SAS

Manager, GRC-A (Information Security Risk)

SAS$110K — $130K *
Cary, NC 27513In-Person
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's or Master's degree in Business, IT, Cybersecurity, Project Management or related field.
  • 4-8 years of experience in risk management, preferably in a regulated industry.
  • Strong management and leadership skills.
  • Familiarity with GRC tools like ServiceNow IRM.
  • Ability to manage multiple projects simultaneously.
  • Strong verbal, written, and interpersonal skills.
  • Deep understanding of security risk frameworks (e.g., NIST, PCI DSS).

Responsibilities

  • Lead the development and maturity of information security and third-party risk assessment programs.
  • Collaborate with various stakeholders to identify and manage cybersecurity risks.
  • Monitor and implement changes in regulatory and industry requirements for cybersecurity management.
  • Conduct risk assessments and document security vulnerabilities across various platforms.
  • Oversee risk treatment plans ensuring accountability and timely remediation.
  • Enhance risk management methodologies and processes.
  • Manage the third-party security risk assessment team and guide on complex assessments.

Benefits

  • Comprehensive medical, dental, vision plans.
  • Onsite Health Care Center free for employees and enrolled family members.
  • Industry-leading 401k plan.
  • Tuition Assistance Program for professional development.
  • Generous vacation time and paid holidays, including a Winter Wellness Break.
  • Volunteer Time Off and generous childcare benefits for full-time employees.
Full Job Description

Manager, Information Security Risk - Governance, Risk, Compliance – Audit - Hybrid, Cary, North Carolina 

  

 

About the job

The Manager, Governance, Risk, Compliance – Audit (GRC-A) is a hands on management role combining technical risk management expertise with people leadership, overseeing a team that evaluates information security and cybersecurity risks across SAS and our third-parties. As a working manager, the position is actively involved in risk analysis and problem-solving while also guiding program execution, stakeholder engagement, and continuous improvement efforts. 

 

The Governance, Risk, Compliance - Audit team provides independent assessment and advisory services, facilitates compliance with regulatory and security requirements, performs assurance activities, and delivers information that enables informed business and risk decisions. Through collaboration, innovation, and practical risk management, the team helps protect SAS while enabling business success. 

  

As a Manager, Information Security Risk - Governance, Risk, Compliance – Audit you will: 

  • Lead and continuously mature the information security risk management and third-party security risk assessment programs, providing direction to team members while driving initiatives that enhance SAS's risk management program. 

  • Partner with business, technology, and service provider stakeholders to identify, assess, monitor, and manage information security risks. 

  • Monitor evolving regulatory and industry requirements affecting cybersecurity, technology risk, privacy, operational resilience, and third-party risk management, and incorporate applicable requirements into program practices. 

Internal Information Security Risk  

  • Perform information security risk assessments and document threats, vulnerabilities, controls, and residual risks across internal systems, cloud services, third-party vendors, and enterprise initiatives. 

  • Oversee risk assessment activities and risk treatment plans, ensuring clear ownership, timely remediation, and accountability for mitigation actions. 

  • Maintain and enhance risk management methodologies, risk scoring models, governance processes, and the risk register to support consistent and effective risk decision-making. 

  • Define, track, and communicate cybersecurity risk metrics, key risk indicators (KRIs), dashboards, and assessment results through recurring reporting for senior leadership. 

Third-Party Risk Management (TPRM) – Information Security  

  • Manage the third-party security risk assessment team, providing guidance on complex assessments and ensuring cybersecurity, privacy, compliance, and operational risks are consistently identified, evaluated, reported, and managed. 

  • Collaborate with Procurement, Legal, and Third-Party Risk Management (TPRM) stakeholders to integrate security and compliance requirements throughout vendor onboarding, contracting, and ongoing oversight processes. 

  • Define, track, and communicate third-party security risk metrics, key risk indicators (KRIs), dashboards, and assessment results through recurring reporting for senior leadership.

  

Required qualifications  

  • Bachelor's or Master’s degree in Business, IT, Cybersecurity, Project Management or related field.  

