The IT Risk, Governance & Privacy Manager is accountable for establishing and maintaining the first-line technology governance, risk, privacy and control environment required of a regulated insurer. The role provides clear, reliable assurance evidence covering POPIA, applicable FSCA and Prudential Authority obligations, technology and cyber risk, third-party risk, and the auditable oversight of outsourced IT arrangements. It ensures that technology risks and obligations are translated into practical controls, assigned to accountable owners, tested for effectiveness and reported transparently.
Key responsibilities:
- IT Governance and Regulatory Alignment
- Technology Risk Management
- Privacy Governance and POPIA Compliance
- Control Framework, Testing and Assurance Evidence
- Third-Party and Outsourced IT Risk
- Policies, Standards, SOPs and Exceptions
- Audit, Compliance and Remediation Management
- Reporting, Stakeholder and Capability Leadership
Requirements
Education & Experience
- Matric / Grade 12 / National Senior Certificate
- Bachelor's Degree / Advanced Diploma (NQF Level 7) in Information Technology, Information Systems, Risk Management, Audit, Law, Compliance or a related field
- COBIT, ISO 27001, ISO 27701 or an equivalent IT risk/governance credential is strongly advantageous
- At least 8 years' relevant experience in IT governance, technology risk, compliance, privacy, controls or IT audit
- At least 3 years' management or senior specialist leadership experience
Job competencies
- IT risk and control framework design
- POPIA and privacy-by-design implementation
- Control testing (walkthroughs, sampling, reperformance)
- Third-party and outsourcing risk management
- Policy and SOP development
- Audit coordination and remediation tracking
- Regulatory interpretation (financial services/insurance)
- Executive reporting and dashboarding