Job Summary
Responsible for establishing and maintaining technology governance, risk, and compliance frameworks across IT, network, cybersecurity, and cloud environments. Ensures effective implementation of policies, standards, and controls aligned with regulatory and industry requirements such as ISO 27001, COBIT, ITIL, and NIST. Provides oversight on risk management, audits, IT controls, and change governance while driving compliance, accountability, and continuous improvement across technology operations and transformation initiatives.
The Day-To-Day Activities
Governance Framework & Policy Management
Develop and maintain technology governance policies, standards, and frameworks.
Review policies regularly to ensure alignment with regulatory and industry requirements (e.g., ISO 27001, COBIT, ITIL, NIST).
Support governance forums, committees, and approval processes.
Risk & Compliance Oversight
Lead and coordinate technology risk assessments across IT, network, cybersecurity, and cloud environments.
Track remediation of audit findings and risk treatment actions.
Support compliance activities related to regulatory and industry requirements.
Identify emerging technology and operational risks.
IT Controls, Audit & Assurance
Maintain and monitor IT General Controls (ITGC), cybersecurity, and network controls.
Support internal and external audits including evidence preparation, audit coordination, and remediation tracking.
Review critical technology processes such as access management, change management, and incident response.
Ensure outsourced and managed services comply with governance and security requirements.
Change, Incident & Problem Governance
Review technology changes to ensure proper risk assessment, testing, approval, and documentation.
Review major incidents and RCA reports to ensure governance and compliance requirements are met.
Monitor incident and change trends to identify improvement opportunities.
Reporting & Stakeholder Management
Prepare governance and risk reports for management and governance committees.
Act as liaison with auditors, regulators, and internal stakeholders on governance matters.
Conduct governance awareness and training sessions for IT, network, and cybersecurity teams.
Project & Investment Governance
Ensure governance, security, and risk requirements are embedded in technology projects and transformation initiatives.
Support secure-by-design practices and alignment with enterprise governance standards.
Continuous Improvement & Governance Culture
Promote governance, accountability, and compliance awareness across technology teams.
Identify opportunities to improve governance processes and controls.
- Lead awareness initiatives related to governance, risk, and policy compliance.