A relevant Degree/BTech in Computer Science/Information Technology/ Cyber Security (NQF level 7) or equivalent qualification as recognised by SAQA with 5 years’ experience at middle/senior managerial level in Performing IT management or cyber security with a strong background in incident management, risk management and security architecture. Computer literacy which includes a good working knowledge of Microsoft Office products. Knowledge of Benefits Administration. Knowledge of relevant Legislative requirements and GPAA policies and procedures. Knowledge of the industry. Knowledge of Financial management including budgeting and forecasting. Knowledge of Pension Fund regulations and rules. Compliance management. Knowledge of relevant systems. Strategic capability. Cloud and wireless security. Service frameworks, standards and technologies. Programme and project management. People management and empowerment. Risk management. Compliance frameworks and control best practices. Anti-virus, anti-spam, internet filtering and patch management tools. Intrusion detection/prevention systems. System technology security testing (vulnerability scanning and penetration testing). Documenting security architecture and plans. Respect. Service excellence. Integrity. Transparency. Courtesy. Emotional intelligence. Team player. Analytical.
The incumbent will be responsible for a wide variety of tasks which includes but are not limited to the following: Manage the implementation of the Information Security Management strategy: Monitor the implementation of the operational plan for the Directorate to support the achievement of GPAA’s strategic objectives. Manage, monitor and review the Directorate policies, procedures and processes, in accordance with best practice and legislation. Compliance and reporting in line with ISO/IEC 27001 and the applicable DPSA directive. Manage the implementation of an effective short, medium and long- term operating strategy for the Directorate. Conduct benchmarks on new developments in practices to improve the effectiveness and efficiency of the organisation. Manage the provision of best practice regarding Directorate functions to all stakeholders. Manage the implementation of a management effectiveness and leadership strategy. Engage in strategic relationships with 29 relevant stakeholders to serve the interest of the organisation. Monitor compliance with relevant legislation throughout all Directorate functions. Analyse service delivery gaps, challenges and implement remedial action strategies. Manager quality of service provided to internal and external customers/clients/stakeholders. Manager the mitigation of identified risks. Ensure information flow to and alignment with all stakeholders to ensure effective engagement. Conduct trends analyses and forecasting. Manager the Security of Organisational information: Collaborate with relevant internal and external stakeholders to identify, monitor and manage Information Security risk proactively. Develop and manage the implementation of appropriate mitigation strategies, achieving stipulated objectives. Ensure that GPAA is appropriately protected against unforeseen events, losses, and damage, to recover Information Infrastructure where required. Conduct operational risk assessments for the Information Security department, in line with the GPAA’s risk management framework, to develop and maintain adequate internal operations controls and standards. Oversee the operations of the business unit: Assess the provision of Information Security Management support and advice to line managers to ensure that line managers are fully equipped to deal with Information Security Management strategy related matters. Drive a culture of compliance with GPAA line managers and staff to ensure greater awareness of Information Security Management policies and procedures. Monitor compliance with relevant legislation throughout all Information Security Management functions. Manage planning of resource requirements for the organization to ensure sufficient resources are in place to meet service delivery demands. Analyse service delivery gaps and challenges, define service delivery operational measures and targets, and implement remedial action strategies. Oversee quality of service provided to internal and external customers/clients/stakeholders. Proactively ensure the identification and mitigation of risk. Establish and manage agreed budgets in consultation with the Chief Information Technology Office and Budget Office, ensuring that costs are contained based on minimum requirements for security controls. Manage, coordinate and oversee the daily operational activities of the subunit to ensure that it functions effectively and efficiently. Proactively mitigate employee relations risks. Ensure information flow to and alignment with all stakeholders to ensure effective engagement. Manage and facilitate business partnering: Assist line managers to prepare business cases and budgets for new projects relating to provision of organizational information, motivating project viability and value to the GPAA. Provide Information Security support and advice to the Technology COE with regard to relevant IT solutions or problems raised by managers. Contribute to Client meetings, demonstrating Information Security capability when required. Establish sound working relationships with various third-party service providers, monitoring achievement of agreed service levels. Manage and develop the capacity requirements plan: Perform Information Security budget and expenditure reconciliations for the Technology COE to ensure prudent financial management of the department. Assist Technology COE to develop and report on cost of Information Security per employee to optimise and manage cost of service provided. Motivate for additional financial and staff resources to meet business requirements. Assess IT infrastructure requirements so that Information Security processes and procedures run smoothly. Manage third party contracts sufficiently to ensure maximum return of benefits to the organisation. Continuously manage the improvement of processes and procedures: Track new developments in the industry, to improve the effectiveness and efficiency of the Information Security function in the GPAA. Identify areas of improvement to meet organisational needs. Formulate process and technological improvement solutions to enhance efficiencies. Work in conjunction with relevant departments to implement changes, providing and integrated service. Manage project implementation evaluating progress in terms of set objectives. Execute IS governance requirements to ensure compliance with best practices. Manage all the resources in the Directorate: Ensure the development and management of staff within the Directorate. Implement and maintain a relevant management approach to support effective business results within the Directorate. Develop and sustain a culture of high performance, professionalism and integrity to support overall quality of service delivery. Ensure control of budgeting and expenditure process in line with strategic objectives and relevant legislation. Ensure the effective utilization of all resources (including IS, Assets, Infrastructure, etc.) within the Directorate. 30
R1 266 714 – R1 492 122 per annum (Level 13), (all-inclusive package)
Pretoria
All positions are permanent, based in Pretoria Head Office, and close on 30 January 2026 before 12:00 noon. Applications must include a signed Z83 form and comprehensive CV emailed to the respective email addresses with the reference number in the subject line.Recruit1@gpaa.gov.za
30 January 2026
ReferenceNo:
DIR/IS/2026/01-1P
