Senior Role: IT Governace & Operations Specialist (Senior IT Auditing, IT Governance, IT Risk Management, General IT Controls, Combined Assurance, Cyber and Information Security, Business Resilience)
BA Personnel · Gauteng · Neg
Stop applying one at a time.
JobAlertsZA auto-applies to South African jobs like this one for you, overnight. Upload your CV once — we do the applying.
Start free — we apply for you →Introduction
BA Personnel is a trusted Executive Principal Talent Specialist Company with a proven track record in identifying, attracting, and securing exceptional talent for niche, specialist, and leadership appointments across South Africa and international markets. Leveraging deep industry expertise, extensive executive networks, and a consultative search methodology, we deliver strategically aligned talent solutions that enable organisations to achieve sustainable growth and competitive advantage. Our reputation is founded on representing high-calibre professionals who possess the leadership capability, technical expertise, and commercial acumen to create lasting business value.
The role is responsible for ensuring that the Scheme’s information technology environment and IT services, which are largely outsourced to the Administrator, are governed effectively, aligned with the Scheme’s strategic objectives and managed within an appropriate risk and control framework.
The incumbent will provide independent oversight of the Administrator’s IT environment and ensure that technology-related risks, controls, governance practices and assurance activities comply with applicable regulatory, governance and industry standards.
The role will support the Principal Officer, Scheme Executives, Board and relevant governance committees in fulfilling their fiduciary and oversight responsibilities by safeguarding the confidentiality, integrity, availability, resilience and security of the Scheme’s information, systems and technology assets.
A key focus will be on strengthening IT Governance, IT Risk Management, General IT Controls, Combined Assurance, Cyber and Information Security, Business Resilience, third-party IT oversight and the responsible adoption of emerging technologies, including Artificial Intelligence.
Duties & Responsibilities
Internal Stakeholders
Principal Officer, Scheme Executives, Scheme Secretariat, Board and Sub-Committees.
External Stakeholders
Administrator’s Operations and IT resources; Group Resilience, Risk Management, Internal Audit and Compliance Functions; External Auditors, Council for Medical Schemes, Industry related bodies.
Objectives/KPA’s
Alignment of IT Strategy and IT Governance Policy and Frameworks
- Draft the Scheme’s IT strategy in support of the Scheme’s strategic objectives and business needs within the Scheme’s risk appetite.
- Maintain and operationalise the Scheme’s IT Governance Policy and Framework in compliance with King V and best-practice standards.
- Draft, review, monitor and enforce comprehensive corporate IT policies.
- Provide regular IT Governance reporting to internal and external stakeholders.
Combined Assurance, Risk, Compliance, and Audit Management
- Design and implement an IT Governance combined assurance framework integrating Scheme and administrator controls and assurance providers.
- Manage and update the IT risk register and IT compliance universe / checklist.
- Provide input into the IT risk appetite, tolerance and assessment.
- Assess and provide input into business resilience arrangements.
- Monitor and provide input into IT audits and resolution of findings.
- Serve as the primary point of contact for the Scheme’s IT related Internal Audit, External Audit and Compliance Monitoring plans.
Oversight of Administrator IT services
- Agree standards and monitor the administrator against IT contractual obligations and performance metrics.
- Maintain oversight over the Administrator’s information security, cyber security, data privacy, disaster recovery and business continuity policies, frameworks and procedures and implementation of the policies, frameworks and procedures.
- Maintain insight into the administrator’s System’s Development Life Cycle and associated controls to ensure best practice implementation of IT system projects.
- Maintain insight into the Administrator’s IT infrastructure, software and applications.
- Lead the Scheme’s response to IT Risk Incidents in conjunction with the Administrator
Oversight of Services outsourced to the Administrator
- Maintain oversight over the Services provided by the administrator.
Emerging technologies and innovation
- Provide strategic guidance based on emerging technology trends, opportunities and risks.
- Design and implement AI governance policies and frameworks to ensure the ethical, secure, and transparent use of AI technologies by the Scheme and its providers.
- Oversight over the IT aspects of the innovation initiatives agreed with the Administrator.
Desired Experience & Qualification
Experience required
- Minimum of 6 to 8 years of post-qualification experience in an IT function and/or as an IT Auditor, with at least 3 to 4 years specialising in IT Governance, Risk, Compliance and General IT Controls.
- Experience managing outsourced IT vendors and third-party service providers (preferred).
Qualification(s) required
- Bachelor’s degree in information technology, computer science, Information systems or a related equivalent.
- Postgraduate qualification in IT Governance, Risk Management, IT Assurance or Cyber Security (preferred).
- Relevant professional certifications are desirable (e.g. CGEIT).
Additional requirements
- Code 8 drivers’ license and own car/transport
- Work extended working hours
- Home conducive to hybrid work environment
Knowledge required
- A strong conceptual understanding of frameworks used in IT governance (e.g. COBIT, ITIL, NIST, ISO)
- Working knowledge of general IT controls, cyber security, combined assurance and IT risk management.
- Sound knowledge of system development lifecycle methodologies (e.g. Agile, Waterfall, DevSecOps).
- Sound knowledge of Artificial Intelligence.
- Understanding of the regulatory and governance environment affecting IT governance (e.g. King V, POPIA).
Skills (Technical & Functional Abilities)
- Ability to identify IT and information risks and assess mitigation strategies.
- Strong analytical skills to evaluate service provider performance.
- Competence in integrating assurance activities for holistic oversight.
Competencies (Behavioural & Strategic Capabilities)
- Integrity and commitment to ethical governance.
- Professional Judgment & Integrity
- Influence Without Direct Authority
- Diplomacy and Stakeholder Engagement
- Operational Agility
- Resilience and Composure Under Pressure
- Ability to work independently
Interested?
Disclaimer
By applying for this role, you consent to having your relevant qualifications and or accreditation verified and confirm that you meet the competency requirements. You further consent to the relevant information being verified by a BA Personnel staff member. We would like to thank you for your application and if you have not received a response within two weeks would like to advise that your application was not successful.
We do look forward to being of service to you in the near future.
We look forward to receiving applications from candidates that fully meet the requirements of the spec.