Manager: Cyber Security Operations Centre (CSOC)

SARS

• $110K — $130K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's Degree or Advanced Diploma in Information Security (NQF 7)
  • 8-10 years of experience in IT Security, with 3-4 years in junior management
  • Recognized certification in Information Security Management (CISM, CISSP, etc.)
  • Senior Certificate (NQF 4) with 15 years of IT Security experience as an alternative qualification
  • Strong leadership and stakeholder management skills

Responsibilities

  • Lead and manage the Cyber Security Operations Centre (CSOC) and User Access Management (UAM) functions
  • Implement and monitor information security controls to protect organizational assets
  • Translate information security strategy into operational execution
  • Manage internal teams and outsourced security service providers
  • Provide oversight and operational management of security functions
  • Develop and implement tactical strategies to achieve operational targets
  • Build strong relationships with internal and external stakeholders

Benefits

  • Opportunity to contribute to a higher purpose and service delivery
  • Engagement in a dynamic and evolving cybersecurity landscape
  • Professional development and continuous capability improvement
  • Collaboration with a diverse team of cybersecurity experts
  • Access to advanced tools and technologies in cybersecurity
Full Job Description
Position Reports to: Area Head IT Security Operations

Division: Strategy Enablement & Modernisation

Location: Head Office Pretoria

Advert Closing Date: 11 October 2026

About the Position

SARS is seeking a highly skilled, results-driven cybersecurity specialist with sound judgement, strong business acumen and a future-focused mindset. The successful candidate will contribute to SARS' higher purpose and service delivery by driving effective IT security controls and strengthening cyber resilience.

The Manager: Cyber Security Operations Centre is responsible for the strategic and operational management of the Security Operations Centre (SOC) and User Access Management (UAM) functions. The role ensures the effective implementation, monitoring and continuous improvement of information security controls to protect the organisation's information assets, systems and services.

The position translates information security strategy into operational execution, driving measurable outcomes across security monitoring, incident response, identity and access management, security governance and operational risk management. The role also manages internal teams and outsourced security service providers, ensuring service excellence, compliance and continuous capability improvement.

The successful candidate must demonstrate strong information security management experience, effective leadership and stakeholder management capabilities, and the ability to align security operations with organisational objectives and risk requirements.

Job Purpose

To lead and manage the Cyber Security Operations Centre (CSOC) and User Access Management (UAM) functions, ensuring the effective monitoring, detection, investigation and response to cyber threats, while strengthening identity and access management, operational resilience and the protection of SARS information assets, systems and services.

Education and Experience

Minimum Qualification & Experience Required

Bachelor's Degree / Advanced Diploma (NQF 7) Information Security AND 8-10 years' experience in an Information Technology Security, of which 3-4 years at a junior management level, as well as a recognised professional certification in Information Security Management, such as Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP), or an equivalent recognised certification.

Alternative #

Senior Certificate (NQF 4) AND 15 years Information Technology Security experience, of which 3 - 4 years at a junior management level, , as well as a recognised professional certification in Information Security Management, such as Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP), or an equivalent recognised certification.

Job Outputs:

Process
  • Act as the bottom-line drivers of tactical implementation within the context of business unit excellence and performance improvement.
  • Direct, control, coordinate and optimise budgeted resources to meet specific objectives and deliver agreed results and productivity requirements.
  • Ensure the development and implementation of a practice in alignment with operational policy and procedural frameworks.
  • Implement tactical strategy and delivery plans through the development of operational activities, ensuring the achievement of operational targets.
  • Convert the approved tactical security strategy into a measurable operational plan, defining deliverables, performance measures, priorities and resource requirements.
  • Plan for handling work outputs, pull together interdependent activities and specify priorities, standards and procedures to ensure tactical implementation.
  • Provide periodic reports on performance against plan & progress on short-term initiatives & use to realign tactical plan and objectives appropriately.
  • Recommend changes to optimise processes, systems, policies and procedures, and execute the implementation of change and innovation initiated by the organisation.
  • Timeously communicate top-down policy modification, objective achievement progress and critical success factors to impacted stakeholders.
  • Use the insights gained through integrated business reports to measure success and realign tactical strategy implementation objectives appropriately.
  • Plan and manage projects in area of accountability.
  • Provide integrated oversight and operational management of Security Operations Centre (SOC) and User Access Management functions to ensure effective protection of SARS information assets and services.
  • Monitor the effectiveness of security controls, operational performance, service delivery standards, risks and compliance requirements, and implement corrective actions where deficiencies are identified.
  • Provide technical direction for the development, design and integration of systems to prevent the loss of SARS assets.
  • Liaise with vendors to get product and service level issues resolved.


Governance
  • Implement governance, risk and compliance policy in own practice area to identify and manage governance and risk exposure liability.
  • Manage and or advise on the translation and application of policy in a specific functional area.
  • Comply with organisational internal control and governance standards in finance and procurement processes.


People
  • Develop and implement appropriate people capacity plans in line with delivery and efficiency targets, on budget and in partnership with specialised area.
  • Plan and implement enhanced organisational efficiency by identifying and addressing development requirements and providing tools for people resources.
  • Translate performance expectations into specific metrics and goals to identify and provide effective services, solve problems and achieve objectives.
  • Ensure compliance with applicable health, safety, security and workplace policies within the Cyber Security Operations Centre environment.


Finance
  • Draw up a budget aligned to tactical delivery plans, monitor planned vs. actual, minimise expenditure and report on cost efficiency.
  • Implement and monitor financial control, management of costs and corporate governance in area of accountability.


Client
  • Build strong relationships and implement service level agreements that promote SARS with internal and external stakeholders.
  • Develop and ensure implementation of practices which builds service delivery excellence and encourage others to provide exceptional client service.
  • Manage an integrated service excellence culture, which builds rewarding relationships and provides opportunity for feedback and exceptional service.


Compliance Competency
  • GOC Confidential

Similar Jobs

More Jobs at SARS

More Information Technology Jobs

Find similar Manager: Cyber Security Operations Centre (CSOC) jobs: