Enter a job title or keyword

Governance, Risk and Compliance Analyst


Job Location:

Johannesburg - South Africa

Monthly Salary: Not provided by the employer
Posted: 7 June 2026 (30+ days ago)
Application Deadline: 4 September 2026
Vacancies: 1 Vacancy
The job posting is outdated and position may be filled

Job Summary

Purpose of the Role

The GRC Analyst is responsible for supporting the implementation
integration and continuous enhancement of the organisations Governance
Risk and Compliance (GRC) framework across IT operations. The role ensuresthat governance structures risk management practices and compliancecontrols are effectively embedded within the business to support regulatoryadherence strengthen operational resilience and align technology processeswith internal policies industry standards and strategic business objectives.

Duties andResponsibilities
  • Support the development implementation and continuous improvementof IT governance policies standards procedures and control frameworks.
  • Monitor adherence to established IT governance frameworks internal
    controls and organisational policies.
  • Maintain accurate governance documentation audit evidence and
    compliance records to support internal and external assessments.
  • Contribute to the enhancement of governance practices that strengthenoperational effectiveness accountability and regulatory alignment.
  • Identify assess monitor and report on IT-related risks across systems
    processes projects vendors and technologies.
  • Maintain and update the IT risk register ensuring risks are appropriatelydocumented assessed and tracked through to resolution.
  • Conduct risk assessments for new initiatives third-party engagements
    system implementations and technology changes.
  • Collaborate with business and IT stakeholders to implement effective riskmitigation and remediation strategies.
  • Support the ongoing monitoring of key risk indicators (KRIs) and emergingtechnology or cybersecurity risks.
  • Support compliance with applicable legislation regulatory requirementsindustry standards and internal policies including frameworks such asPOPIA ISO standards and IT governance best practices.
  • Coordinate and support internal and external IT audits including the
    tracking and closure of remediation actions.
  • Conduct periodic compliance reviews control assessments and testing
    activities to evaluate the effectiveness of controls.
  • Assist with the identification investigation and resolution of compliancegaps and control deficiencies.
  • Prepare and maintain regular reports dashboards and management
    updates relating to risk exposure compliance status audit findings andremediation progress.
  • Communicate GRC requirements policy updates and compliance
    obligations to IT and business stakeholders where required.
  • Support awareness initiatives that promote a strong risk and complianceculture across the organisation.
  • Maintain accurate lifecycle records for all IT assets including hardwaresoftware and licensing assets from procurement through to disposal.
  • Monitor software licensing entitlements and usage to ensure compliancewith vendor agreements and licensing obligations.
  • Ensure IT asset management practices align with organisational policiesregulatory requirements and recognised frameworks such as ITIL.
  • Provide asset management data and reporting to support GRC activitiesincluding audits risk assessments and compliance reviews.
  • Collaborate with procurement legal cybersecurity and operational
    teams to strengthen third-party governance and oversight practices.
  • Conduct vendor and third-party risk assessments covering operational
    cybersecurity compliance and regulatory risks.
  • Monitor vendor compliance with contractual obligations organisational
    policies and applicable regulations including POPIA and information
    security requirements.

Knowledge and Experience
  • Minimum 7 years experience within an IT Governance Risk and
    Compliance (GRC) IT Audit IT Risk IT Asset Management or TechnologyGovernance environment.
  • Proven hands-on experience supporting IT governance frameworks auditprocesses compliance tracking risk registers and control managementactivities within a business or corporate environment.
  • Exposure to financial governance controls audit practices procurementgovernance vendor management and operational compliance processes.
  • Experience managing or supporting IT asset management software
    licensing governance and vendor compliance activities.
  • Experience within a regulated Corporate Financial Services Mining ormulti-site operational environment would be advantageous.
  • Working knowledge of governance frameworks and operational standardssuch as COBIT ITIL SOX or related governance methodologies.

Educational Qualifications
  • Bachelors Degree or Diploma in Information Technology Information
    Systems Governance Risk Management Audit Finance or a related field.
  • ITIL Certification
  • CoBiT Certification

Skills and Attributes
  • Strong analytical thinking with sound judgement and effective decision-
    making capability in complex governance and operational environments.
  • Risk-conscious mindset with the ability to identify assess and proactivelymitigate governance compliance and operational risks.
  • Strong negotiation and influencing skills with the ability to engage
    effectively across vendors service providers and internal stakeholders.
  • Well-developed organisational and coordination abilities with the
    capacity to manage multiple priorities deadlines and governance
    activities simultaneously.
  • Strong stakeholder relationship management capability with the ability tobuild credibility and maintain effective working relationships across ITfinance procurement audit and business functions.
  • Strong presentation and reporting skills with the ability to communicategovernance compliance audit and risk-related information clearly andprofessionally to management and stakeholders.
  • Strategic and solution-oriented mindset with the ability to contribute toprocess improvements operational efficiencies and governanceenhancement initiatives.