Jobs Career Advice Post Job
X

Send this job to a friend

X

Did you notice an error or suspect this job is scam? Tell us.

  • Posted: Oct 8, 2026
    Deadline: Oct 21, 2026
    • @gmail.com
    • @yahoo.com
    • @outlook.com
  • Since 1994, South Africa has been using a multi-agency approach in its border management agenda. In this regard, seven Departments and Agencies, i.e. the Departments of Agriculture, Land Reform and Rural Development; Forestry, Fisheries and the Environment; Health; and Home Affairs; the South African National Defence Force (SANDF); the South African Polic...

     

    Specialist: ICT, Risk and Compliance

    Description

    The successful candidate will be expected to perform the following duties and responsibilities:

    ICT Assurance and Compliance Monitoring.

    • Coordinate ICT internal and external audits.
    • Coordinate audit management responses and evidence submissions.
    • Monitor implementation of ICT audit recommendations and corrective actions.
    • Conduct compliance reviews against approved ICT policies, standards and procedures, excluding specialist identity, endpoint and third-party assurance reviews covered under separate KPAs.
    • Report audit and compliance trends, control weaknesses and remediation status to management.

    ICT Governance Framework

    • Develop, implement and maintain ICTgovernance frameworks to support effectiveICT oversight and decision-making.
    • Develop, review and maintain ICT security policies, standards, procedures and guidelines.
    • Maintain the ICT policy and governance artefact register in line with approved review cycles.
    • Ensure ICT governance alignment with theCorporate Governance of ICT PolicyFramework (CGICTPF) and relevantstandards.
    • Advise stakeholders on governancerequirements for embedding ICT controls intobusiness processes.

    Third-party risk and assurance

    • Review third-party ICT security assurancesduring onboarding, contract renewal ormaterial service changes.
    • Coordinate supplier ICT security, privacy andcompliance reviews.
    • Track third-party ICT risk issues, control gapsand supplier remediation actions.
    • Monitor applicable ICT security SLA andassurance obligations related to suppliers.

    ICT Risk Management.

    • Develop and maintain the ICT risk management process and ICT risk register.
    • Facilitate ICT risk assessments across relevant ICT domains and initiatives.
    • Develop and coordinate risk mitigation strategies and treatment plans for identified ICT risks.
    • Monitor implementation of ICT risk treatment actions and escalate overdue or high-risk items.
    • Support enterprise risk reporting by providing ICT risk inputs and status updates.

    ICT Security, Identity and Endpoint Control Monitoring

    • Support the monitoring of identity and access management controls, including user access reviews, privileged access and account lifecycle processes.
    • Coordinate basic endpoint security compliance checks against approved ICT security standards and baseline requirements. 
    • Track and report exceptions relating to access control, endpoint protection, patching, malware protection and device configuration compliance.
    • Escalate identified ICT security control weaknesses for remediation and management reporting.

    ICT Governance Stakeholder Engagement and Reporting

    • Coordinate and consolidate ICT governance, risk, compliance and security inputs for management and governance structures.
    • Coordinate submission of ICT Steering Committee, Internal Audit Committee and Audit and Risk
    • Committee reports.
    • Facilitate stakeholder engagements on ICT governance, risk, compliance and security matters.
    • Track committee decisions, stakeholder inputs and cross-functional commitments until closure.
    • Maintain consistent stakeholder communication on ICT governance matters without duplicating technical ownership assigned to other KPAs.

    Requirements

    Minimum Requirements

    Minimum Qualifications:

    • Grade 12 (Matric)
    • Undergraduate qualification at NQF 7 as recognised by SAQA in Computer Science, Information Technology, Information Security or equivalent.
    • Certified Information Systems Auditor (CISA) certification is advantageous.

    Minimum Experience

    • 5 years relevant work experience in ICT Governance, Risk and Compliance, or IT Security

    Knowledge

    • ISO/IEC 27001, ISO/IEC 27002, ISO 31000
    • COBIT, ITIL
    • Corporate Governance of ICT Policy Framework
    • ICT Governance structures
    • Minimum Information Security Standards (MISS)
    • Enterprise-wide Risk Management
    • Information Technology Policies
    • Policy Development
    • IT Risk Management
    • IT Governance

    Other requirements:

    • Flexibility in working hours will be required to meet demands of the role.
    • May be required to work overtime.
    • Valid driver’s License

    go to method of application »

    Specialist: Cyber Security

    Description

    The successful candidate will be expected to perform the following duties and responsibilities:

    Cybersecurity Operations

    • Develop, implement and continuously improve the BMA’s cybersecurity operations capability to protect information assets, systems, networks, cloud platforms and digital services against cyber threats.
    • Administer, monitor and optimise operational cybersecurity technologies, including endpoint security, email security, network security, cloud security and related technical symbols.
    • Implement and maintain security configuration baselines, technical hardening standards and secure configuration requirements across ICT infrastructure, operating systems, cloud platforms and business applications.
    • Review cybersecurity configurations for new systems, infrastructure changes and technology implementations to ensure alignment with approved security standards and organisational requirements.
    • Develop and maintain cybersecurity operational procedures, technical standards, implementation guides and supporting documentation.
    • Provide specialist cybersecurity guidance to ICT teams, business units and project teams on operational security risks, controls and mitigation measures.
    • Coordinate vulnerability remediation with ICT infrastructure, application and service owners to ensure identified weaknesses are addressed within agreed risk-based timeframes.
    • Review security logs, alerts and configuration reports from operational cybersecurity tools to identify control failures, misconfigurations and areas requiring corrective action.
    • Support patch management and secure maintenance activities by validating that critical systems, endpoints and security technologies are updated in line with approved security requirements.

