IT Risk and Governance Manager

2 days ago


Midrand, Gauteng, South Africa SNG GrantThornton Full time R18 000 - R57 600 per year

Job description

IT Cybersecurity and Governance, Risk and Compliance, the incumbent is responsible  for  developing, implementing, managing t  I and maintaining a robust IT Governance, Risk and Compliance framework that ensures the integrity, confidentiality, and availability of the Firm's information assets. The role involves implementation of  policies, procedures, and controls to manage IT risks, ensure compliance with regulatory requirements, and align IT strategies with the firm's overall objectives. Manage IT assets and IT projects.

KEY PERFORMANCE AREAS
Policy review and implementation

• Lead the development and implementation of departmental policy, procedures and processes.

• Keep up to date with effective policy and practice execution strategies.

IT Governance

• Develop and implement IT governance frameworks and strategies aligned with organisational goals and industry best practices.

• Establish policies, procedures, and controls to ensure compliance with regulatory requirements and internal standards.

• Develop and maintain a complete controls library for IT controls in line with best practice recommendations.

• Monitor and evaluate the effectiveness of governance processes and recommend improvements as needed.

IT Risk Management

• Design, develop, and implement the Information Technology (IT) Risk Management Framework that is aligned to the SNG Grant Thornton Enterprise Risk Management (ERM) framework.

• Identify, assess, and prioritise IT-related risks across the organisation.

• Develop risk mitigation plans and strategies to minimise potential impacts on IT operations and data integrity.

• Conduct regular risk assessments and audits to ensure ongoing compliance and risk readiness.

• Drive the creation of an understanding of IT policies, processes, risk, and controls in line with the SNG Grant Thornton Policy Framework.

• Act as a liaison between IT Department and all relevant stakeholders to ensure that IT risks are adequately considered in the overall risk profile of the SNG Grant Thornton.

• Proactively ensure that all new projects have correct levels of assurance controls by conducting internal risk reviews before and during project implementation.

Manage third-party risks

Compliance and assurance across the IT environment

• Stay up to date with regulatory requirements and industry standards relevant to IT operations (e.g., POPIA, GDPR, HIPAA, ISO 27001, and relevant legislation).

• Implement and maintain compliance programs and initiatives, including training and awareness campaigns for staff.

• Coordinate audits and assessments by internal/external auditors and regulatory bodies.

• Proactively manage the reduction of unsatisfactory audits by: (1) identifying areas of risk within IT Department, (2) by assisting with the development of remediation plans to address issues by providing risk and audit expertise, and (3) raising and tracking IT Department Issues which may be of a strategic, tactical, or operational nature.

• Ensure involvement during planning, fieldwork, and reporting stages of all audits that are IT-related.

• Review audit reports for factual accuracy and ensure that the correct action owners were identified.

• Review the feasibility of agreed actions and facilitate closure of audit findings.

Training and Awareness

• Oversee the development and delivery of training programs on IT governance, risk management, and compliance for employees.

• Promote a culture of compliance and awareness across the organisation through workshops, seminars, and informational materials. E.g., Cybersecurity awareness, Policy Compliance, POPIA Compliance, etc.

Track the remediation of all observations/findings

• Track and monitor the adequate and on-time remediation of observations raised by all independent assurance bodies.

• Record remediation plans and facilitate closure for IT-related control weaknesses identified.

• Ensure this is done through weekly progress tracking with control owners (typically Senior Managers) and reporting.

• Engage with IT management and senior management to discuss and manage overall progress against remediation plans.

• Ensure that all audit closure documents are reviewed by the appropriate stakeholders before being submitted to Auditors.

Asset management
Manage IT assets throughout the lifecycle of assets

  • Manage movement and allocation of assets
  • Ensure identification and tagging of assets where required
  • Maintain records and an asset register

IT Projects

Develop and implement an IT project management framework

Develop templates and tools

Manage IT projects in line with established frameworks

Reporting & Documentation

• Develop a stakeholder matrix and ensure reporting requirements and timelines are understood

  • Prepare regular reports and updates for senior management and stakeholders on IT governance, risk, and compliance activities on a monthly basis or as and when required.
    Communicate risks, compliance issues, and recommendations clearly and effectively to key stakeholders.

    • Collaborate with IT teams, relevant internal Committees. legal counsel, and business units to address compliance concerns and implement solutions.
  • Maintain documentation of IT Governance, Risk and Compliance processes, policies and procedures.

    Behavioural Competencies Required
    Resilience

    • Communication

    • Working with People

    • Network and Alliances

    • Planning, Organising and Coordinating

    • Employee Engagement

    • Personal Mastery

    • Judgement and Decision Making

    • Ethics and Values

    • Client Service Orientation

    Managerial Competencies Required

    • Change management.

