About the Role
The Department of Basic Education is on the lookout for a skilled Deputy Director: Chief Information Security Officer to join its dedicated team in Pretoria. This pivotal role focuses on enhancing the department’s cybersecurity landscape, ensuring that all information technology assets are protected against ever-evolving threats. As a vital component of the public service, this position plays a crucial part in safeguarding sensitive educational data while complying with statutory and regulatory requirements.
By working in this role, you will directly contribute to the security and integrity of the Department of Basic Education’s infrastructure, which impacts schools and learners across South Africa. This is an opportunity to make a tangible difference in the community, ensuring that educational resources are secure and accessible.
About the Department
The Department of Basic Education is committed to ensuring that all South Africans receive quality education, which is fundamental for the nation’s development. The department oversees the implementation of education policies and programs, striving to improve learning outcomes for all learners. Working within this department means being part of a mission that shapes the future of education in South Africa and empowers the next generation.
What You’ll Do
- Design, configure, deploy, and maintain security controls to protect the department’s infrastructure.
- Actively safeguard the department’s IT assets from various threats, ensuring compliance with information security regulations.
- Analyze security challenges, recommending solutions and technologies to meet security objectives.
- Conduct security assessments for systems and applications, ensuring adherence to cybersecurity standards.
- Develop and implement a comprehensive cybersecurity strategy and framework.
- Lead the adoption of best practice network security controls across both cloud and on-premises environments.
- Manage data protection and encryption initiatives, including implementing software solutions for sensitive information.
- Support disaster response and recovery strategy development and implementation.
- Provide advanced incident response support for security breaches and manage third-party risk assessments.
- Train employees on information security best practices.
What You’ll Need
- NQF level 6 post-matric qualification in Information Technology/Information Systems or equivalent.
- A minimum of four years’ experience as an Assistant Director or similar role.
- At least two certifications in relevant fields such as ITIL, COBIT, CISA, CISM, CISSP, CRISC, or ISO 27001.
- Over five years of experience as a Chief Information Security Officer or Information Security Officer.
- Strong knowledge of network management and enterprise technology architecture.
- Familiarity with Microsoft environments, virtualized and cloud platforms.
- Understanding of business continuity management and the E-government strategy.
- Excellent analytical, problem-solving, and project management skills.
- A valid driver’s license is required.
How to Apply
Please refer to the application instructions below.
Looking for more South African government jobs? Browse the latest vacancies on JobsSouthAfrica.co.za. If you are applying for the first time, read our Complete Guide to Applying for Government Jobs in South Africa, covering the Z83 form, certified copies, CV format, interview tips and more.
Requirements
Applicants must be in possession of NQF level 6 post matric qualification in Information Technology/Information Systems or equivalent qualification as recognised by SAQA; Four (4) years relevant experience as an Assistant Director or equivalent; A minimum of two (2) certifications in any of the following: ITIL, COBIT, CISA, CISM, CISSP, CRISC, ISO 27001 plus a minimum of at least five (5) years’ experience as a Chief Information Security Officer/ Information Security Officer; Experience in managing networks; Sound knowledge of Enterprise or Technology architecture environment is required, strategic management, information and communication technology systems and processes; Sound knowledge of Microsoft environment, virtualised, cloud environments; Sound knowledge of business continuity management; Sound 6 knowledge of the E-government strategy and roadmap, interactive communication, problem solving and analytical thinking orientation, planning and organising skills, project management skills, strategic thinking; Understanding organisational information flows and maintaining an inventory of data; Understanding the data classification framework and implementing controls in accordance with the sensitivity levels; Vulnerability awareness through an understanding of the vulnerability Detection and management program; Patching and Remediation SLAs and Agreed-upon timelines for addressing security vulnerabilities; A valid driver's license.Job Duties
The successful candidate will be responsible for CyberSecurity Program: Designing, configuring, deploying, and maintaining security controls to safeguard the Department’s infrastructure; Actively protecting the Department’s information technology assets and infrastructure from external or internal threats and ensuring compliance with statutory and regulatory requirements regarding information access, security, and privacy; Analysing problems and recommending solutions, products and technologies to meet the Organisation’s security and information security objectives; Performing security assessments for all systems and applications and checking for compliance with cybersecurity standards and regulations in projects and new system design implementation; Developing and interpreting the cybersecurity strategy and framework; Interpreting cybersecurity maturity levels and implementing road maps; Leading the implementation of best practice network security controls across cloud environments and On-premises platforms to maintain resistance against cyberattacks; Focusing on the safe adoption of AI integration; Data protection and encryption: Ensuring sensitive information is identified and adequately protected; Developing or installing software, such as data-at-rest encryption programs and SSL certificates to protect sensitive information in transit and in use; Supporting the development of disaster response and recovery strategies and its implementation within the DBE; Troubleshooting security and network problems to maintain a fit-for-purpose DR site and business continuity plans; Network, web, and Endpoint Security and monitoring; Threat and Vulnerability Management: Leading threat landscape assessment and situational Cyber-attack; Ensuring vulnerability assessments and penetration tests are performed periodically; Analysing and interpreting vulnerability results and facilitating remediation of identified vulnerabilities at Protection and Response Maturity levels in conjunction with other business application owners; Providing reports to Senior Management on the vulnerability management program.Incident response and third-line support: Providing third-line support to any Information security-related queries; Overseeing and providing advanced incident response support for breaches, intrusions, or data theft; Performing Third-Party Risk Management: Effective monitoring of supplier security postures; Ensuring rapid recovery capabilities.
Delivering on Security Projects within budget; Training employees on Information Security.