Learning - 2025
  • Cybersecurity Career: Become a Business Information Security Officer (BISO), LinkedIn Learning - 2024
  • Cyber Risk Management, Nedbank (2024)
  • ISF South Africa Chapter Autumn Meeting 2024
  • Network Firewall - Multiple Requirements, A Common Approach, BrightTALK (2023)
  • Cyber Risk Management, Nedbank (2023)
  • ITWeb Security Summit 2023
  • CISM Cert Prep (2022): 4 Incident Management, LinkedIn Learning
  • CISM Cert Prep (2022): 3 Information Security Program, LinkedIn Learning
  • CISM Cert Prep (2022): 2 Information Security Risk Management, LinkedIn Learning
  • CISM Cert Prep (2022): 1 Information Security Governance, LinkedIn Learning
  • ISF South Africa Chapter Autumn Meeting 2022
  • Digital 2021, ISF WORLD CONGRESS, ISF ATTENDANCE
  • Leadership Training Course, Metric (Grade 12)

Accomplishments

  • BISO Team of the year 2025 Award, Formal recognition and winner for exceptional teamwork, delivering measurable cyber risk reduction, and demonstrating resilience and results driven excellence.
  • Nedbank Achiever 2025 Award, Formal recognition and winner for Nedbank Achievers.
  • Outstanding Performance 2024, Certificate of achievement for outstanding performance at Nedbank CIB Ops Risk Team
  • Significant Development 2024, Certificate of achievement for individual significant development at Nedbank CIB Ops Risk Team.
  • Outstanding Team Performance 2024, Certificate of achievement for best and outstanding team performance at Nedbank CIB Ops Risk Team
  • SHARK TANK WINNER 2024, DISRUPTIVE TECHNOLOGY AND FINTECH RISK MANAGEMENT, NoviaONE GROUP in the Final Project Assignment.
  • Nedbank Top Achiever 2022 Award, Formal recognition and winner for Nedbank Top Achievers.
  • Nedbank RBB Achiever 2022, Formal recognition at Nedbank RBB ERM team.

Languages

Xitsonga
Proficient
C2
English
Advanced
C1
Sepedi
Beginner
A1
IsiZulu
Elementary
A2

Work Availability

monday
tuesday
wednesday
thursday
friday
saturday
sunday
morning
afternoon
evening
swipe to browse

Timeline

Business Information Security Officer (BISO)

Nedbank CIB
07.2024 - Current

Information Security Risk Analyst

Nedbank - RBB
04.2022 - 07.2024

Cyber Risk Administrator

Nedbank - RBB
08.2021 - 03.2022

Cybersecurity BankSeta Internship

Altron Bytes People's Solutions
03.2021 - 03.2022

IT Practical Work Internship

Phalaborwa Foundation
06.2019 - 07.2019

B.Sc. Honours degree in Computing - Computer Science and Information Systems

University of South Africa

Certificate of Higher Education - Banking (Disruptive Technology and FinTech Risk Management)

NoviaOne Group

Certificate of Higher Education - Risk Management

Free State University

Bachelor of Science - Information Technology

North-West University

References

  • Available upon request

Certified Certifications

  • EC-Council Certified Ethical Hecker (CEH), Expired in 2024
  • CompTIA Security +, Expired in 2024

Projects

  • A dynamic Power BI dashboard was developed to track and manage third-party vendors within a cluster. The dashboard enables efficient monitoring and remediation of high-risk, non-compliant vendors by tracking supplier security profiles, contracts, and cybersecurity and privacy risk assessments. This facilitates proactive risk management and informed decision-making
  • A Power BI dashboard was developed to monitor data egress via email, providing real-time insights into sensitive information leaving the organization. The dashboard highlights risk trends, areas of concern, and business unit breakdown analysis, enabling swift identification and mitigation of potential data breaches. Its real-time updates and efficient design facilitate proactive data loss prevention and enhanced security oversight
  • A Cyber Management Information System Power BI dashboard developed to track and monitor the remediation of non-compliant Cyber Key Risk Indicators (KRIs) and policy acknowledgments. The dashboard provides insights at both cluster and business unit levels, enabling effective management and mitigation of cyber risks
    SSL
  • A Power BI dashboard developed to track expiring SSL certificates, providing key details such as expiration dates and the number of days remaining. This dashboard enables proactive renewal of certificates, helping to prevent potential security issues and downtime
  • Throughout my university journey, I worked on various projects that helped me develop a range of technical skills. (1) One of my notable projects was the development of a client interactive responsive website using C# and SQL for database management. (2) I also collaborated on a group project to design and develop a hotel management system using the software development life cycle, which included system analysis, design, and development. (3) Another group project involved building a network system with three interconnected subnetworks using CISCO packet tracer. Additionally, (4) I created a web-based text classification program using Node.js for backend API, MongoDB for database, and HTML, CSS, and EJS for front-end development. (5) I also designed and developed a personal portfolio website using ReactJs, HTML, and CSS. These projects not only improved my programming skills but also exposed me to cloud-based technologies such as Heroku, AWS, Azure, and IBM. I learned new technologies like Node.js, HTML, CSS, EJS, JavaScript, ReactJs, and API development. Furthermore, working on these projects taught me the importance of collaboration and teamwork, including effective communication and problem-solving skills, even in remote online settings using platforms like Zoom and Microsoft Teams during the COVID-19 pandemic

