Government EntitySouth African Reserve Bank
    LocationGauteng, Pretoria
    Reference Number1768
    Centre / LocationPretoria, South Africa
    Closing DateAugust 7, 2026
    Source and Applicationfa-evra-saasfaprod1.fa.ocs.oraclecloud.com

    Brief description

    The main purpose of this position is to provide consulting services on the evaluation and development of security controls and drive security design deliverables aligned with architectural artifacts, and to critically evaluate current security controls.

    Requirements

    Job requirementsTo be considered for this position, candidates must be in possession of:A minimum of a BSc. Computer Science Honours / BSc. Engineering Honours (NQF 8) plus Industry specific qualifications OR equivalent;CISSP qualification is required. 8–10 years’ experience in an information security function with at least 3-5 years of job-related experience in application/infrastructure/cloud security design and consultation. Additional requirements include:Other industry specific qualifications such as SSCP, CCSP, CSSLP, CISM, TOGAF etc.  will be advantageous to aid in the selection of the focus area between applications and infrastructure both on premises and cloudApplication security designData security designInfrastructure security designSystem integrationICT industry standardsInformation securityServices designArchitecture views and viewpoints designThreat and Risk AnalysisIT governance, risk and complianceSecurity frameworks and standards such as ISO 27000-series, NIST, etc In line with the SARB’s commitment to diversifying its workforce, preference will be given to suitable candidates from designated groups. People with disabilities are welcome to apply.The SARB offers remuneration and benefits commensurate with the level of the position and in line with the market. The level at which the successful applicant will be appointed will depend on his/her competence and experience.

    Duties

    Detailed descriptionThe successful candidate will be responsible for the following key performance areas:Advise and drive security minded thinking to ensure effective consideration of security control objectives across the SARB Group, while optimising processes.Provide technical direction, oversight, coaching and mentoring to BSTD team members in the operational and development landscape regarding security controls, ensuring the delivery of secure implementations.Define, design and optimise effective security mechanisms that enable secure business processes.Research and stay abreast of the threat landscape and the latest developments to mitigate cyber and system security risks, aligned to governance controls for systems on-premises and in the cloud.Identify security requirements, from business requirements, and define and guide the development and maturing of controls to enable a mitigated business risk.Liaise with security architects and technical teams as well as security service providers to share best practices and insights both within SARB Group and the industry.Assess the effectiveness and completeness of existing architectural artifacts and security patterns and provide direction on artifacts and pattern expansion in order to reduce the SARB Group’s risk posture.Evaluate implemented security controls and mechanisms for their effectiveness and identify gaps to improve and extend the use of such controls.Guide and ensure effective compliance measurement interpretation in order to ensure effective SARB Group risk posture reporting across all domains.Create, and provide input into the maintenance and definition of, security policies, frameworks and standards in accordance with corporate governance including the Bank’s policies, procedures and other legislative requirements.Develop and evaluate Requests for Information (RFIs) and Requests for Proposals (RFPs) for security specific solutions and provide guidance on security requirements for business solutions.To act on management requests to address or mitigate risks in the SARB Group environment as identified.To play a consulting role in responding to critical security incidents within the SARB Group as a member of the Incident Response team (CSIRT).

    Source / Circular Reference

    fa-evra-saasfaprod1.fa.ocs.oraclecloud.com