Senior Manager: Information Systems Audit (Cybersecurity)

Auditor-General of South Africa

Location
Pretoria, Gauteng
Minimum qualification
Bachelor's degree
Closing date

First listed . Last checked at source .

In brief

**Overview** This role is for a Senior Manager specializing in Information Systems Audit, with a strong focus on Cybersecurity, at the Auditor-General of South Africa (AGSA). The position involves providing strategic input, leading and managing cybersecurity audits, driving innovation in the cyber audit space, and positioning AGSA as a leader in cybersecurity auditing. The Senior Manager will oversee audit portfolios, manage teams, engage with a wide range of stakeholders, and contribute to the financial and operational management of their unit within AGSA. **What you will do** The successful candidate will be responsible for: * **Strategic Function:** * Providing input into strategic objectives for the Business Unit (BU). * Facilitating the implementation of BU and Specialised Audit Solutions (SAS) strategic plans. * Managing teams to align with AGSA's vision, mission, strategic goals, and values. * Providing feedback on the achievement of strategic objectives to stakeholders. * **Strategic Leadership & Innovation:** * Ensuring effective execution of cybersecurity audits. * Driving innovation, efficiency, and effectiveness in cyber audit. * Identifying emerging risks, leveraging new audit techniques, and enhancing audit methodologies for AGSA’s cybersecurity assurance. * **Thought Leadership & Brand Building:** * Serving as a key driver in positioning AGSA as a cybersecurity audit leader locally and internationally. * Contributing to knowledge-sharing platforms and engaging at all levels. * Collaborating with INTOSAI and other stakeholders to shape the future of cybersecurity audit. * **Product Management (Audit Management):** * Managing audits by leading, directing, and coordinating a portfolio across planning, execution, and reporting phases. * Liaising with auditees, initiating and leading team meetings, and providing guidance on audit matters. * Ensuring all risks for audit engagements are addressed, including specialist staff appointments and contracts. * Conducting audit team visits for work review, finalization, working paper conclusion, and report preparation. * Attending meetings with teams and auditees, providing motivation and training. * Engaging with contracted out partners and project managing all projects for timely and quality delivery. * Performing engagement manager functions as per ISA’s and Auditor-General policies. * Preparing and being responsible for presentations, reporting to audit steering committees and audit committees. * Managing audits within allocated timeframes and according to policies, procedures, and legislation. * **Stakeholder Management:** * Ensuring clear understanding of auditees’ business requirements through efficient engagement and translating these into deliverables. * Building collaborative relationships with internal and external stakeholders. * Liaising with key stakeholders and management to share information, resolve challenges, and make recommendations. * Managing and reporting on stakeholder engagements. * Promoting the AGSA brand and reputation. * **Participation in Business Unit Leader/Deputy Business Unit Leader Discussions:** * Informing leaders on issues from audits, auditing administration, financial issues, compliance concerns, and people/resourcing matters. * **Internal Stakeholder Relationships:** * Engaging with regularity audit on proceedings, facilitating debriefing sessions, and communicating with the team on audit and strategic matters. * Liaising with colleagues within the BU and portfolio. * **External Relationships:** * Engaging regularly with auditee management and audit firms for contracted out audits. * Participating in audit and steering committee meetings. * Attending Standing Committee on Public Accounts (SCOPA) and portfolio committee meetings by invitation. * Engaging with prospective employees. * **People Management:** * Implementing BU People Plan activities and managing team performance for productivity. * Contributing to transformation/culture plans, motivating, coaching, and mentoring staff. * Participating in talent attraction initiatives and contributing to BU training office administration. * Cascading strategic organizational alignment messages and implementing centre