weebly statistics
Published on
Image description

 

 

BORDER MANAGEMENT AUTHORITY (BMA)

 

 

SPECIALIST: ICT, RISK AND COMPLIANCE
Centurion

Job Reference Number: BMA-213
Department: Information Communication and Technology - Strategy and governance
Business Unit:
Industry: Admin/Office Support
Job Type: Permanent
Positions Available: 1
Salary: R1 074 389,53 - R1 210 428,88

 

The BMA is established as an armed service in terms of Section 199(3) of the constitution, a third in the country in addition to the South African National Defence Force (SANDF) and the South African Police Service (SAPS) through the Border Management Authority Act No 2 of 2020. The Border Management Authority invites suitable candidates to apply for the following vacant position.

 

Job Description

The successful candidate will be expected to perform the following duties and responsibilities:

ICT Assurance and Compliance Monitoring.

  • Coordinate ICT internal and external audits.
  • Coordinate audit management responses and evidence submissions.
  • Monitor implementation of ICT audit recommendations and corrective actions.
  • Conduct compliance reviews against approved ICT policies, standards and procedures, excluding specialist identity, endpoint and third-party assurance reviews covered under separate KPAs.
  • Report audit and compliance trends, control weaknesses and remediation status to management.

ICT Governance Framework

  • Develop, implement and maintain ICT governance frameworks to support effective ICT oversight and decision-making.
  • Develop, review and maintain ICT security policies, standards, procedures and guidelines.
  • Maintain the ICT policy and governance artefact register in line with approved review cycles.
  • Ensure ICT governance alignment with the Corporate Governance of ICT Policy Framework (CGICTPF) and relevant standards.
  • Advise stakeholders on governance requirements for embedding ICT controls into business processes.

Third-party risk and assurance

  • Review third-party ICT security assurances during onboarding, contract renewal or material service changes.
  • Coordinate supplier ICT security, privacy and compliance reviews.
  • Track third-party ICT risk issues, control gaps and supplier remediation actions.
  • Monitor applicable ICT security SLA and assurance obligations related to suppliers.

ICT Risk Management.

  • Develop and maintain the ICT risk management process and ICT risk register.
  • Facilitate ICT risk assessments across relevant ICT domains and initiatives.
  • Develop and coordinate risk mitigation strategies and treatment plans for identified ICT risks.
  • Monitor implementation of ICT risk treatment actions and escalate overdue or high-risk items.
  • Support enterprise risk reporting by providing ICT risk inputs and status updates.

ICT Security, Identity and Endpoint Control Monitoring

  • Support the monitoring of identity and access management controls, including user access reviews, privileged access and account lifecycle processes.
  • Coordinate basic endpoint security compliance checks against approved ICT security standards and baseline requirements. 
  • Track and report exceptions relating to access control, endpoint protection, patching, malware protection and device configuration compliance.
  • Escalate identified ICT security control weaknesses for remediation and management reporting.

ICT Governance Stakeholder Engagement and Reporting

  • Coordinate and consolidate ICT governance, risk, compliance and security inputs for management and governance structures.
  • Coordinate submission of ICT Steering Committee, Internal Audit Committee and Audit and Risk
  • Committee reports.
  • Facilitate stakeholder engagements on ICT governance, risk, compliance and security matters.
  • Track committee decisions, stakeholder inputs and cross-functional commitments until closure.
  • Maintain consistent stakeholder communication on ICT governance matters without duplicating technical ownership assigned to other KPAs.

 

Job Requirements

Minimum Requirements

Minimum Qualifications:

  • Grade 12 (Matric)
  • Undergraduate qualification at NQF 7 as recognised by SAQA in
    Computer Science, Information Technology, Information Security or equivalent.
  • Certified Information Systems Auditor (CISA) certification is advantageous.

Minimum Experience

  • 5 years relevant work experience in ICT Governance, Risk and Compliance, or IT Security

 

Knowledge

  • ISO/IEC 27001, ISO/IEC 27002, ISO 31000
  • COBIT, ITIL
  • Corporate Governance of ICT Policy Framework
  • ICT Governance structures
  • Minimum Information Security Standards (MISS)
  • Enterprise-wide Risk Management
  • Information Technology Policies
  • Policy Development
  • IT Risk Management
  • IT Governance

 

Other requirements:

  • Flexibility in working hours will be required to meet demands of the role.
  • May be required to work overtime.
  • Valid driver’s License

The BMA is an equal opportunity employer committed to employment equity and workforce diversity. Preference may be given to suitably qualified candidates from designated groups in line with the BMA employment equity plan. The BMA reserves the right not to make an appointment to the advertised positions.

