GRC Analyst
Network Finance · Johannesburg North
Stop applying one at a time.
JobAlertsZA auto-applies to South African jobs like this one for you, overnight. Upload your CV once — we do the applying.
Start free — we apply for you →This role will focus on supporting information security and ICT governance, risk management, regulatory compliance and control assurance within a highly regulated environment. You will work closely with technical and business stakeholders to ensure controls are effectively implemented, risks are appropriately managed and regulatory and audit requirements are met.
Key Responsibilities
- Support the maintenance of governance and control frameworks aligned to ISO 27001/27002 and NIST CSF .
- Maintain control mappings across ISO, NIST, GDPR, DORA and Joint Standard 2 .
- Assist with reviewing and maintaining policies, standards and procedures.
- Collect, validate and maintain control evidence for audit and regulatory purposes.
- Support ICT, information security and cyber risk assessments .
- Maintain risk registers, including inherent and residual risk ratings.
- Track remediation activities and control improvements through to completion.
- Provide risk input into technology changes, cloud initiatives, outsourcing and new systems or services.
- Support compliance activities relating to POPIA, GDPR, DORA and Joint Standard 2 .
- Assist with regulatory submissions, compliance attestations and supervisory requests.
- Monitor regulatory developments and support impact assessments.
- Assist with third-party and ICT supplier risk assessments , due diligence and security questionnaires.
- Support governance activities relating to cyber incidents, business continuity, disaster recovery and operational resilience.
- Assist with incident documentation, classification and regulatory reporting.
- Support internal and external audits and regulatory examinations.
- Track audit findings and remediation actions.
- Prepare risk and compliance reporting for management and governance forums.
- Collaborate with security, IT, cloud, risk and business teams to embed compliance by design .
Requirements
- 2–3 years' experience in GRC, Information Security, Risk or Compliance.
- Experience within financial services or another highly regulated environment .
- Practical experience with:
- ISO/IEC 27001 & 27002
- NIST CSF and related NIST SP standards
- Experience supporting control mapping and evidence collection across multiple frameworks.
- Working knowledge of POPIA/GDPR, DORA and Joint Standard 2 .
- Exposure to ICT risk, cyber risk or technology compliance.
- Experience supporting audit, regulatory or assurance activities.
Apply now!
For more exciting IT vacancies, please visit: www.networkrecruitmentinternational.com
If you have not had any response in two weeks, please consider the vacancy application unsuccessful.
For more information contact: Raees Sadek IT Recruitment Researcher 011 622 9526