- Location
- City of Cape Town Metropolitan Municipality, Western Cape
- Type
- Full-time
- Seniority
- Lead
- Closing date
- Today
- Source
- Vincere
Description
IT GOVERNANCE LEAD
Investment Management | Tygervalley, CPT
Our client, a leading investment organisation, is seeking an experienced and strategically minded IT Governance Lead to join their technology function.
This is a senior governance role operating at the intersection of IT governance, technology risk, enterprise architecture, information security and technology delivery. The successful candidate will play a key role in ensuring that IT governance frameworks, policies, standards and controls are effectively implemented, adopted and embedded across the organisation.
You will work closely with Enterprise Architects, Solution Architects, development and operational IT teams, IT leadership, security practitioners, the Business Information Security Officer (BISO), risk functions and business stakeholders to ensure technology governance supports the organisation's strategy while meeting regulatory, security and risk requirements.
The ideal candidate will bring a pragmatic, enablement-focused approach to governance — someone who can maintain the necessary governance rigour while helping technology teams deliver effectively.
KEY RESPONSIBILITIES
IT Governance & Leadership
-
Establish, coordinate and mature IT governance practices across clusters and business units.
-
Drive the rollout, adoption and practical implementation of IT governance, security and data standards.
-
Provide thought leadership on IT governance, risk, compliance and regulatory alignment.
-
Define, maintain and continuously evolve governance frameworks, policies, standards, guidelines and implementation artefacts.
-
Establish and apply appropriate governance controls and monitoring mechanisms across the IT environment.
-
Establish, facilitate and support IT governance forums and working groups across the organisation.
-
Represent cluster governance positions within broader enterprise governance structures.
-
Provide governance input into IT management decision-making and strategic direction.
-
Support audit, assurance and regulatory activities by ensuring appropriate governance evidence, control effectiveness and traceability.
Governance, Risk & Compliance
-
Coordinate and conduct IT governance maturity assessments and standards compliance reviews.
-
Review and provide governance input into Cloud Risk Assessments (CRA) and similar technology risk processes.
-
Support risk appetite alignment, exception management and remediation planning.
-
Track, monitor and report on governance risks, gaps and remediation actions.
-
Ensure regulatory, legal and organisational policy requirements are appropriately integrated into IT governance practices.
-
Provide guidance on appropriate governance and security remediation actions.
-
Support effective control design, operation and evidence across the IT environment.
Information Security & BISO Support
Working closely with the Business Information Security Officer (BISO), you will:
-
Support the execution of security governance implementation plans aligned to Group Information Security direction.
-
Coordinate and enable implementation of security-related requirements and roadmap initiatives across technology, data and cybersecurity.
-
Assist the BISO across defined service areas by providing governance coordination and enablement.
-
Ensure alignment between IT governance, cybersecurity and data governance requirements.
-
Support third-party and supplier governance considerations in collaboration with security and risk teams.
-
Provide governance input into security initiatives, controls and assurance activities.
-
Translate enterprise security direction into practical, executable actions within technology environments.
-
Support compliance activities and governance oversight within project and delivery environments.
Project & Technology Delivery Governance
-
Provide governance and security oversight across technology projects and solution delivery initiatives.
-
Advise project and delivery teams on governance, security and data requirements.
-
Ensure governance considerations are embedded early in the solution lifecycle.
-
Contribute governance input to architecture, solution design and operational readiness discussions.
-
Work collaboratively with Enterprise and Solution Architects, development teams and operational IT teams to ensure governance requirements are practical and appropriately implemented.
Stakeholder Engagement & Communication
-
Prepare and present governance, maturity, compliance and risk reports.
-
Communicate effectively with stakeholders ranging from delivery teams through to senior and executive management.
-
Engage constructively with enterprise IT governance functions to provide input, review and feedback.
-
Partner with Cluster and Business Unit IT Heads to drive adoption of regulatory requirements, policies and technology standards.
-
Translate complex governance, risk and security concepts into clear, practical and actionable guidance.
-
Build effective relationships across technology, security, risk, architecture and business functions.
-
Be comfortable challenging stakeholders constructively where governance, risk or security requirements are not being met.
WHAT WE'RE LOOKING FOR
Essential Requirements
-
5+ years' relevant experience within enterprise IT environments.
-
Demonstrable experience in IT governance, risk and compliance.
-
Proven experience implementing and operationalising IT policies, standards and governance frameworks.
-
Experience working within a regulated environment, preferably financial services.
-
Experience engaging across enterprise, cluster and business-unit structures.
-
Experience participating in or supporting governance, audit and assurance forums.
-
Strong understanding of technology governance and the ability to work effectively with technical and business stakeholders.
-
Demonstrated ability to drive governance adoption rather than simply define policies or controls.
Advantageous Experience & Qualifications
-
7+ years' overall IT experience across multiple technology disciplines.
-
A formal qualification in IT, Information Systems, Risk Management or a related discipline.
-
Knowledge and practical experience of recognised IT governance and security frameworks, such as:
-
COBIT
-
ISO/IEC 38500
-
ISO 27001
-
NIST
-
-
Experience within financial services or asset management.
-
Previous experience or background within IT security, cybersecurity or technology architecture.
-
Familiarity with CISSP-type responsibilities and security governance environments.
-
Experience with technology risk, information security, data governance or enterprise architecture would be highly beneficial.
THE IDEAL PERSON
We are looking for someone who combines strong governance discipline with commercial and technological pragmatism.
You will be someone who:
-
Has excellent planning, prioritisation and organisational skills.
-
Can confidently engage with senior and executive stakeholders.
-
Understands that effective governance should enable the business rather than create unnecessary bureaucracy.
-
Is action- and results-oriented, with a high degree of personal accountability.
-
Has excellent attention to detail while maintaining a practical, solutions-focused mindset.
-
Is comfortable navigating ambiguity, conflict and difficult conversations.
-
Demonstrates high levels of integrity, resilience and professional maturity.
-
Takes ownership and follows through on commitments.
-
Has a continuous learning and improvement mindset.
-
Can build credibility with both technical specialists and business leaders.
WHY THIS ROLE?
This is an opportunity to play a key role in shaping and maturing IT governance within a sophisticated investment environment.
You will have the opportunity to influence how governance, risk, security, architecture and technology delivery come together — working with senior technology and business stakeholders to ensure the organisation remains well governed, secure, resilient and aligned to its strategic and regulatory obligations.
If you are an experienced IT Governance, Technology Risk, IT GRC, Information Security Governance or Technology Governance professional looking for a role where you can make a meaningful enterprise-level impact, we'd like to hear from you.