  • It is the applicant’s responsibility to have all foreign qualifications evaluated by South African Qualification Authority (SAQA) and to confirm the appropriate NQF level and to provide proof of such evaluation report.
  • Shortlisted candidates may be subjected to an interview and technical assessment(s) (which assesses the candidate's demonstrated professional and technical competency against the job requirements and duties).
  • Candidates potentially considered suitable after the interview and technical test(s) for senior positions, will be subjected to a competency assessment (which tests the candidate's demonstrated proficiency in the professional dimensions attached to the level of the post);
  • Employment suitability checks will be conducted on the shortlisted candidates (credit, criminal, citizenship, employment references and qualification verifications);
  • Appointments will be subjected to a mandatory vetting/security clearance appropriate to the level of the position.

 

Closing date:  21 October 2026

 

CLICK TO APPLY

 

 

 

 

 

 

 

 

 

 

SPECIALIST: CYBER SECURITY
Centurion

Job Reference Number: BMA-212
Department: Information Communication and Technology - Strategy and governance
Business Unit:
Industry: Admin/Office Support
Job Type: Permanent
Positions Available: 1
Salary: R1 178 293,60 - R1 392 528,80

 

The BMA is established as an armed service in terms of Section 199(3) of the constitution, a third in the country in addition to the South African National Defence Force (SANDF) and the South African Police Service (SAPS) through the Border Management Authority Act No 2 of 2020. The Border Management Authority invites suitable candidates to apply for the following vacant position.

 

Job Description

The successful candidate will be expected to perform the following duties and responsibilities:

Cybersecurity Operations

  • Develop, implement and continuously improve the BMA’s cybersecurity operations capability to protect information assets, systems, networks, cloud platforms and digital services against cyber threats.
  • Administer, monitor and optimise operational cybersecurity technologies, including endpoint security, email security, network security, cloud security and related technical symbols.
  • Implement and maintain security configuration baselines, technical hardening standards and secure configuration requirements across ICT infrastructure, operating systems, cloud platforms and business applications.
  • Review cybersecurity configurations for new systems, infrastructure changes and technology implementations to ensure alignment with approved security standards and organisational requirements.
  • Develop and maintain cybersecurity operational procedures, technical standards, implementation guides and supporting documentation.
  • Provide specialist cybersecurity guidance to ICT teams, business units and project teams on operational security risks, controls and mitigation measures.
  • Coordinate vulnerability remediation with ICT infrastructure, application and service owners to ensure identified weaknesses are addressed within agreed risk-based timeframes.
  • Review security logs, alerts and configuration reports from operational cybersecurity tools to identify control failures, misconfigurations and areas requiring corrective action.
  • Support patch management and secure maintenance activities by validating that critical systems, endpoints and security technologies are updated in line with approved security requirements.

Identity and Access Security

  • Develop, implement and continuously improve the organisation’s Identity and Access Management capability to ensure secure, appropriate and auditable access to systems, applications and ICT resources. 
  • Design, implement and maintain identity and access security controls, including authentication, authorisation, multi-factor authentication, role-based access control, privileged access management and adaptive access controls.
  • Implement and maintain Identity Governance and Administration processes for the provisioning, modification, recertification and de-provisioning of user, privileged, service and third-party accounts.
  • Administer enterprise identity services, directory services, authentication mechanisms and access control technologies in line with approved security standards.
  • Monitor identity-related security events, authentication risks and anomalous access activities, and initiate appropriate technical responses where required.
  • Provide specialist advice on identity architecture, authentication mechanisms and access control requirements for new ICT solutions, projects and technology implementations.
  • Maintain technical documentation, operational procedures and standards relating to identity and access security technologies.

Threat Detection, Incident Response and Cyber Resilience

  • Develop, implement and continuously improve the organisation’s cybersecurity monitoring and incident response capability to enable timely detection, analysis, containment, eradication and recovery from cybersecurity threats and incidents.
  • Monitor the organisation’s ICT environment for cybersecurity threats, malicious activity and indicators of compromise using approved security monitoring technologies and threat intelligence sources.
  • Coordinate and manage cybersecurity incidents throughout the incident lifecycle, ensuring incidents are classified, prioritised, investigated, contained, resolved, documented and formally closed.
  • Conduct technical investigations into cybersecurity incidents, analyse root causes and recommend corrective and preventive actions to minimise recurrence.
  • Coordinate or support digital forensic investigations and ensure digital evidence is preserved, collected and handled in accordance with approved procedures and legal requirements.
  • Develop, maintain and periodically review the Cybersecurity Incident Response Plan, incident response playbooks, escalation procedures and communication protocols.
  • Coordinate and participate in cybersecurity incident simulations, tabletop exercises and cyber resilience testing to validate organisational preparedness.
  • Support cyber recovery and ICT disaster recovery planning, testing and improvement in collaboration with ICT infrastructure, business continuity and disaster recovery stakeholders.
  • Develop operational dashboards and management reports on cybersecurity incidents, threat trends, response performance and organisational cyber resilience.

