Share this post on
To apply, click on the link at the end of the posts and all the best with your applications
ICT Contracts Specialist
Closing Date
2026/10/05
Reference Number
DBS260917-1
Job Title ICT Contracts Specialist
Job Grade 00
Job Type Classification Permanent
Location – Town / City Midrand
Location – Province Gauteng
Location – Country South Africa
Job Profile (Downloadable) ICT Contracts Specialist_Job Profile July 2026 Final NS.docx.pdf (328,96 kb) – 2026/09/17 10:12:18
Job Description
The ICT Contracts Specialist is accountable for the end-to-end lifecycle management of ICT contracts, including contract planning, drafting support, review, negotiation facilitation, execution, performance monitoring, renewal, variation, issue resolution and close-out. The role ensures that ICT services, software, hardware, cloud, cybersecurity and managedservice contracts are commercially sound, legally and regulatory compliant, risk-managed, auditable and aligned to DBSA governance, SCM requirements, service delivery objectives and value-for-money principles. The incumbent acts as the central contract and vendor-performance specialist for ICT, working with ICT, SCM, Legal, Risk, Finance, business stakeholders and service providers to ensure contractual obligations, SLAs, KPIs, data protection, security, licensing, service credits, penalties, exit provisions and renewal decisions are actively managed.
Key Responsibilities
KEY PERFORMANCE AREAS
- Contract Management
Coordinate contract signature processes and ensure all contractual documentation is complete, compliant, and properly archived.
Review and negotiate ICT contracts and amendments in collaboration with ICT business units, SCM and Legal.
Track key contract milestones, deliverables, expiry dates, renewals, termination periods, guarantees, insurance requirements, and other contractual obligations.
Liaise with internal stakeholders, service providers, contractors, suppliers, and third parties to obtain required documentation and facilitate contract execution.
Escalate and manage potential contract-related legal risks and disputes in collaboration with ICT business units to Legal and Risk.
Monitor contract renewals, expirations, and compliance with terms and conditions.
Review and analyse contract terms, conditions, and obligations to ensure compliance with internal policies, governance standards, legal frameworks and industry practices.
2. Service Level Agreement Monitoring and Document Management
Create dashboard to monitor SLA performance to track contractor and service provider performance against contractual deliverables, milestones, KPIs, and service level agreements.
Document service level agreements and assist with monitoring contract compliance, performance milestones and deliverables in collaboration with ICT and business units.
Conduct regular contract audits and performance reviews to identify risks, trends, variances, and underperformance.
Drive continuous improvement initiatives to enhance contract performance, compliance, governance, and value realisation.
Facilitate SLA reviews for contractor and service provider performance and implement corrective action plans where required.
Prepare, maintain, and manage accurate central repository of all ICT contract files, registers, and ensure proper classification, version control, audit readiness, and secure record storage.
Keep a record of reported service provider challenges and the tracking of performance issues, corrective actions, and follow-up activities.
Manage relationships with ICT vendors and service providers and document all vendor engagements in alignment with contractual obligations.
3. Risk and Compliance Management
Contribute to the development, implementation, and continuous improvement of contract management frameworks, policies, procedures, controls, and governance standards.
Liaise with Internal Audit, Legal, Procurement, and Risk teams to ensure alignment with governance and compliance requirements.
Identify contract-related risks in ICT engagements and facilitate mitigation strategies to minimise operational, legal, and financial exposure this including training stakeholders on contract management processes.
Maintain compliance with legal, regulatory, and internal governance requirements.
Support audit processes and provide documentation as required.
Monitor adherence to governance, documentation, approval, record-keeping requirements and data protection and privacy laws (e.g., POPIA).
4. Procurement and Sourcing Support
Collaborate with procurement teams to design, manage, and oversee ICT tenders and sourcing strategies, ensuring that all processes are aligned with ICT processes.
Support the tender process by validating and applying both technical and support contract award processes.
Contribute to procurement planning by identifying ICT needs and providing inputs into the sourcing needs plan.
5. Reporting and Monitoring
Support governance submissions, management reviews, and audit processes through the preparation of accurate and comprehensive documentation and reporting inputs.
Generate dashboards, reports, and performance insights to support informed decision-making and continuous improvement.
Contribute to the enhancement and implementation of digital contract management systems, trackers, and reporting tools to improve process efficiency, data integrity, and reporting accuracy.
Prepare regular reports on contract status, SLA performance, and vendor compliance.
Maintain accurate and up-to-date contract documentation.
Key Measurements of Outputs
Contract register maintained at 100% completeness and updated within agreed turnaround times after execution, variation, renewal or termination.
