Head of SecDevOps Re-advertisement
1 month ago
Job category: Others: Transport and Logistics
Location: Johannesburg
Contract: Permanent
Remuneration: Market Related
EE position: Yes
About our company
ATNS
Introduction
Applications are invited for the position of Head of SecDevOps based at Head Office (Bruma). The successful applicant will be reporting to the Chief Technology & Information Officer. Overview: To develop and implement a SecDevOps strategy and roadmap in line with the vision and strategy of the organization. To leverage evolving practices in security, application development, operations and sourcing to provide a world class, resilient technology environment that enables taking full advantage of opportunities in the digital economy. To implement and oversee Secure Software Development Lifecycle (SSDLC) best practices, fostering a culture of security excellence within cross-functional teams. To lead the secure development and maintenance of ATNS digital platforms, in collaboration with relevant stakeholders.
Major Activities
- Develop the SecDevOps strategy to contribute to the overall departmental and organizational strategy.
- Build upon the International Civil Aviation Organisation’s aviation cybersecurity strategy to ensure safety, security and continuity of ATNS services in a world increasingly jeopardized by cybersecurity threats.
- Actively participate in the development and implementation of the national aviation cybersecurity strategy.
- Drive the adoption of best practices in software development, configuration and support that integrate principles of lean thinking, continuous improvement and agility, e.g. test-driven development, continuous integration, etc.
- Lead the secure development and maintenance of ATNS digital platforms, supported by peers working on infrastructure management, data and analytics, and information security, in line with the ATNS modernization strategy.
- Establish together with South African Civil Aviation Authority an information sharing group for governance and compliance consisting of all aviation ecosystem role players with a trust framework that can be leveraged by the RSA aviation community as a whole.
- Participate in relevant regional and international fora.
- Collaborate effectively with technology peers and colleagues across the organization.
- Lead application rationalization informed by business value analysis of the application inventory.
- Transform the application landscape through scalable applications and technology, enabling business efficiency and growth.
- Apply strategic judgement to inform build or buy decisions.
- Ensure that all applications adhere to relevant standards.
- Provide cybersecurity technical leadership and guidance in relevant local, regional and international bodies.
- Develop and maintain the Applications roadmap in line with agreed priorities, initiatives and expected operational service levels.
- Ensure compliance with relevant legal and policy frameworks.
- Develop and maintain relevant policies, processes, procedures and standards.
- Facilitate secure software development lifecycle, ensuring the infusion of security into every phase of systems development and operation.
- Provide cybersecurity controls (covering people, processes and technology) designed to protect CNS systems, networks and data from digital attacks.
- Schedule and implement regular maintenance of applications in order to maintain system reliability and stability.
- Drive cybersecurity controls to ensure that the aviation infrastructure systems and information systems ranging from legacy systems to next generation satellite communication systems are resilient to cyber-attacks and remain safe and trusted globally, whilst continuing to innovate and grow in all the defined or determined areas within the South African sovereign and delegated continental and oceanic airspace.
- Manage solution delivery initiatives, build or buy, to ensure quality coding and/or that solutions are delivered efficiently.
- Collaborate with all relevant technology peers in every phase of the value chain: project management, architecture, information security, quality assurance, business and technical specifications, etc.
- Facilitate continuous improvement of the application development/sourcing processes.
- Establish appropriate metrics for performance measurement of the Applications Team.
- Risk Management: Identify, evaluate, and mitigate security risks, partnering with teams to conceive risk mitigation strategies.
- Agile Collaboration: Actively participate in all planning meetings and stand-ups, addressing security concerns and risks within an agile development framework.
- Incident Response: Lead and coordinate security incident response, encompassing investigation and resolution.
- Policy and Process Management: Create, revise, or archive security policies and documented processes in alignment with industry best practices.
- Technology Trends: Remain abreast of emerging technology trends, frameworks, and security methodologies to bolster software security.
- Security Advocacy: Cultivate a culture of secure coding and configuration across all applications and features.
