Lead SANS IT governance, risk and compliance (GRC) practices across digital platforms, ensuring effective risk oversight, audit readiness, and adherence to policies and regulations, enable accountable, risk-aware operations by embedding GRC frameworks into SANS IT processes, managing third-party risks, and providing actionable reporting to the Section Head.
KEY ACCOUNTABILITIES & ACTIVITIES
Governance Framework & Policy Oversight
- Establish, refine, and enforce IT governance frameworks, policies, and controls across the enterprise technology landscape.
- Ensure governance practices align with standards, regulatory requirements, and industry best practices.
- Provide structured reporting and updates to the Section Head on policy adoption and compliance levels.
Enterprise Risk Management & Vulnerability Oversight
- Lead enterprise-level IT risk assessments and maintain a centralized risk register, ensuring ownership and remediation timelines are defined.
- Prioritize vulnerabilities and risks based on business impact, integrating with architecture, infrastructure, and security functions for remediation.
- Drive adoption of a risk-aware culture across IT teams through awareness and practical guidelines.
Compliance Management & Audit Readiness
- Oversee compliance frameworks (ISO, NCA, GDPR, etc.) and ensure digital platforms are audit ready.
- Lead control testing, gap assessments, and remediation planning; coordinate timely responses to internal/external audits.
- Ensure that evidence repositories are well-maintained for efficient audit responses.
Third-party & Vendor Risk Governance
- Lead assessments of vendor GRC maturity, embed risk-based clauses, and monitor compliance.
- Ensure vendors demonstrate compliance through SLAs, certifications, or independent audits.
Performance Reporting, Metrics & Continuous Improvement
- Define and maintain GRC dashboards covering risk posture, audit findings, remediation timelines, and compliance status.
- Provide regular structured updates to the Section Head and governance committees.
- Continuously uplift GRC practices through benchmarking, maturity assessments, and lessons learned.
Policies, Processes and Procedures
- Support in monitoring day-to-day activities to ensure compliance with stipulated policies and procedures
- Contribute to the identification of opportunities for continuous improvement of systems and processes taking into account leading practices, changes in business environment, cost reduction and productivity improvement
People Management
- Actively participate in on-the-job training, mentoring and coaching of subordinates
- Provide clear direction, prioritize tasks, assign and delegate responsibility and monitor the workflow
- Promote a high-performance working environment embracing SANS’s values
QUALIFICATIONS / REQUIREMENTS
Knowledge and Experience
- Minimum 6 years of experience in a related field or equivalent is required.
Education and Certifications
- A bachelor’s degree in Engineering, Computer Science, Information Technology (IT), or equivalent is required.
- Preferrable qualifications include certifications in audit and assurance, as well as expertise in risk management, KPI-P, compliance, and internal control frameworks.