Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Manager, GRC-A (Information Security Risk)

SAS Institute Inc

Manager, Information Security Risk - Governance, Risk, Compliance – Audit - Hybrid, Cary, North Carolina We’re a leader in data and AI. Through our software and services, we inspire customers around the world to transform data into intelligence - and questions into answers. If you're looking for a dynamic, fulfilling career with flexibility and a world-class employee experience, you'll find it here. We're recognized around the world for our inclusive, meaningful culture and innovative technologies by organizations like Fast Company, Forbes, Newsweek and more.About the jobThe Manager, Governance, Risk, Compliance – Audit (GRC-A) is a hands on management role combining technical risk management expertise with people leadership, overseeing a team that evaluates information security and cybersecurity risks across SAS and our third-parties. As a working manager, the position is actively involved in risk analysis and problem-solving while also guiding program execution, stakeholder engagement, and continuous improvement efforts. The Governance, Risk, Compliance - Audit team provides independent assessment and advisory services, facilitates compliance with regulatory and security requirements, performs assurance activities, and delivers information that enables informed business and risk decisions. Through collaboration, innovation, and practical risk management, the team helps protect SAS while enabling business success. As a Manager, Information Security Risk - Governance, Risk, Compliance – Audit you will: Lead and continuously mature the information security risk management and third-party security risk assessment programs, providing direction to team members while driving initiatives that enhance SAS's risk management program. Partner with business, technology, and service provider stakeholders to identify, assess, monitor, and manage information security risks. Monitor evolving regulatory and industry requirements affecting cybersecurity, technology risk, privacy, operational resilience, and third-party risk management, and incorporate applicable requirements into program practices. Internal Information Security Risk Perform information security risk assessments and document threats, vulnerabilities, controls, and residual risks across internal systems, cloud services, third-party vendors, and enterprise initiatives. Oversee risk assessment activities and risk treatment plans, ensuring clear ownership, timely remediation, and accountability for mitigation actions. Maintain and enhance risk management methodologies, risk scoring models, governance processes, and the risk register to support consistent and effective risk decision-making. Define, track, and communicate cybersecurity risk metrics, key risk indicators (KRIs), dashboards, and assessment results through recurring reporting for senior leadership. Third-Party Risk Management (TPRM) – Information Security Manage the third-party security risk assessment team, providing guidance on complex assessments and ensuring cybersecurity, privacy, compliance, and operational risks are consistently identified, evaluated, reported, and managed. Collaborate with Procurement, Legal, and Third-Party Risk Management (TPRM) stakeholders to integrate security and compliance requirements throughout vendor onboarding, contracting, and ongoing oversight processes. Define, track, and communicate third-party security risk metrics, key risk indicators (KRIs), dashboards, and assessment results through recurring reporting for senior leadership.Embrace curiosity, passion, authenticity and accountability. These are our values and influence everything we do. Required qualifications  Bachelor's or Master’s degree in Business, IT, Cybersecurity, Project Management or related field. Typically requires 4-8 years of demonstrated success performing risk management. Experience in a regulated (pharmaceutical, banking, insurance, government) industry (may be concurrent with the above functional experience). Demonstrated strong management and leadership skills. Excellent awareness of GRC tooling, such as ServiceNow IRM Excellent ability to handle multiple projects at the same time. Excellent ability to supervise and train employees with varying skill sets in a high-pressure environment. Excellent verbal, written, and interpersonal skills. Demonstrated ability to solve complex problems. Equivalent combination of related education, training and experience may be considered in place of the above qualifications. Deep understanding of information security risk frameworks (NIST CSF, CRI Profile, PCI DSS, CIS Controls, etc.) and enterprise risk management principles, with practical experience applying them across systems, processes, and third-party vendors. Ability to lead projects from start to finish, working independently, escalating issues, as appropriate and being flexible, when needed. Additional competencies, knowledge and skills Strategic Planning -Obtains information and identifies key issues and relationships relevant to achieving a long-range goal; committing to a course of action to accomplish a long-range goal after developing alternatives based on logical assumptions, facts, available resources, constraints, and organizational values. Leading Change -Drives organizational and cultural changes needed to achieve strategic objectives; catalyzing new approaches to improve results by transforming organizational culture, systems, or products/services; helping others overcome resistance to change Global Perspective - Demonstrates awareness of and sensitivity to the international market, cultural, technological, political, and legal factors that impact individual and work group priorities and results; leveraging own understanding of the organization’s global strategy, global business trends, and regional differences to enhance individual and work group results. Ability to interview and manage staff, providing appropriate training and guidance as well as ongoing performance management. Strong management, leadership, and executive presentation skills. Experience applying enterprise risk management (ERM) principles and methodologies to identify, assess, prioritize, and communicate technology, cybersecurity, operational, or third-party risks.Ability to build strong partnerships with security and technology teams across the enterprise.  World-class benefits Highlights include...Comprehensive medical, prescription, dental and vision plans.Medical plan options include:PPO with low annual deductible and copays.HDHP combined with a health savings account with a contribution from SAS (no access to on-site health care center).Onsite Health Care Center (HQ) that’s free to employees and family members enrolled in the PPO plan. There's a pharmacy too! Not local to HQ? The pharmacy will ship prescriptions for no additional charge!An industry-leading 401k plan.Tuition Assistance Program and programs and resources to support your developmentGenerous time away including vacation time, a variety of paid holidays, and our much-loved U.S. Winter Wellness Break between December 25 and January 1.Volunteer Time Off, parental leave and unlimited paid sick days.Generous childcare benefits for all full-time employees.You are welcome here.At SAS, it’s not about fitting into our culture – it’s about adding to it. We believe our people make the difference. Our inclusive workforce brings together unique talents and inspires teams to create amazing software that reflects the diversity of our users and customers.Additional Information:To qualify, applicants must be legally authorized to work in the United States, and should not require, now or in the future, sponsorship for employment visa status. SAS is an equal opportunity employer. All qualified applicants are considered for employment without regard to any characteristic protected by law. Read more: Know Your Rights. Resumes may be considered in the order they are received. SAS employees performing certain job functions may require access to technology or software subject to export or import regulations. To comply with these regulations, SAS may obtain nationality or citizenship information from applicants for employment. SAS collects this information solely for trade law compliance purposes and does not use it to discriminate unfairly in the hiring process.SAS only sends emails from verified “sas.com” email addresses and never asks for sensitive, personal information or money. If you have any doubts about the authenticity of any type of communication from, or on behalf of SAS, please contact View email address on us.fitly.work's stay in touch! Join our Talent Community to stay up to date on company news, job updates and more.#SASJob SummaryRequisition ID: 20070892Category: Contracts/LegalVisa Sponsorship: NoTravel Requirements: None