    • Coaching and mentoring

    • Conflict management

    • Critical and innovative thinking

    • Strategic thinking and planning

    • Facilitation and presentation Skills

    • Team leadership and collaboration

    • Service Delivery Innovation

    • Stakeholder development and relations
  • Problem solving
    Reporting

    Technical Competencies Required

    • IT Risk and Governance Frameworks.

    • Understanding of Risk and Compliance Concepts.

    • Project Management Skills.

    • Interpersonal Skills.

    • Policy conceptualisation and formulation

    • Programme/project management
Experience

• Relevant 2-5 years' experience in IT Governance, Risk and Compliance environment of which 2 years must have been on a management/ supervisory level/ area of expertise.

MINIMUM REQUIREMENTS

Qualifications

• Bachelor's Degree/ Advanced Diploma in IT/Risk Management/Audit/IT Governance related qualification.

• Postgraduate in IT/Risk Management/Audit/IT Governance related qualification will be advantageous.

• Certification in CISA, COBIT and ITIL.

• ISO 27001 certification will be an added advantage.


  • Midrand, Gauteng, South Africa Grant Thornton Full time R900 000 - R1 200 000 per year

    Job descriptionIT Cybersecurity and Governance, Risk and Compliance, the incumbent is responsible for developing, implementing, managing t I and maintaining a robust IT Governance, Risk and Compliance framework that ensures the integrity, confidentiality, and availability of the Firm's information assets. The role involves implementation of policies,...


  • Midrand, Gauteng, South Africa Vector Logistics Full time

    PermanentMidrandOverviewWe are a Supply Chain and Sales & Merchandising partner adding value to your business through a fully integrated, temperature-controlled network in Southern Africa.But we are also more than that. We are people serving people. While we boast the best in tech and infrastructure, our people are our greatest resource. With our skilled,...


  • Midrand, Gauteng, South Africa Construction Education and Training Authority Full time

    JOB PURPOSE AND PROFILETo provide coordination and administrative support to the Demand and Contracts Management unit to ensure the effective and efficient coordination of tender and contract management efforts and the monitoring of project progress and implementation in support of the execution of the overall strategy.RESPONSIBILITIES:Provide input into the...

  • Chief Risk Officer

    1 week ago


    Midrand, Gauteng, South Africa Staff Concepts Full time R1 500 000 - R2 500 000 per year

    We looking for a candidate who are responsible for assessing andmitigating significant challenges associated with competition, regulations, anddigital developments. In essence, they manage risks for a large insurance group = Short term experienceExperience and Qualifications:The following experience and qualification will be required:· Post graduate degree...


  • Midrand, Gauteng, South Africa DBSA Full time R1 200 000 - R2 400 000 per year

    Closing Date2025/11/19 Reference NumberDBS Job TitlePrincipal: Strategic Portfolio Management Job Grade00 Job Type ClassificationPermanent Location - Town / CityMidrand Location - ProvinceGauteng Location - CountrySouth Africa Job Profile (Downloadable) kb) - 11/4/2025 10:38:28 AM Job DescriptionThe Principal: Strategic Portfolio Management plays a critical...

  • Financial Manager

    2 days ago


    Midrand, Gauteng, South Africa Network2 Full time R7 200 000 - R10 800 000 per year

    Are you a financial leader with a passion for healthcare funding and the critical role it plays in people's lives? Do you thrive at the intersection of healthcare, insurance and finance, this is your opportunity to make a real impact. We are seeking a dynamic Financial Manager to oversee financial performance, governance, and compliance across a highly...


  • Midrand, Gauteng, South Africa Interdot Solutions Full time R1 200 000 - R2 400 000 per year

    Eskom Holdings SOC Ltd, a state-owned company wholly owned by the South African government, is seeking dynamic and results-oriented professionals to join our Finance Corporate Strategy Development team as Senior Advisors. In this pivotal role, you will contribute to shaping the future of energy in the nation by developing and implementing corporate...

  • Financial Manager

    3 hours ago


    Midrand, Gauteng, South Africa Network2 Full time

    Are you a financial leader with a passion for healthcare funding and the critical role it plays in people's lives? Do you thrive at the intersection of healthcare, insurance and finance? Then this is your opportunity to make a real impact. We are seeking a dynamic Financial Manager to oversee financial performance, governance, and compliance across a highly...


  • Midrand, Gauteng, South Africa Optimal Growth Technologies Full time R750 000 - R1 200 000 per year

    Programme Manager Networks Location: Midrand Duration: 6 monthsRole purpose: Lead the planning, coordination, and delivery of the network security programme across company markets, ensuring alignment to the programmes objectives and governance framework.Oversee the end-to-end programme management of initiatives as well as associated business cases...

  • Group Manager

    4 days ago


    Midrand, Gauteng, South Africa DP World Full time

    JOB PURPOSE:We are looking for a proactive, curious, collaborative Manager to join our DP World Group Internal Audit ("GIA") team. As a Manager within our team, you are responsible to:Lead or participate as a team member to perform high quality audits (in cross-functional teams) at all locations locally and internationally across the DP World Group (or...