Manager, GRC-A (Information Security Risk)

Sas

Cary (NC)

Hybrid

USD 140,000 - 180,000

Full time

6 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Comprehensive medical, prescription, –
401k plan
Tuition Assistance Program
Paid holidays
Winter Wellness Break
Volunteer Time Off
Parental leave
Generous childcare benefits

Job summary

SAS in Cary, North Carolina, seeks a hands-on Manager, Information Security Risk – Governance, Risk, Compliance – Audit. You will lead the risk program across SAS and third parties, mentor a team, and drive risk analysis, remediation, and continuous improvement in a dynamic, hybrid environment.

This role requires deep knowledge of NIST CSF, ERM, and regulatory requirements, with strong leadership and collaboration across business, technology, and procurement.

Qualifications

  • Bachelor’s or Master’s degree in a related field.
  • 4–8 years of demonstrated success in risk management.
  • Strong management and leadership skills.
  • Familiarity with GRC tooling such as ServiceNow IRM.
  • Ability to manage multiple projects and train staff.

Responsibilities

  • Lead and mature information security risk management programs and third-party risk assessments.
  • Partner with stakeholders to identify, assess, monitor, and manage information security risks.
  • Monitor regulatory and industry requirements and integrate them into program practices.
  • Perform risk assessments and document threats, vulnerabilities, controls, and residual risks.
  • Oversee risk treatment plans with clear ownership and timely remediation.
  • Define and communicate risk metrics, KRIs, dashboards, and senior leadership reports.

Skills

Information security
Risk management
GRC
Leadership
Regulatory awareness

Education

Bachelor’s or Master’s degree in Business, IT, Cybersecurity, Project Management or related field

Tools

ServiceNowIRM

Job description

Job Description

Manager,Information Security Risk -Governance, Risk, Compliance – Audit - Hybrid, Cary, North Carolina

We’re a leader in data and AI. Through our software and services, we inspire customers around the world to transform data into intelligence - and questions into answers.

If you're looking for a dynamic, fulfilling career with flexibility and a world-class employee experience, you'll find it here. We're recognized around the world for our inclusive, meaningful culture and innovative technologies by organizations like Fast Company, Forbes, Newsweek and more.

About the job

The Manager, Governance, Risk, Compliance – Audit (GRC-A) is a hands on management role combiningtechnical risk managementexpertisewith people leadership, overseeing a team that evaluatesinformation security andcybersecurity risksacrossSAS and ourthird-parties.As a working manager, the positionisactively involved inrisk analysisand problem-solving while also guiding program execution, stakeholder engagement, and continuous improvement efforts.

The Governance, Risk, Compliance - Audit team provides independent assessment and advisory services,facilitatescompliance with regulatory and security requirements, performs assurance activities, and delivers information that enables informed business and risk decisions. Through collaboration, innovation, and practical risk management, the team helps protect SAS while enabling business success.

As a Manager,Information Security Risk -Governance, Risk, Compliance – Audit you will:

  • Lead and continuously mature the information security risk management andthird-partysecurity risk assessment programs, providing direction to team members while driving initiatives that enhance SAS's risk managementprogram.

  • Partner with business, technology, and service provider stakeholders toidentify, assess,monitor, and manage information securityrisks.

  • Monitor evolving regulatory and industry requirements affecting cybersecurity, technology risk, privacy, operational resilience, and third-party risk management, and incorporate applicable requirements into program practices.

InternalInformationSecurity Risk

  • Perform information security risk assessments and document threats, vulnerabilities, controls, and residual risks across internal systems, cloud services, third-party vendors, and enterprise initiatives.

  • Oversee risk assessment activities and risk treatment plans, ensuring clear ownership,timelyremediation, and accountability for mitigation actions.

  • Maintain and enhance risk management methodologies, risk scoring models, governance processes, and therisk register to support consistent and effective risk decision-making.

  • Define, track, and communicate cybersecurity risk metrics, key risk indicators (KRIs), dashboards, and assessment results through recurring reportingfor senior leadership.

Third-PartyRisk Management (TPRM) –InformationSecurity

  • Managethethird-partysecurity risk assessment team, providing guidance on complex assessments and ensuring cybersecurity, privacy, compliance, and operational risks are consistentlyidentified, evaluated, reported, and managed.

  • Collaborate with Procurement, Legal, and Third-Party Risk Management (TPRM) stakeholders to integrate security and compliance requirements throughout vendor onboarding, contracting, and ongoing oversight processes.

  • Define, track, and communicate third-party security risk metrics, key risk indicators (KRIs), dashboards, and assessment results through recurring reporting for seniorleadership.Embracecuriosity, passion,authenticityand accountability. These are our values and influence everything we do.

Required qualifications

  • Bachelor'sorMaster’s degree in Business, IT, Cybersecurity, ProjectManagementor related field.

  • Typically requires 4-8 years ofdemonstratedsuccess performing riskmanagement.Experience in a regulated (pharmaceutical, banking, insurance, government) industry (may be concurrent with the above functionalexperience).

  • Demonstrated strong management and leadership skills.

  • Excellent awareness ofGRCtooling, such as ServiceNowIRM

  • Excellent ability to handle multiple projects at the same time.

  • Excellent ability to supervise and train employees with varying skill sets in a high-pressure environment.

  • Excellent verbal, written, and interpersonal skills.

  • Demonstrated ability to solve complex problems.

  • Equivalentcombination of related education, training and experience may be considered in place of the above qualifications.