Vacancy posted 7 days ago
Similar jobs that could be interesting for youBased on the Manager, GRC-A (Information Security Risk) in Cary, NC vacancy
  •  ...This position reports to: Head of IS Security, Risk and Compliance __ Your role and...  ...operational aspects, including document management and systems and procedures analysis....  ...ensuring "security by design" across all EL Information Systems projects Oversee... 
    Risk
    Full time
    Temporary work
    Local area
    Monday to Friday

    ABB

    Cary, NC
    10 days ago
  •  ...Job Description: Senior Information Security GRC Analyst Department: Information Security Job Title: Senior Information Security Governance, Risk, and Compliance (GRC) Analyst Reports To: Information Security GRC Manager / Head of Information Security Location: Remote... 
    Risk
    Contract work
    Work at office
    Remote work

    Golden Technology

    Raleigh, NC
    1 day ago
  •  ...Solutions, Inc (OTSI) has an immediate opening for a Sr. Information Security Analyst - GRC   Sr. Information Security Analyst – GRC (Cary...  ...MAJOR RESPONSIBILITES: • Contract Risk Management • Proven experience reviewing client contract provisions... 
    Risk
    Full time
    Contract work
    Immediate start

    O.t.s.i.

    Cary, NC
    9 hours ago
  •  ...employeesJob DescriptionThe Director of (Cyber) Security Architecture and Engineering is a...  ...transformation, and enterprise risk management objectives. This role provides strategic...  ...progressive experience in cybersecurity, information security, or closely related... 
    Risk
    Live in
    Work at office
    Work from home
    Flexible hours

    Bertelsmann

    Morrisville, NC
    a month ago
  •  ...Director Of Security Operations Advance Auto Parts is seeking a...  ...lead the operational arm of our Information Security program. This role...  ...incident response, vulnerability management, and security monitoring...  ...threats. Vulnerability & Risk Management Own the vulnerability... 
    Risk
    Work at office
    Local area
    Remote work
    1 day per week

    Advance Auto Parts

    Raleigh, NC
    2 days ago
  • $118.3k - $219.8k

     ...collaborating with LexisNexis to connect them with exceptional professionals for this role. Manager, Security - Security Compliance & Risk Management Function: Information Security / Compliance & Risk Location: Raleigh / Hybrid About the Role The Manager,... 
    Risk
    Local area
    Raleigh, NC
    11 days ago
  • $300k - $350k

