Information Risk and Privacy Manager
3 weeks ago
Information Risk and Privacy Manager page is loaded## Information Risk and Privacy Managerremote type: Fully On-Sitelocations: Kenilworth - Cape Towntime type: Full timeposted on: Posted Todaytime left to apply: End Date: November 17, 2025 (5 days left to apply)job requisition id: JR It's fun to work in a company where people truly BELIEVE in what they're doingResponsible for supporting and executing the strategic direction and roadmap for improvement of IT Governance, Risk, and Compliance in line with the overall Pick n Pay Information Security Charter and key Information Security principles. This extends to leading, implementing, and supporting the related programs of work to implement related policies, frameworks, structures, processes, controls, and technology. It also requires managing and executing various risk management and control improvement activities in support of our business and Information and Technology Services. This includes ensuring compliance with relevant external and internal requirements, legislation, and regulations. This role also includes supporting and driving the ascription to relevant frameworks and related processes for the ongoing management of the IT GRC activities.Minimum Requirements* Relevant professional certification(s) such as CRISC, CISA, CISM and/or CGEIT (or similar)* Minimum of 5 years’ work experience in the GRC space* Understanding of relevant frameworks, guidelines, and standards (specifically NIST CSF and PCI-DSS)* Understanding of relevant regulatory requirements and standards such as PCI, POPI, KING, EMV, etc.* Experience PCI-DSS Assessments* Experience in and strong understanding of IT Governance, Information Security, Privacy, IT Risk, Internal/External Audit related concepts* Experience working in a multi-vendor and outsourced IT environment (preferred)Competencies* Strong interpersonal capabilities to engage senior stakeholders, business owners and risk community* Have a collaborative and business enabling mindset (not purely compliance or audit)* Excellent written and verbal communication skills, including the ability to report and communicate technical concepts to technical and non-technical audiences* Advanced analytical and problem-solving skills, with the ability to derive practical solutions to complex problems* Ability to work both independently and as part of a team (interpersonal and collaborative skills) to deliver quality work product in a timely fashion in a fast-paced environment* Ability to maintain strict confidentiality* A strong desire to learn and improve. Also, must be able to quickly change own paradigms and ideas when new options or possibilities present themselves.* A strong passion for the mission and vision of the Pick n Pay business, our customers, and staff**IT Governance*** Maintain the overarching GRC Framework linking to the Info-Risk, Security and Privacy control frameworks, driven by the overall GRC and Information Security strategies* Establish and maintain a common language with senior management and executives to ensure that GRC exposures are accurate, clear, understood, and communicated to relevant stakeholders* Develop, review and support the roll-out of the relevant frameworks, policies, standards, and guidelines as well as key security and privacy controls, while ensuring alignment with the supporting IT operational processes* Coordinate with Internal/External Audit and Regulatory Reviews to ensure good quality, and that actionable management comments are agreed as output from such reviews* Benchmark and mature the IT control environment aligned with industry best practices to achieve agreed maturity levels* Establish and oversee processes to ensure that IT operations are monitored for compliance to the applicable policies* Develop, monitor, and support the reporting on Key Risk Indicators (KRIs) for each IT HOD relating to information risk, security, privacy, and compliance matters* Provide support and participate in business impact analyses performed to enhance the IT Business Continuity and Disaster Recovery Plans in alignment with the overall Business Continuity efforts for the enterprise* Actively promote the importance and value of good Governance, Risk and Security practices and a risk aware culture as well as support the corporate-wide User Awareness campaign, which includes developing relevant training material content as needed* Be a trusted adviser to both business and IT for technology and information-related decisions* Participate and provide input in various forums (such as regular Management meetings, Information Security and Risk forums, etc.), both to support oversight of operating control effectiveness and to facilitate the continuous improvement of key control measures and practices* Drive operational process and performance improvements to reduce cost of failure or rework* Mature and deliver Management Information Systems reporting tailored to the relevant audience (IT and business related.)* Maintain up to date knowledge of GRC, Information Security and Privacy best practices, including the evaluation of relevant emerging technologies, opportunities, and threats* Assist Pick n Pay subsidiaries as needed through training, consultative advice and sharing of material* Provide SME support for projects and business-as-usual activities, with a specific focus on the IT Governance, Information Risk, Information Security, Privacy and Compliance related matters**Information Risk Management*** Mature the overall Information Risk Framework to drive value not only for IT but also for the business* Identify risk tolerance levels and risk appetite based on the expectations from IT and the business* Perform and manage a series of internal risk assessments based on the IT landscape’s potential risk exposures* Perform an annual review of the current and future risk scenarios (per IT division) linked to the current IT risk appetite ensuring that this translates into the applicable roadmaps for the next financial year* Track the high-impact risk exposures versus allocated budget, projects and/or BAU activities to remediate the prioritised risk exposures on a bi-annual basis* Designing, drive, and