IT Risk, Governance
3 weeks ago
Johannesburg Metropolitan Area, GT, South Africa
Abacus Insurance Limited
Full-time
Free with email or Google
Save this job and keep your search organized
Create a free account to save jobs, create alerts and return to this listing from your dashboard.
Free with email or Google
By continuing, you agree to our Terms & Privacy Policy.
Abacus Insurance and Abacus Life
Abacus is an authorised financial services provider and a proud member of the Pepkor Group, comprising two separate insurance companies: Abacus Insurance, which provides non-life insurance products, and Abacus Life, which provides life insurance products.
We enable the Pepkor Group of companies to meet the insurance needs of its customers by providing affordable, accessible, and easy-to-understand insurance products.
Our purpose is to:
- Provide easy and affordable insurance products to our customers.
- Support development and growth of our team.
- Recognise, respect, empower and reward our team.
- Grow income and contain costs without compromising value for sustainability.
- Contribute to the insurance industry and uplift society for sustainability.
- Contribute to the conservation of the environment for sustainability.
- Be readily accessible to our customers. Job Purpose The IT Risk, Governance & Privacy Manager is accountable for establishing and maintaining the first-line technology governance, risk, privacy and control environment required of a regulated insurer. The role provides clear, reliable assurance evidence covering POPIA, applicable FSCA and Prudential Authority obligations, technology and cyber risk, third-party risk, and the auditable oversight of outsourced IT arrangements. It ensures that technology risks and obligations are translated into practical controls, assigned to accountable owners, tested for effectiveness and reported transparently. Strategic Mandate
- Embed a practical and demonstrable IT governance and control environment aligned with Abacus strategy, risk appetite and regulatory obligations.
- Maintain a complete view of technology, privacy, third-party and outsourcing risk, with clear ownership, treatment, evidence and escalation.
- Translate regulatory and policy requirements into implementable controls, SOPs, standards, monitoring and auditable records.
- Provide reliable first-line control assurance and transparent exception reporting to IT Manco and relevant risk and governance forums.
- Strengthen privacy-by-design, data protection and responsible information handling across technology services and change initiatives.
- Ensure outsourced technology arrangements remain governed, resilient, compliant and subject to effective insurer oversight. Job Responsibilities IT Governance and Regulatory Alignment
- Develop and operationalise the IT governance framework, decision rights, committees and governance calendar
- Maintain the IT regulatory obligations register, ensuring alignment to POPIA, FSCA, Prudential Authority standards, and related regulations.
- Monitor regulatory change and coordinate time-bound implementation plans with Legal, Compliance, Risk and Security Technology Risk Management
- Own the first-line IT risk-management process, from identification through to treatment and escalation
- Maintain a current IT risk register covering resilience, cyber, privacy, data, cloud and third-party risk
- Facilitate risk assessments and escalate exposure, overdue treatment and appetite breaches to IT Manco and enterprise-risk forums Privacy Governance and POPIA Compliance
- Support the Information Officer in operating the privacy-management framework and demonstrating POPIA compliance within Technology
- Maintain privacy obligations, data-flow records, retention requirements and privacy-control evidence
- Coordinate privacy impact assessments and embed privacy-by-design across systems, architecture and supplier arrangements Control Framework, Testing and Assurance Evidence
- Establish and maintain an IT control library with clear ownership, evidence and testing frequency
- Plan and execute risk-based first-line control testing and maintain an auditable evidence repository
- Report control effectiveness and coordinate combined assurance with Risk, Compliance and Internal Audit Third-Party and Outsourced IT Risk
- Operate third-party risk processes across due diligence, contracting, monitoring and exit
- Maintain a supplier and outsourcing inventory, including materiality, data access and concentration risk
- Monitor supplier attestations, incidents and SLA breaches, escalating unacceptable exposure Policies, Standards, SOPs and Exceptions
- Own the IT policy and standards lifecycle, from drafting through to review and retirement
- Maintain an authoritative policy/SOP register with owners, approvers and review dates
- Operate a governed exception and waiver process, and test adherence to approved policy and standards Audit, Compliance and Remediation Management
- Act as the first-line coordination point for internal audit, external audit and regulatory reviews
- Ensure findings have sound root-cause analysis, realistic remediation plans and accountable owners
- Validate sustainable remediation and maintain audit/issue dashboards to track recurring themes Reporting, Stakeholder and Capability Leadership
- Prepare decision-ready risk, governance, privacy and control reports for IT Manco and executive forums
- Build trusted relationships across Technology, Risk, Compliance, Legal, Security and Internal Audit
- Lead and develop the IT GRC/privacy capability, including methods, tooling and governance maturity Essential Qualifications
- NQF Level
- Matric / Grade 12 / National Senior Certificate
- Bachelor's Degree / Advanced Diploma (NQF Level 7) in Information Technology, Information Systems, Risk Management, Audit, Law, Compliance or a related field Certifications/Accreditation
- COBIT, ISO 27001, ISO 27701 or an equivalent IT risk/governance credential is strongly advantageous Minimum Experience Level
- At least 8 years' relevant experience in IT governance, technology risk, compliance, privacy, controls or IT audit
- At least 3 years' management or senior specialist leadership experience Core Competencies
- IT risk and control framework design
- POPIA and privacy-by-design implementation
- Control testing (walkthroughs, sampling, reperformance)
- Third-party and outsourcing risk management
- Policy and SOP development
- Audit coordination and remediation tracking
- Regulatory interpretation (financial services/insurance)
- Executive reporting and dashboarding Behavioural Competencies
- Risk and Control Judgement
- Governance Discipline
- Regulatory and Privacy Literacy
- Assurance and Analytical Rigour
- Influencing and Executive Communication
- Collaboration and Courage Reports to: Chief Information Officer
Location:
Woodmead Direct Reports: IT Risk, Governance and Privacy Team Job Level: Management Closing Date: 30 September 2026
- Provide easy and affordable insurance products to our customers.
