Specialist: IT Governance, Risk and Compliance

Auditor-General of South Africa

Location
Gauteng
Minimum qualification
Diploma
Closing date

First listed . Last checked at source .

In brief

**Overview** This role is for a Specialist: IT Governance, Risk and Compliance at the Auditor-General of South Africa (AGSA). The position is central to developing and implementing IT risk and compliance frameworks and strategies, supporting the organisation's strategic initiatives, and ensuring adherence to IT governance and regulatory requirements. **What you will do** The Specialist: IT Governance, Risk and Compliance will undertake a range of responsibilities including: * **Strategic Function:** * Contributing to the development of IT Risk and compliance frameworks and strategies for AGSA. * Supporting the implementation of the centre Balance Score Card (BSC) initiatives. * **IT governance and risk management:** * Providing support to senior leadership on service portfolio and governance requirements. * Assessing ICT general controls through reviews of information security, data privacy, and business continuity. * Developing and implementing mitigation plans for identified ICT general control gaps. * Interpreting ICT policies and contributing to the development of compliant procedures, standards, and guidelines. * Developing and maintaining an ICT operational, business, and strategic risk register. * Assessing the impact and likelihood of identified ICT risks and proposing management measures (avoidance, mitigation, sharing, acceptance). * Assessing and reporting on the effectiveness of risk management standards and policies. * Developing processes to monitor compliance with ICT policies, IT risk management, and IT audit engagement management. * Supporting ICT management in awareness activities for IT governance, risk, and compliance. * **Compliance management:** * Facilitating active engagement in ICT internal control meetings to identify, escalate, mitigate, and remediate risks, fostering continuous improvement in ICT risk management and reduction of non-compliance. * Identifying, implementing, monitoring, and reporting on IT compliance to regulatory and legislative requirements. * Conducting regular, at least monthly, compliance assessments against ICT policies, frameworks, principles, SLAs/OLAs, processes, and procedures. * Managing compliance using international standards, frameworks, and best practices for benchmarking. * **IT audit engagement management:** * Coordinating IT internal and external audits as an intermediary between auditors and ICT teams. * Collecting and collating audit evidence as requested by audit teams. * Reviewing audit findings reports and providing responses. * Ensuring adequate storage of audit plans, engagement letters, and reports in the ICT GRSC repository. * Ensuring ICT teams are aware of audit plans and focus areas. * **Clean IT administration resolution of IT audit findings:** * Reviewing IT audit reports and following up with owners to close findings. * Facilitating the resolution of audit/compliance exceptions. * Ensuring timely rectification of security assessment findings. * Conducting ongoing monitoring and evaluation of ICT processes, procedures, and operations to identify and manage ICT risks. * Monitoring and tracking ICT risk mitigation actions until resolution within agreed timelines. * **Education and awareness:** * Providing support to IT management in awareness activities for IT governance, risk, compliance, and IT audit processes. * Ensuring adherence to applicable IT policies, processes, and procedures through regular training and awareness campaigns. * Providing training, coaching, mentoring, and support to first line of defence risk owners, control owners, risk indicator owners, management action owners, and risk coordinators to fulfil their ICT risk management and compliance responsibilities. * **Reporting:** * Tracking and reporting on risk management trends, opportunities, and remediation, providing monthly reports/updates to the leadership team. * Creating and maintaining reporting, problem resolution, and other tasks for continuous improvement and evolution of ICT risk management and compliance services. * Providing monthly reports to the line manager in line with agreed templates and timelines. * **Stakeholder Management:** * Establishing, building, and maintaining collaborative working relationships with internal and external stakeholders. * Scanning the environment to understand stakeholder needs and proactively interacting to deliver on them. * Working collaboratively with AGSA risk management and ICT functional area owners to satisfy internal and external audit requirements. * Partnering with the Risk and Ethics business unit to ensure consistent deployment and implementation of the evolving Enterprise Risk Management (ERM) framework and policies. * Engaging with stakeholders to identify and evaluate performance barriers and successes for continuous service delivery improvement. * Working in collaboration with colleagues to ensure timely delivery of work. * Facilitating cooperation from various stakeholders in implementing the information management strategy. * Establishing and maintaining relations with recognised professional bodies. * Managing service level agreements (SLAs). * **People Management:** * Managing own performance. * Participating in the Business Unit’s transformation, culture, diversity, and employment equity initiatives. * Committing to continuous learning and advancing skills. * Willingness to work extra hours. * **Financial management and operational management:** * Contributing to the compilation of the centre budget and managing project expenditure related to the functional area. * Ensuring compliance with the organisation’s governance processes, policies, and processes. * Managing supply chain processes within the functional area. * **Other responsibilities:** * Performing and/or managing other projects, tasks, and assignments delegated by the senior manager not stipulated in the role profile description as and when required. **Requirements (from the original advert)** * **Formal Education:** * Minimum Degree/diploma NQF 7 in Information Technology/Information Systems or Computer Science. * PLUS the following certifications: CISA, CISM, CRISC, CGEIT or CISSP. * COBIT Training. * **Added advantage:** Any post graduate qualification in IT, compliance, or Internal/External Audit or risk management. * **Experience:** * Minimum 5 years’ experience in IT auditing or ICT governance, risk and compliance in a medium to large organisation. * 3 years managing IT audit teams. * 3 years working with COBIT 19 processes. * **Added advantage:** A strong background in information technology with a clear understanding of the challenges of IT general controls. **Who should apply** The ideal candidate for this role should possess a strong educational background in Information Technology or Computer Science, complemented by specific professional certifications in IT auditing, governance, risk, or security. They must have substantial experience (at least 5 years) in IT auditing or ICT governance, risk and compliance within a sizable organisation, including experience in managing IT audit teams and working with COBIT 19 processes. A candidate with an understanding of IT general control challenges, a commitment to continuous learning, and the ability to manage their own performance while contributing to strategic initiatives would be well-suited. The role also requires an individual capable of effective stakeholder engagement and adherence to organisational governance. **Deadline** 16 October 2026 **Reference** Original posting: https://www.myjobmag.co.za/job/specialist-it-governance-risk-and-compliance-auditor-general-of-south-africa Source: myjobmag

