Specialist - Cyber Grc
6 days ago
**When it comes to putting people first, we're number 1.**
The number 1 Top Employer in South Africa.
Certified by the Top Employer Institute 2025.
**Role Purpose/Business Unit**:
Defining Cyber Governance, Risk & Compliance in order to:
- Lead ongoing evaluation of security policies and relevant standards supporting the continuous improvement of the security governance program.
- Ensure comprehensive Information Security Risk management programs and processes are established.
- Align Information Security Risk management with the enterprise risk management framework.
- Manage cyber security risks while collaborating with other departments to identify, recommend, develop, implement, and support a risk-informed decision and action framework.
- Provide Management with assurance covering controls across the Business environments that are adequately designed and operating effectively.
- Support Management during audits and implement and track Management audit actions to closure.
- Assist in the management and rollout of Cyber Training & Awareness initiatives.
- Provide Management with status update reports as well as insight reporting.
**Your responsibilities will include**:
- Plan, execute, track, and report Cyber Security Training and Awareness initiatives.
- Provide bespoke training for high profile staff based on their potential risk of being attacked (HR, IT, Senior Executives, Executive PAs).
- Deliver Cyber Security Inductions for all new joiners.
- Execute routine phishing simulations to assess the posture of staff reporting and click rates.
- Identify high-risk users through phishing simulations and provide workshops to lower their risks.
- Roll out Cyber Security training for all staff based on current trending global topics.
- Deliver presentations to senior management on results of Cyber Security awareness campaigns, pain points, lessons learned and actions going forward for improvement.
- Research common attack vectors and ways to spot them to reduce the risk.
- Provide security communications based on risks identified within the organization.
- Serve as the main point of contact for Cyber Security Training and Awareness.
- Implement and guide policy compliance across the organization.
- Review Security Policies, Processes, and Standards for non-conformances.
- Identify gaps in policies and provide input to improve them.
- Communicate changes to policies to the organization and the impact of the changes.
- Review processes with partner departments to ensure good security practices are up to date as per industry standards.
- Support Cyber Security audits across the organization.
- Identify and register new risks with the implementation and integration of new systems.
- Support and advise security measures and other security solutions to ensure the security of all data within the organization.
- Assess Cyber and IT Risks associated with policy non-conformities and vulnerabilities.
- Assess and approve policy deviations, track remediation actions, and provide status updates to management.
- Support Implementation of security controls from a GRC standpoint to provide confidence in the organization’s cyber security posture.
- Serve as the ISO 27001 & ISO9001 Coordinator for the department to ensure the Risk and Quality Management System is maintained.
**Key Accountabilities and Decision Ownership**:
- Proactively evaluate cyber security policies to ensure security policy adherence.
- Promote awareness of security policies, training, and the governance strategy across all levels of the organization.
- Maintain and further develop the Cyber Risk Management Program.
- Actively manage risks on the Cyber Risk Register from intake to resolution.
- Communicate risk assessment findings with key stakeholders to develop and monitor risk remediation plans.
- Develop cyber risk portfolios to provide a more holistic view of teams’ risks.
- Conduct regular compliance assessments with the Business to ensure that current and emerging risks are being monitored and managed.
- Provide proactive Control design and implementation guidance to the Business.
- Monitor and report Process and Control Compliance.
- Support Cyber Security Audits and Review of cyber audit reports.
- Support Tracking and monitoring of audit remediation action implementation.
- Deploy cyber security awareness training through innovative approaches.
- Develop and communicate GRC status reports as required by Management.
- Support GRC report development using automation and reporting tools to generate Cyber Risk metrics such as KPIs, KRIs, and KGIs (KxI)
- Matric is essential.
- Degree or relevant tertiary qualification in Information Technology.
- Must have at least once of the following Certifications CISA, CGEIT, CRISC, CISSP, CISM, ISO 27001 Lead Auditor
- At least 5+ years of experience in cyber governance, risk, controls, and compliance management in a Cyber Security or technology environment.
