GRC Analyst – Governance, Risk & Compliance
Jobgether · Afrique du Sud
Description du poste
About the role
This position is based in South Africa and operates in a fast‑scaling, payments‑focused environment. As a GRC Analyst you will own day‑to‑day governance, risk and compliance execution, ensuring continuous compliance across multiple regulatory frameworks while partnering with engineering, security, legal and leadership teams.
Key responsibilities
- Own and manage audit readiness activities, including continuous evidence collection, control monitoring and coordination with external auditors for SOC 2, PCI DSS and ISO 27001.
- Handle external security and compliance requests such as vendor assessments, security questionnaires and RFP responses.
- Support enterprise risk and compliance programs aligned with GDPR, DORA, NIS2 and the EU AI Act.
- Maintain the policy lifecycle – updates, exception handling, violation tracking and remediation follow‑ups.
- Contribute to certification efforts and expand into new compliance frameworks as business needs evolve.
- Collaborate with engineering and security teams to operationalise controls, strengthen vulnerability management and support security awareness initiatives.
- Ensure ongoing compliance visibility through structured documentation and a continuous compliance approach.
Required profile
- 3‑5 years of experience in GRC, compliance or information security governance.
- Hands‑on experience supporting external audits such as SOC 2, PCI DSS or ISO 27001.
- Familiarity with regulatory requirements including GDPR, DORA, NIS2 and emerging EU standards.
- Experience managing vendor risk assessments and third‑party due diligence.
- Strong organisational and communication skills, able to work across technical, legal and business stakeholders.
Required skills
- Proficiency with GRC platforms such as Vanta, Drata or OneTrust.
- Practical knowledge of SOC 2, PCI DSS and ISO 27001 frameworks.
- Understanding of GDPR, DORA, NIS2 and the EU AI Act compliance requirements.
- Experience with continuous control monitoring and evidence management practices.
Questions fréquentes
Pourquoi signalez-vous cette offre ?
Postulez en 30 secondes
Entrez votre email pour postuler. Un compte sera cree automatiquement.
En continuant, vous acceptez nos conditions d'utilisation.
Deja un compte ? Connexion
Publie il y a 4 heures
Expire dans 1 mois
5 vues · 0 candidatures
Boostez vos chances
Importez votre CV : nous vous proposons les offres qui matchent votre profil.
Analyse de votre CV en cours...
Jobgether
Afrique du Sud