×
Register Here to Apply for Jobs or Post Jobs. X

Manager, GRC-; Information Security Risk

Job in Cary, Wake County, North Carolina, 27518, USA
Listing for: Sas
Full Time position
Listed on 2026-09-12
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 120000 - 170000 USD Yearly USD 120000.00 170000.00 YEAR
Job Description & How to Apply Below

Manager,Information Security Risk
-Governance, Risk, Compliance – Audit
- Hybrid, Cary, North Carolina

We’re a leader in data and AI. Through our software and services, we inspire customers around the world to transform data into intelligence - and questions into answers.

If you're looking for a dynamic, fulfilling career with flexibility and a world-class employee experience, you'll find it here. We're recognized around the world for our inclusive, meaningful culture and innovative technologies by organizations like Fast Company, Forbes, Newsweek and more.

About the job

The Manager, Governance, Risk, Compliance – Audit (GRC-A) is a hands on management role combining technical risk managementexpertisewith people leadership, overseeing a team that evaluates information security andcybersecurity risksacrossSAS and ourthird-parties.

As a working manager, the positionisactively involved inrisk analysis and problem-solving while also guiding program execution, stakeholder engagement, and continuous improvement efforts.

The Governance, Risk, Compliance
- Audit team provides independent assessment and advisory services,facilitates compliance with regulatory and security requirements, performs assurance activities, and delivers information that enables informed business and risk decisions. Through collaboration, innovation, and practical risk management, the team helps protect SAS while enabling business success.

you will:
  • Lead and continuously mature the information security risk management andthird-party security risk assessment programs, providing direction to team members while driving initiatives that enhance SAS's risk management program.
  • Partner with business, technology, and service provider stakeholders to identify, assess,monitor, and manage information security risks.
  • Monitor evolving regulatory and industry requirements affecting cybersecurity, technology risk, privacy, operational resilience, and third-party risk management, and incorporate applicable requirements into program practices.
Internal Information Security Risk
  • Perform information security risk assessments and document threats, vulnerabilities, controls, and residual risks across internal systems, cloud services, third-party vendors, and enterprise initiatives.
  • Oversee risk assessment activities and risk treatment plans, ensuring clear ownership,timely remediation, and accountability for mitigation actions.
  • Maintain and enhance risk management methodologies, risk scoring models, governance processes, and therisk register to support consistent and effective risk decision-making.
  • Define, track, and communicate cybersecurity risk metrics, key risk indicators (KRIs), dashboards, and assessment results through recurring reporting for senior leadership.
Third-Party Risk Management (TPRM) –Information Security
  • Managethethird-party security risk assessment team, providing guidance on complex assessments and ensuring cybersecurity, privacy, compliance, and operational risks are consistently identified, evaluated, reported, and managed.
  • Collaborate with Procurement, Legal, and Third-Party Risk Management (TPRM) stakeholders to integrate security and compliance requirements throughout vendor onboarding, contracting, and ongoing oversight processes.
  • Define, track, and communicate third-party security risk metrics, key risk indicators (KRIs), dashboards, and assessment results through recurring reporting for senior leadership.

    Embrace curiosity, passion,authenticity and accountability. These are our values and influence everything we do.
Required qualifications
  • Bachelor'sor Master’s degree in Business, IT, Cybersecurity, Project Manage mentor related field.
  • Typically requires 4-8 years ofdemonstratedsuccess performing risk management.

    Experience in a regulated…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary