Hiring.Camp

DevSecOps Platform Operations Specialist (Ongoing Contract)

60 Degrees

·

2 weeks ago

Salary
$300 – $320/hr
Location
City of Tshwane Metropolitan Municipality, Gauteng
Type
Contract
Department
IT
Education
Bachelor
Closing date
Today
Source
Vincere

Description

 

 

SARB Procure to Pay Professional Services Version 4 21 November 2019 © Copyright 2016 SARB

 

 

Financial Services Department– Procurement Section

370 Helen Joseph Street

Pretoria

Request for Quote (RFQ)

Description of services Required:

DevSecOps Platform Specialist

Date of issue :01 July 2026

Closing date: 09 July 2026 @12h00

 

Issued by: Professional Services

 

Copyright Notice: This document contains information that is proprietary and confidential to the South African Reserve Bank who has all rights of copyright in it. Any dissemination, distribution, reproduction, or disclosure in any form of the content of this document is forbidden without prior written permission of the South African Reserve Bank.

 

 

 

SARB Procure to Pay Professional Services Version 4 21 November 2019 © Copyright 2016 SARB

1. Background

The South African Reserve Bank (SARB) has implemented and continues to expand its

DevSecOps capability to enable secure, automated, and efficient software delivery across

delivery teams and programmes. This capability relies on an integrated toolchain supporting

source code management, CI/CD pipeline orchestration, code quality analysis, application

security scanning (SAST/DAST/SCA), secrets and credential handling, artefact repositories,

dashboards and reporting, and supporting integrations. As adoption increases and tool

usage scales across the organisation, the DevSecOps ecosystem has become both more

complex and more operationally sensitive.

 

Currently, DevSecOps platform administration and operational support are largely

performed on a part-time, best-effort basis by engineers and teams whose primary

responsibilities lie elsewhere. This distributed administration model introduces material risk:

inconsistent configurations, delayed patching and upgrades, configuration drift across

projects/environments, integration instability, slower incident resolution, and reduced ability

to consistently enforce governance and produce audit evidence on demand. These

challenges can directly impact delivery timelines, pipeline reliability, security control

effectiveness, and organisational compliance posture

 

To address these challenges, SARB requires a dedicated resource to provide centralised

operational ownership and administration of the DevSecOps toolchain. The role will

strengthen operational resilience, reduce risk exposure, improve governance consistency,

and enable delivery teams and security specialists to focus on high-value engineering and

security outcomes rather than routine tool maintenance

 

2. Objective of this Scope of Work

 

The objective of this engagement is to appoint a suitably qualified and experienced

DevSecOps Platform Operations Specialist to provide end‑to‑end operational administration

of SARB’s DevSecOps toolchain and associated CI/CD security and quality controls.

 

• Establishing centralised operational ownership for the DevSecOps toolchain as an

enterprise capability managed as a service (not ad‑hoc support).

• Ensuring secure configuration baselines, standardisation, stability, and availability of

DevSecOps tools and integrations.

• Driving patching and upgrades through a defined cadence to reduce exposure

windows to known vulnerabilities.

 

 

 

SARB Procure to Pay Professional Services Version 4 21 November 2019 © Copyright 2016 SARB

• Enabling consistent governance, access control discipline (RBAC/least privilege),

evidence retention, and audit readiness.

• Improving delivery enablement outcomes: fewer tool‑related incidents, reduced

time‑to‑restore, improved pipeline reliability, and faster onboarding for new

teams/projects through templates and standard patterns.

 

3. Scope of Services Definition

 

The scope will include, but will not be limited to, the following services and responsibilities:

 

3.1 Toolchain Administration & Operational Ownership (End‑to‑End)

• Provide day‑to‑day operational ownership and administration of DevSecOps

platforms and supporting tools used within CI/CD workflows. ,

• Install, configure, maintain, and administer DevSecOps tools (where applicable)

and ensure operational stability across environments.,

• Maintain and enforce secure configuration baselines for DevSecOps tools and

ensure consistency across teams and projects to prevent configuration drift.

