Picture
 
SOUTH AFRICAN NATIONAL ROADS AGENCY (SANRAL)
 
​ 
 
3X PROJECT MANAGERS
Southern Region
Permanent      
 
Description
POSITION OBJECTIVE:
To ensure project management in respect of specific norms and standards, according to relevant legislation, and the efficient management of resources, time and budgets associated with projects under the incumbent’s control. To develop and maintain excellent working relationships with external stakeholders and to ensure required business results.
 
MINIMUM REQUIREMENTS:
  • B Eng. or B Sc. or B Tech Eng. Degree in Civil Engineering.
  • A minimum of 10 years’ relevant experience, post qualification (B Eng. or B Sc. or B Tech Eng. Degree in Civil Engineering), in any of the following fields: planning, design, construction, operations and maintenance, project, and contract management of major roadworks.
  • Registered with ECSA as a Professional Engineer or Professional Engineering Technologist.
 
WORKING CONDITIONS / INHERENT REQUIREMENTS OF THE JOB:
  • Travel as and when required.
  • Attend Cluster Meetings as and when required.
  • Driver’s License.
  • Work is performed in a combination of office and construction site environment, as and when required.
 
SKILLS AND COMPETENCY OF THE IDEAL CANDIDATE: 
Extensive knowledge of relevant industry standards and specifications, as well as the FIDIC suite of General Conditions of Contract and relevant legislation. The ability to demonstrate attention to detail and solve problems in a timely manner. The candidate should exhibit sound and accurate engineering and project management judgment and work well under pressure. Extensive project management experience in the roads sector post ECSA registration.
 
KEY PERFORMANCE AREAS INCLUDE, BUT ARE NOT LIMITED TO:
Identification of Projects
  • Participates in the identification and prioritizing of projects using data from relevant management systems, network inspections, and personal knowledge.
  • Based on requirements of the project, prepare annual budget and program.
  • Ensure accurate identification of projects.
  • Ensure effective prioritizing of projects.
  • Ensure correct allocation of project funds.
  • Ensure accurate project scope and realistic timeframes based on relevant requirements.
 
Procurement Management 
  • Participates in the procurement processes for the appointment of consulting engineers and contractors as per the Employer’s standard operating procedures for procurement.
  • Prepare relevant tender documentation for appointment of consulting engineers.
  • Prepare relevant tender documentation for construction, in association with the consulting engineer, based on the scope of the project.
  • Attend tenderer’s briefing meetings and site inspections to brief contractors on services required for project.
  • Understands risk identification and analysis in respect of tender evaluations.
  • Understands Pricing Schedules and analysis of tendered rates.
  • Ensure use of appropriate and correct tender documentation as per specifications.
  • Ensure compliance to SANRAL’s procurement policy.
 
Project Management
  • Manages both Consultant and Construction Contracts over the full spectrum of SANRAL projects.
  • Visits sites on a regular basis to monitor progress against the project plan.
  • Monitors performance of projects through regular meetings with consultants and contractors.
  • Ensure that appointed service provider conducts regular site audits.
  • Monitors financial performance to ensure the project remains within budget.
  • Prepare monthly forecast of expenditure for each project.
  • Verify fee accounts and payment certificates prior to approval for payment.
  • Review scope of work and potential impact on the budget and request additional funds if necessary.
  • Identify possible hazardous locations of pedestrians and vehicles on network.
  • Monitor transformation targets in terms of targets on construction projects.
  • Identify and manage community development projects.
  • Maintain good corporative governance in terms of risks and audits requirements on projects.
  • Consider innovation in project life cycle.
  • Ensure early identification of problems and mitigation thereof.
  • Ensure effective project and contract management.
  • Ensure completion of projects on time, within budget and conformance with quality standards.
  • Ensure compliance with all technical, financial and quality requirements of the contract.
  • Ensure compliance to terms and conditions of the contract.
  • Understand the Claims process and ensure that Notices, Claims and Engineer’s Determinations are reported to the Chair of the Claims Committee.
  • Understand the Dispute process and the functions of the Dispute Adjudication Board.
  • Ensure effective cash flow management.
  • Identify changes in project scope timeously.
  • Mitigate and report on incidents as and when required.
 
