IT Governance Lead
Sanlam Group · Cape Town, Western Cape
Stop applying one at a time.
JobAlertsZA auto-applies to South African jobs like this one for you, overnight. Upload your CV once — we do the applying.
Start free — we apply for you →What will you do?
- The position of IT governance lead operates at the intersection of governance, architecture, security, risk and delivery. Working closely with enterprise architects, solution architects, development teams, operational IT teams, IT leadership, security practitioners, business information security officer BISO and business stakeholders, the role is instrumental in ensuring IT governance policies, standards and guidelines are effectively implemented, adopted and operationalised across the Cluster and Business Units.
- Key to the success of this position is maintaining strong alignment to enterprise strategy, regulatory expectations and broader Sanlam Group governance standards, while applying a pragmatic and enablement‑focused approach to governance implementation.
- From a leadership and governance perspective, the role includes the implementation and facilitation of governance forums, preparation and presentation of governance reporting, and active participation in Group, Cluster and Business Unit governance and assurance bodies. The role provides governance input, advice and implementation support to demonstrate effective control design, operation and evidence within the SI and broader Sanlam environment.
- From a security governance perspective, the role supports the Information Security Officer BISO by coordinating and enabling the implementation of security‑related requirements and roadmap items spanning technology, data and cyber security. This includes translating Group security direction into executable actions, supporting compliance activities, and contributing to governance oversight within project and delivery environments.
- The role also engages with relevant audit stakeholders, both internal and external, to coordinate and manage the audit reporting process.
Key Responsibilities and Competencies
Leadership & Governance Enablement
- Establish, coordinate and mature IT governance practices across Cluster and Business Units
- Drive the rollout, adoption and practical implementation of IT governance, security and data standards
- Provide thought leadership on IT governance, risk, compliance and regulatory alignment
- Define, maintain and evolve governance frameworks, policies, standards, guidelines and implementation artefacts
- Establish and apply governance controls and monitoring mechanisms within the IT environment
- Set up, run and support Cluster‑wide IT governance forums and working groups
- Represent Cluster governance positions into Group governance structures
- Provide input into IT management decision‑making and strategic direction from a governance perspective
- Support audit, assurance and regulatory activities by ensuring governance evidence and traceability
Governance, Oversight, Risk & Compliance
- Coordinate and perform IT governance maturity assessments and standards compliance reviews
- Review and provide input into Cloud Risk Assessments CRA and similar risk processes
- Support risk appetite alignment , exception handling and remediation planning
- Track, monitor and report on governance risks, gaps and remediation actions
- Ensure integration of regulatory, legal and policy requirements into governance practices
- Advise on acceptable governance and security remediation actions
Security & Interaction with BISO Function
- Support execution of security governance implementation plans aligned to Group InfoSec direction
- Assist the BISO across defined service areas by providing governance coordination and enablement
- Ensure alignment between IT governance, cyber security and data governance requirements
- Support third‑party and supplier governance considerations in collaboration with security and risk teams
- Provide governance input into security‑related initiatives, controls and assurance activities
Project & Delivery Governance
- Provide governance and security oversight within projects and solution delivery initiatives
- Advise project teams on governance, security and data requirements to be applied
- Ensure governance considerations are embedded early in solution lifecycles
- Contribute governance input to architecture, design and operational readiness discussions
Communication & Stakeholder Engagement
- Prepare and present governance feedback, maturity and compliance reports
- Communicate effectively across all levels, from executive and senior management to delivery teams
- Engage constructively with Group IT governance functions for input, review and feedback
- Partner with Cluster and Business Unit IT Heads to drive regulatory, policy and standards adoption
- Communicate complex governance and risk concepts in a clear, pragmatic manner
Minimum Requirements, Experience & Behaviour
Must Have
- Experience in IT governance, risk and compliance
- 5+ years relevant experience in enterprise IT environments
- Demonstrated experience in policy and standards rollout and operationalisation
- Experience working in regulated environments, preferably financial services
- Proven ability to engage across Group, Cluster and Business Unit structures
- Experience participating in or supporting governance, audit and assurance bodies
Advantageous
- 7+ years overall IT experience across multiple disciplines
- Formal qualifications in IT, Information Systems, Risk or related fields
- Knowledge of IT governance and security frameworks e.g. ISO/IEC 38500, COBIT, ISO 27001, NIST
- Exposure to financial services or asset management environments
- Experience or background in IT security function or architecture roles
- Familiarity with CISSP type work
Behaviour
- Strong planning, prioritisation and organisational skills
- Ability to effectively engage with Senior to Executive stakeholder
- Ability to balance governance rigour with pragmatism
- Action‑ and result‑oriented with high personal accountability
- Detail‑oriented while avoiding unnecessary bureaucracy
- Comfortable handling ambiguity, conflict and difficult conversations
- High integrity, resilience and professional maturity
- Continuous learning and improvement mindset