About the role
Mary Grace is looking for an IT Governance Manager who will help strengthen IT governance, risk management, compliance, and internal controls as we continue to grow our café, bakery, commissary, and Head Office operations. This role will work closely with IT and various business teams to ensure that our technology, systems, processes, and IT projects are properly governed, secure, compliant, and aligned with business needs.
Key responsibilities
- Develop and implement IT governance policies, standards, procedures, and controls.
- Identify, assess, and monitor IT risks and recommend appropriate mitigation plans.
- Establish and monitor IT General Controls (ITGC), including access management, change management, backup and recovery, system operations, and incident management.
- Manage IT audit requirements and coordinate the resolution and closure of audit findings.
- Monitor compliance with company policies, applicable regulations, data privacy, and information security requirements.
- Oversee user access governance, including access approvals, periodic reviews, privileged access, and employee movement/separation controls.
- Establish governance standards for IT projects, system implementations, upgrades, integrations, and major system changes.
- Support IT vendor governance, including due diligence, risk assessment, SLA monitoring, and third-party access controls.
- Support business continuity and disaster recovery planning and testing for critical systems.
- Develop IT governance reports, dashboards, and risk updates for Management.
About you
- Bachelor's degree in Information Technology, Computer Science, Information Systems, Business, or a related field.
- 5–8 years of relevant experience in IT Governance, IT Audit, IT Risk, IT Compliance, IT Controls, or Information Security.
- Strong knowledge of IT General Controls, risk management, access management, change management, and audit processes.
- Experience developing and implementing IT policies, procedures, and control frameworks.
- Experience working with internal and/or external auditors.
- Knowledge of data privacy and information security principles.
- Strong analytical, documentation, communication, and stakeholder management skills.
- Experience in a multi-site, retail, F&B, hospitality, or similarly operational environment is an advantage.
- CISA, CRISC, COBIT, ITIL, ISO 27001, CISSP, or other relevant certifications are an advantage.
About us
Mary Grace is a café, bakery, commissary, and Head Office operations business.