- Leadership and Team Management: Oversee and mentor a team of DevSecOps engineers and specialists. Set clear objectives, provide consistent feedback, and support team members' professional growth. Foster a collaborative and innovative team milieu.
- DevSecOps Strategy: Formulate and execute a DevSecOps strategy that aligns with the organization's objectives. Define and continuously enhance DevSecOps processes and practices.
- Automation and Tools: Implement and manage SecDevOps automation tools and technologies. Continuously evaluate and select appropriate tools to augment the SecDevOps pipeline.
- Maintain constructive and productive stakeholder relations across the business and with relevant external related parties.
- Visible and active leadership to the organization’s applications landscape.
- Develop a RACI matrix that clearly identifies and assigns information security roles for the various ATSEPs and other stakeholders.
- Identify key risks, develop and implement effective mitigating plans and actions in order to avoid or minimize relevant risks, and report and raise these risks in the appropriate forums.
- Ensure optimization of resources through effective deployment and management of skills.
- Develop a robust cybersecurity culture through structured training and awareness programs to capacitate the ATSEPs from end to end i.e. Cybersecurity Education, Training and Skills.
- Ensure that staff is managed in accordance with HC policies, processes and practices.
- Ensure continuous development of staff. Ensure that staff remain suitably trained to achieve expected performance outcomes in a dynamic technology environment.
- Ensure effective management of finance in line with business priorities and within financial parameters.
Minimum Qualifications
Bachelor’s degree in Information Technology, Information Systems or a related field.
Post Graduate Degree in Information Technology, Information Systems or a related field.
Master's degree preferred.
Certification: PMI-ACP, OSCP, CEH, CISSP. Other certifications like TOGAF, ITIL, COBIT or related certifications would be an advantage.
Knowledge of cloud technologies (Infrastructure or DevOps or Solution Architecture), Certification will be advantageous.
ISACA Professional Registration is an advantage.
Leadership qualification in a field relevant to aviation/aerospace/aeronautics.
Seasoned professional required with minimum 10 years' experience in Information Technology of which at least 5 years' experience in SecDevOps or a related field, and 5 years' experience in managing technical team(s).
Experience in a high technology electronic environment with in-depth knowledge and understanding of aeronautical communication, navigation, surveillance and satellite systems is also required.
Must be experienced in SecDevOps and Agile software development principles, an advocate of lean thinking and display an appreciation for cybersecurity and continuous improvement.
Key knowledge requirements:
Excellent stakeholder management: tactful, diplomatic and empathetic to clients, colleagues and subordinates.
In-depth working knowledge of ICAO global and regional plans and SARP’s.
A working knowledge of ITU regulations.
Demonstrated experience in DevSecOps leadership and security management.
Secure Development: Strong knowledge of secure software development practices and methodologies.
Security Standards: Familiarity with OWASP top 10 and other security standards.
Vulnerability Management: Proficiency in vulnerability management tools and practices.
Proven experience with continuous integration and continuous delivery (CI/CD) pipelines, including tools like Jenkins, Code Pipeline, and CodeBuild.
Knowledge of the aviation regulatory framework and relevant legislation.
Proficiency with Version Control tools such as GitHub, GitLab, or Bitbucket.
Familiarity with CI/CD platforms such as Jenkins, GitLab CI/CD, DevOps, CircleCI, or Travis CI.
Containerization and Orchestration: Experience with containerization technologies like Docker, Kubernetes, Docker Swarm, and OpenShift.
Cloud Experience: Proficiency in cloud platforms like Owncloud, AWS, Openstack, Azure, or Google Cloud Platform.
Familiarity with security frameworks such as OWASP and SANS.
Hands-on experience with DevSecOps tools such as SonarCloud, SonarQube, OWASP ZAP, Burp Suite, Snyk, Fortify, and QualysGuard.
#J-18808-Ljbffr
-
Head of SecDevOps
2 months ago
Johannesburg, South Africa ATNS SOC Limited Full timeJob category: Others: Transport and Logistics Location: Johannesburg Contract: Permanent Remuneration: Market Related EE position: Yes Introduction Applications are invited for the position of Head of SecDevOps based at Head Office (Bruma). The successful applicant will be reporting to the Chief Technology & Information Officer. The role involves...
