IT Risk Specialist/Risk Officer: Hyphen
Quick Summary
1. IT Risk Management Identify, assess, analyse, and evaluate IT risks across applications, infrastructure, projects, third parties, and operational processes. Perform impact and risk assessments,
- Identify, assess, analyse, and evaluate IT risks across applications, infrastructure, projects, third parties, and operational processes.
- Perform impact and risk assessments, determine inherent and residual risk exposure, and evaluate the effectiveness of existing controls.
- Support management in developing and tracking remediation plans to address identified risks and control weaknesses.
- Review and contribute to IT risk reporting and governance activities.
- Monitor IT risk indicators and the overall risk posture of the business unit.
- Analyse trends, identify emerging concerns, and provide recommendations for improvement.
- Track remediation of findings from audits, self-assessments, controls testing, and monitoring reviews.
- Report residual risks and escalating issues to management and governance forums.
- Review and recommend updates to IT policies, standards, procedures, and risk frameworks.
- Ensure alignment with legislative, regulatory, audit, and organisational governance requirements.
- Provide guidance to business and technology teams on risk management methodologies and compliance obligations.
- Conduct risk assessments for new products, services, projects, major technology changes, and strategic initiatives.
- Evaluate compensating controls and ensure risk mitigation actions are appropriately implemented.
- Provide risk input into governance forums such as Change Advisory Boards (CAB), Steering Committees, and New Product Approval processes.
- Assess the adequacy of Disaster Recovery (DR), Business Continuity (BCM), and IT Continuity plans.
- Monitor testing programmes, recovery capabilities, and supporting documentation.
- Ensure material changes are appropriately incorporated into continuity and resilience plans.
- Participate in incident reviews and root cause analysis to identify control failures and recommend corrective actions.
- Monitor compliance with security policies, standards, and risk tolerances.
- Assess cyber and information security risks and monitor remediation activities.
- Support internal and external audits by providing risk insights and validating management action plans.
- Monitor closure of audit findings and ensure appropriate governance over overdue actions.
- Review vendor and third-party arrangements to ensure compliance with sourcing and vendor management requirements.
- Contribute to the enhancement of IT risk, continuity, and governance frameworks.
- Benchmark industry practices, monitor emerging technology threats, and recommend improvements to the control environment.
- Promote risk awareness and support risk training programmes across the organisation.
- Business Unit Management
- Technology and Operations Teams
- Information Security
- Audit (Internal and External)
- Risk Management
- Project and Change Governance Forums
- Third-Party Service Providers and Vendors
Requirements
~1 min readAt least 3-5 years' experience in IT Risk / Audit / Operational Risk and/or any relevant experience in payments.
#Post
#RMB
#LI-JB5
All appointments will be made in line with FirstRand Group’s Employment Equity plan. The Bank supports the recruitment and advancement of individuals with disabilities. In order for us to fulfill this purpose, candidates can disclose their disability information on a voluntary basis. The Bank will keep this information confidential unless we are required by law to disclose this information to other parties.
Location & Eligibility
Listing Details
- First seen
- September 30, 2026
- Last seen
- September 30, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 49%
- Scored at
- September 30, 2026
Signal breakdown
Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.