• Coordinate and execute tool upgrades, patching activities, plugin updates,

certificate rotations, and compatibility updates in line with security expectations. ,

• Coordinate with infrastructure/platform engineering teams where hosting or

underlying platform activities are required (without taking over infrastructure

ownership).

 

3.2 Supported Tools / Platforms (Indicative) • The resource must be able to support and administer tools within the DevSecOps

ecosystem, including but not limited to:

• Source code / collaboration platforms and CI/CD tooling such as GitLab.,

• Code quality and analysis platforms such as SonarQube.,

• Application security testing tools including Fortify SAST/DAST scanners.,

• Artefact repository / software supply chain tooling such as JFrog.,

• Supporting testing tools and integrations used across the CI/CD workflow.,

• (Note: The exact tool list is dependent on SARB’s current DevSecOps standard

toolset and adoption per delivery team.)

3.3 Access Management, Governance & Control Operation

• Administer user access, roles, and permissions using RBAC and least privilege

principles; ensure access requests/changes are traceable and logged. ,

 

 

 

SARB Procure to Pay Professional Services Version 4 21 November 2019 © Copyright 2016 SARB

• Conduct routine access governance activities (e.g., access reviews) and maintain

evidence required for audit and assurance stakeholders.

• Ensure logging and audit trails are enabled, retained, and accessible for

governance, investigations, and audit requests. ,

• Support segregation‑of‑duties expectations by ensuring administrative privileges

are controlled through appropriate access mechanisms and reviews.

 

3.4 Monitoring, Incident Handling & Operational Resilience

• Establish proactive monitoring and health management of DevSecOps tools to

reduce unplanned downtime and pipeline failures. ,

• Provide structured operational support, troubleshooting, and incident resolution

for tool-related issues (including integration failures impacting pipelines). ,

• Implement runbooks and structured troubleshooting approaches to reduce

recurring incidents through root cause remediation.

• Perform capacity management and operational planning to ensure tools remain

stable and scalable as adoption grows.

3.5 Integration Management (CI/CD Ecosystem)

 

• Maintain and support integrations between CI/CD orchestration, scanning

engines, code quality tooling, artefact repositories, and reporting. ,

• Ensure integration reliability as tools evolve (version changes, certificate

rotations, plugin upgrades, service account token handling).

• Maintain secure handling of service accounts, tokens, and secrets used for

integrations, including secure practices, rotation routines, and traceability

requirements.

3.6 Standardisation, Templates, and Enablement Support

• Standardise operating practices across the toolchain to reduce variability and

improve predictability across teams.

• Support faster onboarding of teams/projects by providing standard configurations,

reusable pipeline templates, and operational guidance. ,

• Reduce reliance on vendors/specialist engineers for routine administration by

building repeatable operational routines and internal capability. ,

3.7 Documentation, Evidence Management & Reporting

 

 

 

SARB Procure to Pay Professional Services Version 4 21 November 2019 © Copyright 2016 SARB

• Maintain standard operating procedures, technical documentation, and runbooks

for tool administration and support. ,

• Provide structured monthly operational and governance/compliance reporting,

including: tool uptime/health, incidents, patch compliance status, access

governance activity, recurring issues, and planned maintenance. ,

• Maintain evidence packs (e.g., patch records, access logs/review outputs, configuration baseline evidence) to support audit requests and reduce risk of audit findings

 

The service provider is required to submit a minimum of 3 CV’s that are suitably qualified and experienced resources in order to fulfil the requirements set out below:

4. Consultant Resource

Service Lines Resource

Level Start Date End Date

Hours

Allocated

Bill Rate per

hour [ZAR]

DevSecOps

Toolchain

(Enterprise)

 

DevSecOps

Platform

Specialist x

1(Mid-

Senior level)

01 August

2026 30 July 2027 2160 R 400 p/h

Disclaimer – Rate per hour is inclusive of the following as set out in Part III Schedule D

clause 4&5:

 

• Resource rate;

• Supplier mark-up;

• Leave (Annual and Sick leave in accordance to Basic Condition of Employment Section 198 of the Labour Relations Act 66 of 1995 (LRA); and Employee Benefits (i.e. Medical/pension fund etc.)

