IT and Cyber Risk Analyst
1 day ago
Let's Write Africa's Story Together
Old Mutual is a firm believer in the African opportunity and our diverse talent reflects this.
Job Description
- Minimum 3 years relevant industry experience within the financial services sector in an IT Risk or security role
- Degree/Honours in Information Systems or Information Technology (Essential)
- Knowledge of Information Security and IT Risk
- Knowledge of Information Security Standards and Frameworks such as NIST CSF, ISO27001/2
- Knowledge of Secure Software Development Lifecycles and agile ways of work
Provide risk advisory and support during risk management initiatives.
- Collaborate with IT, ERM and Business Stakeholders to ensure security audit requirements are communicated and monitored.
- Support in driving remediation efforts of technical vulnerabilities.
- Support OMI stakeholders in effectively defining and prioritizing risk reduction action plans in line with policies and standards and manage until closure.
- Contribute to and support the execution of the OMI Information Security and IT Risk reduction plan, closely collaborating with IT and other Stakeholders to ensure information security risks are managed effectively.
- Collaborate with IT Teams in an advisory capacity to ensure security is embedded in the development of applications.
Third-Party Information Security Risk Management
- The primary responsibility in TPRM is ensuring all third-party engagements are assessed, mitigated, and monitored according to internal security standards.
- Conduct third-party risk assessments by reviewing vendor-submitted documentation (e.g., SOC reports, security questionnaires) to identify and quantify both inherent and residual risks related to information security.
- Engage directly with vendors to assist with completing assessments and resolve technical queries regarding their security posture and control documentation.
- Participate in quarterly performance meetings with vendors, specifically focusing on reviewing outstanding information requirements, clarification of control deficiencies, and tracking remediation of high-priority risks.
Crown Jewels Identification
- This involves supporting the organization's data protection strategy by formally supporting the classification of the most critical assets.
- Assist in the identification of Crown Jewel applications by working with IT asset management and architecture teams to define the critical processes they support.
- Identify and confirm business/application owners for all Crown Jewel assets, formally assigning accountability for the data and system security controls.
Project and Process Risk Assessment
- The analyst embeds security controls into new business processes and IT projects, ensuring compliance with IT and Security controls mandate.
- Perform formal IT and security risk assessments within business processes and IT projects by reviewing architectural designs, system requirements during project delivery.
- Translate security requirements into actionable technical configurations and implementation tasks for IT/Development teams, owning the execution of these new controls within the project lifecycle.
- Document all identified IT and Security risks and track the execution of their corresponding mitigation plans until project closure.
- Conduct periodic reviews of existing IT and security processes to identify and document new risks that may arise from process drift or system updates.
Skills
Action Planning, Analytics Software, Budget Management, Computer Literacy, Data Analysis, Database Reporting, Data Compilation, Data Controls, Data Interpretations, Evaluating Information, Management Reporting, Numerical Aptitude, Report Review, Solution AnalysisCompetencies
Business InsightCommunicates EffectivelyCourageDecision QualityEnsures AccountabilityFinancial AcumenInstills TrustManages ComplexityEducation
Bachelor of Commerce (BCom): Information Technology (Required), NQF Level 7 - Degree, Advance Diploma or Postgraduate Certificate or equivalentClosing Date
14 December 2025 , 23:59The appointment will be made from the designated group in line with the Employment Equity Plan of Old Mutual South Africa and the specific business unit in question.
The Old Mutual Story
-
Cyber Security Analyst
1 week ago
Johannesburg, Gauteng, South Africa InfyStrat Full time R250 000 - R500 000 per yearInfyStrat is seeking a motivated Cyber Security Analyst to join our team and contribute to our mission of safeguarding our digital assets and infrastructure. In this role, you will monitor, detect, and respond to security threats, vulnerabilities, and incidents across our systems. You'll perform risk assessments, analyze security breaches, and provide...
