Junior GRC Security Analyst
Network Finance · Johannesburg North, Gauteng
Stop applying one at a time.
JobAlertsZA auto-applies to South African jobs like this one for you, overnight. Upload your CV once — we do the applying.
Start free — we apply for you →Key Responsibilities Governance & Control
• Support the maintenance of information security and ICT governance frameworks. • Work with ISO 27001/27002 and NIST CSF frameworks. • Maintain control mappings across multiple frameworks and regulations. • Assist with reviewing and maintaining policies, standards and procedures. • Collect, validate and maintain evidence for audits and regulatory reviews. Risk Management
• Support ICT and information security risk assessments. • Maintain risk registers, including inherent and residual risk ratings. • Track remediation activities and control improvements through to completion. • Provide risk input into technology changes, cloud initiatives, outsourcing and new systems or services. Regulatory & Compliance
• Support compliance with POPIA, GDPR, DORA and Joint Standard 2 . • Assist with data protection activities, DPIAs and breach documentation. • Support ICT risk management, incident reporting and resilience requirements. • Assist with regulatory submissions, compliance attestations and supervisory requests. • Monitor regulatory changes and assist with impact assessments. Third-Party & Outsourcing Risk
• Support ICT supplier and third-party risk assessments. • Assist with due diligence, security questionnaires and evidence validation. • Track supplier risks and remediation actions. • Support regulatory requirements relating to critical and outsourced service providers. Incident & Operational Resilience
• Support governance around cyber and ICT incident management. • Assist with business continuity, disaster recovery and resilience activities. • Support incident classification, documentation and regulatory reporting. • Participate in post-incident reviews and track resulting control improvements. Audit & Assurance
• Support internal and external audits and regulatory examinations. • Track audit findings and remediation actions. • Prepare risk and compliance reporting for management and governance forums. Collaboration
• Work closely with technical and business stakeholders to embed compliance by design. • Translate regulatory and framework requirements into practical control expectations. • Provide day-to-day GRC guidance to IT, Security, Cloud and business teams. Requirements
- 1–3 years' experience in GRC, Information Security, Risk or Compliance.
- Experience within financial services or another highly regulated environment .
- Practical experience with:
- ISO/IEC 27001 & 27002
- NIST Cybersecurity Framework (CSF)
- Relevant NIST SP standards
- Experience with control mapping and evidence collection across multiple frameworks.
- Working knowledge of:
- POPIA / GDPR
- DORA
- Joint Standard 2 – Cybersecurity and Cyber Resilience
• Exposure to ICT risk, cyber risk or technology compliance. • Experience supporting audit, regulatory or assurance activities. Advantageous
• ISO/IEC 27001 Foundation, Implementer or Auditor certification. • CGRC or similar GRC certification. • Financial services, risk or compliance-related certifications. Skills & Attributes
• Exceptional attention to detail and strong documentation skills. • Structured, analytical and risk-based approach. • Strong written and verbal communication skills. • Ability to engage confidently with both technical and non-technical stakeholders. • High level of integrity, accountability and professionalism. • Strong understanding of governance, risk and compliance principles. Why Join? This is an excellent opportunity for a GRC professional looking to develop their career within a regulated financial services environment , gaining exposure to leading security frameworks, regulatory requirements, ICT risk and operational resilience.
Apply today!