- Support development and growth of our team.
- Recognise, respect, empower and reward our team.
- Grow income and contain costs without compromising value for sustainability.
- Contribute to the insurance industry and uplift society for sustainability.
- Contribute to the conservation of the environment for sustainability.
- Be readily accessible to our customers. Job Purpose The IT Risk, Governance & Privacy Manager is accountable for establishing and maintaining the first-line technology governance, risk, privacy and control environment required of a regulated insurer. The role provides clear, reliable assurance evidence covering POPIA, applicable FSCA and Prudential Authority obligations, technology and cyber risk, third-party risk, and the auditable oversight of outsourced IT arrangements. It ensures that technology risks and obligations are translated into practical controls, assigned to accountable owners, tested for effectiveness and reported transparently. Strategic Mandate
- Embed a practical and demonstrable IT governance and control environment aligned with Abacus strategy, risk appetite and regulatory obligations.
- Maintain a complete view of technology, privacy, third-party and outsourcing risk, with clear ownership, treatment, evidence and escalation.
- Translate regulatory and policy requirements into implementable controls, SOPs, standards, monitoring and auditable records.
- Provide reliable first-line control assurance and transparent exception reporting to IT Manco and relevant risk and governance forums.
- Strengthen privacy-by-design, data protection and responsible information handling across technology services and change initiatives.
- Ensure outsourced technology arrangements remain governed, resilient, compliant and subject to effective insurer oversight. Job Responsibilities IT Governance and Regulatory Alignment
- Develop and operationalise the IT governance framework, decision rights, committees and governance calendar
- Maintain the IT regulatory obligations register, ensuring alignment to POPIA, FSCA, Prudential Authority standards, and related regulations.
- Monitor regulatory change and coordinate time-bound implementation plans with Legal, Compliance, Risk and Security Technology Risk Management
- Own the first-line IT risk-management process, from identification through to treatment and escalation
- Maintain a current IT risk register covering resilience, cyber, privacy, data, cloud and third-party risk
- Facilitate risk assessments and escalate exposure, overdue treatment and appetite breaches to IT Manco and enterprise-risk forums Privacy Governance and POPIA Compliance
- Support the Information Officer in operating the privacy-management framework and demonstrating POPIA compliance within Technology
- Maintain privacy obligations, data-flow records, retention requirements and privacy-control evidence
- Coordinate privacy impact assessments and embed privacy-by-design across systems, architecture and supplier arrangements Control Framework, Testing and Assurance Evidence
- Establish and maintain an IT control library with clear ownership, evidence and testing frequency
- Plan and execute risk-based first-line control testing and maintain an auditable evidence repository
- Report control effectiveness and coordinate combined assurance with Risk, Compliance and Internal Audit Third-Party and Outsourced IT Risk
- Operate third-party risk processes across due diligence, contracting, monitoring and exit
- Maintain a supplier and outsourcing inventory, including materiality, data access and concentration risk
- Monitor supplier attestations, incidents and SLA breaches, escalating unacceptable exposure Policies, Standards, SOPs and Exceptions
- Own the IT policy and standards lifecycle, from drafting through to review and retirement
- Maintain an authoritative policy/SOP register with owners, approvers and review dates
- Operate a governed exception and waiver process, and test adherence to approved policy and standards Audit, Compliance and Remediation Management
- Act as the first-line coordination point for internal audit, external audit and regulatory reviews
- Ensure findings have sound root-cause analysis, realistic remediation plans and accountable owners
- Validate sustainable remediation and maintain audit/issue dashboards to track recurring themes Reporting, Stakeholder and Capability Leadership
- Prepare decision-ready risk, governance, privacy and control reports for IT Manco and executive forums
- Build trusted relationships across Technology, Risk, Compliance, Legal, Security and Internal Audit
- Lead and develop the IT GRC/privacy capability, including methods, tooling and governance maturity Essential Qualifications
- NQF Level
- Matric / Grade 12 / National Senior Certificate
- Bachelor's Degree / Advanced Diploma (NQF Level 7) in Information Technology, Information Systems, Risk Management, Audit, Law, Compliance or a related field Certifications/Accreditation
- COBIT, ISO 27001, ISO 27701 or an equivalent IT risk/governance credential is strongly advantageous Minimum Experience Level
- At least 8 years' relevant experience in IT governance, technology risk, compliance, privacy, controls or IT audit
- At least 3 years' management or senior specialist leadership experience Core Competencies
- IT risk and control framework design
- POPIA and privacy-by-design implementation
- Control testing (walkthroughs, sampling, reperformance)
- Third-party and outsourcing risk management
- Policy and SOP development
- Audit coordination and remediation tracking
- Regulatory interpretation (financial services/insurance)
- Executive reporting and dashboarding Behavioural Competencies
- Risk and Control Judgement
- Governance Discipline
- Regulatory and Privacy Literacy
- Assurance and Analytical Rigour
- Influencing and Executive Communication
- Collaboration and Courage Reports to: Chief Information Officer
Location:
Woodmead Direct Reports: IT Risk, Governance and Privacy Team Job Level: Management Closing Date: 30 September 2026