Find Jobs
Find Jobs Near You – Available Work in Your Location
Manager, GRC-A (Information Security Risk)
Career Insights for Cyber Security Manager / Administrator
See where this job fits in the broader career landscape. Knowing your career path helps you see what's possible from here.
Scorecard
Based on North Carolina data
Review key factors to help you decide if this role fits your goals. How is this calculated?
What they do
A Cyber Security Manager or Administrator monitors, controls, and maintains systems that protect the security of large databases, including databases with customer information and patient files. Manages and administers the examination of client computer systems, identification of weak points in security, development and implementation of new systems, and monitoring and response to security issues.
$133,493 / year median in North Carolina
+6% projected growth
Job Description
- 4.
Full Job Description :
Manager, Information Security Risk- Governance, Risk, Compliance
- Audit
- Hybrid, Cary, North Carolina We're a leader in data and AI. Through our software and services, we inspire customers around the world to transform data into intelligence
- and questions into answers. If you're looking for a dynamic, fulfilling career with flexibility and a world-class employee experience, you'll find it here. We're recognized around the world for our inclusive, meaningful culture and innovative technologies by organizations like Fast Company, Forbes, Newsweek and more. About the job The Manager, Governance, Risk, Compliance
- Audit (GRC-A) is a hands on management role combining technical risk management expertise with people leadership, overseeing a team that evaluates information security and cybersecurity risks across SAS and our third-parties.
- Audit team provides independent assessment and advisory services, facilitates compliance with regulatory and security requirements, performs assurance activities, and delivers information that enables informed business and risk decisions.
- Governance, Risk, Compliance
- Audit you will: Lead and continuously mature the information security risk management and third-party security risk assessment programs, providing direction to team members while driving initiatives that enhance SAS's risk management program.
- Information Security Manage the third-party security risk assessment team, providing guidance on complex assessments and ensuring cybersecurity, privacy, compliance, and operational risks are consistently identified, evaluated, reported, and managed.
Embrace curiosity, passion, authenticity and accountability. These are our values and influence everything we do. Required qualifications Bachelor's or Master's degree in Business, IT, Cybersecurity, Project Management or related field. Typically requires 4-8 years of demonstrated success performing risk management. Experience in a regulated (pharmaceutical, banking, insurance, government) industry (may be concurrent with the above functional experience). Demonstrated strong management and leadership skills. Excellent awareness of GRC tooling, such as ServiceNow IRM Excellent ability to handle multiple projects at the same time. Excellent ability to supervise and train employees with varying skill sets in a high-pressure environment. Excellent verbal, written, and interpersonal skills. Demonstrated ability to solve complex problems. Equivalent combination of related education, training and experience may be considered in place of the above qualifications. Deep understanding of information security risk frameworks (NIST
CSF, CRI
Profile, PCIDSS, CIS
Controls, etc.) and enterprise risk management principles, with practical experience applying them across systems, processes, and third-party vendors. Ability to lead projects from start to finish, working independently, escalating issues, as appropriate and being flexible, when needed. Additional competencies, knowledge and skills Strategic Planning- Obtains information and identifies key issues and relationships relevant to achieving a long-range goal; committing to a course of action to accomplish a long-range goal after developing alternatives based on logical assumptions, facts, available resources, constraints, and organizational values. Leading Change
- Drives organizational and cultural changes needed to achieve strategic objectives; catalyzing new approaches to improve results by transforming organizational culture, systems, or products/services; helping others overcome resistance to change Global Perspective
- Demonstrates awareness of and sensitivity to the international market, cultural, technological, political, and legal factors that impact individual and work group priorities and results; leveraging own understanding of the organization's global strategy, global business trends, and regional differences to enhance individual and work group results.
Medical plan options include:
PPO with low annual deductible and copays. HDHP combined with a health savings account with a contribution from SAS (no access to on-site health care center). Onsite Health Care Center (HQ) that's free to employees and family members enrolled in the PPO plan. There's a pharmacy too! Not local to HQ? The pharmacy will ship prescriptions for no additional charge! An industry-leading 401k plan. Tuition Assistance Program and programs and resources to support your development Generous time away including vacation time, a variety of paid holidays, and our much-loved U.S. Winter Wellness Break between December 25 and January 1. Volunteer Time Off, parental leave and unlimited paid sick days. Generous childcare benefits for all full-time employees. You are welcome here. At SAS, it's not about fitting into our culture- it's about adding to it.
Additional Information:
To qualify, applicants must be legally authorized to work in the United States, and should not require, now or in the future, sponsorship for employment visa status. SAS is an equal opportunity employer. All qualified applicants are considered for employment without regard to any characteristic protected by law.Read more:
Know Your Rights. Resumes may be considered in the order they are received. SAS employees performing certain job functions may require access to technology or software subject to export or import regulations. To comply with these regulations, SAS may obtain nationality or citizenship information from applicants for employment. SAS collects this information solely for trade law compliance purposes and does not use it to discriminate unfairly in the hiring process. SAS only sends emails from verified "sas.com" email addresses and never asks for sensitive, personal information or money. If you have any doubts about the authenticity of any type of communication from, or on behalf of SAS, please contact . Let's stay in touch! Join our Talent Community to stay up to date on company news, job updates and more. #SASBenefits
- Paid Time Off (PTO)
- Sick Leave
- Volunteer Time Off (VTO)
- Financial Aid/Assistance