Senior Cyber Assurance & GRC Analyst

Dixie Recruitment · Cape Town, Western Cape

Stop applying one at a time.

JobAlertsZA auto-applies to South African jobs like this one for you, overnight. Upload your CV once — we do the applying.

Start free — we apply for you →

The Role

  • The primary focus of this role is Cyber Assurance and validation of cybersecurity controls, with the Group framework largely based on CIS Controls v8.
  • You will review business self-assessments, validate supporting evidence, challenge unsupported or overstated responses and ensure cybersecurity risk and maturity reporting is accurate.
  • This is not a technical remediation role. You will not be responsible for fixing the issues; you need to be technically capable of understanding the controls, asking the right questions and determining whether they are genuinely effective.

Key Responsibilities

  • Conduct cybersecurity assurance assessments across multiple businesses.
  • Review and validate business self-assessments and supporting evidence.
  • Assess the effectiveness of cybersecurity controls.
  • Challenge inaccurate or unsupported compliance claims.
  • Identify control gaps, risks and weaknesses.
  • Apply practical knowledge of CIS Controls v8.
  • Maintain and assess cybersecurity risk information and risk registers.
  • Produce portfolio-level risk, maturity and assurance reporting.
  • Engage with technical and non-technical stakeholders across multiple businesses.
  • Support third-party risk, security governance and acquisition-related assurance activities.

Requirements

  • 3–5+ years' experience in Cyber GRC, Cyber Assurance, Information Security, IT/Internal Audit, Risk Management or a related field.
  • Proven experience conducting cybersecurity audits, assurance reviews or control assessments.
  • Strong practical understanding of CIS Controls v8.
  • Strong technical understanding of cybersecurity controls and technologies.
  • Experience reviewing evidence and validating whether controls are genuinely operating.
  • Ability to challenge stakeholders constructively and investigate responses where required.
  • Experience with cyber risk assessments and/or risk registers.
  • Strong analytical, reporting and stakeholder management skills.
  • Ability to work independently across multiple business units.

Advantageous

  • Experience in a global, multi-business or decentralised environment.
  • Knowledge of NIST CSF and/or ISO 27001.
  • Experience with Microsoft 365, Azure, Entra ID or cloud security.
  • GDPR, POPIA or other international regulatory knowledge.
  • Third-party risk management experience.
  • Relevant certifications such as CISA, CRISC, CISSP, CGRC or ISC2 CC.
  • Dual passport / international travel capability.
  • Ability and willingness to travel internationally when required.

The Ideal Candidate

  • We are looking for someone who can look beyond the answer on the audit questionnaire.
Auto-apply to this jobView original posting ↗
Senior Cyber Assurance & GRC Analyst at Dixie Recruitment — Cape Town, Western Cape · JobAlertsZA