IT Governance Risk and Compliance Specialist

6 months ago


Johannesburg, South Africa Affirmative Portfolios Full time

**Information Technology**
**JHB North**
***:
**IT Governance Risk and Compliance Specialist (GRC)**

**R771 300p/a - Sandton - Permanent**

**Job Summary**
- The specialist will identify, classify, and document control issues environment by documenting assessment results, recommending corrective action, tracking remediation, evaluating policy and control standard exceptions, and regularly report to IT management
- Also assist with internal and external auditors performing their mandates.

**Qualifications**
- Minimum qualifications: National Diploma in IT/Bachelor or relevant equivalent to NQF Level 6
- IT governance certification or ITIL & COBIT mandatory; CRISC, CISSP, CISA or CGEIT certification is strongly preferred
- An active member of a professional body within ICT

**Experience & Technical Skills**
- Minimum of 7 years’ experience in IT Governance Risk and Compliance related experience
- Experience with GRC methodologies, tools, and enablers
- Hands-on experience with implementation and monitoring of one or more IT governance frameworks (COBIT, ITIL, ISO, PRINCE II, etc )
- Excellent understanding of IT operational processes and controls including projects
- Excellent understanding of Regulatory requirements facing the IT environment (PCI DSS, POPIA, GDPR)
- Must be persuasive and be able to communicate GRC related concepts to a broad range of technical and non-technical staff
- Be able to map business needs to technology solutions
- Must have a solid understanding of IT governance, Risk management and compliance frameworks
- Solid understanding of security risks and preventative controls

**IT Governance Frameworks**
- Assist in the development and implementation of IT governance, frameworks, IT controls, recommendations from various assessments, and action plans following an appropriate methodology approved by management and aligned with international standards (e.g. COBIT, ITIL, ISO, NIST, PRINCE II, CCM, etc )
- Assist in the implementation of IT governance, Risk, and compliance in line with the company approved policies and frameworks
- Assist in the development and implementation IT Governance, Risk Management and Compliance policies, processes, procedures, and IT controls training materials to keep fellow IT colleagues well-informed of relevant industry, legislative and regulatory requirements, and changes
- Develop, implement, and monitor reporting mechanism for IT governance, Risk management, and Audit, to support compliance and highlight areas of exposure to management
- Support the development of policies, processes, and procedures for the IT division, including control document reviews, meeting coordination, assessment, finding mediation, assisting control owner with remediation plan development, tracking findings through remediation, progress monitoring, reporting, and escalation
- Assess the current adequacy of the business continuity / disaster recovery plans in conjunction with risk management, potential threats to the systems, and then the calculate the impact of potential adverse events
- Participates in the development, adoption and compliance4 of IT governance framework across various governance committees and structures
- Perform design and process analysis for IT business processes that impact IT governance
- Facilitate adoption and continuous improvement of planning practices and processes within IT and the business as a whole

**IT Risk Management, Audit**
- Act as a risk and compliance champion for the IT Division
- Perform ad-hoc duties as assigned to ensure the smooth functioning of the IT GRC function and maintain a good reputation with Auditors, compliance, and risk departments
- Maintain and monitor the IT risk framework as aligned to the companies approached enterprise risk management framework
- Maintain the IT risk register in collaboration with enterprise risk management and drive implantation of mitigation controls of risks (through responsible Senior Managers and/or line of business) within defined period
- Integrate Cyber Risk Register management practices, processes, procedures, and activities
- Co-ordinate periodical internal risk assessments in various IT functions and ensure vulnerability remediation and tracking, examples:

- IT Audits
- Application access reviews
- Active directory reviews
- Security, network, and vulnerability assessments
- Conduct IT risk assessments (including projects risks), and analyse the effectiveness of control activities, and report on them with actionable recommendations
- Ensure that IT risks are identified and monitored continuously
- Review identified security risks and breaches to ensure the IT assets (software and hardware) and information are always appropriately secured
- Ensure visibility, management and escalation of IT risks impacting the delivery of IT services
- Work directly with the clients, third parties and other internal departments such as risk management to facilitate IT risk analysis and risk management pro



  • Johannesburg, South Africa National Risk Managers (Pty) Ltd Full time

    A Medical Insurance Company based in Benoni, Gauteng is looking for a **IT Governance, Risk and Compliance Specialist** who will assist in the development and implementation of IT Governance frameworks and IT controls following appropriate methodology approved by management that is aligned with international and financial industry standards (e. g, GOI...


  • Johannesburg, South Africa National Risk Managers (Pty) Ltd Full time

    A Compliance Company based in Benoni is looking for a IT Governance, Risk and Compliance Specialist who will Assist in the development and implementation of IT Governance frameworks and IT controls following appropriate methodology approved by management that is aligned with international and financial industry standards. And advise the company on best...


  • Johannesburg, South Africa IT Ridge Technologies Full time

    This role will have broad accountability for ICT governance, risk and compliance related functions including ICT policies, standards, risk, and controls management. This role is a key contributor to IT Strategy, which includes developing frameworks aligned to the appropriate industry standards, creating the required forums, and establishing appropriate...


  • Johannesburg, South Africa Scitech Placements Full time

    We are looking for a IT Governance, Risk and Compliance Specialist, East Rand **Overview**: As an IT Governance, Risk and Compliance Specialist, you will be responsible for assisting in the development and implementation of IT Governance frameworks and IT controls. This will involve working closely with cross-functional teams to identify, assess, and...


  • Johannesburg, South Africa The Recruitment Agency South Africa (TRASA) Full time

    **IT Governance, Risk and Compliance Specialist** **1. Job Summary** Assist in the development and implementation of IT Governance frameworks and IT controls following appropriate methodology approved by management that is aligned with international and financial industry standards (e. g, GOI standards (PA), Joint Standards (PA & FSCA), COBIT, ITIL, ISO,...