-
Cyber Security Engineer
7 days ago
Johannesburg, Gauteng, South Africa Boardroom Appointments Full time R1 000 000 - R3 000 000 per yearMinimum Requirements:Information Security related Certification (CISSP / CISM / GCIA).Appropriate professional accreditation GCIH / Ethical Hacking (CEH)Offensive Security Certified Professional (OSCP) is preferred, GPEN, advantageous.Experience:Prior industry experience in a corporate environment (preference Financial Institution) in an IT Security...
-
Cyber Security Engineer
7 days ago
Johannesburg, Gauteng, South Africa Hire Resolve Full time R1 200 000 - R1 800 000 per yearHire Resolve is currently seeking a highly skilled Cyber Security Engineer for our client, a leading independent power producer. This is an exceptional opportunity to join a dynamic and innovative company at the forefront of the energy sector. The successful candidate will play a crucial role in safeguarding critical infrastructure, ensuring the security of...
-
Cyber, Services Manager
7 days ago
Johannesburg, Gauteng, South Africa Boardroom Appointments Full time R2 000 000 - R2 500 000 per yearMinimum requirements:First Degree in Information Technology3 - 4 years Proven experience in risk management 5 - 7 years Prior experience in providing managed services to customers and Experience in managing vendors/suppliers of professional IT services5 - 7 years Strong IT understanding gaining insight into digital and platform operating models and Cyber...
-
Cyber Security Engineer
1 day ago
Johannesburg, Gauteng, South Africa Boardroom Appointments Full time R1 000 000 - R2 500 000 per yearMinimum requirements: First Degree in Information TechnologyInformation Security related Certification (CISSP / CISM / GCIA , an Appropriate professional accreditation GCIH / Ethical Hacking (CEH), Offensive Security Certified Professional (OSCP) is preferred, GPEN, advantageous.Experience in developing threat models, risk profiles, cyber-security risk and...
-
Cyber Security Engineer
7 days ago
Johannesburg, Gauteng, South Africa Boardroom Appointments Full time R500 000 - R1 200 000 per yearContract (Hybrid) PositionMinimum Requirements:MatricCyber Security QualificationSkills Required: An understanding of the cyber security risks associated with various technologies and ways to manage themA good working knowledge of various security technologies such as network and application firewalls, host intrusion prevention and anti-virusThe ability to...
-
Cyber Security Technical Manager
7 days ago
Johannesburg, Gauteng, South Africa Boardroom Appointments Full time R1 200 000 - R2 400 000 per yearKey purpose:As a member of the Global IT Team, you will help develop and maintain the cyber security program and serve as the de facto technical security expert. This role is responsible to provide support and oversight to internal and external teams to ensure incidents and threats are properly handled.A well-qualified candidate will feel comfortable jumping...
-
Market Risk Analyst
3 days ago
Johannesburg, Gauteng, South Africa Ntice Sourcing Solutions Full time R1 000 000 - R3 000 000 per yearMarket Risk AnalystAre you a data-driven thinker who thrives at the intersection of markets, analytics, and strategy?My client is looking for aMarket Risk Analystto help protect a global trading business from external market movements - from shifts in oil prices and FX rates to changes in interest rates and volatility.This position requires the individual to...
-
Market Risk Analyst
3 days ago
Johannesburg, Gauteng, South Africa Ntice Sourcing Solutions Full time R800 000 - R1 200 000 per yearJob DescriptionMarket Risk Analyst Are you a data-driven thinker who thrives at the intersection of markets, analytics, and strategy?My client is looking for a Market Risk Analyst to help protect a global trading business from external market movements — from shifts in oil prices and FX rates to changes in interest rates and volatility.This position...
-
Cyber Risk
2 weeks ago
Johannesburg, Gauteng, South Africa iLaunch Full time R900 000 - R1 200 000 per yearConduct comprehensive technology and cybersecurity reviewsEvaluate existing security controls and identify gaps in complianceDesign and implement self-assessment frameworks for ongoing compliance monitoringLead PCI DSS compliance initiatives and manage assessment processesDevelop and maintain third-party risk assessment programsUpdate cybersecurity policies...