Junior GRC Security Analyst

Network IT · Johannesburg North, Gauteng

Posted 24 August 2026

Stop applying one at a time.

JobAlertsZA auto-applies to South African jobs like this one for you, overnight. Upload your CV once — we do the applying.

Start free — we apply for you →

Reference: ITE007989-Danni-1

A leading organisation within the financial services sector is looking for a detail-oriented Junior GRC Analyst to join its team.

This role will support the day-to-day governance, risk and compliance activities across information security and ICT environments. You will work closely with Security, IT, Cloud and Risk teams to ensure that controls are effectively implemented, risks are accurately managed, and regulatory and audit requirements are consistently met.

The ideal candidate will have practical experience with ISO 27001, ISO 27002 and NIST, together with exposure to POPIA/GDPR, DORA and Joint Standard 2 within a financial services or similarly regulated environment. Duties & Responsibilities

Key Responsibilities Governance & Control

  • Support the maintenance of information security and ICT governance frameworks.
  • Work with ISO 27001/27002 and NIST CSF frameworks.
  • Maintain control mappings across multiple frameworks and regulations.
  • Assist with reviewing and maintaining policies, standards and procedures.
  • Collect, validate and maintain evidence for audits and regulatory reviews.

Risk Management

  • Support ICT and information security risk assessments.
  • Maintain risk registers, including inherent and residual risk ratings.
  • Track remediation activities and control improvements through to completion.
  • Provide risk input into technology changes, cloud initiatives, outsourcing and new systems or services.

Regulatory & Compliance

  • Support compliance with POPIA, GDPR, DORA and Joint Standard 2 .
  • Assist with data protection activities, DPIAs and breach documentation.
  • Support ICT risk management, incident reporting and resilience requirements.
  • Assist with regulatory submissions, compliance attestations and supervisory requests.
  • Monitor regulatory changes and assist with impact assessments.

Third-Party & Outsourcing Risk

  • Support ICT supplier and third-party risk assessments.
  • Assist with due diligence, security questionnaires and evidence validation.
  • Track supplier risks and remediation actions.
  • Support regulatory requirements relating to critical and outsourced service providers.

Incident & Operational Resilience

  • Support governance around cyber and ICT incident management.
  • Assist with business continuity, disaster recovery and resilience activities.
  • Support incident classification, documentation and regulatory reporting.
  • Participate in post-incident reviews and track resulting control improvements.

Audit & Assurance

  • Support internal and external audits and regulatory examinations.
  • Track audit findings and remediation actions.
  • Prepare risk and compliance reporting for management and governance forums.

Collaboration

  • Work closely with technical and business stakeholders to embed compliance by design.
  • Translate regulatory and framework requirements into practical control expectations.
  • Provide day-to-day GRC guidance to IT, Security, Cloud and business teams.

Requirements

  • 1–3 years’ experience in GRC, Information Security, Risk or Compliance.
  • Experience within financial services or another highly regulated environment .
  • Practical experience with:
  • ISO/IEC 27001 & 27002
  • NIST Cybersecurity Framework (CSF)
  • Relevant NIST SP standards
  • Experience with control mapping and evidence collection across multiple frameworks.
  • Working knowledge of:
  • POPIA / GDPR
  • DORA
  • Joint Standard 2 – Cybersecurity and Cyber Resilience
  • Exposure to ICT risk, cyber risk or technology compliance.
  • Experience supporting audit, regulatory or assurance activities.

Advantageous

  • ISO/IEC 27001 Foundation, Implementer or Auditor certification.
  • CGRC or similar GRC certification.
  • Financial services, risk or compliance-related certifications.

Skills & Attributes

  • Exceptional attention to detail and strong documentation skills.
  • Structured, analytical and risk-based approach.
  • Strong written and verbal communication skills.
  • Ability to engage confidently with both technical and non-technical stakeholders.
  • High level of integrity, accountability and professionalism.
  • Strong understanding of governance, risk and compliance principles.

Why Join? This is an excellent opportunity for a GRC professional looking to develop their career within a regulated financial services environment , gaining exposure to leading security frameworks, regulatory requirements, ICT risk and operational resilience.

Apply today!

Auto-apply to this jobView original posting ↗
Junior GRC Security Analyst at Network IT — Johannesburg North, Gauteng · JobAlertsZA