-
Munich Re Graduate Trainee
5 months ago
Johannesburg, South Africa Munich Re Full timeMunich Re Graduate Trainee Fixed Term Contract **Company** Munich Re **Location** Johannesburg, South Africa **Munich Reinsurance Company of Africa Limited (MRoA) has been operating in South Africa for over 50 years, although the Munich Re (Group) was active on the Continent via Munich Re in Munich for some years prior to commencing the Southern African...
-
Head of Enterprise Architecture
2 months ago
Johannesburg, South Africa ATNS SOC Limited Full timeHead of Enterprise Architecture - Re-advertisement Listing reference: atns_000504 Listing status: Online Apply by: 8 October 2024 Position summary Job category: Others: Transport and Logistics Location: Johannesburg Contract: Permanent Remuneration: Market Related EE position: Yes About our company ATNS Introduction Applications are invited for...
-
Head of Data Management
2 months ago
Johannesburg, South Africa ATNS SOC Limited Full timeHead of Data Management - Re-advertisement Listing reference: atns_000503 Listing status: Online Apply by: 8 October 2024 Position summary Job category: Others: Transport and Logistics Location: Johannesburg Contract: Permanent Remuneration: Market Related EE position: Yes About our company ATNS Introduction Applications are invited for the...
-
Re-advertisement Head of Infrastructure
2 months ago
Johannesburg, South Africa AUDA-NEPAD Full timeThe African Union Development Agency invites applicants who are citizens of African Union Member States for the post of **Head of Infrastructure, Digitalisation & Energy Division**.** Under the supervision of the Director of Economy - Infrastructure, Trade, Industrialisation and Regional Integration, the Head of Infrastructure, Digitalisation & Energy will...
-
Business Development Specialist
2 months ago
Johannesburg, South Africa BAIC Automobile SA Full time**Job Title: Business Development Specialist (Re-advertised)** **Location**: Johannesburg **Job Type**: Full-time **COMPANY OVERVIEW**: BAIC Automobile SA, is an automotive manufacturing company, based in the Coega IDZ, dedicated to producing high-quality vehicles that exceed customer expectations. With a focus on innovation, sustainability, and...
-
Life Actuarial Pricing Specialist
1 month ago
Johannesburg, Gauteng, South Africa Munich Re Full timeActuarial Pricing Analyst - Life ReinsuranceWe are seeking an experienced Actuarial Pricing Analyst to join our Life Retail Product and Pricing department. As a key member of our team, you will be responsible for performing experience reviews and pricing for all regions, ensuring that Munich Re's actuarial and risk management standards are met.Your Key...
-
Internal Auditor
6 months ago
Johannesburg, South Africa Munich Re Full timeInternal Auditor Career Level 3 **Company** Munich Re **Location** Johannesburg, South Africa As the world's leading reinsurance company with 40,000 employees at over 50 locations in all parts of the world, Munich Re introduces a paradigm shift in the way you think about insurance. **By turning uncertainty into manageable risk we enable fundamental...
-
Life Data Team Leader
5 months ago
Johannesburg, South Africa Munich Re Full timeLife Data Team Leader Career Level 4 **Company** Munich Re **Location** Johannesburg, South Africa **Munich Reinsurance Company of Africa Limited (MRoA) has been operating in South Africa for 50 years, although the Munich Re (Group) was active on the Continent via Munich Re in Munich for some years prior to commencing the Southern African operation in...
-
Actuarial Analyst
6 months ago
Johannesburg, South Africa Munich Re Full timeActuarial Analyst (FTC) **Company** Munich Re **Location** Johannesburg, South Africa **Munich Reinsurance Company of Africa Limited (MRoA) has been operating in South Africa for over 50 years, although the Munich Re (Group) was active on the Continent via Munich Re in Munich for some years prior to commencing the Southern African operation in Johannesburg...
