Manager: Cybersecurity Operations
Centurion, Gauteng, ZA
The Road Accident Fund’s mission is to provide appropriate cover to all road users within the borders of South Africa; to rehabilitate and compensate persons injured as a result of motor vehicle accidents in a timely and caring manner; and to actively promote safe use of our roads.
Purpose of the Job: Reporting to the Senior Manager: Technology Governance, Risk and Compliance, the successful incumbent is accountable for managing the protection, detection, response and recovery of information that flows within and outside the organization to ensure a seamless and secure operation of all computer systems, related applications, hardware and software used by the organization.
Key Performance Areas
Cyber Security
- Develop, implement, and monitor a strategic cyber security program to protect enterprise IT assets.
- Manage the implementation of effective incident response and recovery plans, enabling the organization to quickly respond to and recover from security incidents.
- Ensure the governance structure and processes for the department are reviewed and manage the implementation thereof.
- Manage the alignment of technology governance with corporate governance.
- Manage the development of periodic reports on operational excellence and cost reductions achieved.
- Oversee risk assessments regarding cyber security and penetration testing.
- Manage the development of cyber security awareness training for the organization.
- Assess current technologies and recommend hardware or software tools to top management.
- Drive the adoption of best ICT and cyber security practices across the organization.
Policy Review and Implementation
- Contribute to the development and implementation of departmental policy, procedures and processes.
- Ensure the organization complies with regulatory requirements and industry best practices related to ICT and cyber security.
Reporting
- Prepare and submit regulation reports as required to provide progress updates and inform management decisions.
- Develop procedures and guide the process through the alignment of the documents to the overall RAF’s Strategy.
- Develop functional reporting systems for management, projects, or performance reporting.
Stakeholder Management
- Facilitate and manage communication with relevant internal and external stakeholders in relation to investments and proactively and progressively manage the relationships.
- Communicate with all levels of stakeholder contact.
People Management
- Lead, mentor, and develop the ICT and Cyber Security teams, fostering a culture of continuous improvement and innovation.
- Manage resource allocation, including budgeting for system maintenance, upgrades, and security projects.
- Manage the implementation of human capital processes and procedures to control or regulate workplace conflict and institute corrective measures and consultation processes to address standard deviations.
Qualifications and Experience
- Bachelor’s Degree/ Advanced Diploma in Information Technology or a Computer Science related qualification.
- A postgraduate in Information Technology or a Computer Science related qualification will be an added advantage.
- Being a Certified Information Systems Security Professional (CISSP), CISM, CISA, or similar certifications will be advantageous.
- Relevant 6 - 8 years experience in an Information Technology/ Risk Management related environment of which 2 years must have been on a management/ supervisory level/ area of expertise.
- Relevant certifications such as CISSP/ CISM/ CISA or ITIL are advantageous.
- Strong understanding of current ICT technologies, cyber security trends, and best practices.
Technical and Behavioral Competencies Required
- Resilience.
- Network and alliance.
- Employee engagement.
- Ethics and values.
- Change management.
- Critical and innovative thinking.
- Policy conceptualisation and formulation.
- Risk Management.
- Stakeholder development and relations.
- Reporting.
- Data Security Management.
- IT Risk Management.
- ICT Security Architecture.
- Secure Development lifecycle.
- Security Operations Management.
- Application Security.
- Information Assurance.
- Innovation and Business Improvement.
- Risk Assessment.
- Vulnerability Management.
NB: “RAF offers Total Employment Cost packages with no additional contributions from the Employer, successful candidates are required to structure their packages in a manner that will suit their needs”.
The Road Accident Fund subscribes to the principles of employment equity and preference will be given to People with Disabilities.
Applicants who have not received any correspondence from us within six weeks from the closing date can consider themselves unsuccessful
Security Vetting shall be conducted on all prospective employees
It is the applicants’ responsibility to have foreign qualification evaluated by the South African Qualification Authority (SAQA) and to provide proof of such evaluation.