It Governance, Risk And Compliance (Grc) Specialist / Analyst

Details of the offer

IT GRC Analyst is a multifaceted role that encompasses responsibilities across IT governance, risk management, compliance, cybersecurity, business and systems requirements and analysis. This position ensures the organisations IT infrastructure is secure, compliant, and aligned with business objectives, while also supporting system improvements, process optimisation, and technology integration within the Numata Managed Services business model and associated IT GRC framework.
The analyst will lead the design and enforcement of security and compliance policies, manage business and system requirements, and provide strategic insights for enhancing overall IT and business operations.
IT GRC specialist / analyst Key Responsibilities:
IT Governance, Risk, and Compliance (GRC) Responsibilities:

Policy Development and Compliance: Design and enforce IT governance frameworks and standards such as CIS, ISO 27001, NIST, and COBIT etc., amongst others.
Ensure compliance with regulatory requirements, privacy and other such as POPIA GDPR, HIPAA, and PCI-DSS as and where applicable.
Conduct internal audits and prepare for external compliance assessments, ensuring that all controls and processes meet regulatory obligations.

Risk Management and Reporting:

Identify, assess, and mitigate IT and cybersecurity risks, maintaining an up-to-date risk register.
Generate risk management reports, perform gap analyses, and recommend risk treatment plans.
Collaborate with internal & Client stakeholders to align risk management practices with business objectives.

Cybersecurity Analysis Responsibilities:

Risk and control assessments and recommendations for improvement (risk mitigation, control strength and maturity roadmaps) for: Threat and Vulnerability Management; Cybersecurity risk and controls such as firewalls, intrusion detection, and endpoint protection.
Incident Response and Continuous Monitoring: Develop and maintain incident response plans, ensuring timely detection, investigation, and resolution of security incidents. Conduct post-incident reviews and root cause analyses to strengthen future incident response capabilities.

Business and Systems Analysis Responsibilities:

Requirements Gathering and Documentation: Work with business stakeholders to understand and document business requirements, translating them into technical solutions and system specifications. Perform gap analyses between current systems and desired outcomes, recommending enhancements to meet business needs.
System Implementation and Optimisation: Collaborate with IT and development teams to ensure that systems are aligned with both security requirements and business objectives. Monitor the performance and effectiveness of business systems, recommending optimisations and enhancements based on data-driven insights.

Collaboration and Engagement:

Cross-Functional Coordination: Act as the liaison between IT, business units, compliance, and development teams, ensuring alignment in project goals and objectives. Support vendor risk management efforts by evaluating third-party compliance and security practices.
Project and Change Management participation: Lead IT and business system projects from inception through delivery, including risk management, timeline tracking, and stakeholder communication.

Qualification, Certification & Skills

Advantage: Bachelors degree in Information Technology, Computer Science, Business Administration, or related field. Certifications (An advantage): CISM, CISSP, CISA, CRISC, CBAP, or similar.
Technical Skills: Strong knowledge of GRC frameworks (CIS, ISO, NIST, COBIT), security tools (SIEM, IDS/IPS), and business process modelling techniques (BPMN, UML).
Analytical Skills: Proficient in conducting risk assessments, vulnerability analysis, and translating business needs into technical requirements.
Communication: Excellent ability to articulate complex technical information to non-technical stakeholders, alongside clear and precise documentation skills.
Project Management: Proven experience in managing cross-functional projects involving IT governance, cybersecurity, and business process improvements.

Key Competencies:

Strong ethical judgment, integrity, and commitment to best practices in compliance and risk management.
Problem-solving, analytical mindset with a focus on problem-solving and continuous improvement.
Effective communication and interpersonal skills, including conflict-management, working across multiple teams and with diverse stakeholders.
Quality management.

Experience:

3+ years of combined experience in IT GRC, cybersecurity, and business systems analysis.

#J-18808-Ljbffr


Nominal Salary: To be agreed

Source: Whatjobs_Ppc

Job Function:

Requirements

Head, Local Market, Business Banking

Business Segment: Business & Commercial Banking Location: ZA, GP, Johannesburg, Baker Street 30 To implement the Business Banking value proposition and life ...


Standard Bank Of South Africa Limited - Gauteng

Published a month ago

Senior Paraplanner

My client is a leading Wealth Manager in South Africa and is seeking a Senior Paraplanner to join their team in Sandton. Do you have a BCom / CFP, with relev...


Ca Financial Appointments - Gauteng

Published a month ago

Financial Planner: Elyon Bluestar

Sanlam Life Ltd is one of the top financial services providers in the South African market. We're all about building strong, lasting relationships with our f...


Sanlam Limited - Gauteng

Published 13 days ago

Head Of Pricing (Insurance)

Johannesburg, Gauteng Head of Pricing R1 200 000.00 - R1 900 000.00 CTC pa Job Description: We are a leading commercial risk specialist in Southern Afri...


A Triple A Recruitment - Gauteng

Published 13 days ago

Built at: 2024-12-24T10:00:50.937Z