Percentage of ICT contracts with current, approved SLAs, KPIs, ownership, renewal dates, termination notice periods, risk ratings and obligation trackers recorded.
Renewals, expiries and termination notices proactively flagged within the agreed lead time, with no avoidable missed renewal, lapse or unmanaged rollover.
SLA and vendor performance dashboards produced accurately and on time, including service credits, penalties, breaches, corrective actions and trend analysis.
Contract compliance reviews, audits and vendor performance review meetings completed in accordance with the approved schedule.
Contractual risks, disputes, non-compliance findings and performance issues documented, escalated and resolved within agreed governance timeframes.
Quality of contract review inputs, procurement support, negotiation preparation and governance submissions, as assessed by line management and key stakeholders.
Compliance with PFMA, PPPFA, SCM policies, POPIA, information security, ICT governance and internal approval requirements evidenced through audit-ready records.
Improvement initiatives implemented to strengthen contract lifecycle management, reporting accuracy, vendor performance, cost control and value realisation.
Stakeholder satisfaction with contract management support, responsiveness, advisory quality and vendor governance coordination.
Expertise & Technical Competencies
QUALIFICATIONS AND EXPERIENCE
Minimum Qualification
Bachelor’s Degree or equivalent NQF Level 7 qualification in Law, Commercial Law, Supply Chain Management, Procurement, Business Administration/Management, Information Technology, Information Systems or a related field.
Minimum Experience
A minimum of 8 years’ relevant experience in ICT contract management, commercial/vendor management, procurement, supply chain management or legal advisory roles, of which at least 5 years must include ICT contracts, technology vendors, software licensing, cloud, cybersecurity, managed services or complex ICT service agreements.
Demonstrated experience in contract lifecycle management, including contract drafting support, review coordination, negotiation support, execution, obligation tracking, SLA/KPI monitoring, variation, renewal, termination and close-out.
Strong working knowledge of South African public sector procurement and governance frameworks, including PFMA, PPPFA, Preferential Procurement Regulations, SCM policies and applicable internal delegation-of-authority requirements.
Working knowledge of contract law principles, service level management, supplier performance management, risk management, data protection and privacy requirements, including POPIA.
Familiarity with ICT governance, information security and service management frameworks such as ITIL, COBIT and ISO/IEC 27001.
Experience maintaining contract registers, vendor records, audit evidence, obligation trackers, dashboards and management reports.
Understanding of BBBEE, local content, commercial evaluation, licensing, warranties, indemnities, liabilities, service credits, penalties, intellectual property, confidentiality, cybersecurity, exit management and business continuity clauses in ICT contracts.
Desirable Requirements
A postgraduate qualification in Contract Management, Commercial Law, Procurement, ICT Governance or Business Management will be advantageous.
Professional certification in contract management, procurement, supply chain management, commercial management or vendor management.
ITIL Foundation, COBIT Foundation, ISO/IEC 27001 awareness, project management or ICT governance certification.
Experience in a public sector, development finance, banking, regulated, audit-intensive or enterprise ICT environment.
Experience supporting ICT audits, governance committees, tender evaluations, sourcing strategies and compliance reviews.
Experience implementing or administering contract lifecycle management systems, vendor management tools, SLA dashboards or digital contract repositories.
Experience negotiating enterprise software, cloud, managed services, cybersecurity, outsourcing or professional services contracts.
TECHNICAL COMPETENCIES
a) Knowledge of Contracts
Through a broad and deep understanding of contracting best practice, is able to define DBSA contracting policy.
Develops contract award documents ensuring DBSA’s interests are protected.
Drafts, monitors and ensures performance of special terms of contract. Ability to apply remedy to protect DBSA’s rights. Ability to enforce compliance.
Monitors contractor compliance to identify, document and resolve potential or actual problems. Determine which contractual remedy, if
any, applies and employ that remedy.
Conducts post-award orientation, monitors contract performance and takes necessary action related to delays in contract performance.
Analyses and negotiates modification and termination of contracts.
Evaluates the impact of selected issues to determine the need for top management involvement.
b) Procurement Services
Based upon a thorough understanding of user requirements, is able to research alternative sources that will fulfil internal customer needs with favourable commercial terms.
Identifies the needs of the user departments and advise on appropriate sourcing and selection approaches and processes.
Articulates and prepares requirement documents and related elements of the procurement request including terms and conditions for the sourcing, selection and award process.
Receives, safeguards, opens, records, tracks, assesses compliance with terms, and summarises bids/quotations.
Evaluates bids including identifying and resolving mistakes, and award contracts.