Specialist Support   
  • Heads up and/or actively participates in activities of a relevant technical cluster.
  • Shares knowledge and experience with colleagues.
  • Pursue research and best practice.
  • Involved with development and improvement of specifications for SANRAL.
  • Reviewing of Regional Memoranda and contract documentation.
  • Ensure quality service delivery through use of appropriate solutions.
  • Promote SANRAL’s credibility and promote aims and objectives of SANRAL.
 
Communication Management
  • Maintains good working relationships with all colleagues in all regions and areas of expertise.
  • Cultivates and maintains good working relationships with key stakeholders, consultants and contractors.  
  • Ensure internal collaboration and co-operation.
  • Promote aims and objectives of SANRAL.
 
 
EMPLOYMENT REFERENCE CHECKS
Employment reference checks are a requirement as part of SANRAL’s recruitment and selection process. In order for SANRAL to conduct these checks a consent form needs to be completed and signed by the applicant. As an applicant of this position, you authorize SANRAL to process all the information provided for the purpose of your application for the position as well as the verification and record keeping of such credentials.
 
EMPLOYMENT EQUITY
  • Appointments will be made in accordance with SANRAL’s Employment Equity plan.
  • SANRAL reserves the right not to fill any position.
 
Please note that further communication will be limited to shortlisted candidates only.
 
Closing date: 8 August 2025
 
Link to apply for this position: https://career2.successfactors.eu/sfcareer/jobreqcareer?jobId=2742&company=southafr02
 
Please submit your CV online (www.nra.co.za)
 
Employment Permanent
Location Eastern Cape Province: 20 Shoreward Drive; Baywest; Gqeberha
Closing Date 08/08/2025
 
 
 
 
 
 
 
 
 
 
MANAGER: APPLICATION SECURITY
National
Permanent     
 
Description
POSITION OBJECTIVE:
The Manager: Application Security will be responsibilities for SANRAL’s application security engineering as well as identifying, assessing, and mitigating vulnerabilities in applications, ensuring they are secure from security threats. The role will also oversee the implementation of security policies and practices within the application development lifecycle, often collaborating with other engineering and development teams.
 
MINIMUM REQUIREMENTS:
  • NQF Level 7 Bachelor’s degree, Advanced Diploma or equivalent in Information Technology
  • Compulsory industry certifications: CISSP, CISM, or CISA
  • 5 years min relevant experience
  • 3 years min supervisory experience
 
WORKPLACE COMPETENCIES:
  • Experience with OWASP Top 10 standard.
  • Experience with securing applications in cloud environments (e.g., AWS, Azure).
  • Strong understanding of authentication and authorization protocols, and encryption.
  • Attention to Detail.
  • Software Development Lifecycle.
  • Demand Management.
  • Technology Trends.
  • Proven experience leading or mentoring a team of security professionals.
  • Relationship Building and Influence.
  • Business Needs Analysis.
  • Project management skills to organize, drive, and execute initiatives.
  • Experience in supporting supplier security activities to ensure third‐party software and development meets SANRAL's security standards.
 
KEY RESPONSIBILITIES:
 
Management:
  • Lead and manage the application security program, closely align with the overall SANRAL Cyber Security program.
  • Establish and drive the adoption of application security testing frameworks, capabilities, and tooling.
  • Scale application security through automation, ensuring security testing is integrated into development pipelines.
  • Provide guidance on secure application design and risk mitigation for technology stakeholders.
 
Operational:
  • Establish and enforce secure development standards, policies, and procedures across the organization.
  • Integrate security tools, standards, and processes into the systems life cycle.
  • Support the incident response and architecture review processes whenever application security expertise is needed.
  • Ensure compliance with relevant security standards and regulations.
  • Conduct security assessments of applications (web, cloud, mobile, API) using range of manual and automated review techniques.
  • Create functional and non-functional application security requirements, including delivering secure cloud services that strike a balance of product usability.
  • Oversees Vulnerability remediation and ensures accountability for risk reduction.
  • Provide security requirements for systems security testing.
  • Serve as a Subject Matter Expert (SME) in the field of Application Security.
 
Reporting:
  • Provide regular updates on application security metrics, program status, and risk assessments to SANRAL’s leadership.
  • Communicate security issues and plans effectively to both technical and non-technical audiences.
 