initiatives for an inclusive culture, enhanced employee experience, and well-being. * Analyzing the business plan to determine deliverables and securing human resources. * Managing the staff performance evaluation system (compiling IPC’s and PDP’s, conducting coaching and performance reviews, one-on-one sessions). * Participating in talent management to drive a high-performance culture. * Managing staff development (Personal Development Plans). * Approving leave, timesheets, subsistence & travel, and cash advances. * Acting as a champion for one of the BU’s five strategic goals and providing feedback at senior management meetings. * Managing the centre’s resources (staff, Contract Work Contractors (CWC), funding). * Providing direction and guidance, developing staff, improving client relations, and managing HR in accordance with policies and legal requirements within allocated timeframes. * **Financial Management and Operational Management:** * Compiling and managing the centre budget, including income and cost, to ensure adherence to financial performance standards. * Managing debtor’s collection, ensuring compliance with internal processes, and managing supply chain processes. * Conducting centre risk assessments. * Analyzing the business plan for financial requirements, consulting with stakeholders, and compiling a comprehensive budget. * Monitoring expenditure against the budget, approving purchase orders, and ensuring timely payments. * Assisting with invoice verification and managing CWC budgets. * Ensuring authorized overspending, consulting relevant role players for corrective actions. * Monitoring and reviewing the centre budget, closing it at year-end. * Managing the centre budget according to policies, procedures, and legal requirements within allocated timeframes. * **Other Responsibilities:** * Performing and/or managing other projects, tasks, and assignments as required. * Monitoring information related to audits, stakeholder engagements, funding, IPC’s, HR/Culture Initiatives, Balanced Scorecard Initiatives, BU Initiatives, and compliance matters. **Requirements (from the original advert)** * **Formal Education:** * Minimum qualification of National Qualifications Framework (NQF) Level 7 (e.g., 4-year Bachelor’s Degree / post-graduate Diploma such as B Com with specialisation in Auditing and/or Information Technology). * Certified Information Systems Auditor (CISA) or equivalent (e.g., a recognised IT auditing certification). * AND * At least one of the following: Offensive Security Certified Professional (OSCP) or equivalent (e.g., CEH); Certified Incident Handler (ECIH/ GCIH) or equivalent (e.g., CRIA). * **Experience:** * Minimum of 8 years’ experience post qualification with at least 4 years’ experience operating at a manager/middle management level. * Extensive experience in managing cybersecurity and network security audits, with a strong understanding of networked environments that support various application hosting infrastructures, including Windows and Unix-based operating systems, as well as MSSQL and Oracle databases. * Extensive experience in conducting cybersecurity maturity assessments, particularly within the Southern African context. This includes a strong ability to position insights and control recommendations for clients, guided by leading frameworks such as NIST CSF, ISO 27001/2, CIS, and COBIT. **Who should apply** The ideal candidate is an experienced cybersecurity audit professional with a strong background in managing complex audits, leading teams, and driving strategic initiatives within the information systems audit domain. They should possess significant leadership experience, particularly at manager/middle management levels, and demonstrate expertise in networked environments, various operating systems, and databases relevant to cybersecurity. The candidate must be proficient in conducting cybersecurity maturity assessments using industry-leading frameworks, capable of fostering innovation, building strong stakeholder relationships, and contributing to both the technical excellence and strategic positioning of AGSA as a cybersecurity audit leader. A commitment to people development, financial acumen, and operational management is also essential. **Deadline** 24 October 2026 **Reference** Original posting: https://www.myjobmag.co.za/job/senior-manager-information-systems-audit-cybersecurity-auditor-general-of-south-africa Source: myjobmag