Summary drafted with AI assistance from the original advert. The advert itself is the authority — how we use AI.

Job description

Apply by: 16 October 2026 Job description Strategic Function * Contribute to the development of IT Risk and compliance frameworks and strategies for AGSA. * Support the implementation of the centre Balance Score Card BSC initiatives. Product Management IT governance and risk management: * Provide support to the senior leadership team on the service portfolio and governance requirements. * Assess ICT general controls by conducting reviews on various aspects of information security, data privacy and business continuity. * Develop and implement a mitigation plan for ICT general control gaps identified during periodic assessments. * Interpret ICT policies and contribute to development of procedures, standards and guidelines that comply with these. * Develop and maintain a risk register that includes ICT operational, business and strategic risks. * Assess the impact and likelihood of identified ICT risks. * Propose measures including avoidance, mitigation, sharing and acceptance to manage risks. * Assess and report on the effectiveness of risk management standards and policies. * Develop processes to effectively monitor compliance with ICT policies, IT risk management and IT audit engagement management. * Provide support to the ICT management in awareness activities in respect of IT governance, risk and compliance requirements. These should include reporting on these focus areas. Compliance management: * Facilitate active engagement in ICT internal control meetings focusing on identification of emerging and existing risks, escalation, mitigation and remediation to ensuring an environment of continuously improving * ICT risk management and reduction of non-compliance culture. * Identify, implement, monitor and report on IT compliance to regulatory and legislative requirements. * Conduct regular at least monthly compliance assessment against ICT policies, frameworks, principles, SLAs/OLAs, processes and procedures. * Manage compliance using international standards, frameworks and best practices for benchmarking. IT audit engagement management: * Coordinate IT internal and external audit by being the intermediary between auditors and ICT teams. * Collect and collate audit evidence in line with requests for information form audit teams. * Review audit findings reports and provide responses to audit teams. * Ensure audit plans, audit engagement letters and audit reports are adequately stored in the ICT GRSC repository. * Ensure that ICT teams are aware of audit plans and focus areas. Clean IT administration resolution of IT audit findings: * Review IT audit reports and follow up with IT audit findings owners in respect of actions to close the findings. * Facilitate the resolution of audit / compliance exceptions * Ensure that the findings from any security assessment are rectified in a timely manner. * Conduct on-going monitoring and evaluation of ICT processes, procedures and operations to identify and manage ICT risks. * Monitor and track ICT risk mitigation actions until resolution and within agreed timelines. Education and awareness: * Provide support to the IT management in awareness activities in respect of IT governance, risk and compliance requirements. * Ensure that applicable IT policies, processes and procedures are adhered to through regular training and awareness campaigns. * Provide support to the IT management in awareness activities in respect IT audit processes * Provide training, coaching, mentoring and support to the first line of defence risk owners, controls owners, risk indicator owners, management action owners and risk coordinators, so they are enabled to fulfil their ICT risk management and compliance responsibilities. Reporting: * Tracks and reports on risk management trends, opportunities and remediation and provides monthly reports / updates to the leadership team. * Create and maintain reporting, problem resolution, and other tasks necessary to continuous improvement and evolution of ICT risk management and compliance services. * Provides monthly reports to