EMPLOYMENT REFERENCE CHECKS:
Employment reference checks are a requirement as part of SANRAL’s recruitment and selection process. In order for SANRAL to conduct these checks a consent form needs to be completed and signed by the applicant. As an applicant of this position, you authorize SANRAL to process all the information provided for the purpose of your application for the position as well as the verification and record keeping of such credentials.
 
Please note that this is a confidential document and is intended for internal use by SANRAL’s Human resources department only.
 
 
EMPLOYMENT EQUITY:
  • Appointments will be made in accordance with SANRAL’s Employment Equity plan.
  • SANRAL reserves the right not to fill any position.
 
Closing date for applications: 05 August 2025
 
Link to apply for this position: https://career2.successfactors.eu/sfcareer/jobreqcareer?jobId=2747&company=southafr02
 
Employment Permanent
Location SANRAL COC Offices, 36 Assegai Wood Road Rooihuiskraal, Centurion 0157
Closing Date 05/08/2025
 
 
 
 
 
 
 
 
 
 
 
MANAGER: INCIDENT AND RESPONSE MANAGEMENT
National
Permanent
 
Description
 
POSITION OBJECTIVE:
The Manager: Incident and Response Management will lead SANRAL's efforts to respond and recover from security incidents. The manager will manage the response team, coordinate investigations, and ensure SANRAL is prepared for and resilient against security breaches. This role requires strong leadership, technical expertise, and the ability to collaborate effectively with various teams and stakeholders.
 
MINIMUM REQUIREMENTS:
  • NQF Level 7 Bachelor’s degree, Advanced Diploma or equivalent in Information Technology
  • Compulsory: Advanced certification as a Certified Incident Handler or equivalent (e.g. ECIH)
  • 5 years min relevant experience
  • 3 years min supervisory experience
 
WORKPLACE COMPETENCIES:
  • A deep understanding of incident response methodologies, cybersecurity frameworks (like NIST or ISO 27001), and familiarity with relevant tools and technologies is essential.
  • Ability to lead cross-functional teams, delegate tasks effectively, and maintain composure under pressure while coordinating the incident response process.
  • Meticulous attention to detail is necessary for thorough investigation, accurate documentation, and effective incident and response management.
  • Software Development Lifecycle.
  • Demand Management.
  • Technology Trends.
  • Leadership skills.
  • Business Needs Analysis.
  • Good interpersonal skills, people skills, organizing and communication skills.
  • Project management skills to organize, drive, and execute initiatives.
  • Experience in supporting supplier security activities to ensure third‐party systems meets SANRAL's security standards.
 
KEY RESPONSIBILITIES:
 
Management:
  • Leadership and Coordination: Ability to lead a cross-functional incident response team and manage high-pressure situations during incidents.
  • Analytical Skills: Strong analytical skills to co-ordinate investigation of incidents, perform root cause analysis, and determine appropriate mitigation strategies.
  • Communication: Excellent communication skills to convey information clearly to both technical and non-technical stakeholders, including senior leadership
 
Incident Response:
  • Oversee and coordinate containment, eradication, and recovery phases of security incidents.
  • Develop and implement incident response playbooks, ensuring SANRAL can respond quickly and effectively to different types of threats.
  • Lead the incident response team during critical security incidents, managing communication between stakeholders and security team.
 
Incident Investigation and Response:
  • Lead investigation of the root cause of security incidents, performing post-incident analyses to identify gaps and areas for improvement.
  • Coordinate with forensic investigators to collect and analyse digital evidence and ensure proper chain-of-custody procedures are followed.
  • Develop and maintain the SANRAL’s incident response plan (IRP), ensuring it aligns with industry standards and regulatory requirements.
  • Conduct regular tabletop exercises and simulations to test the effectiveness of the incident response plan and train staff on incident response procedures.
  • Work with other departments (e.g., IT, legal, compliance) to ensure that the incident response plan integrates seamlessly across the organization.
  • Lead post-incident reviews to identify gaps and implement improvements in processes, technologies, and training to prevent future incidents.
 
Reporting:
  • Prepare detailed incident reports and presentations for SANRAL’s senior management, outlining the impact, resolution, and next steps following an incident.
  • Provide regular updates on incident summaries, performance metrics, threat landscape insights, and compliance status to SANRAL’s leadership
 
 
EMPLOYMENT REFERENCE CHECKS:
Employment reference checks are a requirement as part of SANRAL’s recruitment and selection process. In order for SANRAL to conduct these checks a consent form needs to be completed and signed by the applicant. As an applicant of this position, you authorize SANRAL to process all the information provided for the purpose of your application for the position as well as the verification and record keeping of such credentials.
 
