Manager, GRC-A (Information Security Risk)
SAS Institute Inc
Manager, Information Security Risk - Governance, Risk, Compliance – Audit - Hybrid, Cary, North Carolina We’re a leader in data and AI. Through our software and services, we inspire customers around the world to transform data into intelligence - and questions into answers. If you're looking for a dynamic, fulfilling career with flexibility and a world-class employee experience, you'll find it here. We're recognized around the world for our inclusive, meaningful culture and innovative technologies by organizations like Fast Company, Forbes, Newsweek and more.About the jobThe Manager, Governance, Risk, Compliance – Audit (GRC-A) is a hands on management role combining technical risk management expertise with people leadership, overseeing a team that evaluates information security and cybersecurity risks across SAS and our third-parties. As a working manager, the position is actively involved in risk analysis and problem-solving while also guiding program execution, stakeholder engagement, and continuous improvement efforts. The Governance, Risk, Compliance - Audit team provides independent assessment and advisory services, facilitates compliance with regulatory and security requirements, performs assurance activities, and delivers information that enables informed business and risk decisions. Through collaboration, innovation, and practical risk management, the team helps protect SAS while enabling business success. As a Manager, Information Security Risk - Governance, Risk, Compliance – Audit you will: Lead and continuously mature the information security risk management and third-party security risk assessment programs, providing direction to team members while driving initiatives that enhance SAS's risk management program. Partner with business, technology, and service provider stakeholders to identify, assess, monitor, and manage information security risks. Monitor evolving regulatory and industry requirements affecting cybersecurity, technology risk, privacy, operational resilience, and third-party risk management, and incorporate applicable requirements into program practices. Internal Information Security Risk Perform information security risk assessments and document threats, vulnerabilities, controls, and residual risks across internal systems, cloud services, third-party vendors, and enterprise initiatives. Oversee risk assessment activities and risk treatment plans, ensuring clear ownership, timely remediation, and accountability for mitigation actions. Maintain and enhance risk management methodologies, risk scoring models, governance processes, and the risk register to support consistent and effective risk decision-making. Define, track, and communicate cybersecurity risk metrics, key risk indicators (KRIs), dashboards, and assessment results through recurring reporting for senior leadership. Third-Party Risk Management (TPRM) – Information Security Manage the third-party security risk assessment team, providing guidance on complex assessments and ensuring cybersecurity, privacy, compliance, and operational risks are consistently identified, evaluated, reported, and managed. Collaborate with Procurement, Legal, and Third-Party Risk Management (TPRM) stakeholders to integrate security and compliance requirements throughout vendor onboarding, contracting, and ongoing oversight processes. Define, track, and communicate third-party security risk metrics, key risk indicators (KRIs), dashboards, and assessment results through recurring reporting for senior leadership.Embrace curiosity, passion, authenticity and accountability. These are our values and influence everything we do. Required qualifications Bachelor's or Master’s degree in Business, IT, Cybersecurity, Project Management or related field. Typically requires 4-8 years of demonstrated success performing risk management. Experience in a regulated (pharmaceutical, banking, insurance, government) industry (may be concurrent with the above functional experience). Demonstrated strong management and leadership skills. Excellent awareness of GRC tooling, such as ServiceNow IRM Excellent ability to handle multiple projects at the same time. Excellent ability to supervise and train employees with varying skill sets in a high-pressure environment. Excellent verbal, written, and interpersonal skills. Demonstrated ability to solve complex problems. Equivalent combination of related education, training and experience may be considered in place of the above qualifications. Deep understanding of information security risk frameworks (NIST CSF, CRI Profile, PCI DSS, CIS Controls, etc.) and enterprise risk management principles, with practical experience applying them across systems, processes, and third-party vendors. Ability to lead projects from start to finish, working independently, escalating issues, as appropriate and being flexible, when needed. Additional competencies, knowledge and skills Strategic Planning -Obtains information and identifies key issues and relationships relevant to achieving a long-range goal; committing to a course of action to accomplish a long-range goal after developing alternatives based on logical assumptions, facts, available resources, constraints, and organizational values. Leading Change -Drives organizational and cultural changes needed to achieve strategic objectives; catalyzing new approaches to improve results by transforming organizational culture, systems, or products/services; helping others overcome resistance to change Global Perspective - Demonstrates awareness of and sensitivity to the international market, cultural, technological, political, and legal factors that impact individual and work group priorities and results; leveraging own understanding of the organization’s global strategy, global business trends, and regional differences to enhance individual and work group results. Ability to interview and manage staff, providing appropriate training and guidance as well as ongoing performance management. Strong management, leadership, and executive presentation skills. Experience applying enterprise risk management (ERM) principles and methodologies to identify, assess, prioritize, and communicate technology, cybersecurity, operational, or third-party risks.Ability to build strong partnerships with security