Our client is a global portfolio of software businesses operating across multiple industries and countries. They are strengthening their Group Cyber GRC function and are looking for a technically strong Senior Cyber Assurance & GRC Analyst to provide cybersecurity assurance, risk oversight and governance across the portfolio.
The Role
The primary focus of this role is Cyber Assurance and validation of cybersecurity controls, with the Group framework largely based on CIS Controls v8.
You will review business self-assessments, validate supporting evidence, challenge unsupported or overstated responses and ensure cybersecurity risk and maturity reporting is accurate.
This is not a technical remediation role. You will not be responsible for fixing the issues; you need to be technically capable of understanding the controls, asking the right questions and determining whether they are genuinely effective.
Key Responsibilities
- Conduct cybersecurity assurance assessments across multiple businesses.
- Review and validate business self-assessments and supporting evidence.
- Assess the effectiveness of cybersecurity controls.
- Challenge inaccurate or unsupported compliance claims.
- Identify control gaps, risks and weaknesses.
- Apply practical knowledge of CIS Controls v8.
- Maintain and assess cybersecurity risk information and risk registers.
- Produce portfolio-level risk, maturity and assurance reporting.
- Engage with technical and non-technical stakeholders across multiple businesses.
- Support third-party risk, security governance and acquisition-related assurance activities.
Requirements
- 3–5+ years’ experience in Cyber GRC, Cyber Assurance, Information Security, IT/Internal Audit, Risk Management or a related field.
- Proven experience conducting cybersecurity audits, assurance reviews or control assessments.
- Strong practical understanding of CIS Controls v8.
- Strong technical understanding of cybersecurity controls and technologies.
- Experience reviewing evidence and validating whether controls are genuinely operating.
- Ability to challenge stakeholders constructively and investigate responses where required.
- Experience with cyber risk assessments and/or risk registers.
- Strong analytical, reporting and stakeholder management skills.
- Ability to work independently across multiple business units.
Advantageous
- Experience in a global, multi-business or decentralised environment.
- Knowledge of NIST CSF and/or ISO 27001.
- Experience with Microsoft 365, Azure, Entra ID or cloud security.
- GDPR, POPIA or other international regulatory knowledge.
- Third-party risk management experience.
- Relevant certifications such as CISA, CRISC, CISSP, CGRC or ISC2 CC.
- Dual passport / international travel capability.
- Ability and willingness to travel internationally when required.
The Ideal Candidate
We are looking for someone who can look beyond the answer on the audit questionnaire.
If a business says MFA is implemented, you should be comfortable asking:
“Show me the evidence.”
You need to be technically strong enough to understand whether a control is actually working, while having the GRC, risk and stakeholder skills to assess, challenge and report on it.
Assess → Challenge → Validate → Report
Experience working across a global, multi-business environment will be highly advantageous.
Kindly note that you will be redirected to the Ditto website in order to submit your application for this position.