Job Openings IT Security Governance and Policy Specialist

About the job IT Security Governance and Policy Specialist

IT Security Governance and Policy Specialist

Location: Centurion, Gauteng (provisional – to be confirmed)
Positions Available: 5
Salary: Market-related
Employment Type: To be confirmed

Job Overview

We are seeking experienced and highly skilled IT Security Governance and Policy Specialists to support the development, implementation, maintenance and continuous improvement of information security governance frameworks, policies, standards and procedures within complex enterprise IT environments.

The successful candidates will be responsible for ensuring that information security practices align with organisational objectives, regulatory requirements, industry standards and recognised cybersecurity governance frameworks.

This role requires strong expertise in IT governance, risk management, regulatory compliance, information security policy development and cybersecurity assurance.

The ideal candidates will have proven experience working within structured enterprise environments, with the ability to translate security requirements into practical governance policies, controls and compliance processes.

Key Responsibilities

IT Security Governance and Policy Development

  • Develop, implement, review and maintain information security policies, standards, procedures and governance frameworks.
  • Ensure security policies align with organisational objectives, regulatory requirements and recognised industry standards.
  • Establish and maintain information security governance structures, processes and control frameworks.
  • Review existing security policies and recommend improvements to strengthen organisational security.
  • Support the development and implementation of enterprise information security strategies.
  • Define security governance responsibilities, accountability structures and reporting requirements.
  • Ensure policies and standards remain relevant to emerging cybersecurity risks and evolving technology environments.

Risk Management and Compliance

  • Conduct information security risk assessments and identify governance, risk and compliance gaps.
  • Develop and maintain information security risk registers and risk treatment plans.
  • Monitor compliance with approved security policies, procedures and regulatory obligations.
  • Support compliance with POPIA, ISO 27001, NIST and other applicable security requirements.
  • Assess the effectiveness of information security controls and recommend corrective actions.
  • Assist with third-party and supplier security risk assessments.
  • Monitor emerging regulatory developments and evaluate their implications for information security governance.
  • Coordinate remediation activities arising from compliance assessments and security audits.

Security Assurance and Audit Support

  • Support internal and external information security audits.
  • Coordinate the collection and maintenance of audit evidence and compliance documentation.
  • Review security control effectiveness and identify opportunities for improvement.
  • Track audit findings, corrective actions and remediation progress.
  • Assist with security control testing and governance maturity assessments.
  • Prepare governance reports, risk assessments and compliance updates for management.
  • Support the implementation and ongoing maintenance of information security management systems.

Stakeholder Engagement and Security Awareness

  • Collaborate with cybersecurity, infrastructure, application, risk, compliance and business teams.
  • Provide guidance on information security policies, standards and governance requirements.
  • Assist with information security awareness and compliance initiatives.
  • Support management in understanding information security risks and regulatory obligations.
  • Participate in governance committees, security reviews and risk management discussions.
  • Promote consistent adoption of security policies across the organisation.

Minimum Requirements

  • Relevant diploma or degree in Information Technology, Information Systems, Computer Science, Cybersecurity, Risk Management or a related discipline.
  • Typically 3–5 years of relevant experience in IT security governance, information security risk management, IT compliance or cybersecurity GRC.
  • Proven experience developing, implementing or maintaining information security policies and standards.
  • Strong understanding of information security governance principles and enterprise risk management.
  • Practical experience working with information security frameworks such as ISO/IEC 27001, NIST or COBIT.
  • Knowledge of information security risk assessment methodologies and control frameworks.
  • Experience conducting compliance assessments, governance reviews or security control evaluations.
  • Understanding of IT audit processes, audit findings and remediation management.
  • Familiarity with applicable South African regulatory requirements, including POPIA.
  • Experience maintaining risk registers, policy documentation and compliance reports.
  • Strong stakeholder engagement, communication and technical documentation skills.
  • Ability to interpret security standards and translate them into practical organisational policies and controls.

Technical Skills and Competencies

Information Security Governance

  • Information security policy and standards development
  • IT governance frameworks and control structures
  • Information security management systems (ISMS)
  • Governance maturity assessments
  • Security control design and evaluation
  • Enterprise cybersecurity governance

Risk Management

  • Information security risk assessments
  • Risk identification, analysis and treatment
  • Risk registers and mitigation planning
  • Third-party and supplier risk management
  • Security control gap assessments
  • Risk-based decision-making

Compliance and Regulatory Frameworks

  • ISO/IEC 27001 and ISO/IEC 27002
  • NIST Cybersecurity Framework
  • COBIT
  • CIS Critical Security Controls
  • Protection of Personal Information Act (POPIA)
  • Applicable data protection and information security regulations

IT Security Audit and Assurance

  • Internal and external audit coordination
  • Security control assessments
  • Compliance monitoring and reporting
  • Audit evidence management
  • Corrective action and remediation tracking
  • Governance reporting and management dashboards

GRC Systems and Tools

Experience with one or more of the following would be advantageous:

  • ServiceNow GRC / Integrated Risk Management
  • RSA Archer
  • MetricStream
  • Microsoft Purview Compliance Manager
  • OneTrust
  • Other enterprise governance, risk and compliance platforms

Documentation and Reporting

  • Information security policies and procedures
  • Governance frameworks and standards
  • Security risk assessments
  • Compliance reports and dashboards
  • Audit findings and remediation reports
  • Management and executive-level reporting

Relevant Certifications (Advantageous)

One or more of the following certifications would be beneficial:

  • Certified Information Security Manager (CISM)
  • Certified Information Systems Auditor (CISA)
  • Certified Information Systems Security Professional (CISSP)
  • Certified in Risk and Information Systems Control (CRISC)
  • ISO/IEC 27001 Lead Implementer
  • ISO/IEC 27001 Lead Auditor
  • COBIT Foundation or equivalent
  • Certified in Governance of Enterprise IT (CGEIT)
  • Relevant cybersecurity governance, risk management or compliance certifications

Key Personal Attributes

  • Strong analytical and risk assessment capabilities.
  • Excellent attention to detail and accuracy.
  • Strong policy development and technical writing skills.
  • Ability to interpret regulatory and governance requirements.
  • Excellent communication and stakeholder engagement abilities.
  • Strong organisational and documentation skills.
  • Ability to work independently and collaboratively across departments.
  • Sound judgement and a structured approach to risk management.
  • High levels of confidentiality, integrity and professional ethics.
  • Proactive approach to identifying governance gaps and recommending improvements.

Application Requirements

Interested candidates should submit an updated CV clearly detailing their experience in IT security governance, information security policy development, risk management and regulatory compliance.

Applications should include copies of relevant academic qualifications and professional certifications.

Candidates are encouraged to highlight:

  • Information security governance frameworks they have implemented or maintained.
  • Experience developing and reviewing cybersecurity policies and standards.
  • Exposure to ISO 27001, NIST, COBIT and other recognised frameworks.
  • Involvement in IT security audits, compliance assessments and risk management initiatives.
  • Enterprise GRC platforms and tools they have worked with.
  • Examples of governance improvements, policy implementations or successful audit outcomes.

Please note: Specific project requirements, remuneration, employment arrangements and working conditions will be confirmed during the recruitment process.