Stand out for this role — generate a tailored resume and cover letter in about a minute.
SARS in Pretoria is seeking a Manager for the Cyber Security Operations Centre (CSOC) and User Access Management (UAM). You will lead the SOC, monitor threats, manage incident response, and strengthen identity and access controls to protect information assets and services.
You will oversee internal teams and external security service providers, drive governance, risk management and security operations aligned with business objectives and regulatory requirements.
Requisition ID11599-Posted01/10/2026- Region (1) - Location (1)
Position Reports to: Area Head IT Security Operations
Advert Closing Date: 11 October 2026
About the Position
SARS is seeking a highly skilled, results-driven cybersecurity specialist with sound judgement, strong business acumen and a future-focused mindset. The successful candidate will contribute to SARS' higher purpose and service delivery by driving effective IT security controls and strengthening cyber resilience.
The Manager: Cyber Security Operations Centre is responsible for the strategic and operational management of the Security Operations Centre (SOC) and User Access Management (UAM) functions. The role ensures the effective implementation, monitoring and continuous improvement of information security controls to protect the organisation's information assets, systems and services.
The position translates information security strategy into operational execution, driving measurable outcomes across security monitoring, incident response, identity and access management, security governance and operational risk management. The role also manages internal teams and outsourced security service providers, ensuring service excellence, compliance and continuous capability improvement.
The successful candidate must demonstrate strong information security management experience, effective leadership and stakeholder management capabilities, and the ability to align security operations with organisational objectives and risk requirements.
Job Purpose
To lead and manage the Cyber Security Operations Centre (CSOC) and User Access Management (UAM) functions, ensuring the effective monitoring, detection, investigation and response to cyber threats, while strengthening identity and access management, operational resilience and the protection of SARS information assets, systems and services.
Education and Experience
Minimum Qualification & Experience Required
Bachelor's Degree / Advanced Diploma (NQF 7) Information Security AND 8-10 years' experience in an Information Technology Security, of which 3-4 years at a junior management level, as well as a recognised professional certification in Information Security Management, such as Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP), or an equivalent recognised certification.
Alternative #
Senior Certificate (NQF 4) AND 15 years Information Technology Security experience, of which 3 - 4 years at a junior management level, , as well as a recognised professional certification in Information Security Management, such as Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP), or an equivalent recognised certification.
Job Outputs:
Process
Governance
People
Finance
Client
Compliance Competency
Employment Equity
The Employment Equity policy of SARS will be considered as part of the recruitment and selection process and Persons with Disabilities are encouraged to apply. Successful candidates will be required to undertake an oath of secrecy, pre-employment screening, case study, pre-assessment, psychometric assessment and or vetting, and a declaration of private interest. The appointment is also subject to appropriate reference(s) and security clearance where applicable.