  • Typically requires 4-8 years of demonstrated success performing risk management. Experience in a regulated (pharmaceutical, banking, insurance, government) industry (may be concurrent with the above functional experience). 

  • Demonstrated strong management and leadership skills. 

  • Excellent awareness of GRC tooling, such as ServiceNow IRM 

  • Excellent ability to handle multiple projects at the same time. 

  • Excellent ability to supervise and train employees with varying skill sets in a high-pressure environment. 

  • Excellent verbal, written, and interpersonal skills. 

  • Demonstrated ability to solve complex problems. 

  • Equivalent combination of related education, training and experience may be considered in place of the above qualifications. 

  • Deep understanding of information security risk frameworks (NIST CSF, CRI Profile, PCI DSS, CIS Controls, etc.) and enterprise risk management principles, with practical experience applying them across systems, processes, and third-party vendors. 

  • Ability to lead projects from start to finish, working independently, escalating issues, as appropriate and being flexible, when needed. 

  

Additional competencies, knowledge and skills 

  • Strategic Planning -Obtains information and identifies key issues and relationships relevant to achieving a long-range goal; committing to a course of action to accomplish a long-range goal after developing alternatives based on logical assumptions, facts, available resources, constraints, and organizational values. 

  • Leading Change -Drives organizational and cultural changes needed to achieve strategic objectives; catalyzing new approaches to improve results by transforming organizational culture, systems, or products/services; helping others overcome resistance to change 

  • Global Perspective - Demonstrates awareness of and sensitivity to the international market, cultural, technological, political, and legal factors that impact individual and work group priorities and results; leveraging own understanding of the organization’s global strategy, global business trends, and regional differences to enhance individual and work group results. 

  • Ability to interview and manage staff, providing appropriate training and guidance as well as ongoing performance management. 

  • Strong management, leadership, and executive presentation skills. 

  • Experience applying enterprise risk management (ERM) principles and methodologies to identify, assess, prioritize, and communicate technology, cybersecurity, operational, or third-party risks.

  • Ability to build strong partnerships with security and technology teams across the enterprise.  

World-class benefits  

Highlights include...

  • Comprehensive medical, prescription, dental and vision plans.
  • Medical plan options include:
    • PPO with low annual deductible and copays.
    • HDHP combined with a health savings account with a contribution from SAS (no access to on-site health care center).
  • Onsite Health Care Center (HQ) that’s free to employees and family members enrolled in the PPO plan. There's a pharmacy too! Not local to HQ? The pharmacy will ship prescriptions for no additional charge!
  • An industry-leading 401k plan.
  • Tuition Assistance Program and programs and resources to support your development
  • Generous time away including vacation time, a variety of paid holidays, and our much-loved U.S. Winter Wellness Break between December 25 and January 1.
  • Volunteer Time Off, parental leave and unlimited paid sick days.
  • Generous childcare benefits for all full-time employees.

 

You are welcome here.

At SAS, it’s not about fitting into our culture – it’s about adding to it. We believe our people make the difference. Our inclusive workforce brings together unique talents and inspires teams to create amazing software that reflects the diversity of our users and customers.

 

Additional Information:

To qualify, applicants must be legally authorized to work in the United States, and should not require, now or in the future, sponsorship for employment visa status.

 

Let's stay in touch! Join our Talent Community to stay up to date on company news, job updates and more.

#SAS

About SAS

SAS is a multinational software company that provides advanced analytics, business intelligence, and data management software and services. SAS is the largest privately held software company in the world and is headquartered in Cary, North Carolina. The company was founded in 1976 by Jim Goodnight and John Sall, who are still the CEO and Executive Vice President, respectively. SAS has over 83,000 customers worldwide and employs over 14,000 people in more than 60 countries. SAS has been recognized as one of the best places to work by Fortune magazine and the Great Place to Work Institute.
Learn more about SAS
Size
14,000 employees
Industry
Founded
1976

Similar Jobs

More Jobs at SAS

More Information Technology Jobs

Find similar Manager, GRC-A (Information Security Risk) jobs: