IT Security Governance and Policy Specialist

Sasso Consulting (Pty) Ltd

Johannesburg

On-site

ZAR 550,000 - 850,000

Full time

32 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Sasso Consulting (Pty) Ltd seeks IT Security Governance and Policy Specialists to drive governance and policy development across complex enterprise IT environments. You will translate security requirements into practical governance controls and contribute to ongoing assurance activities.

Role emphasizes risk management, regulatory compliance (POPIA, ISO 27001, NIST), and collaboration with risk, compliance and business teams to support audits and continuous improvement.

Qualifications

  • Minimum requirements include a relevant diploma or degree in Information Technology, Information Systems, Computer Science, Cybersecurity, Risk Management or related discipline.
  • Typically 3–5 years of relevant experience in IT security governance, information security risk management, IT compliance or cybersecurity GRC.
  • Proven experience developing, implementing or maintaining information security policies and standards.
  • Strong understanding of information security governance principles and enterprise risk management.
  • Practical experience with ISO/IEC 27001, NIST or COBIT frameworks.
  • Familiarity with POPIA and other SA regulatory requirements; risk registers and compliance reporting.

Responsibilities

  • Develop, implement, review and maintain information security policies, standards, procedures and governance frameworks.
  • Align security policies with regulatory requirements and industry standards.
  • Establish governance structures, processes and control frameworks.
  • Review policies and recommend improvements to strengthen security.
  • Support enterprise information security strategies and reporting requirements.
  • Coordinate remediation activities and governance maturity assessments.
  • Prepare governance reports and management updates.

Skills

IT governance
Risk management
Regulatory compliance
Policy development
Governance frameworks
Stakeholder engagement

Education

Diploma or degree in IT / Cybersecurity

Tools

ServiceNow GRC
RSA Archer
MetricStream
Purview Compliance Manager
OneTrust

Job description

IT Security Governance and Policy Specialist

Location: Centurion, Gauteng (provisional – to be confirmed)
Positions Available: 5
Salary: Market-related
Employment Type: To be confirmed

Job Overview

We are seeking experienced and highly skilled IT Security Governance and Policy Specialists to support the development, implementation, maintenance and continuous improvement of information security governance frameworks, policies, standards and procedures within complex enterprise IT environments.

The successful candidates will be responsible for ensuring that information security practices align with organisational objectives, regulatory requirements, industry standards and recognised cybersecurity governance frameworks.

This role requires strong expertise in IT governance, risk management, regulatory compliance, information security policy development and cybersecurity assurance.

The ideal candidates will have proven experience working within structured enterprise environments, with the ability to translate security requirements into practical governance policies, controls and compliance processes.

Key Responsibilities

IT Security Governance and Policy Development

  • Develop, implement, review and maintain information security policies, standards, procedures and governance frameworks.
  • Ensure security policies align with organisational objectives, regulatory requirements and recognised industry standards.
  • Establish and maintain information security governance structures, processes and control frameworks.
  • Review existing security policies and recommend improvements to strengthen organisational security.
  • Support the development and implementation of enterprise information security strategies.
  • Define security governance responsibilities, accountability structures and reporting requirements.
  • Ensure policies and standards remain relevant to emerging cybersecurity risks and evolving technology environments.

Risk Management and Compliance

  • Conduct information security risk assessments and identify governance, risk and compliance gaps.
  • Develop and maintain information security risk registers and risk treatment plans.
  • Monitor compliance with approved security policies, procedures and regulatory obligations.
  • Support compliance with POPIA, ISO 27001, NIST and other applicable security requirements.
  • Assess the effectiveness of information security controls and recommend corrective actions.
  • Assist with third-party and supplier security risk assessments.
  • Monitor emerging regulatory developments and evaluate their implications for information security governance.
  • Coordinate remediation activities arising from compliance assessments and security audits.

Security Assurance and Audit Support

  • Support internal and external information security audits.
  • Coordinate the collection and maintenance of audit evidence and compliance documentation.
  • Review security control effectiveness and identify opportunities for improvement.
  • Track audit findings, corrective actions and remediation progress.
  • Assist with security control testing and governance maturity assessments.
  • Prepare governance reports, risk assessments and compliance updates for management.
  • Support the implementation and ongoing maintenance of information security management systems.

