PermanentIT & Software

Manager: Cyber Security Operations Centre (CSOC) at The South African Revenue Service (SARS)

Manager

Contract
Permanent
Minimum qualification
Diploma
Closing date

First listed . Last checked at source .

In brief

**Overview** This role is for a Manager of the Cyber Security Operations Centre (CSOC) at The South African Revenue Service (SARS). SARS is the national tax collecting authority, established as an autonomous agency responsible for administering the South African tax system and customs service, including collecting national taxes, duties, and levies. The primary purpose of this position is to lead and manage the CSOC and User Access Management (UAM) functions. This involves ensuring effective monitoring, detection, investigation, and response to cyber threats, while also strengthening identity and access management, operational resilience, and the overall protection of SARS's information assets, systems, and services. **What you will do** As the Manager: Cyber Security Operations Centre (CSOC), you will be responsible for: * Leading and managing the CSOC and User Access Management (UAM) functions. * Ensuring effective monitoring, detection, investigation, and response to cyber threats. * Strengthening identity and access management, operational resilience, and the protection of SARS information assets, systems, and services. * Driving tactical implementation for business unit excellence and performance improvement. * Directing, controlling, coordinating, and optimising budgeted resources. * Developing and implementing practices aligned with operational policy and procedural frameworks. * Implementing tactical strategy and delivery plans to achieve operational targets. * Converting approved tactical security strategies into measurable operational plans with defined deliverables, performance measures, priorities, and resource requirements. * Planning work outputs, integrating interdependent activities, and specifying priorities, standards, and procedures. * Providing periodic performance reports and realigning tactical plans as needed. * Recommending and executing changes to optimise processes, systems, policies, and procedures. * Communicating policy modifications, objective progress, and critical success factors to stakeholders. * Utilising insights from integrated business reports to measure success and realign tactical strategy. * Planning and managing projects within your area of accountability. * Providing integrated oversight and operational management of SOC and UAM functions. * Monitoring the effectiveness of security controls, operational performance, service delivery, risks, and compliance, implementing corrective actions for deficiencies. * Providing technical direction for the development, design, and integration of systems to prevent the loss of SARS assets. * Liaising with vendors to resolve product and service level issues. * Implementing governance, risk, and compliance policies and managing related exposure liability. * Managing and advising on the translation and application of policy within the functional area. * Complying with organisational internal control and governance standards in finance and procurement. * Developing and implementing appropriate people capacity plans in line with delivery and efficiency targets. * Identifying and addressing development requirements for staff and providing necessary tools. * Translating performance expectations into specific metrics and goals. * Ensuring compliance with health, safety, security, and workplace policies within the CSOC environment. * Drawing up and monitoring budgets, minimising expenditure, and reporting on cost efficiency. * Implementing and monitoring financial control, cost management, and corporate governance. * Building strong relationships and implementing service level agreements with internal and external stakeholders. * Developing and ensuring the implementation of practices that build service delivery excellence. * Managing an integrated service excellence culture that encourages feedback and exceptional service. **Requirements (from the original advert)** * **Job Type**: Full Time * **Qualification**: Bachelors, Matric, Postgraduate Diploma * **Experience**: 8 - 15 years * **Location**: Gauteng * **City**: Pretoria * **Job Field**: ICT / Computer **Minimum Qualification & Experience Required**: * Bachelor's Degree / Advanced Diploma (NQF 7) in Information Security AND 8-10 years' experience in an Information Technology Security role, of which 3-4 years at a junior management level, AND a recognised professional certification in Information Security Management, such as Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP), or an equivalent recognised certification. **Alternative #**: * Senior Certificate (NQF 4) AND 15 years Information Technology Security experience, of which 3-4 years at a junior management level, AND a recognised professional certification in Information Security Management, such as Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP), or an equivalent recognised certification. **Who should apply** This role is suitable for a highly experienced and certified IT Security professional with a proven track record in leadership and management within a Cyber Security Operations Centre (CSOC) and User Access Management (UAM) context. The ideal candidate will possess strong technical expertise in cyber threat detection, investigation, and response, coupled with strategic planning and tactical implementation skills. They should be adept at managing resources, projects, and budgets, ensuring compliance with governance and risk frameworks, and fostering a culture of service excellence. Candidates must meet the specific educational and experience requirements, including significant IT security experience and relevant professional certifications like CISM or CISSP. **Deadline** 11th October, 2026 **Reference** Original posting: https://www.myjobmag.co.za/job/manager-cyber-security-operations-centre-csoc-the-south-african-revenue-service-sars Source: myjobmag

Summary drafted with AI assistance from the original advert. The advert itself is the authority — how we use AI.

At a glance

  • At least 8 years of experience.

Extracted automatically from the advert; confirm requirements on the original listing.

