{"id":1116449,"url":"https://alion.io/job/herotel-it-governance-risk-compliance-officer","title":"IT Governance, Risk & Compliance Officer","company":{"id":177332,"name":"Herotel","domain":"herotel.com","url":"https://alion.io/company/herotel","size_band":null,"is_staffing_agency":false,"is_intermediary":false,"ats_vendor":"Breezy","truth_index":null},"role":"Legal","role_family":"Legal","seniority":"middle","employment_type":"full_time","work_mode":"on_site","remote_scope":null,"hiring_geo_confidence":"structured","locations":[],"countries":[],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":21000,"max_usd":47000,"period":"year","method":"role_seniority_country_remote_cell","sample_n":8},"experience_years_min":3,"visa_sponsorship":false,"relocation_package":false,"has_equity":true,"technologies":[{"name":"ISO 27001","optional":false},{"name":"SIEM","optional":false}],"status":"live","first_seen_at":"2026-09-22T14:40:07Z","employer_posted_date":"2026-09-22","last_verified_at":"2026-09-24T05:51:21Z","board_verified":true,"closed_at":null,"days_open":1,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":1},"description":"Are you a detail oriented governance and compliance specialist with a passion for information security? Join our Information Systems team as an IT Governance, Risk & Compliance Officer in Plattekloof, where you'll lead Herotel's ISO 27001 certification programme and own our POPIA compliance obligations.\nThis role is perfect for someone who thrives on structure, documentation and stakeholder engagement, and who wants to build a governance function from the ground up within a fast growing telecommunications business.\nWhat you'll do:\nLead Herotel's ISO 27001 certification programme, including ISMS scoping, gap and risk assessments, and maintaining the Statement of Applicability\nDevelop, maintain and drive adoption of the information security policy suite\nMaintain the information security risk register and risk treatment plan, tracking remediation with control owners\nPlan and execute the ISMS internal audit programme, coordinate management reviews and maintain ISMS records and evidence\nManage the certification body relationship, including Stage 1 and Stage 2 audits, findings closure and ongoing surveillance audit readiness\nCoordinate implementation of Annex A controls together with the Cybersecurity Engineer and IT teams\nOwn POPIA compliance, developing, maintaining and enforcing policies and procedures aligned with legislative requirements\nManage and respond to POPIA related requests and incidents, including data subject access requests, complaints and data breach notifications\nServe as Herotel's Deputy Information Officer under POPIA\nConduct data protection impact assessments for new systems, processes and third party integrations that handle personal information\nRun the security awareness and training programme, tracking completion and driving adoption across the organisation\nConduct third party and vendor security and privacy risk assessments, reviewing vendor agreements for security and compliance obligations\nProduce the monthly compliance dashboard covering ISMS status, audit findings, POPIA metrics and awareness training\nWhat you'll need:\nDiploma or Degree in Information Technology, Information Security, Audit, Law or a related field\n3 to 5 years experience in information security governance, risk and compliance, ISMS, or privacy roles\nHands on experience implementing or operating an ISO 27001 ISMS\nWorking knowledge of POPIA and its practical application in a South African operating context\nProven policy authorship, with experience driving policy adoption and security awareness training\nExperience with risk assessment methodologies and maintaining risk registers and treatment plans\nExposure to third party and vendor risk assessment\nSufficient understanding of security technologies such as SIEM, endpoint protection and vulnerability management to define and audit controls\nStrong written communication, documentation and stakeholder engagement skills\nISO 27001 Lead Implementer certification is strongly preferred, or willingness to obtain it within the first six months\nParticipation in certification or surveillance audits is advantageous\nDesirable certifications include ISO 27001 Lead Auditor, CISM, CISA, CRISC, CIPP or CIPM\nWhat we offer:\nExposure to a dynamic workplace\nA chance to grow your skills through our internal academy\nA friendly, team driven environment\nGroup Risk Benefits\nMedical Benefits\nHealth and Lifestyle Programmes\nImportant Disclaimer:\nPlease ensure that the information you provide in your application is true, accurate, and correct.\nPreference will be given to candidates from Designated Groups, as defined by the Employment Equity Act and in line with Herotel's Employment Equity Plan.\nBy submitting an application, you consent to the processing of your personal information in accordance with POPIA for recruitment purposes. For more details on how we handle personal information, please refer to our Privacy Policy on our website.\nIf you do not hear from us within 14 days, please consider your application unsuccessful.","description_format":"text","description_chars":4003,"description_truncated":false,"requirements":{"experience_years_min":3,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":["Equity"],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Telecommunications"],"lifecycle":[{"event":"open","at":"2026-09-22T16:04:36Z"}],"liveness":{"score":90,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.903,"p_room":1,"age_days":1,"expected_fill_days":14,"reasons":["conf:2","velocity","win:early"],"computed_at":"2026-09-24T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/herotel-it-governance-risk-compliance-officer","json_url":"https://alion.io/job/herotel-it-governance-risk-compliance-officer.json","meta":{"generated_at":"2026-09-24T07:34:35Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers"}}