Summary drafted with AI assistance from the original advert. The advert itself is the authority — how we use AI.

Job description

Apply by: 24 October 2026 Job description Strategic Function * Provide input into the strategic objectives to assist in establishing the strategic direction of the Business Unit BU. * Facilitate the implementation of the Business Unit and Specialised Audit Solutions SAS strategic plans in accordance with policies, procedures and legislation. * Manage teams to ensure alignment to the vision, mission, strategic goals and values of the Auditor-General of South Africa AGSA or Auditor-General * Provide feedback on implementation / achievement of strategic objectives to the relevant stakeholders Strategic Leadership & Innovation * Ensure the effective execution of cybersecurity audits * Drive innovation, efficiency, and effectiveness in the cyber audit space. * Identifying emerging risks, leveraging new audit techniques, and enhancing audit methodologies to strengthen the AGSA’s cybersecurity assurance. Thought Leadership & Brand Building * Key driver in positioning AGSA as a cybersecurity audit leader, both locally and internationally. * Contribute in knowledge-sharing platforms, engage at all levels * Collaborate with INTOSAI and other key stakeholders to shape the future of cybersecurity audit excellence. Product Management * Manage Audits Lead, direct and coordinate portfolio of audits covering the three audit phases: * Planning * Execution * Reporting * Liaise with auditees in the provision of advice / recommendations, setting up meetings, etc * Initiate and lead meetings with the audit team regarding the direction and progress on the audits * Provide guidance to managers an assistance on audit related matters Ensure that all risks are addressed for the specific audit engagements, for example: * Appointment of specialist staff * Contract in and out Conduct audit team visits to: * Review work * Finalise the audit * Conclude working papers * Prepare audit report * Attend meetings with the team and auditees * Provide motivation talks and training on auditing matters to team members * Engage with contracted out partners * Project manage all projects to ensure timeous delivery on milestones and quality of delivery is met * Perform functions as required by an engagement manager as spelled out in the ISA’s and the Auditor-General policies * Prepare and take responsibility for presentations * Report back to the audit steering committees and audit committees on the planning, execution and reporting of the audits * Manage audits within the allocated time frame * Manage audits in accordance with policies, procedures and legislation Stakeholder Management * Ensure clear understanding of auditees’ business requirements through efficient stakeholder engagement and that this is translated into clear deliverables. * Build collaborative relationships with internal and external stakeholders. * Liaise and interact with key stakeholders & management to share information, resolve challenges and make recommendations for improvements. * Manage and report on stakeholder engagements. * Promote the AGSA brand and reputation. Participate in Business Unit Leader/Deputy Business Unit Leader Discussions Inform the Business Unit Leader and/or the Deputy Business Unit Leader on: * Issues arising from audits * Focus areas for auditing administration matters * Financial issues * Compliance concerns * People and resourcing matters Manage Internal Stakeholder Relationships: * Engage with regularity audit on audit proceedings. * Facilitate debriefing sessions with regularity audit on the previous year’s audits performed * Engage with the team during the three audit phases namely planning, execution and reporting * Communicate with the team on non-audit and strategic matters * Liaise with colleagues within the BU * Liaise with colleagues within the portfolio Manage External Relationships: * Engage regularly with the management of the auditee on audit proceedings * Engage with audit firms regarding contracted out audits * Participate in audit and steering committee meetings * Attend Standing Committee on Public Accounts SCOPA and portfolio committee meetings by invitation * Engage with prospective employees  People Management * Implement the activities outlined on the BU People Plan. * Manage team performance to drive productivity. * Contribute to transformation/culture plans. * Motivate, coach and mentor staff to ensure maximum productivity and development of the staff to their full potential. * Participate in initiatives to attract talent. * Contribute to effective administration of the BU training office. * Cascade strategic organisational alignment messages and commitments. * Implement relevant centre initiatives to bring about an inclusive culture, enhanced employee experience and employee well-being * Analyse the business plan to determine the applicable deliverables and targets * Determine and secure the human resource requirements to ensure that deliverables will be met in accordance with the expected targets Manage the staff performance evaluation system for the centre: * Compile Individual Performance Contracts IPC’s and Performance Development Plans PDP’s * Conduct coaching sessions to ensure staff member/s perform at the optimum level * Conduct performance reviews in accordance with policies and procedures and take corrective action where necessary * Conduct one-on-one sessions * Participate