Job description

  • Location:
    Sandton
  • Employee Type:
    Permanent
  • Department:
    Group Risk - Technology
  • Division:
    Central Services

IT Risk Analyst (GRC) (14061)

Description

The Technology Risk Analyst supports the Technology Risk Lead and broader Technology Risk & Governance team in managing technology and information risks across Digital & Technology. The role works collaboratively with business units, Information Security, Operational Risk, Internal Audit, and other risk and assurance stakeholders to identify, assess, monitor, report, and facilitate the remediation of technology risks. The role also provides risk guidance, promotes compliance with relevant policies and standards, and supports the development of a risk-conscious culture.

 

Key Responsibilities

  • Support the Technology Risk Lead in executing the Digital & Technology risk management process.
  • Engage key stakeholders to ensure that technology risks are understood and managed effectively.
  • Identify threats and assess risks relating to technology and information assets.
  • Conduct and support ongoing risk assessments, including:
    • General technology control assessments
    • Application risk assessments/Control Self-Assessment
    • Risk-event and major-incident reviews
    • Project risk reviews
    • Internal and external audit activities
    • Third-party risk engagements
  • Coordinate and monitor the remediation of identified technology risks.
  • Provide guidance throughout the risk management lifecycle, including risk rating, tracking, reporting, and escalation.
  • Produce relevant Technology Risk status reports, management information, and stakeholder updates.
  • Apply approved risk management tools, processes, and methodologies.
  • Monitor compliance with group policies and standards.
  • Collaborate with Information Security and governance forums to define the scope and coverage of technical security controls.
  • Report on the design and effectiveness of relevant technical security controls.
  • Maintain continuous collaboration with risk, governance, and assurance stakeholders.
  • Promote a risk-conscious culture through stakeholder engagement, risk awareness initiatives, and relevant training.

 

Qualifications, Experience and Skills

  • A completed university degree in Information Systems, Information Technology, Computer Science, Engineering, Accounting or equivalent
  • Favorable that you have obtained professional certifications or passed the examinations for CRISC
  • 4+ years of experience in information technology audits, security operations, or technology risk
  • Strong understanding of complex business and IT processes, and their related risks
  • Proficiency in using AI-enabled productivity tools, such as Copilot, to improve efficiency, generate insight and support decision-making. Applies critical thinking and sound judgement when interpreting outputs, remains accountable for the quality and accuracy of their work
  • Able to multi-task and possess effective time management skills.
  • Able to produce high-quality work deliverables on timely basis.
  • Build and nurture positive working relationships with stakeholders.

 

What We Value

At Investec we seek creative, talented people with passion, energy and stamina, who collaborate unselfishly.

 

 

 

We are committed to diversity and inclusion when recruiting internally and externally. 


 
Close map
Location
Sandton
100 Grayston Drive, Investec Bank Ltd, Johannesburg, South Africa, 2196
Loading...

Meet the recruiter

Kiara Jenna Hendricks

LinkedIn

Share this page
Share with linkedin
Share with facebook
Share with twitter
Share with email
Vacancy Alerts
Create an alert subscription based on this vacancy

Benefits

Pension
Private Medical Cover
Virtual GP
Gym Discounts
Psychologist Service
Annual Leave
Life Assurance
Loading