Johannesburg, ZA
Title: Senior Risk Manager IT and Cyber Risk

Requisition Details & Talent Acquisition Contact
Requisition nr: 147730
Talent Acquisition Specialist: Tshego Semenya
Location: 135 Rivonia Road, Sandown
Closing date: 22 September 2026
Cluster
Personal and Private Banking
Career Stream
Leadership Pipeline
People Specification
Why join our team!
Technology and cyber risk continue to evolve at an unprecedented pace, creating complex challenges for financial institutions. This role offers an opportunity to be at the forefront of managing and overseeing these risks within a leading banking environment.
As the Senior Risk Manager: IT and Cyber Risk, you will play a key role in providing independent oversight and challenge across technology, cyber, cloud and third-party risk domains within the Personal and Private Banking cluster. Working closely with business, technology and risk stakeholders, you will help ensure that key risks are understood, monitored and managed effectively while supporting adherence to regulatory requirements and risk management frameworks.
The role offers broad exposure to a diverse technology and cyber risk landscape, including digital transformation initiatives, operational resilience, cloud adoption, third-party risk management and emerging technology risks. You will have the opportunity to engage with a wide range of stakeholders, contribute to governance forums, provide meaningful risk insights and support the continuous enhancement of the organisation's technology and cyber risk capability.
This position is ideal for an experienced IT or Cyber Risk professional who enjoys working in a dynamic environment, partnering with stakeholders across the business, and contributing to a strong risk culture while helping to strengthen technology and cyber resilience across the organisation.
Job Purpose
To ensure that the Group IT and Cyber Risk Framework is effectively embedded, operationalised and implemented within the business. The role is responsible for providing independent oversight, challenge, guidance and risk advisory services to ensure technology and cyber risks are effectively managed, regulatory requirements are met, and the control environment remains robust across the Personal and Private Banking (PPB) cluster.
The successful incumbent will play a critical role in strengthening cyber resilience, technology governance and risk management practices while supporting the safe delivery of strategic technology, cloud and digital transformation initiatives.
Job Responsibilities
Enterprise Risk Management
- Contribute to a culture conducive to the achievement of transformation goals and support business strategies that improve the corporate image.
- Participate in corporate social responsibility and culture-building initiatives.
- Foster workplace transformation and contribute towards diversity and inclusion objectives.
- Improve work processes, productivity and operational efficiency through innovative ideas and stakeholder engagement.
- Develop risk plans that support business strategy implementation and obtain approval from relevant governance forums.
- Facilitate effective risk management processes to ensure compliance and mitigate potential losses.
- Ensure alignment of area business processes to the Group Risk Framework.
- Analyse information generated through risk monitoring activities and provide meaningful risk insights.
- Identify, document and monitor business and operational risks.
- Allocate and coordinate risk activities across responsible areas.
- Review and enhance cluster risk process guidelines and standards.
- Evaluate audit findings and management actions, providing recommendations for improvement.
- Develop and monitor action plans to address identified risks.
- Contribute to cost management and operational efficiency objectives.
IT & Cyber Risk Oversight
- Provide independent oversight, challenge and reporting of IT and Cyber Risks across the PPB cluster.
- Report on all cluster-specific information security programme elements.
- Support third-party supplier information security and cyber risk assessments and assurance activities.
- Assist business units with cyber security and technology incident management activities.
- Develop, maintain and support an integrated understanding of the IT and Cyber Risk profile across the portfolio.
- Lead and challenge technology, cyber security, cloud and third-party risk assessments.
- Monitor risk appetite metrics, Key Risk Indicators (KRIs) and remediation activities relating to risk appetite breaches.
- Prepare and present technology and cyber risk insights, trends and recommendations to governance forums and management committees.
- Oversee cyber security risk themes, control effectiveness and remediation initiatives across the business.
- Provide oversight of technology, cyber and cloud risks associated with third-party service providers.
- Monitor and challenge risks affecting technology resilience, system availability and operational continuity.
- Assess technology and cyber risks associated with strategic programmes, new products, digital initiatives and transformation projects.
- Ensure adherence to regulatory requirements, internal policies, standards and risk management frameworks.
- Evaluate the adequacy and effectiveness of technology and cyber controls through ongoing assurance activities.
- Provide trusted advisory services to business, technology and executive stakeholders on technology-related risks.
Job Responsibilities Continue
Governance and Stakeholder Management
- Build and maintain strong relationships with business, technology, audit, compliance and risk stakeholders.
- Share knowledge and risk insights through awareness initiatives and stakeholder engagements.
- Report risk matters and emerging issues to relevant governance structures and committees.
- Influence decision-making by providing objective challenge and independent risk perspectives.
- Keep stakeholders informed of industry trends, emerging threats and regulatory developments.
- Support the achievement of business objectives through effective risk partnership and collaboration.
Leadership and Development
- Support the achievement of business strategy, objectives and values.
- Identify development opportunities and maintain an active personal development plan.
- Share knowledge, best practices and industry trends with colleagues and stakeholders.
- Lead, coach and develop team members, risk practitioners and business stakeholders.
- Drive continuous improvement in risk management practices, governance processes and reporting capabilities.
Essential Qualifications - NQF Level
- Advanced Diplomas/National 1st Degrees
Preferred Qualification
- Information Security
- Cyber Security
- Information Technology
- Risk Management
- Or a related discipline
Preferred Certifications
- Certified Information Security Manager (CISM)
- Certified in Risk and Information Systems Control (CRISC)
- Certified Information Systems Auditor (CISA)
Minimum Experience Level
- 7+ years' experience in Information Security Risk and/or Cyber Security Risk.
- 5+ years' experience in IT Risk Management.
- 3+ years' experience providing independent risk oversight, challenge and advisory services within technology, cyber security or enterprise risk environments.
- Experience operating within large, complex organisations and strategic programmes for a minimum of 3 years.
- Experience conducting and challenging technology, cyber, cloud and third-party risk assessments.
- Experience monitoring risk appetite metrics, KRIs, control effectiveness and remediation activities.
- Experience presenting risk insights, trends and recommendations to senior management, governance forums and risk committees.
- Experience supporting cyber incident management, operational resilience and technology risk governance activities.
- Exposure to banking, financial services or similarly regulated environments will be advantageous.
Technical / Professional Knowledge
- Banking knowledge
- Business Acumen
- Data analysis
- Governance, Risk and Controls
- Industry trends
- Principles of project management
- Relevant regulatory knowledge
- Business writing skills
Disclaimer
Preference will be given to candidates from the underrepresented groups
Please contact the Nedbank Recruiting Team at +27 860 555 566

---------------------------------------------------------------------------------------
Please contact the Nedbank Recruiting Team at +27 860 555 566