Develops relationships by effective resolution of complaints and concerns.
c) Planning and Organising
Is relied on to helps others plan and organise their workload.
Uses effectively advance time management processes to deal with high workload and tight deadlines.
Organises, prioritises and schedules tasks so they can be performed within budget and with the efficient use of time and resources.
Achieves goals in a timely manner, despite obstacles encountered, by organising, reprioritising and re-planning.
d) Reporting
Designs / customises reports to meet user needs.
Prepares complex or tailored reports, gathers information from a variety of sources, analyses and includes in a report.
Keeps standard reports under review and
e) Risk Identification and Assessments
Participates in risk assessment and identification efforts.
Identifies and assesses the impact and likelihood of risks to achieving business objectives, monitors changes in risk environment.
f) Data Collection and Analysis
Skilled in the use of advanced/complex analytical techniques.
Is able to use judgement to decide upon the most appropriate analytical techniques according to the situation.
Recognises underlying principles, patterns, or themes in an array of related information, and determine whether additional information would be useful or necessary.
Through an in-depth understanding of the business environment, reviews outputs of analysis to identify anomalies and draws conclusions,
relating these to operational circumstances.
Can model a range of scenarios covering all potential business circumstances and highlight potential risks/opportunities.
Tests the backed data and assures backup quality.proposes improvements to meet user needs.
Required Personal Attributes
BEHAVIOURAL COMPETENCIES
a) Analytical Thinking
Analyses and interprets multiple complex causal links: several potential causes of events, several consequences of actions, or multiple-part chains of events in order to prioritise and develop a plan of action.
b) Attention to Detail
Monitors quality of others’ work.
Checks to see that procedures are followed by others.
Keeps clear detailed records of own and/or others’ activities.
c) Strategic and Innovative Thinking
Experiments with new approaches, tests scenarios, questions assumptions and challenges conventional thinking.
Creates new concepts that are not obvious to others, leveraging internal and external sources of information, to build incremental revenue and growth opportunities.
d) Driving Delivery of Results
Sets challenging goals that will have a significant impact on the business or support the organisational strategy.
Commits significant resources and/or time to ensure that challenging goals are achieved, while also taking action to mitigate risk.
e) Teamwork and Cooperation
Openly praises others who have made contributions to the group’s efforts.
Empowers others, making them feel valued, strong and important.
Encourages others after a setback.
f) Impact and Influence
Includes careful preparation of data for presentation.
Makes two or more different arguments or points in a presentation or a discussion.
Click here to apply
Head: Information Security & GRC
Closing Date
2026/09/29
Reference Number
DBS260909-1
Job Title Head: Information Security & GRC
Job Grade 00
Job Type Classification Permanent
Location – Town / City Midrand
Location – Province Gauteng
Location – Country South Africa
Job Profile (Downloadable) Head ICT Information Security and GRC Job Profile 31 August 2026 Final.docx.pdf (328,68 kb) – 2026/09/09 11:07:38
Job Description
The Head: Information Security & GRC provides enterprise-wide leadership for the Bank’s ICT environment, information and systems security, cyber resilience, technology risk, governance, compliance and assurance. The role is accountable for establishing and maintaining a secure, resilient, compliant and business-aligned technology environment across infrastructure, cloud, applications, data, identity, third-party platforms and emerging technologies. The incumbent develops and executes integrated ICT and information security strategies, policies, standards, controls and operating models aligned to the Bank’s mandate, business strategy, risk appetite, regulatory obligations and recognised frameworks such as ISO/IEC 27001, NIST Cybersecurity Framework, COBIT, ITIL, POPIA and King V. The role enables secure digital transformation, strengthens operational resilience, provides executive and board-level reporting on technology and cyber risk, and embeds a culture of security, accountability, service excellence, innovation and continuous improvement across the organisation.
Key Responsibilities
KEY PERFORMANCE AREAS
- Strategic Delivery
Develop and execute a comprehensive ICT, information security, and GRC strategy aligned to the organisation’s overall business objectives and long-term vision.
Identify strategic priorities and deliverables for Information / Security, and GRC based on the overall Bank strategy, ensuring alignment with organisational priorities.
Own the enterprise ICT and security operating model, ensuring clear accountability for infrastructure, systems security, cloud security, identity and access management, data protection, resilience and GRC outcomes.
Translate strategic priorities into clear digitalisation goals, initiatives, milestones, and measurable outcomes.
Develop both long-term and short-term digitalisation strategies and implementation plans aligned to approved budgets and resource frameworks.
Drive enterprise-wide adoption of digital solutions through structured communication and stakeholder engagement internally and externally.