     ...automotive markets Holman serves include fleet management and leasing; vehicle fabrication and...  ...; commercial and personal insurance and risk management; and retail automotive sales...  ...a resume or cover letter, provided the information is accurate and truthful. However,... 
    Risk
    Full time
    Temporary work
    Part time
    Work experience placement
    Local area
    Flexible hours

    Holman Inc

    Cary, NC
    4 days ago
  • $75k - $80k

     ...CampusGuard, a Nelnet Company, provides information security services for campus-based organizations...  ...services. The Customer Success Manager (CSM) is responsible for owning the client...  ...proactively monitors client health, identifies risks and opportunities, and drives value... 
    Risk
    Full time
    Temporary work
    Local area
    Remote work

    Nelnet

    Raleigh, NC
    2 days ago
  •  ...and flexible staffing. Governance, Risk & Compliance (GRC) Specialist Location: Houston, TX (...  ...(GRC) Specialist to join a growing Information Security team supporting a large-scale critical...  ...in strengthening governance, risk management, compliance, and cybersecurity... 
    Risk
    Contract work
    Remote work
    Flexible hours

    Beacon Hill Staffing Group

    Raleigh, NC
    4 days ago
  •  ...an Assistant General Counsel (Claims & Litigation) to lead the company’s management of all claims, litigation, arbitration, and dispute resolution. You will partner with executives, operations, risk management, and outside counsel to mitigate risk and achieve favorable... 
    Risk

    Jobleads-US

    Cary, NC
    2 days ago
  • $100k - $153k

     ...Job Title Technical Project / Program Manager – Network Security & Cyber Resilience Corporate Title...  ...vulnerability trends, architectural risks, operational issues, and security...  ...degree in Computer Science, Engineering, Information Security, or a related discipline... 
    Risk
    Full time
    Work at office
    Remote work
    Work from home
    Shift work
    Cary, NC
    10 days ago
  • $125k - $220k

     ...innovating new ways for utilities and cities to manage energy and water. We create a more...  ...resourceful world. Join us.As a member of the Information Security leadership team, you will lead security architecture, risk remediation, threat intelligence, vulnerability... 
    Risk
    Full time

    Itron

    Raleigh, NC
    a month ago
  •  ...proposition: Relevant. Simple. Reliable. For more information, visit AtticusLLC.com. What you will do in this role As a technical project manager, you will be responsible for establishing...  ...the overall project health (what’s at risk, what’s blocked, and what’s working). This... 
    Risk
    Work at office

    Atticus LLC

    Cary, NC
    2 days ago
  • $160k - $170k

     ...and as a member of the Project Management Team, you will be challenged...  ...: project planning; risk assessment; resource management...  ...project plans. Work with the security team to ensure the applications...  ...Qualifications: Bachelor's Degree in information systems, business systems,... 
    Risk
    Work experience placement
    H1b
    Work at office
    Local area
    Shift work

    Karsun Solutions, LLC

    Raleigh, NC
    5 days ago
  •  ...GSW in Morrisville seeks an experienced Senior Project Manager to drive cross-disciplinary programs and ensure projects are delivered on...  ...resource managers, and studio teams, write actionable tasks in Wrike, and lead risk reviews to keep programs on track. #J-18808-Ljbffr... 
    Risk

    Syneos Health/ inVentiv Health Commercial LLC

    Morrisville, NC
    3 hours ago
  •  ...Summary The Senior Project Manager is responsible for all project...  ...partners, purchase orders, and risk management. This individual also...  ...Focus on keeping the Owner well informed of important matters to prevent surprises Work to secure a strong letter of recommendation... 
    Risk
    Contract work
    Apprenticeship
    For subcontractor
    Local area
    Immediate start

    BE&K Building Group

    Morrisville, NC
    5 days ago
  • $118.3k - $219.8k

     ...Raleigh, NC Full time R116072 Manager, Security - Security Compliance & Risk Management Core...  ...years of progressive experience in information security compliance, risk management...  ...development ~ Deep, hands-on knowledge of GRC disciplines across risk management... 
    Risk
    Full time
    Local area

    RELX

    Raleigh, NC
    1 day ago
  •  ...Head of Information Technology Position Overview The Head of...  ...highly desirable. Experience managing technology teams, external service...  ..., operational technology security, disaster recovery, business continuity planning, and risk management. Experience with... 
    Risk
    For contractors
    Work at office
    Local area

