Specialist: IT Governance, Risk and Compliance
Auditor-General of South Africa
- Location
- Gauteng
- Minimum qualification
- Diploma
- Closing date
First listed . Last checked at source .
In brief
**Overview** This role is for a Specialist: IT Governance, Risk and Compliance at the Auditor-General of South Africa (AGSA). The position is central to developing and implementing IT risk and compliance frameworks and strategies, supporting the organisation's strategic initiatives, and ensuring adherence to IT governance and regulatory requirements. **What you will do** The Specialist: IT Governance, Risk and Compliance will undertake a range of responsibilities including: * **Strategic Function:** * Contributing to the development of IT Risk and compliance frameworks and strategies for AGSA. * Supporting the implementation of the centre Balance Score Card (BSC) initiatives. * **IT governance and risk management:** * Providing support to senior leadership on service portfolio and governance requirements. * Assessing ICT general controls through reviews of information security, data privacy, and business continuity. * Developing and implementing mitigation plans for identified ICT general control gaps. * Interpreting ICT policies and contributing to the development of compliant procedures, standards, and guidelines. * Developing and maintaining an ICT operational, business, and strategic risk register. * Assessing the impact and likelihood of identified ICT risks and proposing management measures (avoidance, mitigation, sharing, acceptance). * Assessing and reporting on the effectiveness of risk management standards and policies. * Developing processes to monitor compliance with ICT policies, IT risk management, and IT audit engagement management. * Supporting ICT management in awareness activities for IT governance, risk, and compliance. * **Compliance management:** * Facilitating active engagement in ICT internal control meetings to identify, escalate, mitigate, and remediate risks, fostering continuous improvement in ICT risk management and reduction of non-compliance. * Identifying, implementing, monitoring, and reporting on IT compliance to regulatory and legislative requirements. * Conducting regular, at least monthly, compliance assessments against ICT policies, frameworks, principles, SLAs/OLAs, processes, and procedures. * Managing compliance using international standards, frameworks, and best practices for benchmarking. * **IT audit engagement management:** * Coordinating IT internal and external audits as an intermediary between auditors and ICT teams. * Collecting and collating audit evidence as requested by audit teams. * Reviewing audit findings reports and providing responses. * Ensuring adequate storage of audit plans, engagement letters, and reports in the ICT GRSC repository. * Ensuring ICT teams are aware of audit plans and focus areas. * **Clean IT administration resolution of IT audit findings:** * Reviewing IT audit reports and following up with owners to close findings. * Facilitating the resolution of audit/compliance exceptions. * Ensuring timely rectification of security assessment findings. * Conducting ongoing monitoring and evaluation of ICT processes, procedures, and operations to identify and manage ICT risks. * Monitoring and tracking ICT risk mitigation actions until resolution within agreed timelines. * **Education and awareness:** * Providing support to IT management in awareness activities for IT governance, risk, compliance, and IT audit processes. * Ensuring adherence to applicable IT policies, processes, and procedures through regular training and awareness campaigns. * Providing training, coaching, mentoring, and support to first line of defence risk owners, control owners, risk indicator owners, management action owners, and risk coordinators to fulfil their ICT risk management and compliance responsibilities. * **Reporting:** * Tracking and reporting on risk management trends, opportunities, and remediation, providing monthly reports/updates to the leadership team. * Creating and maintaining reporting, problem resolution, and other tasks for continuous improvement and evolution of ICT risk management and compliance services. * Providing monthly reports to the line manager in line with agreed templates and timelines. * **Stakeholder Management:** * Establishing, building, and maintaining collaborative working relationships with internal and external stakeholders. * Scanning the environment to understand stakeholder needs and proactively interacting to deliver on them. * Working collaboratively with AGSA risk management and ICT functional area owners to satisfy internal and external audit requirements. * Partnering with the Risk and Ethics business unit to ensure consistent deployment and implementation of the evolving Enterprise Risk Management (ERM) framework and policies. * Engaging with stakeholders to identify and evaluate performance barriers and successes for continuous service delivery improvement. * Working in collaboration with colleagues to ensure timely delivery of work. * Facilitating cooperation from various stakeholders in implementing the information management strategy. * Establishing and maintaining relations with recognised professional bodies. * Managing service level agreements (SLAs). * **People Management:** * Managing own performance. * Participating in the Business Unit’s transformation, culture, diversity, and employment equity initiatives. * Committing to continuous learning and advancing skills. * Willingness to work extra hours. * **Financial management and operational management:** * Contributing to the compilation of the centre budget and managing project expenditure related to the functional area. * Ensuring compliance with the organisation’s governance processes, policies, and processes. * Managing supply chain processes within the functional area. * **Other responsibilities:** * Performing and/or managing other projects, tasks, and assignments delegated by the senior manager not stipulated in the role profile description as and when required. **Requirements (from the original advert)** * **Formal Education:** * Minimum Degree/diploma NQF 7 in Information Technology/Information Systems or Computer Science. * PLUS the following certifications: CISA, CISM, CRISC, CGEIT or CISSP. * COBIT Training. * **Added advantage:** Any post graduate qualification in IT, compliance, or Internal/External Audit or risk management. * **Experience:** * Minimum 5 years’ experience in IT auditing or ICT governance, risk and compliance in a medium to large organisation. * 3 years managing IT audit teams. * 3 years working with COBIT 19 processes. * **Added advantage:** A strong background in information technology with a clear understanding of the challenges of IT general controls. **Who should apply** The ideal candidate for this role should possess a strong educational background in Information Technology or Computer Science, complemented by specific professional certifications in IT auditing, governance, risk, or security. They must have substantial experience (at least 5 years) in IT auditing or ICT governance, risk and compliance within a sizable organisation, including experience in managing IT audit teams and working with COBIT 19 processes. A candidate with an understanding of IT general control challenges, a commitment to continuous learning, and the ability to manage their own performance while contributing to strategic initiatives would be well-suited. The role also requires an individual capable of effective stakeholder engagement and adherence to organisational governance. **Deadline** 16 October 2026 **Reference** Original posting: https://www.myjobmag.co.za/job/specialist-it-governance-risk-and-compliance-auditor-general-of-south-africa Source: myjobmag
Summary drafted with AI assistance from the original advert. The advert itself is the authority — how we use AI.
Job description
Before you apply
- Confirm the requirements and closing date on the original listing (myjobmag). SPANi lists vacancies from other sites and may not reflect last-minute changes.
- Legitimate employers do not charge application, registration or training fees.
- Don't send your ID or bank details before you have confirmed the employer is real.
Before you apply
- Read the full advert and confirm you meet the minimum requirements before applying.
- Tailor your CV headline and most recent experience to the job title and key skills.
- Note the closing date and reference number, and keep a copy of what you submit.
- Apply only through the employer or job board link — never pay to apply.