Role & responsibilities
1. Regulatory and Internal Compliance
- Monitor applicable information security and cyber security requirements issued by regulators, government bodies, payment networks and other competent authorities.
- Assess applicability with relevant stakeholders, record obligations and coordinate implementation and evidence collection.
- Maintain compliance trackers and support timely, accurate responses to advisories, questionnaires, inspections and regulatory submissions.
- Escalate overdue, incomplete or potentially non-compliant items through the prescribed governance process.
2. Audit and Assurance Coordination
- Coordinate internal, external, information systems, regulatory and other security-related audits and assessments.
- Collate evidence, verify completeness, maintain an audit trail and coordinate responses with accountable owners.
- Track observations, management actions and target dates through closure and validate the supporting closure evidence.
- Identify recurring themes and support improvements to controls, processes and documentation.
3. Policy, Standards and Exception Management
- Support preparation, review, approval, communication and periodic updating of information security policies, standards, procedures and guidelines.
- Maintain document-control information, review schedules, approval records and version history.
- Coordinate policy exceptions and risk-acceptance requests, ensuring justification, compensating controls, approvals and validity periods are recorded.
- Promote consistent alignment between documented requirements and operational practices.
4. Risk, Metrics and Governance Reporting
- Support cyber and technology risk assessments and maintenance of risk registers, treatment plans and residual-risk records.
- Monitor key risk indicators, compliance metrics, audit status and action-plan progress.
- Prepare concise dashboards, management information and committee papers with validated data and clear status commentary.
- Maintain organized, retrievable and audit-defensible records for governance and assurance activities.
5. Coordination and Awareness
- Coordinate with technology, business, risk, legal, audit and service-provider teams to close compliance requirements.
- Support information security awareness, policy communication and role-based training activities.
- Provide guidance on evidence expectations, control ownership and compliance documentation without assuming the control owner's accountability.
Preferred candidate profile
Mandatory experience: Minimum 2 years of experience in IT security compliance, information security governance, IT audit, technology risk management, regulatory compliance, cyber security assurance or a closely related area.
- Graduate or postgraduate qualification in Computer Science, Information Technology, Cyber Security, Commerce, Risk Management or a related discipline.
- Experience in banking, financial services or another regulated industry is preferred.
- Relevant certifications such as CISA, CRISC, ISO 27001 Lead Auditor or Lead Implementer, Security+ or COBIT Foundation are desirable.