Cybersecurity Programme Delivery 

  • Develop, implement, coordinate and monitor cybersecurity projects and initiatives that support the organisation’s cybersecurity strategy, ICT strategic objectives and digital transformation programme.
  • Provide specialist cybersecurity input into ICT projects, solution designs, technology acquisitions and procurement activities to ensure security requirements are embedded throughout the project lifecycle.
  • Develop cybersecurity technical specifications, standards and security requirements for ICT infrastructure, cloud services, applications, software, hardware and managed security services.
  • Evaluate cybersecurity technologies and solutions and provide recommendations on suitability, technical capability, security effectiveness, integration requirements and alignment with organisational needs.
  • Support cybersecurity procurement processes by reviewing technical proposals, validating compliance with security requirements and contributing to bid evaluation activities where required.
  • Manage cybersecurity vendors, managed security service providers and technology partners to ensure contracted services are delivered in accordance with agreed service levels, contractual obligations and organisational expectations.
  • Track cybersecurity programme risks, issues, dependencies, milestones and deliverables, and escalate matters requiring management intervention.
  • Develop, monitor and report cybersecurity Key Risk Indicators, Key Performance Indicators and operational metrics to provide management with insight into cybersecurity posture, service performance and emerging risks.

Stakeholder Management

  • Build and maintain effective working relationships with internal business units, ICT teams, governance structures, service providers and relevant external stakeholders to support the delivery of cybersecurity services and initiatives.
  • Provide specialist cybersecurity advice, technical guidance and recommendations to management, ICT teams, project teams and business stakeholders on cybersecurity risks, controls and mitigation measures.
  • Coordinate cybersecurity-related inputs, updates and follow-ups with stakeholders to support incident response, access security, operational control improvements and cybersecurity programme delivery.
  • Promote cybersecurity awareness, responsible technology use and a strong security culture through collaboration, communication and engagement with relevant stakeholders.

 

Job Requirements

MINIMUM REQUIREMENTS

Minimum Qualifications: 

  • Matric (Grade 12)
  • Undergraduate qualification at NQF 7 as recognised by SAQA in Computer Science, Information Technology or equivalent 
  • A recognised vendor-neutral entry-to-intermediate level cybersecurity certification, or equivalent, will be an added advantage, including ISO 27001, Security +, CySA +, etc

Minimum Experience:

  • 5 Years working experience within a Cyber/IT Security role.

 

Knowledge

  • Cybersecurity governance and strategy
    Identity and Access Management
  • Security Operations Centre
  • CIS Controls 
  • Zero trust principles 
  • ISO 27001 
  • Border Management Authority,2020

 

Other requirements

  • Flexibility in working hours will be required to meet demands of the role.
  • May be required to work overtime.
  • Valid driver’s License

The BMA is an equal opportunity employer committed to employment equity and workforce diversity. Preference may be given to suitably qualified candidates from designated groups in line with the BMA employment equity plan. The BMA reserves the right not to make an appointment to the advertised positions.

  • It is the applicant’s responsibility to have all foreign qualifications evaluated by South African Qualification Authority (SAQA) and to confirm the appropriate NQF level and to provide proof of such evaluation report.
  • Shortlisted candidates may be subjected to an interview and technical assessment(s) (which assesses the candidate's demonstrated professional and technical competency against the job requirements and duties).
  • Candidates potentially considered suitable after the interview and technical test(s) for senior positions, will be subjected to a competency assessment (which tests the candidate's demonstrated proficiency in the professional dimensions attached to the level of the post);
  • Employment suitability checks will be conducted on the shortlisted candidates (credit, criminal, citizenship, employment references and qualification verifications);
  • Appointments will be subjected to a mandatory vetting/security clearance appropriate to the level of the position.

 

Closing date:  21 October 2026

 

CLICK TO APPLY

 

 

 

 

JOIN OUR WHATSAPP CHANNEL

JOIN OUR TELEGRAM CHANNEL