- Knowledge of common information technology ma
-
Specialist: Information Security Grc
4 days ago
Johannesburg, South Africa NTT Ltd. Full timeNTT is a leading global IT solutions and services organisation that brings together people, data and things to create a better and more sustainable future. In today’s ‘iNTTerconnected’ world, connections matter more now than ever. By bringing together talented people, world-class technology partners and emerging innovators, we help our clients solve...
-
Grc Pre-sales Specialist
6 days ago
Johannesburg, South Africa DataTech Recruitment Full timeGRC Specialist: Become a Pre-Sales Consultant & Champion World-Leading Solution! Are you passionate about technology and helping companies solve complex governance, risk, and compliance (GRC) challenges? Do you thrive in a fast-paced environment and enjoy building relationships with all levels of an organization? If so, we're looking for a talented...
-
Solutions Sales Specialist
6 days ago
Johannesburg, South Africa DataTech Recruitment Full timeGrowth-Minded Solutions Sales Specialist: Sell a World-Leading GRC Solution! Are you a revenue specialist with a passion for enterprise sales? Do you thrive in a fast-paced, team-oriented environment and enjoy building strong client relationships? If so, we have an exciting opportunity for you as a Solutions Sales Specialist! We're looking for a highly...
-
Enterprise Cyber GRC Manager
2 weeks ago
Johannesburg, South Africa The Hiring House Full timeRequirementsAt least 2 years in Technology Risk, Security Compliance, GRC, CISO, or a similar position.Extensive experience managing compliance projects and audits (e.g., SOC 2, ISO 27001).Background in IT audit, including ITGC and SOX compliance for US-listed companies.Deep understanding of PCAOB standards.Familiarity with enterprise applications, including...
-
Enterprise Cyber GRC Manager
2 weeks ago
Johannesburg, South Africa The Hiring House Full timeRequirements At least 2 years in Technology Risk, Security Compliance, GRC, CISO, or a similar position. Extensive experience managing compliance projects and audits (e.g., SOC 2, ISO 27001). Background in IT audit, including ITGC and SOX compliance for US-listed companies. Deep understanding of PCAOB standards. Familiarity with enterprise applications,...
-
Software Training Facilitator
6 days ago
Johannesburg, South Africa DataTech Recruitment Full timeAre you passionate about technology and helping companies excel in Governance, Risk, and Compliance (GRC)? Do you thrive in a dynamic environment and enjoy building relationships while delivering exceptional training? If so, we're looking for a talented GRC Software Trainer to join our growing team! In this role, you'll be the knowledge powerhouse, ensuring...
-
Technical Implementation Specialist
6 days ago
Johannesburg, South Africa DataTech Recruitment Full timeUnleash Innovation & Shape the Future of Compliance! Are you a passionate GRC professional with a knack for problem-solving and a desire to make a real impact? Do you thrive in a collaborative environment and enjoy exceeding client expectations? We are looking for a talented Technical Implementation Specialist to join a growing team. In this exciting role,...
-
GRC Solutions Consultant
2 weeks ago
Johannesburg, South Africa Careers Full timeA technology solutions firm in Johannesburg is seeking a GRC software implementation specialist to oversee deployment of Diligent One software. The role involves collaborating with clients, configuring software, conducting training, and managing stakeholder relationships. Ideal candidates will have a degree in Internal Audit and experience in internal audit...
-
Cyber Security Specialist
6 days ago
Johannesburg, Gauteng, South Africa LSA Recruit Full timeJob opportunity forCyber Security Specialistbased inJohannesburg, SA- ContractKey Roles:Secures platforms and pipelines that handle sensitive geospatial and subscriber informationFor more info, Please reach me at for further discussions
-
Johannesburg, South Africa Scitech Placements Full timeWe are looking for a IT Governance, Risk and Compliance Specialist, East Rand **Overview**: As an IT Governance, Risk and Compliance Specialist, you will be responsible for assisting in the development and implementation of IT Governance frameworks and IT controls. This will involve working closely with cross-functional teams to identify, assess, and...