Stakeholder Engagement and Security Awareness

  • Collaborate with cybersecurity, infrastructure, application, risk, compliance and business teams.
  • Provide guidance on information security policies, standards and governance requirements.
  • Assist with information security awareness and compliance initiatives.
  • Support management in understanding information security risks and regulatory obligations.
  • Participate in governance committees, security reviews and risk management discussions.
  • Promote consistent adoption of security policies across the organisation.
Minimum Requirements
  • Relevant diploma or degree in Information Technology, Information Systems, Computer Science, Cybersecurity, Risk Management or a related discipline.
  • Typically 3–5 years of relevant experience in IT security governance, information security risk management, IT compliance or cybersecurity GRC.
  • Proven experience developing, implementing or maintaining information security policies and standards.
  • Strong understanding of information security governance principles and enterprise risk management.
  • Practical experience working with information security frameworks such as ISO/IEC 27001, NIST or COBIT.
  • Knowledge of information security risk assessment methodologies and control frameworks.
  • Experience conducting compliance assessments, governance reviews or security control evaluations.
  • Understanding of IT audit processes, audit findings and remediation management.
  • Familiarity with applicable South African regulatory requirements, including POPIA.
  • Experience maintaining risk registers, policy documentation and compliance reports.
  • Strong stakeholder engagement, communication and technical documentation skills.
  • Ability to interpret security standards and translate them into practical organisational policies and controls.
Technical Skills and Competencies

Information Security Governance

  • Information security policy and standards development
  • IT governance frameworks and control structures
  • Information security management systems (ISMS)
  • Governance maturity assessments
  • Security control design and evaluation
  • Enterprise cybersecurity governance

Risk Management

  • Information security risk assessments
  • Risk identification, analysis and treatment
  • Risk registers and mitigation planning
  • Third-party and supplier risk management
  • Security control gap assessments
  • Risk-based decision-making

Compliance and Regulatory Frameworks

  • ISO/IEC 27001 and ISO/IEC 27002
  • NIST Cybersecurity Framework
  • COBIT
  • CIS Critical Security Controls
  • Protection of Personal Information Act (POPIA)
  • Applicable data protection and information security regulations

IT Security Audit and Assurance

  • Internal and external audit coordination
  • Security control assessments
  • Compliance monitoring and reporting
  • Audit evidence managementCorrective action and remediation tracking
  • Governance reporting and management dashboards

GRC Systems and Tools

Experience with one or more of the following would be advantageous:

  • ServiceNow GRC / Integrated Risk Management
  • RSA Archer
  • MetricStream
  • Microsoft Purview Compliance Manager
  • OneTrust
  • Other enterprise governance, risk and compliance platforms

Documentation and Reporting

  • Information security policies and procedures
  • Governance frameworks and standards
  • Security risk assessments
  • Compliance reports and dashboards
  • Audit findings and remediation reports
  • Management and executive-level reporting
Relevant Certifications (Advantageous)

One or more of the following certifications would be beneficial:

  • Certified Information Security Manager (CISM)
  • Certified Information Systems Auditor (CISA)
  • Certified Information Systems Security Professional (CISSP)
  • Certified in Risk and Information Systems Control (CRISC)
  • ISO/IEC 27001 Lead Implementer
  • ISO/IEC 27001 Lead Auditor
  • COBIT Foundation or equivalent
  • Certified in Governance of Enterprise IT (CGEIT)
  • Relevant cybersecurity governance, risk management or compliance certifications
Key Personal Attributes
  • Strong analytical and risk assessment capabilities.
  • Excellent attention to detail and accuracy.
  • Strong policy development and technical writing skills.
  • Ability to interpret regulatory and governance requirements.
  • Excellent communication and stakeholder engagement abilities.
  • Strong organisational and documentation skills.
  • Ability to work independently and collaboratively across departments.
  • Sound judgement and a structured approach to risk management.
  • High levels of confidentiality, integrity and professional ethics.
  • Proactive approach to identifying governance gaps and recommending improvements.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Application and Data Security Specialist
Application and Data Security Specialist

Sasso Consulting (Pty) Ltd • Johannesburg

On-site
ZAR 420,000 - 660,000
IT MANAGER
IT MANAGER

Steinmuller Africa • Sandton

On-site
ZAR 1,200,000 - 1,800,000
Threat and Vulnerability Management Specialist
Threat and Vulnerability Management Specialist

Sasso Consulting (Pty) Ltd • Johannesburg

On-site
ZAR 700,000 - 1,000,000
IT Governance, Risk and Compliance Specialist
IT Governance, Risk and Compliance Specialist

ATS Client • Johannesburg

On-site
ZAR 600,000 - 900,000
Governance, Risk and Compliance Specialist
Governance, Risk and Compliance Specialist

Rory Mackie & Associates • Cape Town

On-site
ZAR 600,000 - 800,000
Information Security Manager
Information Security Manager

Parvana • Cape Town

On-site
ZAR 1,200,000 - 1,800,000
Information Security Compliance Specialist
Information Security Compliance Specialist

Placements24 • Mbombela (Nelspruit)

Hybrid
ZAR 420,000 - 720,000
Hybrid work model
Certification support
Collaborative governance culture
IT GRC Governance Compliance Specialist
IT GRC Governance Compliance Specialist

NTT DATA, Inc. • Johannesburg

On-site
ZAR 900,000 - 1,200,000
IT Risk Officer
IT Risk Officer

Rhodes University • Wes-Kaap

On-site
ZAR 450,000 - 600,000
Identity and Access Management Specialist
Identity and Access Management Specialist

Sasso Consulting (Pty) Ltd • Johannesburg

On-site
ZAR 600,000 - 900,000