and technology teams across the enterprise. World-class benefits Highlights include...Comprehensive medical, prescription, dental and vision plans.Medical plan options include:PPO with low annual deductible and copays.HDHP combined with a health savings account with a contribution from SAS (no access to on-site health care center).Onsite Health Care Center (HQ) that’s free to employees and family members enrolled in the PPO plan. There's a pharmacy too! Not local to HQ? The pharmacy will ship prescriptions for no additional charge!An industry-leading 401k plan.Tuition Assistance Program and programs and resources to support your developmentGenerous time away including vacation time, a variety of paid holidays, and our much-loved U.S. Winter Wellness Break between December 25 and January 1.Volunteer Time Off, parental leave and unlimited paid sick days.Generous childcare benefits for all full-time employees.You are welcome here.At SAS, it’s not about fitting into our culture – it’s about adding to it. We believe our people make the difference. Our inclusive workforce brings together unique talents and inspires teams to create amazing software that reflects the diversity of our users and customers.Additional Information:To qualify, applicants must be legally authorized to work in the United States, and should not require, now or in the future, sponsorship for employment visa status. SAS is an equal opportunity employer. All qualified applicants are considered for employment without regard to any characteristic protected by law. Read more: Know Your Rights. Resumes may be considered in the order they are received. SAS employees performing certain job functions may require access to technology or software subject to export or import regulations. To comply with these regulations, SAS may obtain nationality or citizenship information from applicants for employment. SAS collects this information solely for trade law compliance purposes and does not use it to discriminate unfairly in the hiring process.SAS only sends emails from verified “sas.com” email addresses and never asks for sensitive, personal information or money. If you have any doubts about the authenticity of any type of communication from, or on behalf of SAS, please contact View email address on click.appcast.io's stay in touch! Join our Talent Community to stay up to date on company news, job updates and more.#SASJob SummaryRequisition ID: 20070892Category: Contracts/LegalVisa Sponsorship: NoTravel Requirements: None
- ...world.This position reports to:Head of IS Security, Risk and Compliance__Your role and... ...operational aspects, including document management and systems and procedures analysis.The... ...ensuring "security by design" across all EL Information Systems projectsOversee implementation...RiskTemporary workLocal areaMonday to Friday
$133.4k - $160k
Sr. GRC EngineerThe Team + The RolePendo's Information Security team protects the data entrusted to Pendo and helps ensure our... ...Product Security, and Compliance and Risk. With a small team and broad... ...independently own auditor relationships and manage an audit cycle end-to-end,...RiskWork at officeRemote workFlexible hours3 days per week- Job Description: Senior Information Security GRC Analyst Department: Information Security Job Title: Senior Information Security Governance, Risk, and Compliance (GRC) Analyst Reports To: Information Security GRC Manager / Head of Information Security Location: Remote,...RiskContract workWork at officeRemote work
- ...employeesJob DescriptionThe Director of (Cyber) Security Architecture and Engineering is a... ...transformation, and enterprise risk management objectives. This role provides strategic... ...progressive experience in cybersecurity, information security, or closely related...RiskLive inWork at officeWork from homeFlexible hours
- ...Solutions, Inc (OTSI) has an immediate opening for a Sr. Information Security Analyst - GRC Sr. Information Security Analyst – GRC (Cary... ...MAJOR RESPONSIBILITES: • Contract Risk Management • Proven experience reviewing client contract provisions...RiskFull timeContract workImmediate start
$100k - $153k
...Position Overview Job Title Network Security & Cyber Resilience Project Manager Corporate Title Assistant Vice... ...trends, architectural risks, operational issues, and security... ...in Computer Science, Engineering, Information Security, or a related discipline...RiskFull timeWork at officeRemote workWork from homeShift work- Manager, Information Security The Manager, Information Security leads Jewelers Mutual's security engineering... ...engineering, application teams, and GRC to strengthen security controls, mature... ..., and align security work to business risk priorities. The role balances team...RiskContract workWork experience placement
$169.5k
...environment, partnering with product management, underwriting, actuarial,... ...) Underwriting/pricing/risk management domain expertise... ...employees may have access to covered information, cardholder data, or other... ...as well as all data security guidelines established within...RiskFor contractorsWork at officeLocal area- ...seasoned and strategic Director of Security Operations to lead the operational arm of our Information Security program. This role is... ...response, vulnerability management, and security monitoring across... ...security threats.Vulnerability & Risk ManagementOwn the vulnerability...RiskWork at officeLocal areaRemote work1 day per week
$125k - $220k
...innovating new ways for utilities and cities to manage energy and water. We create a more... ...resourceful world. Join us.As a member of the Information Security leadership team, you will lead security architecture, risk remediation, threat intelligence, vulnerability...RiskFull time- ...seeking an Associate Director, Regional Information Security Awareness Lead to join our Global... ...the implementation of KPMG information risk and security standards / requirementsAssist... ...at least two years of experience in management positionBachelor's degree from an...RiskH1bLocal area
- ...join our team. Wingstop is hiring immediately for a General Manager to join their team! ROLE The General Manager provides strategic... ...the support of the Restaurant Support Center Ensure all risk management issues are in compliance with company standards...RiskImmediate startShift work