-
Actuarial Graduate Trainee
6 months ago
Johannesburg, South Africa Munich Re Full timeActuarial Graduate Trainee Graduate Trainee Fixed Term Contract **Company** Munich Re **Location** Johannesburg, South Africa **Munich Reinsurance Company of Africa Limited (MRoA) has been operating in South Africa for over 50 years, although the Munich Re (Group) was active on the Continent via Munich Re in Munich for some years prior to commencing the...
-
Senior Actuarial Analyst
6 months ago
Johannesburg, South Africa Munich Re Full timeSenior Actuarial Analyst Career Level 3 **Company** Munich Re **Location** Johannesburg, South Africa Munich Reinsurance Company of Africa Limited (MRoA) has been operating in South Africa for over 50 years, although the Munich Re (Group) was active on the Continent via Munich Re in Munich for some years before commencing the Southern African operation in...
-
Life Actuarial Pricing Analyst
4 months ago
Johannesburg, South Africa Munich Re Full timeCareer Level 3 We are looking for an Actuarial Analyst for our Technical Pricing Team which falls under the Life Retail Product and Pricing department. The Life Retail Product and Pricing department ensures profitable reassurance business across South Africa and Sub Saharan Africa. This adds to the value of new business and embedded value by pricing...
-
Risk Trainee
5 months ago
Johannesburg, South Africa Munich Re Full timeRisk Trainee Risk Trainee **Company** Munich Re **Location** Johannesburg, South Africa Munich Reinsurance Company of Africa Limited (MRoA) has been operating in South Africa for over 50 years, although the Munich Re (Group) was active on the Continent via Munich Re in Munich for some years before commencing the Southern African operation in Johannesburg...
-
Senior Actuarial Consultant
4 weeks ago
Johannesburg, Gauteng, South Africa Munich Re Full timeRole OverviewAs the Senior Actuary for MRoA Structured Solutions, you will play a pivotal role in developing innovative reinsurance solutions to support the business goals of our life assurance clients. Reporting to the Head of MRoA Structured Solutions, you will be responsible for analyzing the financial, trading, and regulatory environment to identify...
-
Senior Structured Solutions Actuary
6 months ago
Johannesburg, South Africa Munich Re Full timeSenior Structured Solutions Actuary Career Level 4 **Company** Munich Re **Location** Johannesburg, South Africa **Your Business Unit**: The MRoA Structured Solutions business unit is the leading player in the Sub-Saharan region that develops tailored cash financing, profitability management and capital optimisation reinsurance solutions for its life...
-
Life Actuarial Analyst
3 months ago
Johannesburg, South Africa Munich Re Full timeLife Actuarial Analyst - Experience Studies Career Level 3 **Company** Munich Re **Location** Johannesburg, South Africa We are currently looking for an Actuarial Analyst for our Experience Studies Team reporting to the Head of Experience Analysis and Terms of Trade in the Life Department. Established in 1968, Munich Reinsurance Company of Africa serves...
-
Digital Advertising Strategist
3 weeks ago
Johannesburg, Gauteng, South Africa InMobi Full timeOur company, InMobi, is a leading global advertising platform that powers our customers' growth by helping them engage their audiences and drive real connections.We are seeking an experienced Account Manager with a strong background in search engine marketing to join our team. As an Account Manager, you will be responsible for managing a portfolio of...
-
Terms of Trade Actuary
2 months ago
Johannesburg, South Africa Munich Re Full timeTerms of Trade Actuary **Company** Munich Re **Location** Johannesburg, South Africa **Career Level 4** We are currently looking for a Senior Actuary for our Terms of Trade Team reporting to the Head of Experience Analysis and Terms of Trade in the Life Department. Established in 1968, Munich Reinsurance Company of Africa serves life and non-life...
-
Terms of Trade Actuary
1 month ago
Johannesburg, South Africa Munich Re Full timeTerms of Trade Actuary Company Munich Re Location Johannesburg , South Africa Career Level 4 We are currently looking for a Senior Actuary for our Terms of Trade Team reporting to the Head of Experience Analysis and Terms of Trade in the Life Department. Established in 1968, Munich Reinsurance Company of Africa serves life and non-life reinsurance clients...