IT Risk Specialist/Risk Officer: Hyphen

  • Johannesburg
  • Full-time
  • POSTED 5 DAYS AGO

About the job

Job Description

Provide specialist IT risk advisory, oversight, and governance support to ensure the effective identification, assessment, monitoring, mitigation, and reporting of technology risks. The role supports the business and technology communities in maintaining a well-controlled IT environment aligned with governance frameworks, regulatory requirements, and risk management standards. Key Accountabilities:

1. IT Risk Management

Identify, assess, analyse, and evaluate IT risks across applications, infrastructure, projects, third parties, and operational processes. Perform impact and risk assessments, determine inherent and residual risk exposure, and evaluate the effectiveness of existing controls. Support management in developing and tracking remediation plans to address identified risks and control weaknesses. Review and contribute to IT risk reporting and governance activities. 2. Risk Monitoring, Reporting and Assurance

Monitor IT risk indicators and the overall risk posture of the business unit. Analyse trends, identify emerging concerns, and provide recommendations for improvement. Track remediation of findings from audits, self-assessments, controls testing, and monitoring reviews. Report residual risks and escalating issues to management and governance forums. 3. Governance, Policies and Compliance

Review and recommend updates to IT policies, standards, procedures, and risk frameworks. Ensure alignment with legislative, regulatory, audit, and organisational governance requirements. Provide guidance to business and technology teams on risk management methodologies and compliance obligations. 4. IT Project and Change Risk Oversight

Conduct risk assessments for new products, services, projects, major technology changes, and strategic initiatives. Evaluate compensating controls and ensure risk mitigation actions are appropriately implemented. Provide risk input into governance forums such as Change Advisory Boards (CAB), Steering Committees, and New Product Approval processes.

5. IT Continuity and Resilience

Assess the adequacy of Disaster Recovery (DR), Business Continuity (BCM), and IT Continuity plans. Monitor testing programmes, recovery capabilities, and supporting documentation. Ensure material changes are appropriately incorporated into continuity and resilience plans.

6. Incident, Security and Operational Risk Management

Participate in incident reviews and root cause analysis to identify control failures and recommend corrective actions. Monitor compliance with security policies, standards, and risk tolerances. Assess cyber and information security risks and monitor remediation activities.

7. Audit and Third-Party Risk Management

Support internal and external audits by providing risk insights and validating management action plans. Monitor closure of audit findings and ensure appropriate governance over overdue actions. Review vendor and third-party arrangements to ensure compliance with sourcing and vendor management requirements.

8. Risk Framework Development and Continuous Improvement

Contribute to the enhancement of IT risk, continuity, and governance frameworks. Benchmark industry practices, monitor emerging technology threats, and recommend improvements to the control environment. Promote risk awareness and support risk training programmes across the organisation. Key Stakeholders

Business Unit Management Technology and Operations Teams Information Security Audit (Internal and External) Risk Management Project and Change Governance Forums Third-Party Service Providers and Vendors

Minimum requirements:

At least 3-5 years' experience in IT Risk / Audit / Operational Risk and/or any relevant experience in payments.

Are you interested to take the step? We look forward to engaging with you further. Apply now!

#Post

#RMB

#LI-JB5

Job Details Take note that applications will not be accepted on the below date and onwards, kindly submit applications ahead of the closing date indicated below.

05/10/26

All appointments will be made in line with FirstRand Group’s Employment Equity plan. The Bank supports the recruitment and advancement of individuals with disabilities. In order for us to fulfill this purpose, candidates can disclose their disability information on a voluntary basis. The Bank will keep this information confidential unless we are required by law to disclose this information to other parties.