Risk and Compliance Specialist
Oceana Group Limited · Cape Town, Western Cape
Stop applying one at a time.
JobAlertsZA auto-applies to South African jobs like this one for you, overnight. Upload your CV once — we do the applying.
Start free — we apply for you →Job Purpose
- Specialist supports the Group's enterprise risk management ERM and compliance oversight model. The role facilitates Group-wide risk assessments and registers, monitors the legislative and regulatory landscape, coordinates combined assurance, and drives a culture of compliance across Oceana's South African, Namibian and US operations.
Key Responsibilities
Risk management
- Support the annual review and update of the ERM Policy, Framework and Compliance Policy and Framework for RiskCom approval, and help ensure they are consistently followed.
- Facilitate divisional and functional risk assessments, monitor the implementation and effectiveness of mitigation actions and KRIs, prepare risk reporting for governance forums, and support the continuous improvement and maturity of Oceana's Enterprise Risk Management framework.
- Review and amend risk registers and mitigation plans and monitor the applicable risk landscape and context changes PESTLE.
- Track the completion of risk actions and report on implementation progress.
- Own the data quality and governance of the Oceana risk registers — including the consistency, completeness and accuracy of risk descriptions, ratings and mitigation status — in addition to facilitating its update.
- Identify emerging risks arising from legislative impacts, regulatory developments and PESTLE analysis, and incorporate relevant findings into risk registers, mitigation plans and reporting.
- Provide guidance and training to risk owners on risk management methodologies and requirements.
- Support with updating of and enhancements to the Risk Management tools as implemented from time to time – including rolling-out any training where required.
Compliance management
- Monitor the legislative and regulatory landscape for changes and assess their implications for the Oceana Group.
- Support divisions and functions in assessing implications and developing action plans and monitor closure of new legislative requirements.
- Act as convenor of the Compliance Forum and develop and implement the annual compliance and risk training and awareness plan SRC policies, online compliance training.
- Compile input into the quarterly Risk and Compliance Board reports legislative updates, Compliance Forum feedback, health and safety incidents, and legislative non-conformances.
- Promote a culture of compliance through awareness campaigns, communications and targeted training initiatives. Develop and distribute regular compliance updates and guidance material on emerging legislative and regulatory developments.
- Coordinate the review, update and implementation of compliance-related policies, standards and procedures to ensure alignment with regulatory requirements and leading practice.
- Investigate incidents and instances of non-compliance with applicable legislation, policies and procedures.
- Maintain the Group legislative universe and compliance obligations register, coordinate compliance risk assessments and monitoring activities, and track remediation actions arising from compliance reviews, investigations and regulatory changes.
Assurance and risk-control coordination
- Support the drafting of the Combined Assurance Plan CAP and evaluate the effectiveness of the CAP quarterly.
- Complete second-level compliance assurance i.e. compliance with policies and standards.
- Track the completion of property risk recommendations arising from underwriting surveys.
Business continuity planning BCP
- Responsible for amending, updating, training and scenario planning of the Oceana BCP.
- Monitor the readiness and applicability of the Divisional BCP.
- Develop and maintain the Oceana Group wide BCP standards and management system.
Minimum Qualifications required
- A relevant bachelor's degree in risk management, Law, Commerce, Internal Auditing or a related field.
- A postgraduate qualification or professional certification in risk or compliance management e.g. IRMSA, Compliance Institute of South Africa, or equivalent is advantageous.
Minimum Experience and Technical Skills Required
- 3–5 years' experience in enterprise risk management and/or regulatory compliance, ideally within a JSE-listed or similarly governed organisation.
- Demonstrated experience facilitating risk assessments, maintaining risk registers, and supporting combined assurance processes.
Behavioural Skills and Competencies
- Strong analytical skills, with the ability to apply structured frameworks such as PESTLE to identify emerging and evolving risks.
- Sound understanding of the three-lines-of-defence model and combined assurance principles.
- Excellent facilitation and stakeholder-engagement skills across Group and divisional teams.
- Strong written and verbal communication skills for board- and committee-level reporting.
- High attention to detail, sound judgement, and the ability to manage multiple concurrent workstreams and deadlines.
- Working knowledge of a GRC or enterprise risk management system/tool for risk register maintenance, data quality management and reporting.
- Ability to interpret and apply legislation to real-world business scenarios.