- Salary
- $300 – $320/hr
- Location
- City of Tshwane Metropolitan Municipality, Gauteng
- Type
- Contract
- Department
- IT
- Education
- Bachelor
- Closing date
- Today
- Source
- Vincere
Description
SARB Procure to Pay Professional Services Version 4 21 November 2019 © Copyright 2016 SARB
Financial Services Department– Procurement Section
370 Helen Joseph Street
Pretoria
Request for Quote (RFQ)
Description of services Required:
DevSecOps Platform Specialist
Date of issue :01 July 2026
Closing date: 09 July 2026 @12h00
Issued by: Professional Services
Copyright Notice: This document contains information that is proprietary and confidential to the South African Reserve Bank who has all rights of copyright in it. Any dissemination, distribution, reproduction, or disclosure in any form of the content of this document is forbidden without prior written permission of the South African Reserve Bank.
SARB Procure to Pay Professional Services Version 4 21 November 2019 © Copyright 2016 SARB
1. Background
The South African Reserve Bank (SARB) has implemented and continues to expand its
DevSecOps capability to enable secure, automated, and efficient software delivery across
delivery teams and programmes. This capability relies on an integrated toolchain supporting
source code management, CI/CD pipeline orchestration, code quality analysis, application
security scanning (SAST/DAST/SCA), secrets and credential handling, artefact repositories,
dashboards and reporting, and supporting integrations. As adoption increases and tool
usage scales across the organisation, the DevSecOps ecosystem has become both more
complex and more operationally sensitive.
Currently, DevSecOps platform administration and operational support are largely
performed on a part-time, best-effort basis by engineers and teams whose primary
responsibilities lie elsewhere. This distributed administration model introduces material risk:
inconsistent configurations, delayed patching and upgrades, configuration drift across
projects/environments, integration instability, slower incident resolution, and reduced ability
to consistently enforce governance and produce audit evidence on demand. These
challenges can directly impact delivery timelines, pipeline reliability, security control
effectiveness, and organisational compliance posture
To address these challenges, SARB requires a dedicated resource to provide centralised
operational ownership and administration of the DevSecOps toolchain. The role will
strengthen operational resilience, reduce risk exposure, improve governance consistency,
and enable delivery teams and security specialists to focus on high-value engineering and
security outcomes rather than routine tool maintenance
2. Objective of this Scope of Work
The objective of this engagement is to appoint a suitably qualified and experienced
DevSecOps Platform Operations Specialist to provide end‑to‑end operational administration
of SARB’s DevSecOps toolchain and associated CI/CD security and quality controls.
• Establishing centralised operational ownership for the DevSecOps toolchain as an
enterprise capability managed as a service (not ad‑hoc support).
• Ensuring secure configuration baselines, standardisation, stability, and availability of
DevSecOps tools and integrations.
• Driving patching and upgrades through a defined cadence to reduce exposure
windows to known vulnerabilities.
SARB Procure to Pay Professional Services Version 4 21 November 2019 © Copyright 2016 SARB
• Enabling consistent governance, access control discipline (RBAC/least privilege),
evidence retention, and audit readiness.
• Improving delivery enablement outcomes: fewer tool‑related incidents, reduced
time‑to‑restore, improved pipeline reliability, and faster onboarding for new
teams/projects through templates and standard patterns.
3. Scope of Services Definition
The scope will include, but will not be limited to, the following services and responsibilities:
3.1 Toolchain Administration & Operational Ownership (End‑to‑End)
• Provide day‑to‑day operational ownership and administration of DevSecOps
platforms and supporting tools used within CI/CD workflows. ,
• Install, configure, maintain, and administer DevSecOps tools (where applicable)
and ensure operational stability across environments.,
• Maintain and enforce secure configuration baselines for DevSecOps tools and
ensure consistency across teams and projects to prevent configuration drift.
• Coordinate and execute tool upgrades, patching activities, plugin updates,
certificate rotations, and compatibility updates in line with security expectations. ,
• Coordinate with infrastructure/platform engineering teams where hosting or
underlying platform activities are required (without taking over infrastructure
ownership).
3.2 Supported Tools / Platforms (Indicative) • The resource must be able to support and administer tools within the DevSecOps
ecosystem, including but not limited to:
• Source code / collaboration platforms and CI/CD tooling such as GitLab.,
• Code quality and analysis platforms such as SonarQube.,
• Application security testing tools including Fortify SAST/DAST scanners.,
• Artefact repository / software supply chain tooling such as JFrog.,
• Supporting testing tools and integrations used across the CI/CD workflow.,
• (Note: The exact tool list is dependent on SARB’s current DevSecOps standard
toolset and adoption per delivery team.)
3.3 Access Management, Governance & Control Operation
• Administer user access, roles, and permissions using RBAC and least privilege
principles; ensure access requests/changes are traceable and logged. ,
SARB Procure to Pay Professional Services Version 4 21 November 2019 © Copyright 2016 SARB
• Conduct routine access governance activities (e.g., access reviews) and maintain
evidence required for audit and assurance stakeholders.