    Identity and Access Security

    • Develop, implement and continuously improve the organisation’s Identity and Access Management capability to ensure secure, appropriate and auditable access to systems, applications and ICT resources. 
    • Design, implement and maintain identity and access security controls, including authentication, authorisation, multi-factor authentication, role-based access control, privileged access management and adaptive access controls.
    • Implement and maintain Identity Governance and Administration processes for the provisioning, modification, recertification and de-provisioning of user, privileged, service and third-party accounts.
    • Administer enterprise identity services, directory services, authentication mechanisms and access control technologies in line with approved security standards.
    • Monitor identity-related security events, authentication risks and anomalous access activities, and initiate appropriate technical responses where required.
    • Provide specialist advice on identity architecture, authentication mechanisms and access control requirements for new ICT solutions, projects and technology implementations.
    • Maintain technical documentation, operational procedures and standards relating to identity and access security technologies.

    Threat Detection, Incident Response and Cyber Resilience

    • Develop, implement and continuously improve the organisation’s cybersecurity monitoring and incident response capability to enable timely detection, analysis, containment, eradication and recovery from cybersecurity threats and incidents.
    • Monitor the organisation’s ICT environment for cybersecurity threats, malicious activity and indicators of compromise using approved security monitoring technologies and threat intelligence sources.
    • Coordinate and manage cybersecurity incidents throughout the incident lifecycle, ensuring incidents are classified, prioritised, investigated, contained, resolved, documented and formally closed.
    • Conduct technical investigations into cybersecurity incidents, analyse root causes and recommend corrective and preventive actions to minimise recurrence.
    • Coordinate or support digital forensic investigations and ensure digital evidence is preserved, collected and handled in accordance with approved procedures and legal requirements.
    • Develop, maintain and periodically review the Cybersecurity Incident Response Plan, incident response playbooks, escalation procedures and communication protocols.
    • Coordinate and participate in cybersecurity incident simulations, tabletop exercises and cyber resilience testing to validate organisational preparedness.
    • Support cyber recovery and ICT disaster recovery planning, testing and improvement in collaboration with ICT infrastructure, business continuity and disaster recovery stakeholders.
    • Develop operational dashboards and management reports on cybersecurity incidents, threat trends, response performance and organisational cyber resilience.

    Cybersecurity Programme Delivery 

    • Develop, implement, coordinate and monitor cybersecurity projects and initiatives that support the organisation’s cybersecurity strategy, ICT strategic objectives and digital transformation programme.
    • Provide specialist cybersecurity input into ICT projects, solution designs, technology acquisitions and procurement activities to ensure security requirements are embedded throughout the project lifecycle.
    • Develop cybersecurity technical specifications, standards and security requirements for ICT infrastructure, cloud services, applications, software, hardware and managed security services.
    • Evaluate cybersecurity technologies and solutions and provide recommendations on suitability, technical capability, security effectiveness, integration requirements and alignment with organisational needs.
    • Support cybersecurity procurement processes by reviewing technical proposals, validating compliance with security requirements and contributing to bid evaluation activities where required.
    • Manage cybersecurity vendors, managed security service providers and technology partners to ensure contracted services are delivered in accordance with agreed service levels, contractual obligations and organisational expectations.
    • Track cybersecurity programme risks, issues, dependencies, milestones and deliverables, and escalate matters requiring management intervention.
    • Develop, monitor and report cybersecurity Key Risk Indicators, Key Performance Indicators and operational metrics to provide management with insight into cybersecurity posture, service performance and emerging risks.

    Stakeholder Management

    • Build and maintain effective working relationships with internal business units, ICT teams, governance structures, service providers and relevant external stakeholders to support the delivery of cybersecurity services and initiatives.
    • Provide specialist cybersecurity advice, technical guidance and recommendations to management, ICT teams, project teams and business stakeholders on cybersecurity risks, controls and mitigation measures.
    • Coordinate cybersecurity-related inputs, updates and follow-ups with stakeholders to support incident response, access security, operational control improvements and cybersecurity programme delivery.
    • Promote cybersecurity awareness, responsible technology use and a strong security culture through collaboration, communication and engagement with relevant stakeholders.

    Requirements

    MINIMUM REQUIREMENTS

    Minimum Qualifications: 

    • Matric (Grade 12)
    • Undergraduate qualification at NQF 7 as recognised by SAQA in Computer Science, Information Technology or equivalent 
    • A recognised vendor-neutral entry-to-intermediate level cybersecurity certification, or equivalent, will be an added advantage, including ISO 27001, Security +, CySA +, etc

    Minimum Experience:

    • 5 Years working experience within a Cyber/IT Security role.

    Knowledge

    • Cybersecurity governance and strategy
      Identity and Access Management
    • Security Operations Centre
    • CIS Controls 
    • Zero trust principles 
    • ISO 27001 
    • Border Management Authority,2020

    Other requirements

    • Flexibility in working hours will be required to meet demands of the role.
    • May be required to work overtime.
    • Valid driver’s License

    Method of Application

    Use the link(s) below to apply on company website.

     

    Build your CV for free. Download in different templates.

  • Get new ICT / Computer jobs like this on Telegram.Get Jobs on Telegram
  • Send your application

    Back To Home

Career Advice

View All Career Advice
 

Subscribe to Job Alert

 

Join our happy subscribers

 
 
Send your application through

GmailGmail YahoomailYahoomail