Confidential mandate
Operational Resilience Audit Recovery Director
Planned Hiring / New
Operational Resilience Audit Recovery Director mandate in Johannesburg, South Africa
Confidential Operational Resilience Audit Recovery Director in Johannesburg, South Africa, reporting to the Chief Audit Executive. Interim Internal & Statutory Audit appointment at Director level, a 7-month mandate horizon; five days a week.
The mandate
The interim Director will recover assurance over operational resilience where audit coverage has become fragmented across continuity, technology recovery, third parties and incident governance. Individual reviews contain useful findings, but the end-to-end ability to remain within approved impact tolerances has not been tested consistently. The appointee must start within three weeks.
The assignment will create an integrated resilience audit view, complete targeted fieldwork and establish issue validation before a fixed committee cycle. Testing must examine dependency, scenario severity, decision authority and recovery evidence without revealing protected services or configurations in candidate-facing material.
Temporary authority covers audit scope, safe-testing conditions, specialist deployment, evidence conclusions, ratings and escalation. The Director cannot own continuity plans, run management exercises, accept resilience risk or operate remediation. Unsafe testing may be stopped immediately and redesigned.
A permanent specialist leader should be appointed by month three. Handover requires that successor to approve one scope, supervise a scenario-observation file, validate one high-risk issue and report to the Committee. Exit follows completion of those tests and acceptance of the residual coverage plan.
What you will own
- Consolidate the resilience auditable universe across important services, people, premises, technology, data, suppliers and decision governance.
- Reconcile existing assurance to end-to-end objectives and identify gaps hidden by component-level testing.
- Design scenarios that test severe but plausible disruption, compound dependency and management decision lead time.
- Observe management exercises independently, distinguishing planned response from demonstrated capability and untested assumption.
- Evaluate impact tolerances, recovery objectives, fallback capacity and dependency mapping against evidence rather than documentation alone.
- Issue concise ratings that connect technical or operational weaknesses to service consequence and residual exposure.
- Validate priority remediation through safe reperformance, scenario evidence or sustained operation as appropriate.
- Certify the successor across scope, observation, validation and committee communication.
Candidate qualifications
- At least 15 years in internal audit, operational resilience, continuity assurance or technology risk, including interim leadership.
- Active CA(SA), CPA, ACA, ACCA or equivalent audit qualification, supported by CIA, CISA or a recognised resilience credential.
- Evidence of an end-to-end audit that exposed a dependency missed by separate continuity or technology reviews.
- Strong knowledge of important-service mapping, impact tolerance, severe-but-plausible scenarios, recovery and third-party dependency.
- A case where you distinguished successful exercise choreography from actual resilience capability.
- Experience stopping or modifying testing to protect live operations while preserving assurance value.
- Availability for full-time Johannesburg work and permanent-successor development during the core term.
Working terms and boundaries
- The seven-month, five-day-week interim term permits a two-month extension only for failed retesting or transfer criteria.
- Audit scope, evidence, ratings and safe-testing choices are included; plan ownership, exercise operation and risk acceptance are excluded.
- Protected service details and configurations must remain within authorised audit environments.
- The successor takes functional lead by month five and completes four live acceptance events.
- Completion requires integrated coverage, validated priority issues, transparent residual gaps and committee-approved handover.
Application
Applications for this mandate are received in one way only: through the India Board Terminal's application process. It is automated end to end. Your Executive Passport travels to the mandate holder in its confidential form, your answers to the three questions below are read before anything else in your file, and every stage that follows is recorded on your applications page.
There is no address to write to and no intermediary to call. The mandate holder reads what the Terminal delivers and nothing else, which is what keeps the process the same for every applicant and keeps your name out of it until you release it. Applications close on 10 October 2026. Mandate reference AUD-INT-2026-JNB-31.
More seats like this one
This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.