Manager: IT Risk and Governance

Tafadzwa

Pretoria

On-site

ZAR 900,000 - 1,500,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Tafadzwa is seeking a Manager: IT Risk and Governance to oversee ICT risk, governance and compliance objectives in Pretoria, South Africa. The role leads policy development, IT risk management, and regulatory compliance across the organisation.

Responsibilities include designing IT governance frameworks, maintaining controls, coordinating audits, and driving training on governance topics. A strong collaboration with stakeholders is essential to enhance risk readiness and policy adherence.

Qualifications

  • Bachelor’s Degree/Advanced Diploma in IT/Risk Management/Audit/IT Governance.
  • Postgraduate in IT/Risk Management/Audit/IT Governance will be advantageous.
  • Certification in CISA, COBIT and ITIL.
  • ISO 27001 certification will be an added advantage.
  • Relevant 6-8 years’ experience in IT Governance, Risk and Compliance environment, with at least 2 years at management/supervisory level.

Responsibilities

  • Policy development and implementation; lead policy, procedures and processes.
  • Develop and implement IT governance frameworks aligned with goals and best practices.
  • Establish ICT controls to ensure regulatory compliance and internal standards.
  • Design and implement an IT Risk Management Framework aligned to ERM.
  • Identify, assess and mitigate IT risks; conduct risk assessments and audits.
  • Coordinate audits and remediation plans; track ICT risk issues and actions.
  • Oversee training programs on IT governance, risk and compliance; promote culture of compliance.
  • Track remediation of observations and report progress to senior management.

Skills

IT Governance
IT Risk Management
Compliance
Policy development
Stakeholder management
Leadership
Training delivery
Risk assessments

Education

Bachelor’s Degree in IT/Risk Management/Audit
Postgraduate in IT/Risk Management/Audit/IT Governance
CISA Certification
COBIT Certification
ITIL Certification
ISO 27001 Certification

Job description

Our client is recruiting for a Manager: IT Risk and Governance to be responsible for managing ICT Risk, Governance, and Compliance objectives.

