A large financial Service Company based in Johannesburg seeks an IT Security Administrator Risk and Compliance with:
Minimum Requirements
- Degree/diploma in Information Technology/Information Systems or Computer Science
- Any post graduate qualification in IT will be an advantageous
- CISA or CISM or CISSP or CRISC or studying towards such qualification
- Implementation, monitoring and reporting of IT Security focus areas according to (ISC)2
- IT Security administration or auditing experience
- Minimum five years working experience in a medium to large organisation, three of which was in IT audit team(s)
Role Purpose:
Identify, implement, monitor and report on IT compliance in regard to regulatory and legislative requirements.
Provide objective oversight, monitor and report on the effectiveness of the processes adopted and implemented by the first line of defence, in relation to the Risk Governance and Management Framework.
Responsibilities:
- Facilitate active engagement in ICT internal control meetings focusing on the identification of emerging and existing risks, escalation, mitigation and remediation to ensure the continuous improvement of ICT risk management and the elimination of a non-compliance culture.
- Manage IT compliance using international standards, frameworks and best practices for benchmarking.
- Review ICT audit reports and follow up with ICT audit findings owners in respect of actions to close the findings.
- On-going monitoring and evaluation of IT processes, procedures and operations to identify and manage IT risks.
- Monitoring and tracking IT risk mitigation actions until resolution and within agreed timelines
- Develop and maintain key relationships within the ICT management team, the CIO and Risk and Ethics team (Enterprise Risk Management) and internal and external auditors.
- Work with Risk Management and IT functional area owners to satisfy internal and external audit requirements.
- Cultivate working relationships with internal and external stakeholders to engender trust and confidence.
- Assist IT management in awareness activities in regard to IT compliance requirements
- Research, development and maintenance of the Enterprise ICT Risk and Compliance programme and ensure adherence to ICT Risk Management best practices for the following types of ICT risks:
- Strategic risks
- Risk appetite statement
- Project risks
- Operational risks
- Third party (Vendor/Contractors)
- Facilitate and co-ordinate the integration of the business-related IT risk requirements into the broader governance structures.
- Challenge IT risk profiles through reviews of risk assessments, evaluation of risk management processes and monitoring of exposure and corrective action.
- Report on IT risk exposure and performance with reference to management of IT risk exposure to the relevant governance structures (Exco, Manco, Risk Committee, and Audit Committee) and IT Management.
- Assist project and operational risk analysts in considering IT risks during risk assessments.
- Ensure IT risk registers are accurately and completely updated in accordance with the business requirements.
- Communicate and implement the ICT risk management requirements and standards, and actively promote and embed the risk culture by the first line of defence (ICT process owners) in relation to decision making.
- Ensure that applicable ICT policies, processes and procedures and standards are adhered to through regular training and awareness campaigns.
- Provide training, coaching, mentoring and support to the first line of defence, controls owners, and management action owners so that they are enabled to fulfil their ICT risk management and compliance responsibilities.
- Partner with the Risk and Ethics business unit to ensure the consistent deployment and implementation of the evolving Enterprise Risk Management (ERM) risk framework and policies.
- Update own knowledge, skills and competencies through applicable internal and external learning opportunities and channels.
- Track and report on risk management trends, opportunities and remediation monthly and provide updates to the applicable managers.
- Create and maintain reporting, problem resolution, and other tasks necessary for the continuous improvement and evolution of ICT risk management and compliance services.
- Perform and/or manage other projects, tasks and assignments not stipulated on the Job description as and when required.
For more information please contact Sinisa 011 234 0388, alternatively email your updated CV to Sinisa@esmartgroup.co.za
If you do not receive a response within 2 weeks please consider your application declined.
Please be advised that we are currently experiencing technical problems receiving emails from Yahoo account, please use an alternative email address when communicating with us. If you do not have alternative address please contact the Recruiter (number above) for an alternative way to submit your application.
Our apologies for the inconvenience caused
