IT Governance, Compliance and Information Security

2 weeks ago


Sandton, South Africa IQbusiness South Africa Full time

**About**:
IQbusiness is the largest independent management and technology consulting firm in Africa.

We are looking for someone to join our Governance, Risk and Compliance (GRC) team as the IT Governance, Compliance and Information Security Risk Lead.

In a world that is constantly changing, organisations need to adapt quickly to respond to new risks and take advantage of new opportunities. IQ’s GRC division advises organisations on how to effectively mitigate risk and make informed and intelligent risk decisions around business processes, technology, and operations.

Our clients are our priority. A one size fits all approach does not work for us. We provide our clients with solutions tailored to their specific needs, using tried and tested methodologies and best practices in the industry. We are looking for a dynamic Self-starter, passionate about making a positive impact to our clients by delivering cutting edge solutions, through a robust delivery approach.

**Summary**:
To lead the IT Governance and Information Security Risk stream within the GRC line of business. Core responsibilities will be to establish and maintain a framework that provides clients with resilient risk, governance, compliance and information security strategies that support sustainable business growth. These strategies need to be aligned with applicable regulations and standards, adhere to relevant frameworks, policies and internal controls and outline the necessary roles and responsibilities to manage identified risks. The position will provide leadership in IT governance, compliance, risk management and project management. The individual must be well versed in Information systems and technology.

**Qualifications**:

- Computer Science or Information Technology Degree or equivalent
- Project Management, Governance and Risk Management qualifications
- The following certifications or equivalent would be advantageous:

- Technology GRC Certifications such as CGEIT or COBIT
- Information Security Management Certifications such as CISSP, CISM, or CCISO
- Privacy Certifications such as CDPSE or CIPP/CIPM/CIPT
- Risk Management and Audit Certifications such as CRISC, CISA or CRM
- Framework Certifications such as ISO 27001 Implementer/Auditor

Knowledge:

- IT Security Governance, IT Compliance, IT Audit, Risk Management and Cybersecurity management knowledge is mandatory.
- Regulatory requirements, standards, policies and procedures applicable to information technology and information security management.
- Sound understanding of ISO security standards
- Knowledge of familiar IT Infrastructure Management frameworks including ITIL, COBIT and TOGAF.
- Information systems auditing, monitoring, controlling, and assessment processes.
- Risk assessment and management methodologies.
- Knowledge of cyber and cloud security standard governance frameworks, risk strategies, architecture, design, operations, controls, technology, solutions, and services will be advantageous.

**Experience & Skills**:

- Minimum 8-10 years proven track record in IT Security and GRC
- 2-3years experience in the management consulting business or a strategic role
- 3 - 5 years in a senior leadership role, managing and growing a team within the IT Security and GRC domains.
- Developing and implementing governance, risk, and compliance frameworks, policies, strategies and solutions.
- Reporting on GRC and security in an organisation.
- Embedment of Technology and Information related compliance practices.
- Updating compliance to the IT regulatory landscape.
- Project management and planning.
- Developing IT security teams and strategies.
- Incident response management and disaster recovery experience would be beneficial.
- Troubleshooting and operating a computer and various software packages.
- Privacy Management & Compliance.
- Cyber Security Risk management and assessments.
- Third Party Risk Management, vendor assessments and oversight.
- Strong vendor management and partner relationship skills.

**Ability**:

- Communicate technical issues to diverse audiences, both in writing and verbally.
- Investigate and analyse data to identify gaps and problem solve.
- Adapt to changes easily and update project plans and materials appropriately.
- Handle sensitive, confidential and private information appropriately.
- Understand complex client requirements and develop fit for purpose solutions.
- Manage relationships with a broad range of stakeholders.
- Provide quality service in pressured environments.
- Prioritise multiple tasks, work well in a team and independently, and delegate effectively.
- Pay attention to detail.

**Key Responsibilities**:

- Lead GRC’s approach to IT Security Risk Management, Governance and Compliance.
- Develop a team of IT Governance and Risk Compliance specialists to deliver on client projects.
- Provide advisory and monitoring assistance to GRC clients to enable them to develop resilience in their IT environments.
- Review, develop and impl



  • Sandton, South Africa LZ Security & Service GmbH Full time

    A Security Engineer is a crucial member of an organization's IT team, specializing in safeguarding digital assets and maintaining the security posture of the company. They work to design, implement, and manage security measures to protect against cyber threats, unauthorized access, and data breaches.Key Responsibilities:Security Infrastructure Design:Design...


  • Sandton, South Africa LZ Security & Service GmbH Full time

    A Security Engineer is a crucial member of an organization's IT team, specializing in safeguarding digital assets and maintaining the security posture of the company. They work to design, implement, and manage security measures to protect against cyber threats, unauthorized access, and data breaches. Key Responsibilities: Security Infrastructure Design: ...


  • Sandton, South Africa LZ Security & Service GmbH Full time

    Safety Engineers at LZ Security & Service GmbH play a pivotal role in maintaining the confidentiality, integrity, and availability of our organization's information assets.Job Description:A crucial member of our IT team, the Safety Engineer specializes in safeguarding digital assets and maintaining our security posture. They work to design, implement, and...


  • Sandton, South Africa Paracon Full time

    Our global financial services organization within the Banking Sector is seeking an experienced IT / Security Manager – Cyber Security to ensure all IT Service Management areas are fully functional, operational, and effectively managed. This role involves managing IT Service Continuity planning, Information Security enhancements, and Infrastructure capacity...