in the talent management of the Business Unit to drive a high performance culture in accordance with the AGSA’s roles and responsibilities and competency framework * Manage the development of staff and ensure each staff member has a Personal Development Plan * Approve leave, timesheets, subsistence and travel S&T and cash advances * Act as a champion on one of the five strategic goals of the business unit value add, visibility with impact, viability and visions and values to ensure that the Business Unit achieves its objectives: * Provide feedback at the monthly senior management meeting Manage the centre’s resources staff, Contract Work Contractors CWC and funding: * Participate in meetings * Provide direction and guidance to achieve a timely high quality product * Develop the staff to optimum productivity levels * Improve on client relations within the overall business processes captured in the Business Scorecard BSC * Manage Human Resources in accordance with policies, procedures and legal requirements * Complete Human Resource Management actions within the allocated time frames Financial management and operational management * Responsible for compiling the centre budget. * Manage the centre budget, income and cost to ensure adherence to the required financial performance standards for the portfolio * Manage debtor’s collection. * Ensure compliance with internal processes and procedures * Manage supply chain processes. * Conduct centre risk assessment. * Analyse the business plan for the Business Unit to determine the financial requirements for the centre * Consult with the relevant stakeholders to determine requirements in terms of expenditure * Compile the comprehensive budget indicating the financial requirements in accordance with the budgeting guidelines * Submit the budget for approval in accordance with policies and procedures * Monitor the expenditure against the budget to ensure that spending occurs within the budgetary restrictions * Approve purchase orders * Ensure that debtor payments are followed up and creditors are paid timeously * Assist RA with the verification of invoices * Manage and monitor the CWC budgets * Ensure that only authorised overspending is approved in accordance with procedures * Consult the relevant role players where overspending took place and take corrective actions to rectify the overspending * Monitor the centre budget to ensure that figures balance in terms of budgeted and actual figures * Conduct the budget reviews as prescribed by Finance and adjust budget where necessary * Close the budget at the end of the financial year * Manage centre budget in accordance with policies, procedures and legal requirements * Complete centre budget management actions within the allocated time frames Other responsibilities Applicable to All JD’s * Perform and/or manage other projects, tasks and assignments not stipulated on the Job description as and when required. * Monitor Information Track the following to gather and monitor the centre: * Audits Own and CWC * Stakeholder engagements * Funding income and expenditure * IPC’s * HR/Culture Initiatives * Balanced Scorecard Initiatives * BU Initiatives * Compliance matters internal control Minimum requirements Formal Education * Minimum qualification of National Qualifications Framework NQF Level 7 i.e. 4 year Bachelor’s Degree / post graduate Diploma e.g. B Com with specialisation in Auditing and/or Information Technology * Certified Information Systems Auditor CISA or equivalent e.g. a recognised IT auditing certification AND At least one of the following: * Offensive Security Certified Professional OSCP or equivalent e.g. CEH * Certified Incident Handler ECIH/ GCIH or equivalent e.g. CRIA Experience * Minimum of 8 years’ experience post qualification with at least 4 years’ experience operating at a manager/middle management level. * Extensive experience in managing cybersecurity and network security audits, with a strong understanding of networked environments that support various application hosting infrastructures, including Windows and Unix-based operating systems, as well as MSSQL and Oracle databases. * Extensive experience in conducting cybersecurity maturity assessments, particularly within the Southern African context. This includes a strong ability to position insights and control recommendations for clients, guided by leading frameworks such as NIST CSF, ISO 27001/2, CIS, and COBIT.

Before you apply

  • Confirm the requirements and closing date on the original listing (myjobmag). SPANi lists vacancies from other sites and may not reflect last-minute changes.
  • Legitimate employers do not charge application, registration or training fees.
  • Don't send your ID or bank details before you have confirmed the employer is real.

How to spot a job scam

Before you apply

  • Read the full advert and confirm you meet the minimum requirements before applying.
  • Tailor your CV headline and most recent experience to the job title and key skills.
  • Note the closing date and reference number, and keep a copy of what you submit.
  • Apply only through the employer or job board link — never pay to apply.

Similar roles

Get new accounting & finance jobs in gauteng by email

Free. No account needed. Unsubscribe with one click.

We only use your email to send this alert. See our privacy policy.

Senior Manager: Information Systems Audit (Cybersecurity) at Auditor-General of South Africa | SPANi - South African Jobs