...
Address: 115 ED Mnangagwa Rd, Highlands, Harare Whatsapp (ONLY for CV Making): +263784644514

ICT GOVERNANCE, RISK & COMPLIANCE ANALYST – NSSA 47 views

Job Expired
NSSA is an organisation undergoing a transformation journey to position itself as a modern and relevant entity that delivers real value to its members through responsive social security services. In addition, we strive to stimulate economic activity, generate foreign currency, and create jobs for the benefit of Zimbabweans.

The new NSSA conducts its business in an honest, accountable, and transparent manner and we seek to recruit like-minded individuals in the following areas:

Reporting to the ICT Systems Security Manager, the successful candidate strengthens the Authority’s cyber resilience by ensuring that ICT operations and information assets comply with approved governance frameworks, regulatory requirements, and internal policies.

Job Summary

  • Type: contract
  • Location: Harare
  • Category: IT Governance
  • Closing Date: 2026-06-05

Key Responsibilities

  • Leads the application and continuous improvement of ICT governance frameworks by ensuring that approved policies, procedures and standards are consistently implemented across the Authority and adhered to by all departments. Risk Assessment, Decision Making and Mitigation.
  • Drives ICT risk assessment activities by identifying key risks, evaluating the adequacy of existing controls, deciding on required risk treatments, and guiding departments on appropriate actions to reduce exposure. Audit Coordination and Follow-up Management.
  • Coordinates internal and external ICT audits, liaises with auditors and business units, ensures the timely provision of required information, and monitoring of agreed corrective measures. Regulatory and Standards Compliance Assurance.
  • Oversees compliance with applicable legislation, including the Cyber and Data Protection Act (CDPA), ISO 27001 and related standards, providing authoritative guidance and recommending compliance actions to management. Governance Documentation and Reporting.
  • Develops and maintains governance documents such as risk registers, compliance dashboards and control records, ensuring information is accurate and available to support informed decisionmaking. Control Testing and Compliance Monitoring.
  • Leads periodic control reviews and compliance checks to assess whether ICT activities align with approved governance requirements, identifying noncompliance and recommending improvements. Policy Compliance Enforcement Across Departments.
  • Monitors adherence to ICT policies and procedures throughout the Authority, identifies gaps or deviations, and drives corrective actions to strengthen accountability and compliance. Strategic Support to ICT and Business Units.
  • Works closely with ICT teams and business units to guide the integration of governance, risk and compliance requirements into daily operations, projects and change initiatives, ensuring decisions incorporate proper oversight. Business Continuity and Resilience Support.
  • Supports business continuity and disaster recovery planning by reviewing documentation, assessing recovery readiness, and coordinating resilience testing activities. Governance, Risk and Compliance Awareness and Training.
  • Drives awareness programmes by organising training, workshops and briefings that promote understanding of governance, risk and compliance responsibilities across the Authority. Contract, Vendor and SLA Governance Review.
  • Reviews contractual agreements with vendors and service engagements to ensure alignment with governance and compliance requirements, advising on risks and recommending safeguards before approval. Governance, Risk and Compliance Reporting.
  • Prepares and presents GRC reports and metrics to ICT Management and relevant committees, providing insights that support decisionmaking and highlight emerging risks or compliance issues.

Requirements

  • Degree in Computer Science, Information Systems, Software Engineering or equivalent.
  • Data Protection Officer Certification is mandatory.
  • At least one of the following certifications is required: ISO 27001 Lead Implementer, ISO 27001 Lead Auditor, CRISC, CISA or CGEIT, COBIT 2019, ISO 27005 Risk Manager, ISO 27701 Lead Implementer, NIST CSF Practitioner.
  • A minimum of 5 years’ experience in ICT governance, ICT risk management, ICT audit or cybersecurity compliance. Technical Skills.
  • Strong knowledge of ICT governance frameworks (e.g., COBIT, ITIL).
  • Understanding of cybersecurity standards (ISO 27001, NIST CSF, CIS Controls).
  • Experience working with governance frameworks (COBIT, ITIL), cybersecurity standards (ISO 27001), and risk methodologies.
  • Strong knowledge of ICT governance frameworks, regulations and compliance bodies.
  • Proficiency in ICT risk assessment methodologies and tools.
  • Knowledge of regulatory and legal requirements, including the Zimbabwe Cyber and Data Protection Act (CDPA). Other Requirements and Competencies.

How to Apply

Interested candidates should apply online using NSSA website (www.nssa.org.zw) on the following link www.nssa.org.zw/careers

To reach not later than close of business on Friday 5th June 2026.

About the Company

In Zimbabwe the National Social Security Authority (NSSA), constituted and established in terms of the NSSA Act of 1989, Chapter 17: 04 DOWNLOAD: NATIONAL SOCIAL SECURITY AUTHORITY ACT 17 04 (PDF 128.4 KB), is the statutory corporate body tasked by the Government to provide social security. The provision of social security can be defined as instituting public policy measures intended to protect an individual in life situations or conditions in which his/her livelihood and well being may be threatened, such as those engendered by sickness, workplace injuries, unemployment, invalidity, old age, retirement and death. It is based on the principle of social solidarity and pooling of resources and risks, involving drawing of savings from periods of employment, earnings and good health to provide for periods of unemployment, old age, invalidity and death. At the moment NSSA is administering two schemes: Pension and Other Benefits Scheme and Accident Prevention and Workers’ Compensation Scheme, although, in an endeavor to provide a more comprehensive social security package for the Zimbabwean society, groundwork for the introduction of more schemes is underway.

View all jobs at this company →

  • This job has expired!
Share this job
Email Me Jobs Like These

Leave your thoughts

Get daily jobs updates through your email

JobsZW