  • Sandton, South Africa Discovery Ltd. Full time

    **Business Unit**:Discovery Central Services **Function**:Information Security **Date**:7 Apr 2025 - Discovery - Information Governance and Security - Information Security Officer **About Discovery** - Discovery’s core purpose is to make people healthier and to enhance and protect their lives. We seek out and invest in exceptional individuals who...


  • Sandton, South Africa Paracon Full time

    We are seeking a Chief Information Security Officer at Paracon, a global organization within the financial services and banking sector.Key ResponsibilitiesCyber Security Management: Oversee all IT service management related areas to ensure they are fully functional, operational, and effectively managed.Information Security Enhancements: Develop and implement...


  • Sandton, South Africa Discovery Limited Full time

    About Discovery LimitedWe strive to ignite positive change in society by making people healthier and enhancing their lives. Our commitment to this mission drives us to find exceptional individuals who align with our values and contribute to our goal of creating meaningful impact.Our ApproachWe believe in empowering our employees to drive innovation and...


  • Sandton, South Africa Experian Full time

    Company Description We are the leading global information services company, providing data and analytical tools to our clients around the world. We help businesses to manage credit risk, prevent fraud, target marketing offers and automate decision making. We also help people to check their credit report and credit score, and protect against identity theft....


  • Sandton, South Africa Discovery Limited Full time

    About UsDiscovery Limited is a leading global insurance and financial services company that aims to make people healthier and enhance their lives. Our core purpose drives us to invest in exceptional individuals who share our values and contribute to creating positive change in society.We seek out innovative thinkers, risk managers, and security professionals...


  • Sandton, South Africa Clientèle Life Assurance Company Limited Full time

    Information Security OfficerWe are looking for an Information Security Officer to join the Clientèle Infrastructure and Operations department. As the Information Security Officer, you will be responsible for the information security vision, strategy, governance, management, processes, and user education.Purpose:Responsible for creating the vision and...


  • Sandton, South Africa Sasria Recruitment Full time

    **Job Advert Summary**: The intern will gain exposure and training in the IT Governance, Risk, and Cybersecurity team by assisting with governance processes,compliance assessments, risk identification, and cybersecurity initiatives. This includes supporting incident response processes, assisting with patch management, and responding to security alerts as...


  • Sandton, South Africa Discovery Limited Full time

    Our Commitment to Information SecurityAt Discovery Limited, we're committed to protecting our information assets and ensuring the confidentiality, integrity, and availability of our data. This commitment requires a robust Information Security Strategy that addresses the evolving threat landscape.About the RoleThe Security Governance Specialist will play a...


  • Sandton, South Africa Paracon Full time

    Job SummaryWe are seeking an experienced Cybersecurity Manager for IT Operations to join our team at Paracon. The successful candidate will be responsible for ensuring the security and resilience of our IT systems and services.Key ResponsibilitiesBusiness Continuity Management: Develop and implement business continuity plans to ensure minimal disruption to...


  • Sandton, South Africa Sasria Full time

    Closing Date - 2025/02/27 - Reference Number - SAS250213-1 - Job Title - IT Governance, Risk and Compliance (IT GRC) Intern - Job Type - Graduate Internship - Division - Business Change and Technology - Department - IT GRC - EE Occupational Levels - Level 4 & 5: Skilled, Technical and Academically Qualified - Location - Town / City - Sandton - Location -...


  • Sandton, South Africa Blue Label Telecoms Full time

    **Job Purpose** To assist in maintaining framework(s) that provides assurance that information security and strategies are aligned and support the business objectives.To ensure the security of the company, customer and proprietary information, including information transmitted to and from the company environment, ensuring compliance with regulatory...


  • Sandton, South Africa Tych Business Solutions Full time

    As an Information Security Manager, you’ll be responsible for the security of the organisation’s information assets. You will develop and implement a strategy to protect sensitive data from loss or theft while ensuring that business operations are not disrupted. Information Security Management has the responsibility to work closely with the Information...


  • Sandton, South Africa Emporium Human Capital Full time

    Information Security Analyst with qualifications and experiencePOSITION INFO :Information Security Analyst (POS24161)R 986 000 to R 1 080 000 per annumJob PurposeTo collaboratively perform in-depth analysis with stakeholders on complex information security issues and provide optimum solutions which meet both business and technical requirements while aligning...


  • Sandton, South Africa HRnMORE Full time

    Define, own and drive the Information Security framework with supporting policies, processes, standards and benchmarks - Define rolling 3 year information security strategy and roadmap, and supporting operations plan and budget estimates to close identified gaps - Submit benefits case to initiate information security related projects, conduct rigorous...


  • Sandton, South Africa Discovery Limited Full time

    As a Business Analyst at Discovery Limited, you'll have the opportunity to work with multiple business areas and teams to unpack and integrate solutions. You'll build and maintain strong relationships with stakeholders and communicate complex ideas effectively.About the RoleThis Business Analyst position is an exciting opportunity for an experienced...


  • Sandton, South Africa Discovery Limited Full time

    Select how often (in days) to receive an alert:Talent Pool: Information Security AdministratorBusiness Unit: Discovery Central ServicesFunction: Information SecurityDate: 10 Apr 2025Discovery – Information Governance and SecurityInformation Security AdministratorAbout DiscoveryDiscovery's core purpose is to make people healthier and to enhance and protect...