Junior GRC (Governance, Risk, and Compliance) Analyst
Network IT · Johannesburg South, Gauteng
Stop applying one at a time.
JobAlertsZA auto-applies to South African jobs like this one for you, overnight. Upload your CV once — we do the applying.
Start free — we apply for you →Reference: ITE007991-Mish-1
Are you a detail-oriented GRC professional with a passion for cybersecurity, risk management, and regulatory compliance? This is an exciting opportunity to join a highly regulated environment where you'll play a key role in strengthening governance frameworks, managing risk, and supporting cybersecurity resilience initiatives. Duties & Responsibilities
Join a dynamic financial services environment where governance, risk, and compliance are critical to business success. As a GRC Analyst, you will support the day-to-day operation of information security and ICT governance frameworks while ensuring compliance with industry regulations and best practices. This role offers exposure to internationally recognised frameworks and standards, allowing you to work closely with security, IT, cloud, and risk teams to support audits, regulatory requirements, risk management processes, and operational resilience initiatives. If you are passionate about risk, cybersecurity governance, and regulatory compliance, this role offers excellent development opportunities within a growing and evolving field.
Key Responsibilities
- Support the maintenance and improvement of information security governance frameworks
- Assist with ICT and information security risk assessments and risk register management
- Maintain control evidence and support internal, external, and regulatory audits
- Support compliance initiatives relating to data protection, cybersecurity, and operational resilience requirements
- Conduct third-party and supplier risk assessments and due diligence reviews
- Assist with incident governance, business continuity, and disaster recovery processes
- Track remediation actions, audit findings, and control improvements through to completion
- Prepare risk and compliance reporting for management and governance forums
- Collaborate with technical and business teams to embed compliance and risk management practices
Job Experience and Skills Required
- Education: Relevant Degree or Diploma in Information Technology, Information Security, Risk Management, Compliance, or a related field
- Experience:
- 2–3 years' experience in Governance, Risk & Compliance, Information Security, Risk Management, or Compliance
- Experience within financial services or another highly regulated environment
- Exposure to ICT risk, cyber risk, or technology compliance activities
- Frameworks & Standards:
- ISO/IEC 27001 & 27002
- NIST Cybersecurity Framework (CSF)
- Experience with control mapping and evidence collection across multiple frameworks
- Regulatory Knowledge:
- POPIA and GDPR
- DORA
- Joint Standard 2 (Cybersecurity and Cyber Resilience)
- Experience supporting audits and regulatory activities
- Advantageous Certifications:
- ISO/IEC 27001 Foundation, Implementer, or Auditor
- CGRC or similar certification
- Financial services or risk-related certifications
- Additional Requirements:
- Strong analytical and risk-based thinking skills
- Excellent attention to detail and documentation abilities
- Strong communication and stakeholder engagement skills
- High level of integrity, professionalism, and accountability
Apply now! For more exciting IT vacancies, please visit: https://www.networkrecruitmentinternational.com/ I also specialise in recruiting in the following:
- Data Engineer
- Software Developer
- Data Analyst
- Infrastructure
• Architecture …and more!
If you have not had any response in two weeks, please consider the vacancy application unsuccessful. Your profile will be kept on our database for any other suitable roles / positions.
For more information, contact: Karmishka Naidoo Specialist Recruitment Consultant Connect with me on LinkedIn! https://za.linkedin.com/in/karmishka-naidoo-088772290 Package & Remuneration
Monthly