Cyber Operations Manager
Flash · South Africa - Western Cape
Posted 26 June 2026
Stop applying one at a time.
JobAlertsZA auto-applies to South African jobs like this one for you, overnight. Upload your CV once — we do the applying.
Start free — we apply for you →MINIMUM REQUIREMENTS: • A diploma or degree in Information Technology, Computer Science, Finance, Business Management, or a related field. • A postgraduate qualification or management diploma is advantageous. • Certifications in fraud management (e.g. CFE - Certified Fraud Examiner), cybersecurity (e.g. CompTIA Security+), or IT service management (e.g. ITIL Foundation) are advantageous. • 5 - 8 years' experience in a cybersecurity operations, fraud analytics, operations centre, or critical systems monitoring environment (required), with at least 1 - 2 years in a formal supervisory or team lead capacity. • Prior experience within a financial services or payments environment. REQUIRED KNOWLEDGE / TECHNICAL SKILLS: • Sound knowledge of detection methodologies, alert triage frameworks, and escalation protocols in a real-time monitoring environment. • Demonstrated ability to lead, schedule, and performance-manage shift-based operational teams. • Proficiency in incident and case management tools. • Strong working knowledge of payment systems and transaction processing (e.g. EFT, card schemes, real-time payments). • Ability to produce operational reports, shift performance summaries, and management information for senior stakeholders. • Hands-on experience with Flash or comparable payment processing platforms is advantageous. • Exposure to monitoring or analytics tools is advantageous. • Familiarity with cloud-native security tooling. • Working knowledge of AML, or relevant South African financial regulatory frameworks (e.g. SARB, POPIA) is advantageous. • Experience authoring or maintaining SOPs, runbooks, and operational process documentation is advantageous. • Experience in red team / blue team exercises, penetration testing frameworks, or threat modelling methodologies is advantageous. COMPETENCIES / ATTRIBUTES: • Leadership & people development - coaches, motivates, and grows a team across rotating shifts, building a high-performance monitoring culture and addressing performance gaps proactively. • Decision-making under pressure - exercises sound, timely judgement during high-severity cyber, fraud or system incidents, often with incomplete information and under time constraints. • Analytical thinking - interprets alert patterns, incident data, and team performance metrics to identify systemic risks and improvement opportunities. • Strategic analytical thinking – synthesis security telemetry, fraud data, and operational metrics to identify systemic risks, detection gaps, and strategic improvement priories beyond the immediate incident. • Effective communication - conveys complex operational and cyber or fraud-related information clearly to the team, senior management, and cross-functional stakeholders, both verbally and in written reports. • Accountability & ownership - holds end-to-end accountability for shift operations, SLA adherence, and team compliance with protocols. • Planning & organising - manages shift rosters, workload allocation, and operational priorities to sustain 24/7 monitoring coverage without gaps. • Stakeholder engagement - builds effective working relationships with information security, fraud, technology, compliance, risk, and business teams to align monitoring activities with broader organisational goals. • Continuous improvement - proactively identifies process gaps, false-positive trends, and tooling limitations, and drives enhancements to improve detection effectiveness and team efficiency. We are looking for leaders who provide ongoing coaching and feedback, proactively manage team performance, and support employee career development. Ideal candidates will excel in hiring and retaining high performers, actively managing change, and role modelling behaviours that align with our culture and values. #LI-AR1