MINIMUM JOB REQUIREMENTS
Qualifications
  • Bachelor’s Degree/ Advanced Diploma in IT/Risk Management/Audit/ IT Governance related qualification.
  • Postgraduate in IT/Risk Management/Audit/ IT Governance related qualification will be advantageous.
  • Certification in CISA, COBIT and ITIL.
  • ISO 27001 certification will be an added advantage.
Experience
  • Relevant 6-8 years’ experience in IT Governance, Risk and Compliance environment, of which 2 years must have been at management/supervisory level/area of expertise.
KEY PERFORMANCE AREAS
Policy review and implementation
  • Lead the development and implementation of departmental policy, procedures and processes.
  • Keep up to date with effective policy and practice execution strategies.
IT Governance
  • Develop and implement IT governance frameworks and strategies aligned with organisational goals and industry best practices.
  • Establish policies, procedures, and controls to ensure compliance with regulatory requirements and internal standards.
  • Develop and maintain a complete controls library for ICT controls in line with best practice recommendations.
  • Monitor and evaluate the effectiveness of governance processes and recommend improvements as needed.
IT Risk Management
  • Design, develop and implement the Information Technology (IT) Risk Management Framework that is aligned to the COMPANY’s Enterprise Risk Management (ERM) framework.
  • Identify, assess, and prioritise IT-related risks across the organisation.
  • Develop risk mitigation plans and strategies to minimise potential impacts on IT operations and data integrity.
  • Conduct regular risk assessments and audits to ensure ongoing compliance and risk readiness.
  • Drive the creation of an understanding of ICT policies, processes, risk and controls’ in line with the COMPANY’s Policy Framework.
  • Act as a liaison between ICT and all relevant stakeholders to ensure that IT risks are adequately considered in the overall risk profile of the COMPANY.
  • Proactively ensure that all new projects have correct levels of assurance controls by conducting internal risk reviews before and during project implementation.
Compliance and assurance across IT environment.
  • Stay up to date with regulatory requirements and industry standards relevant to IT operations (e.g., GDPR, HIPAA, ISO 27001).
  • Implement and maintain compliance programs and initiatives, including training and awareness campaigns for staff.
  • Coordinate audits and assessments by internal/external auditors and regulatory bodies.
  • Pro-actively manage the reduction of unsatisfactory audits by: (1) identifying areas of risk within ICT, (2) by assisting with the development of remediation plans to address issues by providing risk and audit expertise and (3) raisin g and tracking ICT Issues which may be of a strategic, tactical or operational nature.
  • Ensure involvement during planning, fieldwork and reporting stages of all audits that are ICT related.
  • Review audit reports for factual accuracy and ensure that correct action owners were identified.
  • Review the feasibility of agreed actions and facilitate closure of audit findings.
Training and Awareness
  • Oversee the develop and delivery of training programs on IT governance, risk management, and compliance for employees.
  • Promote a culture of compliance and awareness across the organisation through workshops, seminars, and informational materials. E.g. Cybersecurity awareness,
  • Policy Compliance, POPIA Compliance etc.
Track remediation of all observations.
  • Track and monitor the adequate and on time remediation of observations raised by all independent assurance bodies.
  • Record remediation plans and facilitate closure for ICT related control weaknesses identified.
  • Ensure this is done through weekly progress tracking with control owners (typically Senior Managers) and reporting.
  • Engage with ICT management and senior management to discuss and manage overall progress against remediation plans.
  • Ensure that all audit closure documents are reviewed by the appropriate stakeholders before being submitted to IA.
Reporting
  • Prepare regular reports and updates for senior management and stakeholders on IT governance, risk, and compliance activities on a monthly basis or as and when required.
  • Communicate risks, compliance issues, and recommendations clearly and effectively to key stakeholders.
  • Collaborate with IT teams, legal counsel, and business units to address compliance concerns and implement solutions.
Stakeholder management
  • Facilitate and manage communication with relevant internal and external stakeholders and proactively and progressively manage the relationships.
  • Represent the organization in relevant external activities and events.
People management
  • Ensure the sourcing, development and retention of a high-performance team.
  • Manage the recruitment of the operational workforce in line with employment equity targets.
  • Manage staff in the department to ensure that they achieve their objectives in line with the strategic objectives of the COMPANY.
  • Manage the implementation of human capital processes and procedures to control/regulate workplace conflict and/or institute corrective measures and consultation processes to address deviations from standards.
  • Allocate, direct, motivate and evaluate subordinates to help them achieve their individual goals.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT Governance, Risk and Compliance Specialist
IT Governance, Risk and Compliance Specialist

ATS Client • Johannesburg

On-site
ZAR 600,000 - 900,000
ICT Risk & Projects Officer
ICT Risk & Projects Officer

Durpro Workforce Solutions • Durban

On-site
ZAR 600,000 - 800,000
ICT Operations Manager
ICT Operations Manager

Impronics Technologies • Gauteng

On-site
ZAR 600,000 - 800,000
Governance, Risk and Compliance Specialist
Governance, Risk and Compliance Specialist

Rory Mackie & Associates • Cape Town

On-site
ZAR 600,000 - 800,000
Senior Manager: Business & Technical Services
Senior Manager: Business & Technical Services

3L Consulting (Pty) Ltd • Midrand

On-site
ZAR 800,000 - 1,100,000
Competitive total target compensation package
IT Internal Audit Manager
IT Internal Audit Manager

Network Recruitment • Johannesburg

On-site
ZAR 1,100,000 - 1,500,000
Director: ICT Security, Risk and Compliance
Director: ICT Security, Risk and Compliance

AtripleA recruitment & temps • Pretoria

On-site
ZAR 600,000 - 900,000
IT Security Manager (Compliance & Risk)
IT Security Manager (Compliance & Risk)

Top Vitae Recruitment • Gqeberha

On-site
ZAR 900,000 - 1,300,000
IT Governance, Risk and Compliance Manager
IT Governance, Risk and Compliance Manager

Impronics Technologies • Gauteng

On-site
ZAR 700,000 - 1,100,000
IT Specialist
IT Specialist

Interdot Solutions • Pretoria

On-site
ZAR 600,000 - 800,000