Specialist: IT Governance, Risk and Compliance
Position summary
Introduction
Job description
- Contribute to the development of IT Risk and compliance frameworks and strategies for AGSA.
- Support the implementation of the centre Balance Score Card (BSC) initiatives.
- Provide support to the senior leadership team on the service portfolio and governance requirements.
- Assess ICT general controls by conducting reviews on various aspects of information security, data privacy and business continuity.
- Develop and implement a mitigation plan for ICT general control gaps identified during periodic assessments.
- Interpret ICT policies and contribute to development of procedures, standards and guidelines that comply with these.
- Develop and maintain a risk register that includes ICT operational, business and strategic risks.
- Assess the impact and likelihood of identified ICT risks.
- Propose measures including avoidance, mitigation, sharing and acceptance to manage risks.
- Assess and report on the effectiveness of risk management standards and policies.
- Develop processes to effectively monitor compliance with ICT policies, IT risk management and IT audit engagement management.
- Provide support to the ICT management in awareness activities in respect of IT governance, risk and compliance requirements. These should include reporting on these focus areas.
- Facilitate active engagement in ICT internal control meetings focusing on identification of emerging and existing risks, escalation, mitigation and remediation to ensuring an environment of continuously improving
- ICT risk management and reduction of non-compliance culture.
- Identify, implement, monitor and report on IT compliance to regulatory and legislative requirements.
- Conduct regular (at least monthly) compliance assessment against ICT policies, frameworks, principles, SLAs/OLAs, processes and procedures.
- Manage compliance using international standards, frameworks and best practices for benchmarking.
- Coordinate IT internal and external audit by being the intermediary between auditors and ICT teams.
- Collect and collate audit evidence in line with requests for information form audit teams.
- Review audit findings reports and provide responses to audit teams.
- Ensure audit plans, audit engagement letters and audit reports are adequately stored in the ICT GRSC repository.
- Ensure that ICT teams are aware of audit plans and focus areas.
- Review IT audit reports and follow up with IT audit findings owners in respect of actions to close the findings.
- Facilitate the resolution of audit / compliance exceptions
- Ensure that the findings from any security assessment are rectified in a timely manner.
- Conduct on-going monitoring and evaluation of ICT processes, procedures and operations to identify and manage ICT risks.
- Monitor and track ICT risk mitigation actions until resolution and within agreed timelines.
- Provide support to the IT management in awareness activities in respect of IT governance, risk and compliance requirements.
- Ensure that applicable IT policies, processes and procedures are adhered to through regular training and awareness campaigns.
- Provide support to the IT management in awareness activities in respect IT audit processes
- Provide training, coaching, mentoring and support to the first line of defence risk owners, controls owners, risk indicator owners, management action owners and risk coordinators, so they are enabled to fulfil their ICT risk management and compliance responsibilities.
- Tracks and reports on risk management trends, opportunities and remediation and provides monthly reports / updates to the leadership team.
- Create and maintain reporting, problem resolution, and other tasks necessary to continuous improvement and evolution of ICT risk management and compliance services.
- Provides monthly reports to line manager in line with agreed to reporting templates and timelines.
- Establish, build and maintain collaborative working relationships with relevant internal and external stakeholders.
- Build and maintain positive and value-adding relationships with relevant external stakeholders.
- Scan the environment to ensure a clear understanding of stakeholder needs.
- Proactively interact with stakeholders to determine their needs and deliver on them accordingly.
- Work collaboratively with AGSA risk management and ICT functional area owners to satisfy internal and external audit requirements.
- Partner with Risk and Ethics business unit to ensure consistent deployment and implementation of the evolving Enterprise Risk Management (ERM) framework and policies.
- Engage with both internal and external stakeholders to identify and evaluate performance barriers and success in order to continuously improve on the service delivery.
- Work in collaboration with colleagues in the centre to ensure timeous delivery of the work.
- Facilitate the cooperation by various stakeholders in the implementation of the information management strategy.
- Establish and maintain relations with recognised professional bodies within own professional sphere.
- Manage service level agreements (SLAs).
- Manage own performance.
- Participate in the BU’s transformation, culture, and diversity and employment equity initiatives.
- Commit to continuous learning and advancing of one’s skills so as to remain abreast with industry trends.
- Willing to work extra hours.
Financial management and operational management
- Contribute to the compilation of centre budget, and manage project expenditure related to functional area.
- Ensure compliance to the organisation’s governance processes, policies and processes.
- Manage supply chain processes within own functional area.
Other responsibilities
- Perform and/or manage other projects, tasks and assignments delegated by the senior manager not stipulated in the role profile description as and when required.
Minimum requirements
• CISA, CISM, CRISC, CGEIT or CISSP
• COBIT Training
Any post graduate qualification in IT, compliance or Internal/External Audit or risk management will be an advantage.
Experience
Added advantage:
Have a strong background in information technology with a clear understanding of the challenges of IT general controls.
Closing Statement
The AGSA is not responsible for the verification of data provided and shall not be liable for any errors, factual, transcription or otherwise, contained in the information posted. Therefore, ensure that your online application and CV is correct, accurate and up to date. To successfully upload documents on the career site, ensure that the document name does not contain any special characters. This appointment is subject to the preferred candidate obtaining the necessary security clearance, reference checking and competency assessment. We embrace and committed in achieving employment equity within the organization. Auditor General welcomes applications
from all persons with disabilities.
Preference will be given to candidates within the hiring BU
False & Inaccurate information provided will result in a disqualified application
NB: Please note that only shortlisted candidates will be contacted. Should you not hear from the us
within four weeks, kindly consider your application unsuccessful