Lead the communication of the strategy to all stakeholders internally and externally.
Drive ICT and cybersecurity as strategic business enablers by aligning technology and security initiatives with business objectives, digital transformation priorities, and enterprise risk management outcomes.
2. Governance and Compliance
Establish and enforce information security policies, standards, and procedures.
Maintain compliance with South African and international regulations (e.g.., POPIA, GDPR, ISO/IEC 27001).
Conduct regular policy reviews and updates in line with regulatory changes.
Liaise with legal, risk, compliance and audit teams to manage regulatory risks and compliance obligations.
Promote cyber risk ownership across business units by embedding cybersecurity risk management into business processes and decision-making.
Maintain an integrated technology, cyber and compliance control framework, including control ownership, testing, evidence management, remediation tracking and assurance reporting.
Facilitate and drive appropriate, reasonable technical and organisational measures are implemented and evidenced to protect personal information, critical systems and sensitive business information.
3. Cyber Security Operations
Oversee the Security Operations Centre (SOC) and ensure effective threat monitoring and response.
Manage incident response plans and lead investigations into security breaches.
Implement and maintain security technologies (e.g.., SIEM, DLP, firewalls, endpoint protection).
Conduct regular vulnerability assessments and simulation(penetration) testing.
Leverage AI, automation, and advanced analytics to improve threat detection, monitoring, incident response, and security operations effectiveness.
Drive the adoption of modern cybersecurity practices, including Zero Trust Architecture, cloud security governance, and continuous threat exposure management.
4. Third-Party Risk Management
Develop and implement a third-party risk management framework.
Conduct due diligence and risk assessments for new and existing vendors.
Monitor third-party compliance with security requirements and SLAs.
Maintain a centralised third-party risk register and reporting mechanism.
Ensure third-party engagements do not compromise the organisation’s security, data, or operational integrity.
5. Reporting and Governance
Establish and enforces robust governance frameworks and reporting mechanisms to ensure transparency, compliance, and effective decision-making across all operations.
Provide timely and accurate reporting of key performance indicators, risks, and progress against strategic objectives to relevant internal and external bodies.
Prepare for and lead internal and external security audits.
Maintain audit trails and documentation for compliance purposes.
Report on security posture, incidents, and risk metrics to executive leadership and the board.
Implement corrective actions and track remediation progress.
6. Stakeholder Engagement
Build and maintains strong, collaborative relationships with key internal and external stakeholders, including leadership, government entities, commercial banks, development partners, and community representatives, to drive shared objectives.
Navigate complex stakeholder landscapes, influencing outcomes and fostering consensus to achieve strategic goals.
Collaborate with enterprise architecture, infrastructure and solution delivery teams to ensure security-by-design principles are incorporated into technology and digital solutions
7. People Management
Lead, mentor, and develop a high-performing team, fostering a culture of collaboration, accountability, and continuous learning to maximise individual and collective potential.
Drive talent development initiatives, including coaching, performance management, and career pathing, to build and retain a skilled and motivated team.
Attract, retain, and develop talent and ensure succession planning and sufficient capacity and capability in all critical functions, supporting diversity strategies and initiatives as well.
Promote DBSA values and a culture of high performance through implementing performance management in line with the planned strategic objectives, goals, quality standards and agreed key performance measures using sound performance management principles.
Contribute to building synergies & cooperation across functions in the DBSA.
Promote cybersecurity and AI literacy across the organisation through awareness, behavioral change, and capability-building programmes.
8. Security and Digital Transformation
Foster a culture of security awareness and ensuring that third-party engagements do not compromise the organisation’s security or operational integrity.
Ensure that information and cyber security capabilities, controls, and governance frameworks effectively support and enable digital transformation initiatives, while protecting DBSA’s information assets and technology environment.
Foster a mindset of innovation, identifying opportunities to adopt emerging technologies and best practices to modernise processes and deliver impactful solutions.
Key Measurements of Outputs
Percentage reduction and prevention in security incidents.
Percentage of critical systems compliant with approved security baselines, patching thresholds and resilience requirements.
Successful adherence to compliance & audit performance.
Improvement of security awareness & training impact of employees.
Advancement in the organisation’s cybersecurity maturity model score.
Percentage of critical assets covered by key security controls.
Number of open critical/high-risk findings identified in third-party assessments.
Number of security incidents originating from or involving third parties.
Reduction in material cyber risk exposure.
Board and executive reporting delivered on agreed technology risk, cyber resilience, compliance, control effectiveness and remediation metrics.
Management of team performance, talent development, and succession planning using the performance management system.
