IT Risk & Compliance Analyst (SP5) - IT Risk & Compliance
Position summary
Introduction
Job description
KEY PERFORMANCE AREAS (KPAs)
1. Provide audit services in accordance with IT audit standards to assist the group in protecting and controlling information systems and assets.
· Execute a risk-based IT audit strategy in compliance with IT audit standards to ensure that key risk areas are audited and managed.
· Communicate audit results and make recommendations to key stakeholders.
· Plan specific audits to determine whether information systems are protected, controlled and provide value to the organization.
2. Ensure that the necessary organizational structures and processes are in place to achieve objectives and to support the group's strategy.
· Evaluate the effectiveness of the IT governance structure to ensure it supports the group’s strategies and objectives.
· Evaluate the group’s IT policies, standards and procedures, and the processes ensure they support the IT strategy and comply with regulations, legal requirements and industry standards.
· Evaluate risk management practices to ensure the group’s IT risks are identified, assessed, monitored, reported and managed.
· Evaluate monitoring and reporting of IT Key Performance Indicators (KPIs) to ensure management receives sufficient and timely information.
· Evaluate the group’s Business Continuity Plan (BCP), including alignment of the IT Disaster Recovery Plan (DRP) with the BCP, to ensure the group has the ability to continue essential business operations during the period of an IT disruption.
3. Ensure that the practices for the acquisition, development, testing and implementation of information systems meet the group’s strategies and objectives.
· Evaluate controls for information systems during the requirements, acquisition, development and testing phases for compliance with the group's policies, standards, procedures and applicable external requirements.
· Evaluate IT risk and perform due diligence and periodic security reviews on IT vendors.
4. Ensure that the processes for information systems operations, maintenance and service management meet the group’s strategies and objectives.
· Evaluate change management practices to ensure changes made to systems and applications are adequately controlled and documented.
· Evaluate incident management practices to ensure problems and incidents, are prevented, detected, analysed, reported and resolved in a timely manner.
· Evaluate the IT service management practices to ensure the controls and service levels expected by the group are adhered to.
5. Ensure that the group’s policies, standards, procedures and controls ensure the confidentiality, integrity, availability and privacy of information assets.
· Evaluate the IT policies, standards and procedures for completeness, alignment with best practices, industry standards and compliance with regulatory and legal requirements.
· Evaluate the design, implementation, maintenance, monitoring and reporting of system and logical security controls to ensure the confidentiality, integrity, availability and privacy of information.
· Partner with other stakeholders to develop and maintain IT procedures and periodically test those procedures for effectiveness.
Minimum requirements
CORE COMPETENCIES
- Problem solving and analytical skills
- Logical thinker
- Persistence
- Communication skills (orally/written)
- Enquiring mind
- Should be able to work under pressure
- Friendliness
- Teamwork
- Reliability
EXPERIENCE/ KNOWLEDGE & SKILLS
- Minimum of 2 years of experience in risk management, IT audit, IT compliance, or related
- Computer literacy essential (Excel, Word)
- General understanding of underlying IT infrastructure, architecture, and concepts.
- Sound knowledge of IT risk management
- Sound knowledge of audit techniques
- Good time management and related organizational skills
- IT asset management
- Knowledge of enterprise risk management
- Knowledge of benefits realization practices
QUALIFICATIONS
- Bachelor’s degree in Informatics, Risk Management, Auditing, Information Systems or equivalent.
- Certified Information Systems Auditor (CISA) Certification will be an advantage.
- Certified in the Governance of Enterprise IT (CGEIT) Certification will be an advantage.