Please note that this is a confidential document and is intended for internal use by SANRAL’s Human resources department only.
 
EMPLOYMENT EQUITY:
  • Appointments will be made in accordance with SANRAL’s Employment Equity plan.
  • SANRAL reserves the right not to fill any position.
 
Closing date for applications: 05 August 2025
 
Link to apply for this position: https://career2.successfactors.eu/sfcareer/jobreqcareer?jobId=2745&company=southafr02
 
Employment Permanent
Location SANRAL COC Offices, 36 Assegai Wood Road Rooihuiskraal, Centurion 0157
Closing Date 05/08/2025
 
 
 
 
 
 






​MANAGER: SECURITY AND NETWORK MONITORING  NATIONAL

Permanent
 
Description
 
POSITION OBJECTIVE:
The Manager: Security and Network Monitoring will be responsible for monitoring, analysing, and responding to cybersecurity threats and incidents within SANRAL. This role will also involve protecting the organization's assets including intellectual property, personnel data, business systems, and brand integrity The role is a crucial component of a comprehensive cybersecurity strategy, providing SANRAL with a proactive and reactive defense against cyber-attacks and threats.
 
MINIMUM REQUIREMENTS:
  • NQF Level 7 Bachelor’s degree, Advanced Diploma or equivalent in Information Technology
  • Industry certifications: CISSP, CISM, or CISA, are compulsory
  • 5 years min relevant experience
  • 3 years min supervisory experience
 
WORKPLACE COMPETENCIES:
  • Knowledge of information security management frameworks, such as ISO/IEC 27001, and NIST. and security services (firewalls, proxy’s, DNS, Mail relays etc.)
  • A strong understanding of cybersecurity principles, threat landscapes, and security technologies.
  • Extensive experience working with SIEM, Log Aggregators, Incident Response Management solutions.
  • Strong technical knowledge of Networking, Operating Systems and enterprise integrations.
  • Experience managing standards, developing Security Operations Process.
  • Understanding of risk assessment and mitigation strategies.
  • Attention to Detail: Reviewing logs, analyzing patterns, and documenting incident responses. Ensure that no potential threat is missed and that all necessary steps are taken to mitigate risks.
  • Software Development Lifecycle: Act as a bridge between development and security, providing guidance, overseeing security controls, and responding to incidents that may arise during development or after deployment.
  • Demand Management: Able to understand, anticipate, and manage the demand for security and network monitoring services and resources within SANRAL.
  • Leadership skills: Ability to analyse security incidents, identify root causes, and implement solutions. Knowledge of cybersecurity technologies, threat landscapes, and incident response protocols.
  • Relationship Building and Influence: Ability to build work relationships with stakeholders and drive outcomes and decisions.
  • Business Needs Analysis: Ability to assess business imperatives and goals, and articulate them as per the Information Technology needs.
  • Communication skills.
  • Project management skills to organize, drive, and execute initiatives.
  • Experience in supporting supplier security activities to ensure third‐party systems meet SANRAL's security standards.
 
KEY RESPONSIBILITIES:
 
Management:
  • Effective management of the Security and Network monitoring team, ensuring the organization's security posture, and reporting on security operations to senior management.
  • Manage ongoing information and cyber security threat monitoring and regularly analyse security risks through qualitative risk analysis to ensure compliance with security governance.
  • Manage the team's day-to-day operations, developing and implementing security procedures, coordinating incident response efforts, and ensuring compliance with regulatory requirements.
 
Operational:
  • Lead Investigation of security incidents, identify threats, and determine the root causes of vulnerabilities.
  • Identify and analyse potential threats and vulnerabilities, proactively mitigating risks.
  • Manage security incidents, ensuring the appropriate process is followed from start to finish.
  • Familiar with fundamentals of attack frameworks such as Mitre, Lock Head kill-chain, etc.
  • Responsible for selecting, implementing, and managing threat intelligence platforms, ensuring the team has the necessary tools to detect, analyze, and respond to security incidents.
  • Set up and manage security monitoring and detection systems to identify suspicious activities and potential threats.
  • Lead the process to continually identify, assess, report on, manage and remediate vulnerabilities across endpoints, workloads and systems.
  • Oversee the collection, analysis, and response to security alerts and events to ensure the protection of an SANRAL's assets and information.
  • Define security monitoring policies, procedures, and guidelines for monitoring and detecting security threats.
  • Overseeing the deployment, configuration, and maintenance of security monitoring tools, such as security information and event management (SIEM).
  • Continuously research and evaluate new security technologies, tools, and methodologies to enhance the organization's security posture.
 