 

Key responsibilities:

 

4.1 Core Deliverables

• Secure configuration baselines and standardisation across DevSecOps tools.

• Defined patching/upgrade cadence and execution aligned to security expectations. ,

• Proactive monitoring and operational health management for DevSecOps tools.

• Incident response runbooks and structured troubleshooting approach.

• Monthly operational and governance reporting (uptime, incidents, patch compliance, access governance). ,

• Audit evidence management and readiness support (access, patching, baselines, logs).

 

 

 

 

SARB Procure to Pay Professional Services Version 4 21 November 2019 © Copyright 2016 SARB

 

4.2 KPI Examples (to be tracked month‑on‑month)

• Tool uptime and availability targets (service performance visibility and improvement).

• Patch compliance within defined SLAs (critical/high urgency).

• Reduction in tool‑related security incidents and pipeline-impacting issues. ,

• Improved time‑to‑restore (MTTR) for tool outages or integration failures.

• Reduced onboarding lead times for new teams/projects through standard templates and patterns.

• Zero or reduced audit findings related to DevSecOps tool governance/evidence gaps.

Knowledge, experience and personal competencies

Education and experience:

• Five to eight years’ experience in DevSecOps, DevOps.

• A Bachelor’s degree in Information Technology (IT), Computer Science, or

equivalent qualification (NQF 7) is preferred. Candidates with equivalent experience

and demonstrable skills will also be considered.

 

Additional Requirements

 

Knowledge and skills in: industry awareness, quality assurance, continuous improvement, professional development, business continuity planning, IT governance and compliance, collaboration, integration testing, business relationship management, and capacity/performance management.

Attitude and Adaptability

 

The ideal candidate must demonstrate a proactive, solution-oriented attitude, adaptability to evolving requirements, and a collaborative mindset. They should be comfortable working in an agile environment, embracing continuous learning, and contributing positively to team dynamics.

Day rates as specified herein shall be based on no less than 8 hours per day.

 

5. Training and Transfer of Knowledge

 

 

 

 

SARB Procure to Pay Professional Services Version 4 21 November 2019 © Copyright 2016 SARB

Training and knowledge transfer documents to be submitted and presented to SARB

in a traceable and accessible repository to enable smooth handover to SARB

employees when need arises and or at the end of each project.

 

Minimum knowledge transfer outputs include:

• Operational runbooks per tool (support routines, incident handling, standard fixes).

• Configuration baseline documentation and change control guidance

• Patch cadence plan and evidence retention approach.

• Monthly reporting pack templates and instructions.

 

 

6. Reporting

 

The consultant will report directly to the manager of the unit in terms of managing

deliverables.

The resource must produce monthly reports that include both operational

performance and governance assurance (uptime/health, incidents, patch compliance,

access governance activity, planned maintenance, recurring issues and trend

indicators).

 

7. Post Implementation Support

 

As applicable. The role constitutes an ongoing operational service capability and

must provide constinuous support and maintenance of the DevSecOps toolchain for

the duration of the contract.

 

 

 

 

 

SARB Procure to Pay Professional Services Version 4 21 November 2019 © Copyright 2016 SARB

8. Terms and Conditions

 

8.1. Standard terms and conditions of the Temporary Employment Services (TES)

Agreement shall govern this RFQ.

 

8.2. The following additional terms and conditions will apply:

 

8.2.1. TES Panel Engagement model

 

a) In the event that the Customer requires a TES resource, a competitive

process will be followed in which the Customer will execute a procurement

process. A request for quotation (RFQ) process will be followed to obtain

proposals/CVs from Suppliers on the TES Panel for a specific resource role.

b) The panel engagement model will be one that focuses on quality over

quantity in that the Customer will request a limited number of from each

Supplier on the TES panel (based on the category). The Suppliers on the

TES panel will be required to submit a proposal/CV as well as any other

required documentation for the provision of a TES resource for the specific

role/s.

c) The Supplier will therefore endeavour to put forward their best available

candidates for each role needed by the Customer.