  • Johannesburg, Gauteng, South Africa IT Ridge Technologies Full time

    This key role is responsible for spearheading the development of a comprehensive IT governance framework that encompasses risk management, compliance, and internal controls.Duties and Responsibilities:GovernanceEstablish a robust IT governance operating model, outlining the mandate and inter-relationship between governance structures.Monitor the...


  • Johannesburg, Gauteng, South Africa IT Ridge Technologies Full time

    This role plays a critical part in IT Strategy, overseeing ICT governance, risk, and compliance functions, including policy development, risk management, and control monitoring.Key Responsibilities:GovernanceDevelop and maintain the IT governance operating model, defining the mandate and relationships between governance structures.Monitor and assess the...


  • Johannesburg, South Africa Six Sense Full time

    Gauteng, JHB - Northern Suburbs - Annually Cost To Company (Market related) A well-established short term insurer is seeking to appoint a IT Governance Risk and Compliance (GRC) Specialist **Qualifications**: - National Diploma in IT /Bachelor or Relevant equivalent to NQF Level 6 - IT Governance certification or ITIL & COBIT mandatory; CRISC, CISSP, CISA...

  • Regulatory Risk

    7 months ago


    Johannesburg, South Africa Sanlam Full time

    **What will you do?** - A position as - **Regulations Specialist** exists in Regulatory Risk & Governance, Santam Specialist Solutions.Provide proactive Regulatory advice, support to, and manage regulatory change in Specialist Solutions. Ensure that products, business solutions and services within Specialist Solutions are provided within the existing...


  • Johannesburg, Gauteng, South Africa EMPIRE RECRUITMENT Full time

    Job Title: Compliance and Governance SpecialistSalary: R450,000 - R600,000 per annumAbout the Role:We are seeking a highly skilled Compliance and Governance Specialist to join our team at Empire Recruitment. As a key member of our compliance department, you will play a crucial role in ensuring that our business operations remain aligned with regulatory...


  • Johannesburg, South Africa Black Pen Recruitment Full time

    Our client holds a prominent position as the leading licensed platform for stablecoin on/off-ramp services in Africa. They are dedicated to pioneering innovative solutions within the African stablecoin landscape. **Job Type**:Full Time l Remote **Role Overview** **Requirements**: - Bachelor’s degree in discipline related to functional work or role -...


  • Johannesburg, Gauteng, South Africa Numata Full time

    Job DescriptionWe are seeking an experienced Senior IT Governance and Risk Management Specialist to join our team at Numata. This is a unique opportunity to leverage your expertise in IT governance, risk management, and compliance to drive business growth and enhance overall IT operations.About the RoleThis role will lead the design and implementation of IT...


  • Johannesburg, Gauteng, South Africa Network Recruitment Full time

    Business Protection Specialist Opportunity:We are seeking a highly skilled Business Protection Specialist to join our team at Network Recruitment. As a Business Protection Specialist, you will play a critical role in safeguarding our organization's interests and protecting its reputation. Your expertise in risk management will enable you to identify and...


  • Johannesburg, Gauteng, South Africa Network Recruitment Full time

    About the RoleNetwork Recruitment seeks a highly skilled Operational Risk Governance Specialist to safeguard our organization by identifying and managing potential threats to business objectives from an operational viewpoint.This role reports directly to the Head of Risk, ensuring seamless integration with existing risk frameworks. Key responsibilities...


  • Johannesburg, South Africa Hera Group Full time

    Hera Group is a leading cybersecurity firm, founded in South Africa, and operating across 18 African countries. Our mission is to provide innovative, top-tier cybersecurity solutions to organizations, ensuring they stay ahead of emerging cyber threats. As part of our commitment to excellence, we are seeking an experienced **IT Governance Specialist** to help...


  • Johannesburg, South Africa Hera Group Full time

    Hera Group is a leading cybersecurity firm, founded in South Africa, and operating across 18 African countries. Our mission is to provide innovative, top-tier cybersecurity solutions to organizations, ensuring they stay ahead of emerging cyber threats. As part of our commitment to excellence, we are seeking an experienced IT Governance Specialist to help us...


  • Johannesburg, Gauteng, South Africa FirstRand Bank Limited Full time

    About the RoleWe are seeking an experienced Compliance Risk Management Specialist to join our team at FirstRand Bank Limited.Job DescriptionThe successful candidate will be responsible for advising on and providing guidance and support to stakeholders in relation to the execution of financial crime relevant legislation, frameworks, policies, processes, and...


  • Johannesburg, Gauteng, South Africa Zanati Search Group Full time

    Zanati Search Group is seeking a Head of Governance and Compliance to lead our efforts in maintaining high standards of corporate governance and compliance. In this role, you will be responsible for developing and implementing policies and procedures to ensure compliance with regulatory requirements.About the PositionThe estimated salary for this position is...

  • Compliance Specialist

    1 month ago


    Johannesburg, South Africa FirstRand Full time

    Job Description Dear Future, Compliance Specialist The role requires you to monitor processes and related controls in accordance with compliance methodology and minimum standards and provide support to experienced Regulatory Risk and Compliance professionals that require robust regulatory compliance advice and guidance Are you someone who can: - Ensure...

  • Compliance Specialist

    6 months ago


    Johannesburg, South Africa FirstRand Full time

    Job Description To assist with the development and implementation of risk management plans and establishing risk-reporting requirements Hello Future Compliance Specialist Welcome to FNB, the home of the #changeables. We design for the shapeshifters and deliver products and services that make us incredibly proud of people that make it happen. As part of...