JobsZA
Back to Johannesburg jobs

Risk Officer - ERM (IT Risk)

Nedbank

Johannesburg, Gauteng

Salary not listedFull-time · Posted 2 weeks ago

IT roles span help desk, support, networking and software development, and remain one of SA's most in-demand and best-paid skill areas.

This listing does not state a salary. As a guide, it roles in South Africa typically pay R18 000 to R65 000 a month (indicative).

Job description

Job Classification

  • Job Requisition: 146989
  • TA Specialist: Refilwe Falatsi
  • Closing Date: 13 August 2026
  • Location: 135 Rivonia Campus, Sandown
  • Cluster: Personal and Private Banking | Nedbank Insurance | Governance
  • Employment Equity Statement: Preference will be given to applicants from Underrepresented Groups Job Purpose

To facilitate and support the effective management of the Enterprise Wide and Operational Risk Frameworks in order to manage current and emerging risks to assist Nedbank in achieving its objectives.Job Responsibilities

  • Contribute to a culture conducive to the achievement of transformation goals by participating in Nedbank Culture building initiatives (e.g. staff surveys etc).

  • Participate and support corporate social responsibility initiatives for the achievement of key business strategies.

  • Identify and recommend opportunities to enhance processes; systems and policies and support implementation of new processes; policies and systems.

  • Facilitate the implementation and maintenance of the Technology Risk Management Framework across Nedbank Insurance.

  • Conduct risk assessments covering information technology, cyber security, cloud computing, third-party service providers, and emerging technology risks.

  • Identify, assess, monitor, and report on key technology risks and control weaknesses.

  • Maintain risk registers and ensure risks are appropriately escalated and mitigated.

  • Review and challenge technology-related risk assessments performed by first-line technology teams.

  • Develop, monitor and assess technology risk indicators (KRIs) and provide meaningful reporting to management and governance forums.

  • Support the development and execution of risk treatment plans for identified control gaps.

  • Keep abreast of legislation and other industry changes that impacts on role by reading the relevant newsletters; websites and attending sessions.

  • Understand and embrace the Nedbank vision and demonstrate the values through interaction with team and stakeholders.

  • Improve personal capability and stay abreast of developments in field of expertise by identifying training courses and career progression for self through input and feedback from managersEnsure personal growth and enable effectiveness in performance of roles and responsibilities by ensuring all learning activities are completed; experience practiced and certifications obtained and/or maintained within specified time frames.

  • Ensure information is provided correctly to stakeholders by maintaining knowledge sharing knowledge with team.

  • Make recommendations for service improvements by using feedback gathered in training sessions and other engagements with stakeholders.

  • Build relationships and identify synergies with internal clients stakeholders

  • Conduct gap analysis of Nedbank Insurance processes using the relevant guidelines and checklists to confirm compliance to bank standards and compliance to national legislation.

  • Provide coaching and/or recommendations for corrective measures based on gap analysis; using root cause analysis techniques and effective feedback and coaching skills.

  • Train/coach relevant internal stakeholders in business systems by following training guides and using approved support material. Job Responsibilities Continue

  • Governance, Risk and Compliance

    • Support compliance with relevant regulations, standards, and frameworks including:
    • King IV
    • COBIT
    • ISO 27001 and 31000
    • NIST Cybersecurity Framework
    • POPIA
    • Financial Sector Conduct Authority (FSCA) requirements
    • Prudential Authority standards
    • Facilitate technology risk governance forums and committees.
    • Prepare risk reports and dashboards for executive management, risk committees, and board structures.
    • Ensure adherence to risk appetite and risk tolerance thresholds
  • Cyber and Information Security Risk

    • Collaborate with Information Security teams to monitor cyber security risks and control effectiveness.
    • Evaluate cyber security incidents, root causes, and remediation plans from a risk management perspective.
    • Review vulnerability management, access management, data protection, and security control assessments.
    • Assess risks associated with digital transformation, cloud adoption, and emerging technologies.
  • Operational Resilience and Business Continuity