line manager in line with agreed to reporting templates and timelines. Stakeholder Management * Establish, build and maintain collaborative working relationships with relevant internal and external stakeholders. * Build and maintain positive and value-adding relationships with relevant external stakeholders. * Scan the environment to ensure a clear understanding of stakeholder needs. * Proactively interact with stakeholders to determine their needs and deliver on them accordingly. * Work collaboratively with AGSA risk management and ICT functional area owners to satisfy internal and external audit requirements. * Partner with Risk and Ethics business unit to ensure consistent deployment and implementation of the evolving Enterprise Risk Management ERM framework and policies. * Engage with both internal and external stakeholders to identify and evaluate performance barriers and success in order to continuously improve on the service delivery. * Work in collaboration with colleagues in the centre to ensure timeous delivery of the work. * Facilitate the cooperation by various stakeholders in the implementation of the information management strategy. * Establish and maintain relations with recognised professional bodies within own professional sphere. * Manage service level agreements SLAs. People Management * Manage own performance. * Participate in the BU’s transformation, culture, and diversity and employment equity initiatives. * Commit to continuous learning and advancing of one’s skills so as to remain abreast with industry trends. * Willing to work extra hours. Financial management and operational management * Contribute to the compilation of centre budget, and manage project expenditure related to functional area. * Ensure compliance to the organisation’s governance processes, policies and processes. * Manage supply chain processes within own functional area. Other responsibilities * Perform and/or manage other projects, tasks and assignments delegated by the senior manager not stipulated in the role profile description as and when required. Minimum requirements Formal Education This position requires a minimum Degree/diploma NQF 7 in Information Technology/Information Systems or Computer Science PLUS the following certifications: * CISA, CISM, CRISC, CGEIT or CISSP * COBIT Training Added advantage: * Any post graduate qualification in IT, compliance or Internal/External Audit or risk management will be an advantage. Experience * Minimum 5 years’ experience in IT auditing or ICT governance, risk and compliance in a medium to large organisation, with 3 years managing IT audit teams and working with COBIT 19 processes. Added advantage: * Have a strong background in information technology with a clear understanding of the challenges of IT general controls.

Before you apply

  • Confirm the requirements and closing date on the original listing (myjobmag). SPANi lists vacancies from other sites and may not reflect last-minute changes.
  • Legitimate employers do not charge application, registration or training fees.
  • Don't send your ID or bank details before you have confirmed the employer is real.

How to spot a job scam

Before you apply

  • Read the full advert and confirm you meet the minimum requirements before applying.
  • Tailor your CV headline and most recent experience to the job title and key skills.
  • Note the closing date and reference number, and keep a copy of what you submit.
  • Apply only through the employer or job board link — never pay to apply.

Similar roles

PermanentIT & Software

Senior C# Developer

MultiSEARCH RecruitmentGauteng

Sectors: Information Technology Functions: Software Developer Qualification Types: Diplomas, Post Graduate Degrees Qualifications: Diploma: Information Technology, BTech (Honours)(Information Technology), National Diploma: Information Technology, Post Graduate Diploma: IT

Get new it & software jobs in gauteng by email

Free. No account needed. Unsubscribe with one click.

We only use your email to send this alert. See our privacy policy.

Specialist: IT Governance, Risk and Compliance at Auditor-General of South Africa | SPANi - South African Jobs