Reporting:
  • Provide regular updates on incident summaries, performance metrics, threat landscape insights, and compliance status to SANRAL’s leadership.
  • Develop dashboards and visualizations to provide an overview of the function's performance and security posture, allowing for quick identification of areas of concern.
 
 
EMPLOYMENT REFERENCE CHECKS:
Employment reference checks are a requirement as part of SANRAL’s recruitment and selection process. In order for SANRAL to conduct these checks a consent form needs to be completed and signed by the applicant. As an applicant of this position, you authorize SANRAL to process all the information provided for the purpose of your application for the position as well as the verification and record keeping of such credentials.
 
Please note that this is a confidential document and is intended for internal use by SANRAL’s Human resources department only.
 
EMPLOYMENT EQUITY:
  • Appointments will be made in accordance with SANRAL’s Employment Equity plan.
  • SANRAL reserves the right not to fill any position.
 
Closing date for applications: 05 August 2025
 
Link to apply for this position: https://career2.successfactors.eu/sfcareer/jobreqcareer?jobId=2746&company=southafr02
 
Employment Permanent
Location SANRAL COC Offices, 36 Assegai Wood Road Rooihuiskraal, Centurion 0157
Closing Date 05/08/2025










​SENIOR MANAGER: INFORMATION AND CYBER SECURITY INTELLIGENCE

National
Permanent
 
Description
POSITION OBJECTIVE:
The Senior Manager of Information and Cyber Security will lead and manage the implementation of SANRAL's cybersecurity strategy and program, focusing on security architecture and operations. This includes, but not limited management of data, network, endpoint and identity and access security operations to ensure the confidentiality, integrity, and availability of SANRAL’s data and systems by implementing and maintaining robust security controls.
 
MINIMUM REQUIREMENTS:
  • NQF Level 7 Bachelor’s degree, Advanced Diploma or equivalent in Information Technology.
  • Advanced certifications such as CISSP or equivalent.
  • 10 years min relevant experience.
  • 5 years managerial experience.
 
WORKPLACE COMPETENCIES:
  • Ability to monitor all information and cyber security operations and infrastructure.
  • Proficiency in the maintenance of all security tools and technology.
  • Monitor regulation compliance requirement and ensure compliance.
  • Ability to work with different departments in the organization to reduce information and cyber security related risk.
  • Ability to ensure that cybersecurity stays on SANRAL’s radar.
  • Project management skills to organize, drive, and execute initiatives
  • Experience in supporting supplier security activities to ensure third‐party systems meets SANRAL's security standards
  • Attention to Detail: Thorough scrutiny of systems, data, and processes to identify vulnerabilities, anomalies, and potential threats.
  • Software Development Lifecycle: Act as a bridge between development and security, providing guidance, overseeing security controls, and responding to incidents that may arise during development or after deployment.
  • Demand Management: Able to prioritize tasks. Able to understand, anticipate, and manage the demand.
  • Technology Trends: Should lead the team in staying ahead of emerging threats and technologies like AI, ML, and cloud security.
  • Proficiency in the following: Security Architecture, Endpoint Protection, IDS/IPS, Full Packet Capture, Network security, Identity and Access Management, etc.
  • Demonstrable experience in securing and knowledge of mobile technology and operating systems (i.e., Android, iOS, Windows).
  • Hands-on experience and proficiency in Information and Cyber Security operations management.
  • Knowledge of Data Loss Prevention, Data Replication, and Disaster Recovery Systems.
  • A deep understanding of Technology Security risks and mitigating solutions.
 