Hobbies and Interests

  • Artificial Intelligence
  • Emerging Technology
  • Reading
  • Music
  • TV Shows / Series
  • Sports
  • Information Security
  • Mathematics

References

  • Available upon request

Certified Certifications

  • EC-Council Certified Ethical Hacker (CEH), Expired in 2024
  • CompTIA Security +, Expired in 2024

Projects

  • A dynamic Power BI dashboard was developed to track and manage third-party vendors within a cluster. The dashboard enables efficient monitoring and remediation of high-risk, non-compliant vendors by tracking supplier security profiles, contracts, and cybersecurity and privacy risk assessments. This facilitates proactive risk management and informed decision-making.
  • A Power BI dashboard was developed to monitor data egress via email, providing real-time insights into sensitive information leaving the organization. The dashboard highlights risk trends, areas of concern, and business unit breakdown analysis, enabling swift identification and mitigation of potential data breaches. Its real-time updates and efficient design facilitate proactive data loss prevention and enhanced security oversight.
  • A Cyber Management Information System Power BI dashboard developed to track and monitor the remediation of non-compliant Cyber Key Risk Indicators (KRIs) and policy acknowledgements. The dashboard provides insights at both cluster and business unit levels, enabling effective management and mitigation of cyber risks
    SSL.
  • A Power BI dashboard developed to track expiring SSL certificates, providing key details such as expiration dates and the number of days remaining. This dashboard enables proactive renewal of certificates, helping to prevent potential security issues and downtime.
  • Developed a Power BI dashboard to track quarterly line manager access reviews, providing visibility into completion rates across business units and enhancing reporting accuracy. The dashboard Identified and highlighted areas of concern, enabling proactive risk management and improved oversight.
  • Throughout my university journey, I worked on various projects that helped me develop a range of technical skills. (1) One of my notable projects was the development of a client interactive responsive website using C# and SQL for database management. (2) I also collaborated on a group project to design and develop a hotel management system using the software development life cycle, which included system analysis, design, and development. (3) Another group project involved building a network system with three interconnected subnetworks using CISCO packet tracer. Additionally, (4) I created a web-based text classification program using Node.js for backend API, MongoDB for database, and HTML, CSS, and EJS for front-end development. (5) I also designed and developed a personal portfolio website using ReactJs, HTML, and CSS. These projects not only improved my programming skills but also exposed me to cloud-based technologies such as Heroku, AWS, Azure, and IBM. I learned new technologies like Node.js, HTML, CSS, EJS, JavaScript, ReactJs, and API development. Furthermore, working on these projects taught me the importance of collaboration and teamwork, including effective communication and problem-solving skills, even in remote online settings using platforms like Zoom and Microsoft Teams during the COVID-19 pandemic.

Hobbies and Interests

  • Artificial Intelligence
  • Emerging Technology
  • Information Security
  • Reading
  • Music
  • Sports

References

  • Available upon request

Certified Certifications

  • EC-Council Certified Ethical Hacker (CEH), Expired in 2024
  • CompTIA Security +, Expired in 2024