• Ensure logging and audit trails are enabled, retained, and accessible for
governance, investigations, and audit requests. ,
• Support segregation‑of‑duties expectations by ensuring administrative privileges
are controlled through appropriate access mechanisms and reviews.
3.4 Monitoring, Incident Handling & Operational Resilience
• Establish proactive monitoring and health management of DevSecOps tools to
reduce unplanned downtime and pipeline failures. ,
• Provide structured operational support, troubleshooting, and incident resolution
for tool-related issues (including integration failures impacting pipelines). ,
• Implement runbooks and structured troubleshooting approaches to reduce
recurring incidents through root cause remediation.
• Perform capacity management and operational planning to ensure tools remain
stable and scalable as adoption grows.
3.5 Integration Management (CI/CD Ecosystem)
• Maintain and support integrations between CI/CD orchestration, scanning
engines, code quality tooling, artefact repositories, and reporting. ,
• Ensure integration reliability as tools evolve (version changes, certificate
rotations, plugin upgrades, service account token handling).
• Maintain secure handling of service accounts, tokens, and secrets used for
integrations, including secure practices, rotation routines, and traceability
requirements.
•
3.6 Standardisation, Templates, and Enablement Support
• Standardise operating practices across the toolchain to reduce variability and
improve predictability across teams.
• Support faster onboarding of teams/projects by providing standard configurations,
reusable pipeline templates, and operational guidance. ,
• Reduce reliance on vendors/specialist engineers for routine administration by
building repeatable operational routines and internal capability. ,
•
3.7 Documentation, Evidence Management & Reporting
SARB Procure to Pay Professional Services Version 4 21 November 2019 © Copyright 2016 SARB
• Maintain standard operating procedures, technical documentation, and runbooks
for tool administration and support. ,
• Provide structured monthly operational and governance/compliance reporting,
including: tool uptime/health, incidents, patch compliance status, access
governance activity, recurring issues, and planned maintenance. ,
• Maintain evidence packs (e.g., patch records, access logs/review outputs, configuration baseline evidence) to support audit requests and reduce risk of audit findings
The service provider is required to submit a minimum of 3 CV’s that are suitably qualified and experienced resources in order to fulfil the requirements set out below:
4. Consultant Resource
Service Lines Resource
Level Start Date End Date
Hours
Allocated
Bill Rate per
hour [ZAR]
DevSecOps
Toolchain
(Enterprise)
DevSecOps
Platform
Specialist x
1(Mid-
Senior level)
01 August
2026 30 July 2027 2160 R 400 p/h
Disclaimer – Rate per hour is inclusive of the following as set out in Part III Schedule D
clause 4&5:
• Resource rate;
• Supplier mark-up;
• Leave (Annual and Sick leave in accordance to Basic Condition of Employment Section 198 of the Labour Relations Act 66 of 1995 (LRA); and Employee Benefits (i.e. Medical/pension fund etc.)
Key responsibilities:
4.1 Core Deliverables
• Secure configuration baselines and standardisation across DevSecOps tools.
• Defined patching/upgrade cadence and execution aligned to security expectations. ,
• Proactive monitoring and operational health management for DevSecOps tools.
• Incident response runbooks and structured troubleshooting approach.
• Monthly operational and governance reporting (uptime, incidents, patch compliance, access governance). ,
• Audit evidence management and readiness support (access, patching, baselines, logs).
SARB Procure to Pay Professional Services Version 4 21 November 2019 © Copyright 2016 SARB
4.2 KPI Examples (to be tracked month‑on‑month)
• Tool uptime and availability targets (service performance visibility and improvement).
• Patch compliance within defined SLAs (critical/high urgency).
• Reduction in tool‑related security incidents and pipeline-impacting issues. ,
• Improved time‑to‑restore (MTTR) for tool outages or integration failures.
• Reduced onboarding lead times for new teams/projects through standard templates and patterns.
• Zero or reduced audit findings related to DevSecOps tool governance/evidence gaps.
Knowledge, experience and personal competencies
Education and experience:
• Five to eight years’ experience in DevSecOps, DevOps.
• A Bachelor’s degree in Information Technology (IT), Computer Science, or
equivalent qualification (NQF 7) is preferred. Candidates with equivalent experience
and demonstrable skills will also be considered.
Additional Requirements
Knowledge and skills in: industry awareness, quality assurance, continuous improvement, professional development, business continuity planning, IT governance and compliance, collaboration, integration testing, business relationship management, and capacity/performance management.
Attitude and Adaptability
The ideal candidate must demonstrate a proactive, solution-oriented attitude, adaptability to evolving requirements, and a collaborative mindset. They should be comfortable working in an agile environment, embracing continuous learning, and contributing positively to team dynamics.
Day rates as specified herein shall be based on no less than 8 hours per day.
5. Training and Transfer of Knowledge
SARB Procure to Pay Professional Services Version 4 21 November 2019 © Copyright 2016 SARB
Training and knowledge transfer documents to be submitted and presented to SARB
in a traceable and accessible repository to enable smooth handover to SARB
employees when need arises and or at the end of each project.