 

d) A clearly defined objective and scope of work, required minimum

qualifications, minimum years of experience, SOW duration including

expected availability dates, and expected deliverables, among other things,

together with the nature and reasons for the temporary engagement, will be

published for the Supplier to respond to. The Supplier must respond to the

Customer request within 7 (seven) Business Days.

 

 

e) Failure by the Supplier to respond within the specified time will result in the

Supplier’s proposal not being considered.

 

 

 

 

SARB Procure to Pay Professional Services Version 4 21 November 2019 © Copyright 2016 SARB

f) The Suppliers will ensure that a prospective candidate makes him/herself

available for a formal interview on the proposed interview date. The

Customer will give reasonable notice of the interview date to the Supplier.

The Parties will ensure that the interview takes place within 10 (ten)

Business Days from the date that the Customer has advised the Supplier

that the prospective candidate has been shortlisted by the Customer.

 

9. Temporary Employment Service

9.1.1. Supplier will ensure that the temporary employment resources provided by the

Supplier have the necessary tools, for example, laptop (including but not limited

to Office 365 (MS Project or MS Visio as required), anti-virus software, One Drive,

etc.) and cell phone, and if the Service is performed remotely, sufficient data and

reliable connectivity to perform the Service.

9.1.2. In the event that the Service is rendered at a Customer premises, the Customer

will provide parking, a workstation, excluding a laptop and cell phone,

connectivity, printing facilities, etc.

 

 

10. Pricing

10.1.1. The Service Fee proposed by the Supplier must be based on a transparent

model, be comparative and market related and the Supplier may be required to

demonstrate how they approached determining the rates and how the rates were

benchmarked against IT industry rates. The model must clearly indicate the cost

elements that constitute the overall rate per resource as follows:

 

Cost Breakdown element Weight

Resource rate

Employee Benefits *

Mark-up*

Leave benefits

Rate 100

 

 

 

SARB Procure to Pay Professional Services Version 4 21 November 2019 © Copyright 2016 SARB

* The Employee Benefit and Mark-Up is calculated as a percentage of the

Resource Rate.

 

10.1.2. In the event that the supplier bidder does not provide the resource with Employee

Benefits the cost breakdown must be as follows:

 

Cost Breakdown element Weight

Resource rate

Mark-up*

Rate 100

* The Mark-Up is calculated as a percentage of the Resource Rate.

10.1.3. The Supplier as the employer of the temporary employment resource will be liable

for payment of the temporary employment resource’s renumeration payment of

overtime, leave and any other employment benefits that may be payable to the

temporary employment resource.

 

11. Selection

 

11.1. The Customer will upon receiving the Supplier proposals review and identify the

best suited TES resource for temporary deployment. An interview with the

shortlisted and further selected resource and/or reference checks may be

conducted, at the sole discretion of the Customer.

11.2. The Supplier will advise all prospective candidates upfront of the Customer’s vetting

and security requirements and will not propose any prospective candidate that is

unwilling or unable to comply with the said requirements. Although the Customer

will carry the cost of its own vetting requirements, the Supplier and or the prospective

candidate will be responsible for its own costs in attending to and completing the

vetting forms and attending vetting appointments.

 

11.3. The Supplier undertakes to, at its own costs, conduct regular credit, qualification

verification, criminal record and employment history, as well as reference checks for

 

 

 

SARB Procure to Pay Professional Services Version 4 21 November 2019 © Copyright 2016 SARB

all TES resources proposed/provided prior to proposing/putting forward such

resources.

 

11.4. The shortlisted resources will be invited for interviews and will be selected based on

the outcome of the interview.

 

 

 

 

Skills

CI/CDGitLabDevOpsComplianceProcurement