KEY RESPONSIBILITIES:
Management:
  • Lead complex projects in a matrixed, multi-stakeholder environment.
  • Vendor and contract security negotiations.
  • Project and resource management.
  • Report writing and dashboard presentation.
  • Ability to provide input in the development of the cyber security strategies, aligned with organizational goals.
  • Manage and develop subordinates.
  • Performance management.
  • Training and development.
  • Employee relations.
  • Recruitment.
  • Leave management.
  • Strong knowledge and implementation of security frameworks (e.g. NIST, ISO/IEC 27001).
  • Knowledge of legal, regulatory, and privacy requirements.
  • Strong knowledge and experience with defining and implementing ICT security controls.
  • Provide guidance to and monitor the IT security operations teams regarding patching and antivirus practices, particularly the response to zero-day threats.
  • Develop security policies, procedures, processes and frameworks following industry trends.
 
Reporting:
Prepare detailed information and cyber security operations reports and presentations for SANRAL’s senior management.
 
Micro Planning Cycle:
  • Information and Cybersecurity Program Management & Project Planning (Quarterly/Monthly): Break down SANRAL’s strategic initiatives into actionable projects and manage their execution.
  • Operational Security Management (Daily/Weekly): Oversee the day-to-day operations of security functions (e.g. Security Operations Center (SOC).
  • Oversight: Ensure effective threat monitoring, detection, and alerting. Review SOC performance metrics).
  • Threat & Vulnerability Management (Continuous/Weekly): Proactively identify and address emerging cyber security threats and vulnerabilities.
  • Compliance & Audit Management (Quarterly/Ad-hoc): Ensure ongoing adherence to regulatory requirements and internal policies, and prepare for audits.
 
Macro Planning:
  • Organisational & Business Context Alignment (Annual) – Understand SANRAL’s business strategy, critical assets, digital transformation initiatives, and risk tolerance to ensure security efforts support organizational goals.
  • Threat Landscape Assessment – Conduct annual threat assessments to understand the global, regional (including specific threats relevant to South Africa/Africa), and industry-specific threat landscape.
  • Cyber Security Threat Management Gap Analysis - Identify the most significant cyber risks to the organization based on the threat landscape and current security posture.
 
 
EMPLOYMENT REFERENCE CHECKS:
Employment reference checks are a requirement as part of SANRAL’s recruitment and selection process. In order for SANRAL to conduct these checks a consent form needs to be completed and signed by the applicant. As an applicant of this position, you authorize SANRAL to process all the information provided for the purpose of your application for the position as well as the verification and record keeping of such credentials.
 
Please note that this is a confidential document and is intended for internal use by SANRAL’s Human resources department only.
 
EMPLOYMENT EQUITY:
  • Appointments will be made in accordance with SANRAL’s Employment Equity plan.
  • SANRAL reserves the right not to fill any position
 
Closing date for applications: 05 August 2025
 
Link to apply for this position: https://career2.successfactors.eu/sfcareer/jobreqcareer?jobId=2743&company=southafr02
 
Employment Permanent
Location SANRAL COC Offices, 36 Assegai Wood Road Rooihuiskraal, Centurion 0157
Closing Date 05/08/2025











​SENIOR MANAGER: IT GOVERNANCE, RISK AND AUDIT

National
Permanent
 
Description
POSITION OBJECTIVE:
The Senior Manager: IT Governance, Risk and Audit will be responsible for overseeing and ensuring that SANRAL's ICT operations align with business objectives, regulatory requirements, and industry best practices. This role involves developing and implementing IT governance frameworks, risk management strategies, and internal audit programs to protect assets and maintain integrity. The Senior Manager will also be expected to contribute to the development of the internal audit strategy and annual assurance plan. Build and maintain relationships with the allocated portfolio of business units and other assurance providers as well as attend and present at selected governance committee meetings.
 
MINIMUM REQUIREMENTS:
  • NQF Level 7 Bachelor’s degree, Advanced Diploma or equivalent in Information Technology.
  • Certificate in CISA, CRISC, CISM, CGEIT or COBIT.
  • 10 years min relevant experience.
  • 5 years managerial experience in IT GRC.
 
