IT Governance, Risk & Compliance Officer

Posted 7 Days Ago
Be an Early Applicant
Plattekloof, City of Cape Town, Western Cape, ZAF
In-Office
Mid level
Information Technology • Professional Services • Infrastructure as a Service (IaaS)
The Role
Lead the ISO 27001 certification program and maintain the information security management system. Own POPIA compliance, risk registers, policies, audits, certification-body relationships, data protection impact assessments, vendor risk reviews, security awareness training, and compliance reporting. Coordinate with cybersecurity and IT teams to implement controls, manage incidents and requests, track remediation, and maintain audit evidence.
Summary Generated by Built In

Are you a detail oriented governance and compliance specialist with a passion for information security? Join our Information Systems team as an IT Governance, Risk & Compliance Officer in Plattekloof, where you'll lead Herotel's ISO 27001 certification programme and own our POPIA compliance obligations. 

This role is perfect for someone who thrives on structure, documentation and stakeholder engagement, and who wants to build a governance function from the ground up within a fast growing telecommunications business.

What you'll do:

  • Lead Herotel's ISO 27001 certification programme, including ISMS scoping, gap and risk assessments, and maintaining the Statement of Applicability
  • Develop, maintain and drive adoption of the information security policy suite
  • Maintain the information security risk register and risk treatment plan, tracking remediation with control owners
  • Plan and execute the ISMS internal audit programme, coordinate management reviews and maintain ISMS records and evidence
  • Manage the certification body relationship, including Stage 1 and Stage 2 audits, findings closure and ongoing surveillance audit readiness
  • Coordinate implementation of Annex A controls together with the Cybersecurity Engineer and IT teams
  • Own POPIA compliance, developing, maintaining and enforcing policies and procedures aligned with legislative requirements
  • Manage and respond to POPIA related requests and incidents, including data subject access requests, complaints and data breach notifications
  • Serve as Herotel's Deputy Information Officer under POPIA
  • Conduct data protection impact assessments for new systems, processes and third party integrations that handle personal information
  • Run the security awareness and training programme, tracking completion and driving adoption across the organisation
  • Conduct third party and vendor security and privacy risk assessments, reviewing vendor agreements for security and compliance obligations
  • Produce the monthly compliance dashboard covering ISMS status, audit findings, POPIA metrics and awareness training

What you'll need:

  • Diploma or Degree in Information Technology, Information Security, Audit, Law or a related field
  • 3 to 5 years experience in information security governance, risk and compliance, ISMS, or privacy roles
  • Hands on experience implementing or operating an ISO 27001 ISMS
  • Working knowledge of POPIA and its practical application in a South African operating context
  • Proven policy authorship, with experience driving policy adoption and security awareness training
  • Experience with risk assessment methodologies and maintaining risk registers and treatment plans
  • Exposure to third party and vendor risk assessment
  • Sufficient understanding of security technologies such as SIEM, endpoint protection and vulnerability management to define and audit controls
  • Strong written communication, documentation and stakeholder engagement skills
  • ISO 27001 Lead Implementer certification is strongly preferred, or willingness to obtain it within the first six months
  • Participation in certification or surveillance audits is advantageous
  • Desirable certifications include ISO 27001 Lead Auditor, CISM, CISA, CRISC, CIPP or CIPM

What we offer:

  • Exposure to a dynamic workplace
  • A chance to grow your skills through our internal academy
  • A friendly, team driven environment
  • Group Risk Benefits
  • Medical Benefits
  • Health and Lifestyle Programmes

Important Disclaimer:

  • Please ensure that the information you provide in your application is true, accurate, and correct.
  • Preference will be given to candidates from Designated Groups, as defined by the Employment Equity Act and in line with Herotel's Employment Equity Plan.
  • By submitting an application, you consent to the processing of your personal information in accordance with POPIA for recruitment purposes. For more details on how we handle personal information, please refer to our Privacy Policy on our website.
  • If you do not hear from us within 14 days, please consider your application unsuccessful.

Skills Required

  • Diploma or degree in Information Technology, Information Security, Audit, Law, or a related field
  • 3 to 5 years of experience in information security governance, risk and compliance, ISMS, or privacy roles
  • Hands-on experience implementing or operating an ISO 27001 ISMS
  • Working knowledge of POPIA and its practical application in South Africa
  • Experience authoring policies and driving policy adoption and security awareness training
  • Experience with risk assessment methodologies and maintaining risk registers and treatment plans
  • Exposure to third-party and vendor risk assessment
  • Sufficient understanding of SIEM, endpoint protection, and vulnerability management to define and audit controls
  • Strong written communication, documentation, and stakeholder engagement skills
  • ISO 27001 Lead Implementer certification or willingness to obtain it within six months
  • Participation in certification or surveillance audits
  • ISO 27001 Lead Auditor, CISM, CISA, CRISC, CIPP, or CIPM certification
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: City of Cape Town
1,163 Employees
Year Founded: 2013

What We Do

Build the Future of Connectivity. Join a purpose driven team shaping the future of connectivity across South Africa, connecting people and empowering communities.

Similar Jobs

Xero Logo Xero

HR & Talent Business Partner

Cloud • Fintech • Information Technology • Machine Learning • Software
Hybrid
Kenridge, City of Cape Town, Western Cape, ZAF
4500 Employees

Hewlett Packard Enterprise Logo Hewlett Packard Enterprise

HPE Networking Senior Presales Engineer

Artificial Intelligence • Cloud • Information Technology • Consulting
In-Office
2 Locations
85422 Employees

CDW Logo CDW

Sales Support Associate

Information Technology
Hybrid
Cape Town, Western Cape, ZAF
15100 Employees

Morningstar Logo Morningstar

Infrastructure Engineer

Artificial Intelligence • Big Data • Enterprise Web • Fintech • Software • Financial Services
Remote or Hybrid
South Africa
11500 Employees

Similar Companies Hiring

Axle Health Thumbnail
Artificial Intelligence • Healthtech • Information Technology • Logistics
Santa Monica, CA
25 Employees
NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account