    • Support technology resilience, disaster recovery, and business continuity risk assessments.
    • Monitor critical technology services and associated resilience controls.
    • Participate in resilience testing, scenario analysis, and incident response exercises.
    • Evaluate operational resilience risks impacting customer service and business operations.
  • Risk Assurance and Control Effectiveness

    • Assess design and operating effectiveness of technology controls.
    • Track and monitor audit findings, risk issues, and management actions.
    • Conduct thematic reviews and control assessments across technology environments.
    • Perform root cause analysis on recurring technology incidents and losses.
  • Stakeholder Engagement

    • Build effective relationships with Technology, Information Security, Internal Audit, Compliance, Risk Management, and business stakeholders.
    • Provide risk advisory support to technology projects and strategic initiatives.
    • Promote awareness of technology risk management practices across the organisation.
    • Influence risk-informed decision-making through effective communication and challenge People Specification Essential Qualification - NQF Level Bachelor's Degree in Information Systems, Computer Science, Information Technology, Risk Management, Internal Auditing, Accounting and Engineering Preferred Qualification
  • Postgraduate Diploma in Risk Management

  • BCom Honours (Risk Management/Internal Auditing)

  • BSc Information Systems

  • Master's Degree in Information Systems, Cyber Security, or Risk Management Preferred Certifications

  • CISA (Certified Information Systems Auditor)

  • CRISC (Certified in Risk and Information Systems Control)

  • CGEIT (Certified in Governance of Enterprise IT)

  • CISSP (Certified Information Systems Security Professional)

  • ISO 27001 Lead Implementer or Lead Auditor

  • COBIT Foundation

  • Certified Third-Party Risk Professional (CTPRP)

  • ITIL Foundation Minimum Experience Level

  • Minimum 5 years experience in Technology Risk Management, Information Security Risk, IT Audit, IT Governance, Cyber Risk, or Operational Risk.

  • Minimum 5 years experience within Financial Services, Insurance, Banking, or a regulated environment.

  • Demonstrated experience performing technology risk assessments, control reviews, issue management, and risk reporting.

  • Experience working with technology governance frameworks such as COBIT, ISO 27001, NIST, and ITIL.

  • Experience engaging with technology stakeholders, auditors, regulators, and senior management. Technical / Professional Knowledge

  • Cluster specific operations

  • Communication Strategies

  • Data analysis

  • Governance, Risk and Controls

  • Principles of financial management

  • Principles of project management

  • Relevant software and systems knowledge

  • Research methodology

  • Decision-making process Behavioural Competencies

  • Earning Trust

  • Communication

  • Decision Making

  • Work Standards

  • Managing Work

  • Technical/Professional Knowledge and Skills

- Please contact the Nedbank Recruiting Team at +27 860 555 566

Good to know

What does this it job pay?

This listing does not state a salary. As a guide, it roles in South Africa typically pay R18 000 to R65 000 a month (indicative).

Do I need experience for it jobs in Johannesburg?

This it role may ask for some experience or a relevant qualification. Read the listing for the specifics before you apply.

How do I apply for this job?

Tap "Apply on Indeed" to open the original listing, where you can read the full description and apply directly. JobsZA never charges you to apply, and you should never pay money to get a job.

Found on Indeed · Posted 2 weeks ago

More it and similar jobs in Johannesburg

Accountant

Confidential

Johannesburg, GautengToday

R40K - R40K/mo

Senior Accountant

Confidential

Johannesburg, GautengToday

R50K - R50K/mo

Senior Financial Accountant

Confidential

Johannesburg, GautengToday

R41.7K - R41.7K/mo

Diesel Mechanic

Confidential

Johannesburg, GautengToday

R15K - R15K/mo

Get jobs on WhatsApp (free)

New jobs every morning. No spam.

Follow on WhatsApp