monitor control remediation according to a prioritised, risk-based approach (whether project- orientated, or BAU) in collaboration with business and IT management* Support the business and/ or risk owners control remediation for threats and/or exposures* Manage and mature the IT Risk Register (SharePoint) and Risk Dashboard (Power-BI) to enhance the management and reporting of IT-related risk exposures (including audit findings)* Coordinate regular review of controls* Manage and sustain the 3rd-party risk management practices, including coordinating the Data/ Information Asset Management process, and engaging with risk owners in conjunction with Legal and/or Corporate Procurement* Drive security-by-design and privacy-by-design principles (especially within the project management space)* Coordinate the collation of IT support to mature group cyber insurance in cooperation with Investor Relations**Information Security Management*** Maintain the Information Security Management System (ISMS) by focusing on data protection which spans across the group and govern all business units* Maintain and monitor compliance to the NIST Cyber Security Framework by evaluating the current practices against the set of security requirements* Own and manage the information policies’ exemption process together with the applicable IT HODs* Actively promote the importance and value of good Information Security Practices* Assist in developing and monitoring the execution of the annual Cyber Security Plan and Roadmap to ensure the effectiveness of the design and implementation of security controls in support of a sustainable and measurable information security effort*#J-18808-Ljbffr
-
Information Risk and Privacy Manager
2 weeks ago
Cape Town, Western Cape, South Africa Pick n Pay Full time R1 500 000 - R2 500 000 per yearIt's fun to work in a company where people truly BELIEVE in what they're doingResponsible for supporting and executing the strategic direction and roadmap for improvement of IT Governance, Risk, and Compliance in line with the overall Pick n Pay Information Security Charter and key Information Security principles. This extends to leading, implementing, and...
-
Information Risk and Privacy Manager
4 days ago
Cape Town, Western Cape, South Africa Pick n Pay Full time R1 200 000 - R2 400 000 per yearIt's fun to work in a company where people truly BELIEVE in what they're doingResponsible for supporting and executing the strategic direction and roadmap for improvement of IT Governance, Risk, and Compliance in line with the overall Pick n Pay Information Security Charter and key Information Security principles. This extends to leading, implementing, and...
-
Information Privacy Manager
2 weeks ago
Cape Town, South Africa dLocal Full time**Why you should join dLocal** You will be a part of an amazing global team who makes it all happen, in a flexible, remote-first dynamic culture with travel, health, and learning benefits, among others. Being a part of dLocal means working with 600+ teammates from 25+ different nationalities and developing an international career that impacts millions of...
-
Cape Town, South Africa Rain Full time**Job Purpose**: The person will be responsible for developing and implementing risk management strategies and compliance programs that identify and mitigate against cybersecurity and data privacy related risks, ensuring that the business follows regulatory guidelines and maintains the reasonable and required standards. **Key Responsibilities**: - Manage,...
-
Data Privacy Analyst
4 days ago
Cape Town, Western Cape, South Africa Boardroom Appointments Full timeKey purpose:Support the company on implementing and integrating data governance & privacy practices, in line with regulatory requirements, across the Group to enhance privacy maturity, and ensure compliance with privacy laws and regulations when processing personal information. Duties and responsibilities: IT Privacy Assessments Conduct and maintain privacy...
-
Data Privacy Analyst
2 weeks ago
Cape Town, South Africa ABC Worldwide (Pty) Ltd Full time**Data Privacy Analyst** Implementing and integrating data governance & privacy practices, in line with regulatory requirements, across the Group to enhance privacy maturity, and ensure compliance with privacy laws and regulations when processing personal information. **KEY RESPONSIBILITIES** IT Privacy Assessments - Conduct and maintain privacy processes...
-
Senior Manager Privacy
1 week ago
Cape Town, South Africa Atlas Technology Solutions Full timeWe believe in a world where growth thrives across borders and cultures. As an EOR, Atlas employs people to work for companies anywhere in the world. Before we came along, the only businesses offering a similar solution were essentially brokers. They'd outsource your HR and payroll services to third-party providers in different countries. Today, we're the...
-
Privacy Specialist
3 weeks ago
Cape Town, South Africa Resourgenix (Pty) Ltd Full timeOur client is seeking a Privacy Specialist to join their team and help drive the delivery of our privacy programme. As a Privacy Specialist you'll be supporting the delivery of the privacy programme across the business by supporting the Privacy Operations Team Lead and the Group Privacy Operations & Projects Manager in managing data subject rights requests...
-
Privacy Counsel
19 hours ago
Cape Town, South Africa Bolt Technology Full timeThe main task of Privacy Counsel is to perform a critical first-line support function from within the Privacy Team. Part of a fast-expanding international team, in this HQ function Privacy Counsel will be expected to provide best-in-class legal advice and counsel support on privacy matters across the Bolt Group companies and verticals. In particular, this...
-
Associate Privacy and Security Counsel
1 week ago
Cape Town, South Africa DigiCert Full time**ABOUT DIGICERT** We're a leading, global security authority that's disrupting our own category. Our encryption is trusted by the major ecommerce brands, the world's largest companies, the major cloud providers, entire country financial systems, entire internets of things and even down to little things like surgically embedded pacemakers. We help companies...