Johannesburg, ZA
Title: Risk Officer - ERM (IT Risk)

Job Classification
- Job Requisition: 146989
- TA Specialist: Refilwe Falatsi
- Closing Date: 13 August 2026
- Location: 135 Rivonia Campus, Sandown
- Cluster: Personal and Private Banking | Nedbank Insurance | Governance
- Employment Equity Statement: Preference will be given to applicants from Underrepresented Groups
Job Purpose
To facilitate and support the effective management of the Enterprise Wide and Operational Risk Frameworks in order to manage current and emerging risks to assist Nedbank in achieving its objectives.
Job Responsibilities
- Contribute to a culture conducive to the achievement of transformation goals by participating in Nedbank Culture building initiatives (e.g. staff surveys etc).
- Participate and support corporate social responsibility initiatives for the achievement of key business strategies.
- Identify and recommend opportunities to enhance processes; systems and policies and support implementation of new processes; policies and systems.
- Facilitate the implementation and maintenance of the Technology Risk Management Framework across Nedbank Insurance.
- Conduct risk assessments covering information technology, cyber security, cloud computing, third-party service providers, and emerging technology risks.
- Identify, assess, monitor, and report on key technology risks and control weaknesses.
- Maintain risk registers and ensure risks are appropriately escalated and mitigated.
- Review and challenge technology-related risk assessments performed by first-line technology teams.
- Develop, monitor and assess technology risk indicators (KRIs) and provide meaningful reporting to management and governance forums.
- Support the development and execution of risk treatment plans for identified control gaps.
- Keep abreast of legislation and other industry changes that impacts on role by reading the relevant newsletters; websites and attending sessions.
- Understand and embrace the Nedbank vision and demonstrate the values through interaction with team and stakeholders.
- Improve personal capability and stay abreast of developments in field of expertise by identifying training courses and career progression for self through input and feedback from managersEnsure personal growth and enable effectiveness in performance of roles and responsibilities by ensuring all learning activities are completed; experience practiced and certifications obtained and/or maintained within specified time frames.
- Ensure information is provided correctly to stakeholders by maintaining knowledge sharing knowledge with team.
- Make recommendations for service improvements by using feedback gathered in training sessions and other engagements with stakeholders.
- Build relationships and identify synergies with internal clients stakeholders
- Conduct gap analysis of Nedbank Insurance processes using the relevant guidelines and checklists to confirm compliance to bank standards and compliance to national legislation.
- Provide coaching and/or recommendations for corrective measures based on gap analysis; using root cause analysis techniques and effective feedback and coaching skills.
- Train/coach relevant internal stakeholders in business systems by following training guides and using approved support material.
Job Responsibilities Continue
- Governance, Risk and Compliance
- Support compliance with relevant regulations, standards, and frameworks including:
- King IV
- COBIT
- ISO 27001 and 31000
- NIST Cybersecurity Framework
- POPIA
- Financial Sector Conduct Authority (FSCA) requirements
- Prudential Authority standards
- Facilitate technology risk governance forums and committees.
- Prepare risk reports and dashboards for executive management, risk committees, and board structures.
- Ensure adherence to risk appetite and risk tolerance thresholds
- Cyber and Information Security Risk
- Collaborate with Information Security teams to monitor cyber security risks and control effectiveness.
- Evaluate cyber security incidents, root causes, and remediation plans from a risk management perspective.
- Review vulnerability management, access management, data protection, and security control assessments.
- Assess risks associated with digital transformation, cloud adoption, and emerging technologies.
- Operational Resilience and Business Continuity
- Support technology resilience, disaster recovery, and business continuity risk assessments.
- Monitor critical technology services and associated resilience controls.
- Participate in resilience testing, scenario analysis, and incident response exercises.
- Evaluate operational resilience risks impacting customer service and business operations.
- Risk Assurance and Control Effectiveness
- Assess design and operating effectiveness of technology controls.
- Track and monitor audit findings, risk issues, and management actions.
- Conduct thematic reviews and control assessments across technology environments.
- Perform root cause analysis on recurring technology incidents and losses.
- Stakeholder Engagement
- Build effective relationships with Technology, Information Security, Internal Audit, Compliance, Risk Management, and business stakeholders.
- Provide risk advisory support to technology projects and strategic initiatives.
- Promote awareness of technology risk management practices across the organisation.
- Influence risk-informed decision-making through effective communication and challenge
People Specification
Essential Qualification - NQF Level
Bachelor's Degree in Information Systems, Computer Science, Information Technology, Risk Management, Internal Auditing, Accounting and Engineering
Preferred Qualification
- Postgraduate Diploma in Risk Management
- BCom Honours (Risk Management/Internal Auditing)
- BSc Information Systems
- Master's Degree in Information Systems, Cyber Security, or Risk Management
Preferred Certifications
- CISA (Certified Information Systems Auditor)
- CRISC (Certified in Risk and Information Systems Control)
- CGEIT (Certified in Governance of Enterprise IT)
- CISSP (Certified Information Systems Security Professional)
- ISO 27001 Lead Implementer or Lead Auditor
- COBIT Foundation
- Certified Third-Party Risk Professional (CTPRP)
- ITIL Foundation
Minimum Experience Level
- Minimum 5 years experience in Technology Risk Management, Information Security Risk, IT Audit, IT Governance, Cyber Risk, or Operational Risk.
- Minimum 5 years experience within Financial Services, Insurance, Banking, or a regulated environment.
- Demonstrated experience performing technology risk assessments, control reviews, issue management, and risk reporting.
- Experience working with technology governance frameworks such as COBIT, ISO 27001, NIST, and ITIL.
- Experience engaging with technology stakeholders, auditors, regulators, and senior management.
Technical / Professional Knowledge
- Cluster specific operations
- Communication Strategies
- Data analysis
- Governance, Risk and Controls
- Principles of financial management
- Principles of project management
- Relevant software and systems knowledge
- Research methodology
- Decision-making process
Behavioural Competencies
- Earning Trust
- Communication
- Decision Making
- Work Standards
- Managing Work
- Technical/Professional Knowledge and Skills

---------------------------------------------------------------------------------------
Please contact the Nedbank Recruiting Team at +27 860 555 566