Projects

  • A dynamic Power BI dashboard was developed to track and manage third-party vendors within a cluster. The dashboard enables efficient monitoring and remediation of high-risk, non-compliant vendors by tracking supplier security profiles, contracts, and cybersecurity and privacy risk assessments. This facilitates proactive risk management and informed decision-making.
  • A Power BI dashboard was developed to monitor data egress via email, providing real-time insights into sensitive information leaving the organization. The dashboard highlights risk trends, areas of concern, and business unit breakdown analysis, enabling swift identification and mitigation of potential data breaches. Its real-time updates and efficient design facilitate proactive data loss prevention and enhanced security oversight.
  • A Cyber Management Information System Power BI dashboard developed to track and monitor the remediation of non-compliant Cyber Key Risk Indicators (KRIs) and policy acknowledgements. The dashboard provides insights at both cluster and business unit levels, enabling effective management and mitigation of cyber risks
    SSL.
  • A Power BI dashboard developed to track expiring SSL certificates, providing key details such as expiration dates and the number of days remaining. This dashboard enables proactive renewal of certificates, helping to prevent potential security issues and downtime.
  • Developed a Power BI dashboard to track quarterly line manager access reviews, providing visibility into completion rates across business units and enhancing reporting accuracy. The dashboard Identified and highlighted areas of concern, enabling proactive risk management and improved oversight.
  • Throughout my university journey, I worked on various projects that helped me develop a range of technical skills. (1) One of my notable projects was the development of a client interactive responsive website using C# and SQL for database management. (2) I also collaborated on a group project to design and develop a hotel management system using the software development life cycle, which included system analysis, design, and development. (3) Another group project involved building a network system with three interconnected subnetworks using CISCO packet tracer. Additionally, (4) I created a web-based text classification program using Node.js for backend API, MongoDB for database, and HTML, CSS, and EJS for front-end development. (5) I also designed and developed a personal portfolio website using ReactJs, HTML, and CSS. These projects not only improved my programming skills but also exposed me to cloud-based technologies such as Heroku, AWS, Azure, and IBM. I learned new technologies like Node.js, HTML, CSS, EJS, JavaScript, ReactJs, and API development. Furthermore, working on these projects taught me the importance of collaboration and teamwork, including effective communication and problem-solving skills, even in remote online settings using platforms like Zoom and Microsoft Teams during the COVID-19 pandemic.

Hobbies and Interests

  • Artificial Intelligence
  • Emerging Technology
  • Information Security
  • Reading
  • Music
  • Sports

References

  • Available upon request

Certified Certifications

  • EC-Council Certified Ethical Hacker (CEH), Expired in 2024
  • CompTIA Security +, Expired in 2024

Projects

  • A dynamic Power BI dashboard was developed to track and manage third-party vendors within a cluster. The dashboard enables efficient monitoring and remediation of high-risk, non-compliant vendors by tracking supplier security profiles, contracts, and cybersecurity and privacy risk assessments. This facilitates proactive risk management and informed decision-making.
  • A Power BI dashboard was developed to monitor data egress via email, providing real-time insights into sensitive information leaving the organization. The dashboard highlights risk trends, areas of concern, and business unit breakdown analysis, enabling swift identification and mitigation of potential data breaches. Its real-time updates and efficient design facilitate proactive data loss prevention and enhanced security oversight.
  • A Cyber Management Information System Power BI dashboard developed to track and monitor the remediation of non-compliant Cyber Key Risk Indicators (KRIs) and policy acknowledgements. The dashboard provides insights at both cluster and business unit levels, enabling effective management and mitigation of cyber risks
    SSL.
  • A Power BI dashboard developed to track expiring SSL certificates, providing key details such as expiration dates and the number of days remaining. This dashboard enables proactive renewal of certificates, helping to prevent potential security issues and downtime.
  • Developed a Power BI dashboard to track quarterly line manager access reviews, providing visibility into completion rates across business units and enhancing reporting accuracy. The dashboard Identified and highlighted areas of concern, enabling proactive risk management and improved oversight.
  • Throughout my university journey, I worked on various projects that helped me develop a range of technical skills. (1) One of my notable projects was the development of a client interactive responsive website using C# and SQL for database management. (2) I also collaborated on a group project to design and develop a hotel management system using the software development life cycle, which included system analysis, design, and development. (3) Another group project involved building a network system with three interconnected subnetworks using CISCO packet tracer. Additionally, (4) I created a web-based text classification program using Node.js for backend API, MongoDB for database, and HTML, CSS, and EJS for front-end development. (5) I also designed and developed a personal portfolio website using ReactJs, HTML, and CSS. These projects not only improved my programming skills but also exposed me to cloud-based technologies such as Heroku, AWS, Azure, and IBM. I learned new technologies like Node.js, HTML, CSS, EJS, JavaScript, ReactJs, and API development. Furthermore, working on these projects taught me the importance of collaboration and teamwork, including effective communication and problem-solving skills, even in remote online settings using platforms like Zoom and Microsoft Teams during the COVID-19 pandemic.

Hobbies and Interests

  • Artificial Intelligence
  • Emerging Technology
  • Information Security
  • Reading
  • Music
  • Sports

References

  • Available upon request
Clifford Mathebula