Unlock the next level of your career with the Auditor-General of South Africa (AGSA) by stepping into the role of Specialist – IT Security Governance. This position offers a unique blend of challenges and opportunities for IT professionals passionate about safeguarding information systems and contributing to the integrity of public sector auditing.
About the Company
The Auditor-General of South Africa is the supreme audit institution of the country, tasked with auditing state expenditures and ensuring transparency, accountability, and effective use of public funds. AGSA is committed to promoting good governance and delivering insights that drive meaningful change.
IT Security Governance Job Overview
- Company: Auditor-General of South Africa (AGSA)
- Location: Gauteng, South Africa
- Job Title: Specialist – IT Security Governance
- Job ID: 4706
- Full/Part Time: Full-Time
- Closing Date: 24 February 2024
- Apply Online: IT Security Governance
Minimum Requirements:
Candidates aspiring to the role of Specialist – IT Security Governance at the Auditor-General of South Africa must embody a strong foundational knowledge in information technology and security governance, supported by formal education and specialized certifications. Specifically, applicants must possess:
- A Degree/Diploma (NQF 7) in Information Technology, Information Systems, Computer Science, or a closely related field. This foundational requirement ensures candidates have a solid understanding of the theoretical and practical aspects of IT and can apply these principles to real-world security governance challenges.
- Certifications in CISA (Certified Information Systems Auditor), CISM (Certified Information Security Manager), CRISC (Certified in Risk and Information Systems Control), or CISSP (Certified Information Systems Security Professional). These certifications are recognized globally and indicate a deep, specialized knowledge in IT security, risk management, and governance. They are critical for understanding complex security frameworks and for applying best practices in auditing and securing information systems.
- COBIT/ITIL Training. Knowledge of COBIT (Control Objectives for Information and Related Technologies) and ITIL (Information Technology Infrastructure Library) frameworks is essential for aligning IT security governance with overall business goals, managing IT risks effectively, and ensuring that IT processes support the strategic needs of the organization.
- A Postgraduate Qualification in IT is considered advantageous and signifies an advanced level of expertise and commitment to continuous learning in the rapidly evolving field of IT security.
- Candidates must bring at least 5 years’ experience in IT auditing or ICT security governance within a medium to large organization. This experience is critical in understanding the complexities and challenges of safeguarding information assets in large and diverse environments.
- At least 3 years of managing IT audit teams and working with COBIT processes are required. This management experience ensures candidates are capable of leading teams, directing audits, and applying COBIT frameworks to real-world IT governance issues.
- IT security management or auditing experience, particularly within a recognized security, audit, or risk consulting firm, offers a broad perspective on the variety of security challenges organizations face across different technologies and domains.
- A strong background in information technology, coupled with a clear understanding of the challenges of Information Security, enables candidates to approach IT governance with a strategic mindset, focused on risk mitigation, compliance, and aligning IT security practices with business objectives.
Key Responsibilities
This position encompasses a wide range of duties, from strategic functions to operational management, each critical to ensuring that AGSA’s IT infrastructure is secure, compliant, and aligned with both internal objectives and external regulatory requirements. Here’s a detailed breakdown:
- Develop IT Security Governance Frameworks: Spearhead the creation and refinement of frameworks and strategies that align with AGSA’s overarching goals, ensuring robust IT security governance that anticipates and mitigates emerging threats.
- Balance Score Card Initiatives: Actively support and contribute to the implementation of Balanced Scorecard initiatives, translating strategic objectives into actionable plans that drive performance and accountability across IT security governance.
- Leadership Support: Offer critical support to senior leadership by advising on service portfolio management and governance requirements, ensuring strategic alignment and operational efficiency.
- Vision and Strategy: Play a key role in shaping the IT security governance vision, driving the strategic direction, and ensuring its alignment with AGSA’s mission and objectives.
- Enterprise Security Strategy: Lead the development and implementation of an enterprise-wide information security strategy, establishing security technology standards, governance processes, and performance metrics.
- Framework Maintenance: Ensure the establishment and continuous improvement of an information security governance framework, alongside supporting processes that align the security strategy with organizational goals.
- Risk Assessment and Mitigation: Conduct comprehensive IT security reviews, develop mitigation plans for identified security gaps, and provide expert recommendations on governance tools and strategies.
- Vulnerability and Penetration Testing: Coordinate and execute thorough vulnerability assessments and penetration tests across diverse architectures and platforms to identify potential security weaknesses.
- Risk Analysis and Engagement: Engage in detailed risk analysis and security design reviews, applying appropriate policies and standards in line with AGSA’s risk appetite and legal requirements.
- ICT Risk Meetings: Lead discussions in ICT internal control meetings, focusing on the identification, escalation, and mitigation of emerging and existing risks, fostering a culture of continuous improvement in ICT risk management.
- Regulatory Compliance: Ensure adherence to regulatory and legislative requirements by conducting regular compliance assessments and managing compliance through international standards and best practices.
- Audit Finding Resolution: Review IT audit reports, follow up on audit findings, and facilitate the resolution of compliance exceptions, ensuring the timely rectification of security assessments’ findings.
- Training and Support: Provide essential training, coaching, and mentoring to empower the first line of defense, ensuring compliance with IT security policies through regular training and awareness campaigns.
- Risk Management Reporting: Keep track of risk management trends and opportunities, providing regular updates and reports to the leadership team to support the continuous improvement of ICT risk management and compliance services.
- Collaborative Relationships: Establish and maintain productive working relationships with both internal and external stakeholders, ensuring the effective delivery of IT security governance objectives and the successful implementation of the information management strategy.
- Performance Management: Manage personal performance, actively participate in transformation, culture, diversity, and employment equity initiatives, and commit to continuous learning to stay abreast of industry trends.
- Budget and Expenditure: Contribute to budget compilation, manage project expenditures related to IT security governance, and ensure compliance with AGSA’s governance processes and policies.
- Flexible Role Adaptation: Undertake additional projects, tasks, and assignments as delegated by the senior manager, demonstrating flexibility and adaptability in addressing the evolving needs of IT security governance.
How to Apply
- Required Documents: Comprehensive CV, Cover Letter, Certifications, and Academic Transcripts.
- Application Process: Submit your application through the AGSA careers portal, including all required documents and referencing the job title and ID.
Joining AGSA as a Specialist in IT Security Governance offers a promising path to professional growth and the opportunity to contribute significantly to the public sector’s transparency and accountability. We welcome dedicated professionals to apply and become part of our mission to ensure the secure and effective use of information technology in government auditing.