Expertise & Technical Competencies
QUALIFICATIONS AND EXPERIENCE
Minimum Qualification
A Postgraduate qualification in Information Security Risk Management, Information Technology, Computer Science or Cybersecurity.
Minimum Experience
A minimum of 12 years’ experience in ICT, Information / Cyber Security Governance and Risk Management with at least 5 years in a management role leading an ICT function.
Extensive experience in leading security audits, forensic investigations, regulatory inspections and third-party risk and vendor security assessments.
Proven experience in Security Operations Centre (SOC) oversight and incident response.
Deep understanding of South African and global cybersecurity regulations and standards.
Awareness of emerging threats and technologies (AI, IoT, blockchain).
In-depth understanding of third-party risk frameworks (e.g.., SIG, TPRM lifecycle), cybersecurity architecture and frameworks (e.g.., NIST, ISO/IEC 27001), vendor risk management and due diligence.
Understanding and working knowledge of regulatory compliance (e.g., POPIA, GDPR, FICA, King V).
Working knowledge of cloud security and data protection.
Technical experience in penetration testing and vulnerability management.
Experience in business continuity and disaster recovery planning.
In depth knowledge of security tools and technologies (SIEM, DLP, IAM, etc.).
Demonstrated experience in delivering executive and Board-level technology and cyber risk reporting, with a proven track record of embedding a culture of security, accountability, service excellence, innovation, and continuous improvement across the organisation.
Desirable Requirements
A Master’s Degree in Computer Science, or Information/Cyber Security, Information Systems or Business Administration
Professional certification such as Certified Information Systems Security Professional (CISSP) or Certified Information Security Manager (CISM)
Experience in managing cross-border teams and projects.
Knowledge of financial services, telecommunications, or public sector environments.
TECHNICAL COMPETENCIES
a) Risk Management Policies and Procedures
Drives integration and standardisation of risk management processes across the organisation.
Advises on the application of the organisation’s risk management policies, industry best practices and constructs organisation guidelines.
Analyses trends in risk management and internal control, evaluates implications, defines and implements organisation-wide response.
b) Information Technology Strategy and Planning
Able to develop a larger vision for the IT function and able to develop an integrated IT plan across the organisation covering all IT systems.
Can report on best practices at the highest level of the organisation and develop best of breed plans to drive through the organisation.
Able to develop best practices for applying IT solutions for functions by anticipating their needs and identifying areas that can be transformed through IT support.
c) Information Technology Security
Possesses in-depth practical and theoretical knowledge of a process area to enable the jobholder to act as a technical point of reference for staff.
Demonstrates an expert understanding or very detailed area of expertise in multiple security subject(s).
Demonstrates expert knowledge of law, regulation, and policies, and interprets policies and standards.
Is an expert in multiple security applications and tools.
Mitigates threats and serious security incidents at the enterprise level.
Consults on security issues and recommends IT strategies.
Is able to develop and implement systems for the analysis of performance across a department or functional area.
Knows how to develop and implement emergency policies and procedures, including the defining of individual roles and actions to be taken.
d) Systems Security, Architecture and Resilience
Defines and oversees secure architecture, hardening standards, identity controls, privileged access management, vulnerability management, patch governance, backup resilience and recovery controls across enterprise systems.
Embeds security-by-design, privacy-by-design and resilience-by-design principles into cloud, application, infrastructure, data and integration solutions.
e) Risk Response and Reporting
Develop innovative and strategic approaches to managing significant business risks across the organisation.
Interpret risk reporting and make effective decisions based on high-level understanding and expertise.
Required Personal Attributes
LEADERSHIP/BEHAVIOURAL COMPETENCIES
a) Analytical Thinking
Identifies multiple elements of a problem and breaks down each of those elements in detail, showing causal relationships between them.
Uses analytical techniques to identify several solutions and weighs the value of each.
b) Information Seeking & Analysis
Analyses relationships among several parts of a problem or situation.
Anticipates obstacles and thinks ahead about next steps in detail.
c) Integrity
Is willing to end a business relationship because it was associated with unethical business practice.
Is capable of challenging senior management (in a n appropriate and respectable manner) in order to act on espoused values.
d) Leading & Managing Change
Anticipates the need for change when not obvious and influences others to gain support.
Builds sustainable business and organisational capacity to embrace and thrive on change.
Re-engineers and aligns structures, processes, and practices to support and sustain the desired change.
e) Decisiveness
Makes timely decisions about complex issues even when information is missing.
Makes decisions and stands by them even when they are controversial or unpopular.
Grasps critical business opportunities when they arise by making timely decisions.
Click here to apply
We wish you all the best with your applications
Leave a Reply