Job description

- The South African Revenue Service (SARS) is the nations tax collecting authority. Established in terms of the South African Revenue Service Act 34 of 1997 as an autonomous agency, we are responsible for administering the South African tax system and customs service. Its main functions are to: collect and administer all national taxes, duties and levies; c... Manager: Cyber Security Operations Centre (CSOC) ------------------------------------------------ * Job Type Full Time * Qualification Bachelors , Matric , Postgraduate Diploma * Experience 8 - 15 years * Location Gauteng * City Pretoria * Job Field ICT / Computer Job Purpose * To lead and manage the Cyber Security Operations Centre (CSOC) and User Access Management (UAM) functions, ensuring the effective monitoring, detection, investigation and response to cyber threats, while strengthening identity and access management, operational resilience and the protection of SARS information assets, systems and services. Education and Experience Minimum Qualification & Experience Required * Bachelor's Degree / Advanced Diploma (NQF 7) Information Security AND 8-10 years' experience in an Information Technology Security, of which 3-4 years at a junior management level, as well as a recognised professional certification in Information Security Management, such as Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP), or an equivalent recognised certification. Alternative # * Senior Certificate (NQF 4) AND 15 years Information Technology Security experience, of which 3 - 4 years at a junior management level, , as well as a recognised professional certification in Information Security Management, such as Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP), or an equivalent recognised certification. Job Outputs: Process * Act as the bottom-line drivers of tactical implementation within the context of business unit excellence and performance improvement. * Direct, control, coordinate and optimise budgeted resources to meet specific objectives and deliver agreed results and productivity requirements. * Ensure the development and implementation of a practice in alignment with operational policy and procedural frameworks. * Implement tactical strategy and delivery plans through the development of operational activities, ensuring the achievement of operational targets. * Convert the approved tactical security strategy into a measurable operational plan, defining deliverables, performance measures, priorities and resource requirements. * Plan for handling work outputs, pull together interdependent activities and specify priorities, standards and procedures to ensure tactical implementation. * Provide periodic reports on performance against plan & progress on short-term initiatives & use to realign tactical plan and objectives appropriately. * Recommend changes to optimise processes, systems, policies and procedures, and execute the implementation of change and innovation initiated by the organisation. * Timeously communicate top-down policy modification, objective achievement progress and critical success factors to impacted stakeholders. * Use the insights gained through integrated business reports to measure success and realign tactical strategy implementation objectives appropriately. * Plan and manage projects in area of accountability. * Provide integrated oversight and operational management of Security Operations Centre (SOC) and User Access Management functions to ensure effective protection of SARS information assets and services. * Monitor the effectiveness of security controls, operational performance, service delivery standards, risks and compliance requirements, and implement corrective actions where deficiencies are identified. * Provide technical direction for the development, design and integration of systems to prevent the loss of SARS assets. * Liaise with vendors to get product and service level issues resolved. Governance * Implement governance, risk and compliance policy in own practice area to identify and manage governance and risk exposure liability. * Manage and or advise on the translation and application of policy in a specific functional area. * Comply with organisational internal control and governance standards in finance and procurement processes. People * Develop and implement appropriate people capacity plans in line with delivery and efficiency targets, on budget and in partnership with specialised area. * Plan and implement enhanced organisational efficiency by identifying and addressing development requirements and providing tools for people resources. * Translate performance expectations into specific metrics and goals to identify and provide effective services, solve problems and achieve objectives. * Ensure compliance with applicable health, safety, security and workplace policies within the Cyber Security Operations Centre environment Finance * Draw up a budget aligned to tactical delivery plans, monitor planned vs. actual, minimise expenditure and report on cost efficiency. * Implement and monitor financial control, management of costs and corporate governance in area of accountability. Client * Build strong relationships and implement service level agreements that promote SARS with internal and external stakeholders. * Develop and ensure implementation of practices which builds service delivery excellence and encourage others to provide exceptional client service. * Manage an integrated service excellence culture, which builds rewarding relationships and provides opportunity for feedback and exceptional service Deadline:11th October,2026 Check how your CV matches this job Method of Application ------------------------- Interested and qualified? Go to The South African Revenue Service (SARS) on career2.successfactors.eu to apply Build your CV for free. Download in different templates.

Before you apply

  • Confirm the requirements and closing date on the original listing (myjobmag). SPANi lists vacancies from other sites and may not reflect last-minute changes.
  • Legitimate employers do not charge application, registration or training fees.
  • Don't send your ID or bank details before you have confirmed the employer is real.

How to spot a job scam

Applying for permanent roles

  • Mirror the job title and top three requirements in your CV summary and most recent experience.
  • Quantify results where possible: sales targets, cases handled, tickets closed, or team size.
  • Proofread contact details and filenames before submitting — small errors cost interviews.
  • Verify the company and role on the source page before sharing ID copies or banking details.

Similar roles