    Vaco

    Apex, NC
    4 days ago
  •  ...Project Manager Reports to: VP of Operations The Project Manager (PM) is responsible for leading and executing high-profile, complex...  ...for assigned projects. • Proactively identify project risks, constraints, and dependencies; develop and execute mitigation plans... 
    Risk

    Storr Office Environments

    Morrisville, NC
    2 days ago
  •  ...Construction Manager II: ccountable for all Civil Works and associated financial control...  ...and on-site supervision during where risk of disturbances in customer site performance...  ...project • Provide accurate status information on the progress to project management.... 
    Risk
    Contract work
    Local area

    ADEX

    Cary, NC
    1 day ago
  •  ...governance solutions that reduce risk while improving operational...  ...for identity lifecycle management.  Provide technical leadership...  ...Bachelor's degree in Information Security or Computer Science or related...  ...privacy, and other relevant GRC areas. All applicants must... 
    Risk
    Flexible hours

    Black & Veatch Family of Companies

    Cary, NC
    3 days ago
  • $36 per hour

     .... Each engineer, technician, project manager, and administrator are part of a team that...  ...Identify, assess, and mitigate project risks. Review and approve survey data,...  ...age (40 or older), disability or genetic information (including family medical history), national... 
    Risk
    Hourly pay
    Full time
    Temporary work
    For contractors
    Work experience placement
    Local area

    Bateman Civil Survey Company

    Apex, NC
    9 hours ago
  • $95.5k - $177.3k

     ...resource. From our residential water filtration to industrial water management to pool products and more, our 9,000 global employees serve...  ..., and regulatory requirements.Report audit results, compliance risks, and improvement opportunities to leadership.Corrective Action... 
    Risk
    Full time

    Pentair

    Apex, NC
    11 days ago
  •  ...opportunity available for an experienced A/E design side Project Manager to join our team. The Project Manager will plan and organize all...  ...quality plans. Properly identify and assess project risks and escalate to senior leadership as appropriate. Create and... 
    Risk
    Work at office
    Local area
    Flexible hours

    DPS Group LLC

    Cary, NC
    1 day ago
  • $175k

     ...Construction Manager Are you a driven and experienced Construction Manager with a background in heavy civil projects? In this role,...  ...budget and schedule. Provides technical input to resolve project risks and documents daily activities and meetings. Promotes strict... 
    Risk
    Contract work
    For subcontractor
    Local area

    FD.io

    Morrisville, NC
    2 days ago
  •  ...Director of Security Etix is an international, web-based ticketing provider serving...  ...design, and company-wide risk management. You've built and evolved security...  ...client facing team members. Other Information No sponsorship or H1B situations... 
    Risk
    Temporary work
    Casual work
    H1b
    Work at office
    Remote work
    Relocation
    Flexible hours
    1 day per week

    Etix

    Morrisville, NC
    4 days ago
  • $110k - $140k

     ...experienced and driven Technical Project Manager to join our team. In this role, you will...  ...leadership to highly specialized engineers. Risk Management: Taking ownership of project...  ...discussions on product health to drive informed phase-gate exits and mitigate... 
    Risk
    Temporary work
    Work at office
    Relocation

    OnLogic

    Cary, NC
    26 days ago
  •  ...relationships with clients, team partners, managers, and in-house multi-disciplinary teams?...  .... Familiarity and understanding of risk management and loss prevention. Demonstrated...  ...’s driving (MVR) policy. Corporate Information: ESP is a multi-discipline... 
    Risk
    Contract work
    Temporary work
    Flexible hours

    ESP Associates

    Morrisville, NC
    12 days ago
  •  ...Project Manager - Advanced Power Generation Together, we own our company, our future,...  ...Construction (EPC)/Service projects, including risk to cost, schedule, quality. Responsible...  ...adding to the much-needed supply of secure, clean power to our industries and communities... 
    Risk
    Full time
    Contract work
    Part time
    Work at office
    Relocation
    Visa sponsorship
    Flexible hours

    Black & Veatch

    Cary, NC
    2 days ago
  •  ...s success. As a Relationship Manager within PNC's Business Banking...  ...clients with basic levels of risk and complexity of needs. Generally...  ...and able to leverage that information in creating customized...  ...for any registered role, the Secure and Fair Enforcement for Mortgage... 
    Risk
    Full time
    Temporary work
    Part time
    Work experience placement
    Work at office

    The PNC Financial Services Group

    Cary, NC
    7 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Manager, GRC-A (Information Security Risk). Be the first to apply!