Minimum knowledge transfer outputs include:
• Operational runbooks per tool (support routines, incident handling, standard fixes).
• Configuration baseline documentation and change control guidance
• Patch cadence plan and evidence retention approach.
• Monthly reporting pack templates and instructions.
6. Reporting
The consultant will report directly to the manager of the unit in terms of managing
deliverables.
The resource must produce monthly reports that include both operational
performance and governance assurance (uptime/health, incidents, patch compliance,
access governance activity, planned maintenance, recurring issues and trend
indicators).
7. Post Implementation Support
As applicable. The role constitutes an ongoing operational service capability and
must provide constinuous support and maintenance of the DevSecOps toolchain for
the duration of the contract.
SARB Procure to Pay Professional Services Version 4 21 November 2019 © Copyright 2016 SARB
8. Terms and Conditions
8.1. Standard terms and conditions of the Temporary Employment Services (TES)
Agreement shall govern this RFQ.
8.2. The following additional terms and conditions will apply:
8.2.1. TES Panel Engagement model
a) In the event that the Customer requires a TES resource, a competitive
process will be followed in which the Customer will execute a procurement
process. A request for quotation (RFQ) process will be followed to obtain
proposals/CVs from Suppliers on the TES Panel for a specific resource role.
b) The panel engagement model will be one that focuses on quality over
quantity in that the Customer will request a limited number of from each
Supplier on the TES panel (based on the category). The Suppliers on the
TES panel will be required to submit a proposal/CV as well as any other
required documentation for the provision of a TES resource for the specific
role/s.
c) The Supplier will therefore endeavour to put forward their best available
candidates for each role needed by the Customer.
d) A clearly defined objective and scope of work, required minimum
qualifications, minimum years of experience, SOW duration including
expected availability dates, and expected deliverables, among other things,
together with the nature and reasons for the temporary engagement, will be
published for the Supplier to respond to. The Supplier must respond to the
Customer request within 7 (seven) Business Days.
e) Failure by the Supplier to respond within the specified time will result in the
Supplier’s proposal not being considered.
SARB Procure to Pay Professional Services Version 4 21 November 2019 © Copyright 2016 SARB
f) The Suppliers will ensure that a prospective candidate makes him/herself
available for a formal interview on the proposed interview date. The
Customer will give reasonable notice of the interview date to the Supplier.
The Parties will ensure that the interview takes place within 10 (ten)
Business Days from the date that the Customer has advised the Supplier
that the prospective candidate has been shortlisted by the Customer.
9. Temporary Employment Service
9.1.1. Supplier will ensure that the temporary employment resources provided by the
Supplier have the necessary tools, for example, laptop (including but not limited
to Office 365 (MS Project or MS Visio as required), anti-virus software, One Drive,
etc.) and cell phone, and if the Service is performed remotely, sufficient data and
reliable connectivity to perform the Service.
9.1.2. In the event that the Service is rendered at a Customer premises, the Customer
will provide parking, a workstation, excluding a laptop and cell phone,
connectivity, printing facilities, etc.
10. Pricing
10.1.1. The Service Fee proposed by the Supplier must be based on a transparent
model, be comparative and market related and the Supplier may be required to
demonstrate how they approached determining the rates and how the rates were
benchmarked against IT industry rates. The model must clearly indicate the cost
elements that constitute the overall rate per resource as follows:
Cost Breakdown element Weight
Resource rate
Employee Benefits *
Mark-up*
Leave benefits
Rate 100
SARB Procure to Pay Professional Services Version 4 21 November 2019 © Copyright 2016 SARB
* The Employee Benefit and Mark-Up is calculated as a percentage of the
Resource Rate.
10.1.2. In the event that the supplier bidder does not provide the resource with Employee
Benefits the cost breakdown must be as follows:
Cost Breakdown element Weight
Resource rate
Mark-up*
Rate 100
* The Mark-Up is calculated as a percentage of the Resource Rate.
10.1.3. The Supplier as the employer of the temporary employment resource will be liable
for payment of the temporary employment resource’s renumeration payment of
overtime, leave and any other employment benefits that may be payable to the
temporary employment resource.
11. Selection
11.1. The Customer will upon receiving the Supplier proposals review and identify the
best suited TES resource for temporary deployment. An interview with the
shortlisted and further selected resource and/or reference checks may be
conducted, at the sole discretion of the Customer.
11.2. The Supplier will advise all prospective candidates upfront of the Customer’s vetting
and security requirements and will not propose any prospective candidate that is
unwilling or unable to comply with the said requirements. Although the Customer
will carry the cost of its own vetting requirements, the Supplier and or the prospective
candidate will be responsible for its own costs in attending to and completing the
vetting forms and attending vetting appointments.
11.3. The Supplier undertakes to, at its own costs, conduct regular credit, qualification
verification, criminal record and employment history, as well as reference checks for
SARB Procure to Pay Professional Services Version 4 21 November 2019 © Copyright 2016 SARB
all TES resources proposed/provided prior to proposing/putting forward such
resources.
11.4. The shortlisted resources will be invited for interviews and will be selected based on
the outcome of the interview.