Operating Division : TPT POD Corporate H/O
Position Title : Officer : Risk and Compliance
Employee Group : Permanent
Department : ICT
Location : Durban
Reporting To : Manager: System & Governance
Grade Level : G
Reference Number : 20200703
Position Purpose:
To embed an effective risk management program within ICT and to implement all necessary measures to ensure achievement of the objectives of an effective compliance program by ensuring that all processes are in compliance with the rules and regulations of regulatory frameworks, and that company policies, procedures and standards are being complied with.
Position outputs:
RISK
- Provide guidance, feedback and support across ICT regarding identification of risk, risk mitigation and management.
- Create an appropriate metrics to quantify, track and report on identified risk across ICT.
- Analyze and assess for risks associated with relevant ICT projects and initiatives.
- Provide support with tracking of project risks and mitigation actions.
- Conduct ICT risk awareness and training – design and publish communications which develop awareness and accountabilities for risk management activities. Perform training on the risk management tool. 6. Develop and implement of an appropriate risk reporting discipline in ICT and to the TPT and Transnet Risk Committees
- Participate in various internal and external audits.
- Working with Audit /Security/Compliance officers in ICT to collate and improve risk reporting and evaluation
- Keeps abreast of developments by identifying emerging risks and creation of associated risks registers within the organization.
- Provide guidance and identification of emerging ICT strategic risks, within the department and Operating Division and Transnet and global environment
- Contribute to TPT and Transnet risk framework and reporting
- Maintain a certain level of internal auditing to proactively deal with lower level operational risks
- Provide feedback to related governance forums such as MANCO and RISKCO, regarding latest risk posture of TPT ICT.
COMPLIANCE
- Develop and test processes to ensure compliance in accordance with all aspects of the ICT PPSG’s and frameworks.
- Ensure that IT staff understand their role in compliance 16. Ensure that IT compliance issues/concerns are being appropriately evaluated, investigated and resolved
- Identify potential areas of compliance vulnerability and risk; recommend, get approval for and drive corrective action plans
- Participate in various internal and external audits.
- Ensure that all project and task activities comply with the appropriate governance frameworks
- Keeps abreast of developments in the areas of legal, regulatory, corporate requirements.
- Ensure vendor and stakeholder compliance to Transnet’s Governance frameworks and adherence to SLA’s
- Weekly, monthly and quarterly reporting on the compliance across the various application systems in the organization.
- Ensure that compliance vulnerabilities are raised and appropriate steps are taken to resolve.
- Monitor and coordinate IT compliance activities to remain abreast of the status of all compliance activities on a continuing basis.
- Take appropriate steps to identify trends and improve compliance effectiveness.
- Assist in executing other tasks of the Information Security, Governance, Risk and Compliance function, as and when required.
Qualifications & Experience:
- .National Diploma in Information Technology, Computer Science or Auditing;
- .Professional Qualifications Optional: CISA, CRISC or CGEIT certification is an advantage
Experience:
- A minimum of five (5) years’ experience in ICT Governance, Risk and Compliance;
- Experiencing in coordinating ICT Risk and Compliance activities across multiple ICT Departments, Projects and Operations;
- Ability to operate and engage with Stakeholders at a Senior Management level.
Competencies:
Skills Required:
- Strong English communication skills – verbal and written;
- Attention to detail;
- Analytical thinking and creative problem solving;
- Decision making skills;
- Prioritization and time management skills;
- Able to work under pressure and meet deadlines;
- Able to work cooperatively and proficiently both independently and in a team environment; and
- Continual improvement mind-set.
- Strong customer focus – able to meet the demands of internal and external customers
- Flexible and adaptable – capable of changing direction where required and showing flexibility to meet new demands
- Forms business partnerships that help drive the IT GRC strategy forward
- Can make decisions that are well informed and timely
- Creative thinking – able to look at
Knowledge required:
- Knowledge/application of COBIT, ITIL. KING IV and/or ISO2700/1/2, ISO27031
- Project Management Methodologies and Frameworks
- Risk Management
- Business Continuity Management
- IT Risks, Compliance and Governance Frameworks
- Competencies Required:
- Srategy and Sustainability
- .Strategic Alignment
- Inspirational Leadership
- .Inspiring People
- .Managing Talent
- .Embracing and Implementing Change
- .Embracing Diversity
- Business Performance and Delivery
- .Planning and Coordinating
- .Driving Performance
- .Decision and Solution Focused
- .Business Acumen
- .Analyzing
- Relationship Management
- .Communicating Effectively
- .Collaborating
- .Service Orientated
- .Conflict Management
- Corporate Governance and Compliance
- .Managing Compliance
- .Managing Safety
- Personal Mastery
- .Resilience
- .Learning and Applying Expertise
- .Emotional Intelligence
- .Vigour and Personal Drive alternatives and consider new ways of thinking to problem solve
- .Multi-tasking – can manage several concurrent projects and prioritise demands # Adaptable and flexible to take on
- additional tasks as part of the Information Security, Governance, Risk and Compliance function
How to apply
Applicants that are interested in applying for any of the advertised positions must apply by registering on the Careers section
of the Transnet Internet. Please take care in completing all required details on the profile, and then apply for the position.
Any questions regarding the application or recruitment process should be sent in writing to
The closing date is on 10.08.2020. It is the responsibility of the applicant to ensure that HR has received the application
before the closing date of the advertisement.
Note: if you have not been contacted within 30 days of the closing date of this advertisement please consider your
application as unsuccessful.
Join Our WhatsApp Group for More Job Opportunities
Stay updated with the latest jobs, internships, learnerships and career opportunities across South Africa.
Join WhatsApp Group Now