The Government Pensions Administration Agency (GPAA) is a government component that reports to the Minister of Finance and administers funds and schemes on behalf of the Government Employees Pension Fund (GEPF), the largest pension fund in Africa. It thus administers the pension affairs of approximately 1,7 million government employees and pensioners, as wel...
Read more about this company
A relevant 3-year National Diploma/Degree in Risk Management/Information Technology or equivalent qualification (at least 360 credits). Minimum six (6) years appropriate experience in ICT risk/ relevant environment with 3 years in management or middle management experience. Computer literacy which includes a good working knowledge of Microsoft Office products.
Key Performance Areas
The successful candidate will be responsible for: Manage the optimal information communication technology security processes. Implement IT Security and standards in alliance with all stakeholders (SITA, Service Providers etc.) Develop IT security requirements specifications. Monitor the maintenance of security breach records. Monitor IT security compliance in all areas.
Manage disaster prevention and recovery processes and backup. Implement all IT procedures, standards and policies on procurement of IT equipment. Monitor and evaluate the management and functioning of IT operations. Assess the reliability of existing IT controls against the required standards. Monitor the IT systems and controls in order to identify potential risks. Evaluate identified IT risks and escalate the awareness. Communicate with all stakeholders on a regular basis with regard to identified risks. Provide awareness sessions to all staff. Conduct regular IT security systems audit. Develop, maintain and communicate the GPAA IT risk management strategy to maximise awareness and compliance.
Develop and implement IT risk management strategy that meets organisational objectives and aligns with GPAA’s overall strategy. Measure the effectiveness of risk preventative strategies on an ongoing basis and make recommendations to review and amend the strategy appropriately. Report back to key internal stakeholders at regular intervals to ensure that strategy is fit for purpose. Conduct risk awareness sessions relating to IT. Monitor system security and information ownership. Monitor patch management of systems, anti-virus and applications. Ensure the upgrading of IT security anti-virus software. Monitor system logs for breaches of security and initiates remedial actions. Monitor the adherence of security standards by all stakeholders.
20 Initiatives to Boost Employee EngagementAre you struggling with improving employee engagement at work? This article covers everything from better communication to building a strong workplace culture.
30 Common Interview Mistakes to AvoidThis piece examines 30 of the most common mistakes applicants make at interviews, so you know how to better avoid them.