$155.63k - $317.88k
...Tax Enterprise Architect, Sr. Manager, you will be responsible to... ...current and competitive.Establish security best practices and duide... ...and escalate Product-related risks.Conduct design reviews and provide... ...in Risk and Information Systems Controls (CRISC)Certified...RiskWork at officeLocal areaShift work- ...excellence. Strengthen customer success.Join Ascom as a Project Manager (S&O) and play a key role in delivering customer-specific technical... ...solution and service delivery, managing project scope and risk, and ensuring projects are completed on time, within budget, and...Risk
$142.5k - $228k
...position reports to:Division General Counsel & Head of Contract Management IAPI__Your role and responsibilities In this role, you will... ...Contract Management Framework, and best contract management and risk management practices, with a focus on risk mitigation and opportunity...RiskFull timeContract work- ...with business, technology, architecture, security, risk, and compliance leaders while guiding... ...approvals, monitoring, and evidence retention.Manages, develops, and coaches developers,... ...and work experience in cybersecurity, information technology, or related field.Minimum of...RiskPermanent employmentFull timePart timeWork experience placementH1bWork visaShift workDay shift
$118.4k
...application software development management for IT projects. Creates... ...Liaising with clients to keep them informed of progress and to make... ...Advise clients on options, risks, cost vs benefit, impact on other... ...as well as all data security guidelines established within...RiskTemporary workFor contractorsWork at officeLocal area- ...Transactions Manager Together, we own our company, our future, and our shared success. As an employee-owned company, our people are... ...expectations, sub-task delegation and work stream resourcing, and risk project management. Demonstrates high quality project execution,...RiskWork experience placement
$118.3k - $219.8k
Manager, Security - Security Compliance & Risk Management Core Responsibilities Risk Management Own and operate the... ...years of progressive experience in information security compliance, risk... ...development Deep, hands-on knowledge of GRC disciplines across risk management...RiskFull timeLocal area$95.5k - $177.3k
...resource. From our residential water filtration to industrial water management to pool products and more, our 9,000 global employees serve... ..., and regulatory requirements.Report audit results, compliance risks, and improvement opportunities to leadership.Corrective Action...RiskFull time- ...s success. As a Relationship Manager within PNC's Business Banking... ...clients with basic levels of risk and complexity of needs. Generally... ...and able to leverage that information in creating customized... ...for any registered role, the Secure and Fair Enforcement for Mortgage...RiskFull timeTemporary workPart timeWork experience placementWork at office
$110k - $118k
...and practical for water, waste and energy management. Through its three complementary... ...ensuring a balance of customer centricity and risk management. The Commercial Contracts Manager... ..., other compensation, and benefits information is accurate as of the date of this posting...RiskContract workFor contractorsH1bImmediate startWorldwideFlexible hours$98.5k - $188k
...#VTeamLife.What you’ll be doing...We are seeking a Senior Manager in Cyber Security to drive high-impact data investigations and operational threat... ...security.Proven experience in fraud detection, security, risk management, or threat operations.Demonstrated ability to...RiskFull timeTemporary workPart timeWork experience placementWork at officeWork from homeShift workWeekend work3 days per week- ...North America and existing of experienced Managers and Account Executives. Together with... ...Data & AI Productivity and Decisioning, Risk Management, Revenue Assurance, Supply Chain... ...of our users and customers. Additional Information:SAS only sends emails from verified “sas...RiskFlexible hours
- ...Head of Information Technology Position Overview The Head of... ...highly desirable. Experience managing technology teams, external service... ..., operational technology security, disaster recovery, business continuity planning, and risk management. Experience with...RiskFor contractorsWork at officeLocal area
- ...Summary The Senior Project Manager is responsible for all project... ...partners, purchase orders, and risk management. This individual also... ...Focus on keeping the Owner well informed of important matters to prevent surprises Work to secure a strong letter of recommendation...RiskContract workApprenticeshipFor subcontractorLocal areaImmediate start
- ...Description NOW HIRING: Preconstruction Manager - Commercial Construction — Design/Build... ...projects, and ****@*****.*** (construction manager at risk) progressive cost estimates. Cost... ...bids from trade partners and suppliers to secure competitive pricing and ensure quality standards...RiskContract workTemporary workFor contractorsLocal areaImmediate startFlexible hours
- ...General Information Req # WD00094859 Career area: Hardware... ...and experienced Supply Chain Manager (SCM) to serve as the critical... ...Lenovo" strategy, mitigating risk, and ensuring synergy across... ...Commodity Management (GCM) to secure critical, long-lead server...RiskFull timeLocal area
- Description Study Manager - Future roles (US)Syneos Health is a leading fully integrated... ...projects.Accountable for maintenance of study information on a variety of databases and systems.... ....Developing contingency planning and risk mitigation strategies to ensure...RiskContract workImmediate startFlexible hours
$160k - $200k
General Information LocationNew York, New York Alternative Location(s) Posting Location... ...for technology strategy, product management, delivery execution, and operational performance... ...enterprise architecture, information security, risk management, operations, and external...RiskFull timeContract workTemporary workWork at officeLocal areaWorldwideRelocation package3 days per week
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Manager, GRC-A (Information Security Risk). Be the first to apply!



