IT Governance Leader; Hybrid
Listed on 2026-05-08
-
IT/Tech
Cybersecurity, Data Security
Position Overview
At Securian, the internal job title is Infrastructure Manager.
The Change Governance Leader is accountable for defining, enforcing, and continuously improving Securian’s enterprise change management and release readiness practices. Reporting to the IT Technology Services leader, this role ensures that all production changes, whether manual or automated, are executed safely, compliantly, and predictably through policy-driven controls, auditable evidence, and readiness validation.
Mission StatementTo safeguard production stability and compliance by governing risk-aware, evidence-driven, and policy-aligned change practices that enable safe, auditable, and reliable technology delivery.
Role PurposeThe Change Governance Leader owns the enterprise change policy, the control framework, and the service readiness governance functions for ET production deployment. They define how changes are proposed, risk-assessed, approved, validated, and evidenced. They partner with engineering, operations, and compliance stakeholders to embed risk-based change governance, policy-as-code automation, and service readiness gates into the technology delivery lifecycle. By integrating governance into engineering and operational workflows, this role ensures that every change entering production meets defined criteria for testing, rollback readiness, security validation, and operational preparedness.
Key Responsibilities- Change Governance & Policy Ownership:
Own and evolve the enterprise change management policy and supporting standards. - Define and govern risk-based change classifications (Standard, Normal, Emergency) aligned with regulatory and industry expectations.
- Ensure every change to production is authorized, tested, validated, and evidenced in accordance with policy.
- Maintain alignment with ITIL, GRC, and regulatory frameworks applicable to Securian’s environment.
- Leadership & Organization:
Lead the Change Enablement and Release team, focused on service governance functions. - Foster a culture of accountability, empowerment, and professional growth within the team.
- Policy-as-Code & Continuous Compliance:
Partner with Platform & Reliability Engineering to implement automated guardrails that enforce policy-as-code across CI/CD pipelines. - Define control evidence requirements for testing, approvals, rollback, and post-change verification.
- Govern the integration of change metrics, control data, and approval evidence within Service Now and related systems.
- Ensure real-time visibility of change posture, compliance, and risk exposure across production environments.
- Release Readiness & Service Validation:
Govern the release readiness process for all critical deployments. - Define and enforce Go/No-Go criteria — including validation of testing, observability instrumentation, rollback plans, and capacity readiness.
- Ensure operational validation across observability, performance, and failover preparedness before changes are deployed.
- Facilitate Service Readiness Reviews (SRR) and Operational Readiness Assessments (ORA) for all major initiatives.
- Change Advisory & Risk Governance:
Modernize the Change Advisory Board (CAB) process, emphasizing risk intelligence, automation evidence, and cross-domain visibility. - Govern emergency change protocols and ensure 100% post-implementation reviews (PIRs).
- Partner with compliance, risk, and audit teams to ensure continuous control adherence and evidence integrity.
- Report on change success, emergency rates, and compliance health across all domains.
- Metrics, Transparency & Continuous Improvement:
Define and monitor KPIs including Change Success Rate, Change Failure Rate (CFR), Emergency Change Rate, Approval Cycle Time, Evidence Completeness, and Audit Findings Closure. - Leverage analytics from Reliability Insights & Analytics to detect patterns, prevent regressions, and identify improvement opportunities.
- Continuously evolve the change policy and readiness framework based on lessons learned, audit results, and incident correlations.
- Deep understanding of ITIL-based change enablement and risk governance in regulated enterprises.
- Familiarity with policy-as-code concepts,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).