WORKPLACE COMPETENCIES:
  • Strong leadership, communication, and stakeholder management skills.
  • Expertise in IT governance frameworks, risk management, and compliance requirements.
  • Good knowledge of Information Security standards and principles (e.g. ISO 27001).
  • Experience in facilitating compliance audits / internal self-assessments.
  • Strong planning, organizing, coordinating and work management skills.
  • Diligence in developing and maintaining governance documentation, conducting thorough risk assessments, and ensuring accurate reporting.
  • Software Development Lifecycle: Act as a bridge between development and security, providing guidance, overseeing security controls, and responding to IT GRC issues.
  • Demand Management.
  • Technology Trends: Play a crucial role in aligning IT with business objectives, managing risks, and ensuring compliance with regulations.
  • Project management skills to organize, drive, and execute initiatives
  • Experience in continuously improving IT GRC processes and practices to adapt to changing business needs and emerging risks.
  • Leadership skills
  • Customer Focus
  • Business Needs Analysis
  • Relationship Building and Influence
  • Communication skills
 
KEY RESPONSIBILITIES:
 
Management:
  • Oversee the development, implementation, and management of an organization's IT GRC program.
  • Establish IT governance frameworks.
  • Identify and mitigate IT risks.
  • Ensuring compliance with relevant regulations and policies.
  • Lead and mentor a team of GRC professionals, fostering a culture of accountability and continuous improvement.
 
IT Governance:
  • Work closely with the IT team to develop and implement organization-wide IT policies, processes and procedures.
  • Assist in the review of IT management processes (and decisions) and confirm that they are compliant with the organisation's strategy for corporate governance of IT.
  • Assist with establishing policy and standards for compliance with relevant global legislation relating to IT Governance, Privacy laws, data integrity, PCI-DSS, and other applicable laws.
  • Act as the Subject Matter Expert for line managers and employees on matters relating to IT Governance.
  • Research and keep up to date with international best practice in IT governance.
  • Create IT RACI charts to clearly outline the responsibilities for managing the supply and demand aspects of IT.
  • Perform regular IT Governance Maturity Assessments and implement improvement plans.
  • Develop training plans to embed the IT Governance Programme.
 
IT Risk Management:
  • Oversee the implementation of organisation-wide processes and procedures, tools and techniques for the identification, assessment, and management of IT risk inherent in the operation of business processes and of potential risks arising from planned changes – including technology upgrades.
  • Monitor the implementation and maintenance of IT risk self-assessment programs across the organization.
  • Work closely with the IT department management to ensure that IT risks are communicated and mitigated.
  • Pro-actively manage and mitigate all potential IT Risks to the organization, in association with Senior Manager and team members.
  • Perform third-party IT supplier risk assessments to ensure supply chain risk is managed throughout the supplier's lifecycle.
 
IT Audit Management:
  • Develop and execute IT annual audit plans based on organisational priorities and risk assessments.
  • Identify audit objectives, scope, and methodologies for each engagement in collaboration with the internal\external audit team.
  • Communicate audit findings and recommendations to relevant stakeholders.
  • Prepare clear and concise audit responses in collaboration with senior management.
 
IT Compliance Management:
  • Develop, enhance and maintain compliance, best practice and legislative requirements.
  • Prepare and submit reports showcasing compliance with regulatory requirements, industry standards and internal policies.
 
Reporting:
  • Prepare and submit reports showcasing compliance with regulatory requirements, industry standards and internal policies.
  • Prepare reports for relevant governance committees.
  • Compile, deliver and communicate ICT performance and status updates to key stakeholders including executive leadership.
  • Continuously evaluate and improve ICT reporting processes and reports to deliver more valuable insights and recommendations.
  • Establish robust reporting mechanisms for tracking IT performance metrics, cybersecurity incidents, and regulatory compliance, promoting transparency and accountability.
 
 
EMPLOYMENT REFERENCE CHECKS:
Employment reference checks are a requirement as part of SANRAL’s recruitment and selection process. In order for SANRAL to conduct these checks a consent form needs to be completed and signed by the applicant. As an applicant of this position, you authorize SANRAL to process all the information provided for the purpose of your application for the position as well as the verification and record keeping of such credentials.
Please note that this is a confidential document and is intended for internal use by SANRAL’s Human resources department only.
 
EMPLOYMENT EQUITY:
  • Appointments will be made in accordance with SANRAL’s Employment Equity plan.
  • SANRAL reserves the right not to fill any position.
 
Closing date for applications: 5 August 2025
 
Link to apply for this position: https://career2.successfactors.eu/sfcareer/jobreqcareer?jobId=2744&company=southafr02
 
Employment Permanent
Location SANRAL COC Offices, 36 Assegai Wood Road Rooihuiskraal, Centurion 0157
Closing Date 05/08/2025