An application made for this job — a tailored resume and cover letter that speak straight to the posting.
Network Recruitment is seeking a GRC Analyst in Johannesburg to support governance frameworks aligned to ISO/IEC 27001, NIST CSF, GDPR, DORA and Joint Standard 2. You will maintain control mappings, evidence for audits, and lead risk assessments across ICT and information security.
The role involves compliance activities across POPIA, GDPR and supplier due diligence, plus contributing to incident management, resilience testing, and reporting to management forums.
As a GRC Analyst, you will: Support governance frameworks aligned to ISO/IEC 27001, NIST CSF, GDPR, DORA, and Joint Standard 2. Maintain control mappings and evidence to support audits and regulatory reviews. Perform ICT and information security risk assessments, updating risk registers and tracking remediation. Assist with compliance activities across POPIA, GDPR, DORA, and Joint Standard 2. Support third-party and outsourcing risk assessments, due diligence, and supplier compliance. Contribute to incident management, resilience testing, and post-incident reviews. Provide audit and assurance support, producing risk and compliance reporting for management forums. Collaborate with IT, cloud, security, and risk teams to embed compliance by design.
Essential Skills & Experience: Practical experience with ISO/IEC 27001 & 27002 and NIST CSF. Knowledge of POPIA, GDPR, DORA, and Joint Standard 2. 23 years experience in GRC, Information Security, Risk, or Compliance. Exposure to ICT risk, cyber risk, or technology compliance in financial services.
ISO/IEC 27001 Foundation, Implementer, or Auditor. CGRC or similar. Financial services or risk-focused certifications.
Strong attention to detail and documentation discipline. Analytical, structured, and risk-based thinking. Clear communication with both technical and non-technical stakeholders. Integrity, accountability, and a collaborative mindset.
This is an exciting opportunity to work at the intersection of cybersecurity, compliance, and financial services. You willl play a key role in safeguarding resilience, supporting regulatory obligations, and embedding a strong governance culture across the organisation.