  • Deep understanding of information security risk frameworks (NIST CSF, CRI Profile, PCI DSS, CIS Controls, etc.) and enterprise risk management principles, with practical experience applying them across systems, processes, and third-party vendors.

  • Ability to lead projects from start to finish, working independently, escalating issues, asappropriateand being flexible, when needed.

Additionalcompetencies,knowledgeand skills

  • Strategic Planning-Obtains information andidentifieskey issues and relationships relevant to achieving a long-range goal; committing to a course of action toaccomplisha long-range goal after developing alternatives based on logical assumptions, facts, available resources, constraints, and organizational values.

  • Leading Change-Drives organizational and cultural changes needed to achieve strategicobjectives; catalyzingnew approachesto improve results by transforming organizational culture, systems, or products/services; helping others overcome resistance to change

  • Global Perspective-Demonstrates awareness of and sensitivity to the international market, cultural, technological, political, and legal factors that impact individual and work group priorities and results; leveraging own understanding of the organization’s global strategy, global business trends, and regional differences to enhance individual and work group results.

  • Ability to interview and manage staff, providingappropriate trainingand guidance as well as ongoing performance management.

  • Strong management, leadership, and executive presentation skills.

  • Experience applying enterprise risk management (ERM) principles and methodologies to identify, assess, prioritize, and communicate technology, cybersecurity, operational, or third-party risks.

  • Ability to build strong partnerships with security and technology teams across the enterprise.

World-class benefits

Highlights include...

  • Comprehensive medical, prescription, dental and vision plans.
  • Medical plan options include:
    • PPO with low annual deductible and copays.
    • HDHP combined with a health savings account with a contribution from SAS (no access to on-site health care center).
  • Onsite Health Care Center (HQ) that’s free to employees and family members enrolled in the PPO plan. There's a pharmacy too! Not local to HQ? The pharmacy will ship prescriptions for no additional charge!
  • An industry-leading 401k plan.
  • Tuition Assistance Program and programs and resources to support your development
  • Generous time away including vacation time, a variety of paid holidays, and our much-loved U.S. Winter Wellness Break between December 25 and January 1.
  • Volunteer Time Off, parental leave and unlimited paid sick days.
  • Generous childcare benefits for all full-time employees.

You are welcome here.

At SAS, it’s not about fitting into our culture – it’s about adding to it. We believe our people make the difference. Our inclusive workforce brings together unique talents and inspires teams to create amazing software that reflects the diversity of our users and customers.

Additional Information:

To qualify, applicants must be legally authorized to work in the United States, and should not require, now or in the future, sponsorship for employment visa status. SAS is an equal opportunity employer. All qualified applicants are considered for employment without regard to any characteristic protected by law. Read more: Know Your Rights.

Resumes may be considered in the order they are received. SAS employees performing certain job functions may require access to technology or software subject to export or import regulations. To comply with these regulations, SAS may obtain nationality or citizenship information from applicants for employment. SAS collects this information solely for trade law compliance purposes and does not use it to discriminate unfairly in the hiring process.

SAS only sends emails from verified “sas.com” email addresses and never asks for sensitive, personal information or money. If you have any doubts about the authenticity of any type of communication from, or on behalf of SAS, please contact Recruiting​support@sas.com.

Let's stay in touch! Join our Talent Community to stay up to date on company news, job updates and more.

#SAS

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr Application Security Architect
Sr Application Security Architect

Sas • Cary (NC)

On-site
USD 140,000 - 210,000
Comprehensive medical, prescription, 

401k plan
Tuition Assistance Program
+1
Manager, Software Development
Manager, Software Development

Sas • Cary (NC)

On-site
USD 140,000 - 190,000
Comprehensive medical/dental/vision
401k plan
Tuition assistance
+1
Security Officer (SAS Cary Campus) Full Benefits, 3 weeks PTO
Security Officer (SAS Cary Campus) Full Benefits, 3 weeks PTO

Sas • Cary (NC)

On-site
USD 58,000 - 85,000
Onsite Health Care Center
Tuition Assistance Program
Generous vacation and holidays
+1
Sr Program Manager, Continuous Monitoring
Sr Program Manager, Continuous Monitoring

SAS • Cary (NC)

Hybrid
USD 120,000 - 160,000
Health benefits
401k plan
Tuition assistance
+3
AI/Model Security Architect
AI/Model Security Architect

Sas • Cary (NC)

Hybrid
USD 150,000 - 210,000
Comprehensive benefits
401k plan
Tuition assistance
+4
Legal Counsel
Legal Counsel

SAS • Cary (NC)

On-site
USD 120,000 - 190,000
Comprehensive medical plans
401k plan
Tuition assistance
+5
Senior Forward Deployed Industry Consultant, Pharma
Senior Forward Deployed Industry Consultant, Pharma

SAS • Trenton (NJ)

On-site
USD 136,948 - 167,380
Comprehensive medical, prescription, dental and vision plans
401k plan with competitive contributions
Tuition Assistance Program
+2
Software Development Manager, SAS Developer Portal
Software Development Manager, SAS Developer Portal

Sas • Cary (NC)

Hybrid
USD 140,000 - 180,000
Medical plan
401k plan
Paid holidays
+2
C Software Developer (Emerging Careers)
C Software Developer (Emerging Careers)

SAS • Cary (NC)

Hybrid
USD 95,000 - 135,000
Comprehensive medical, prescription, d
Dental & vision plans
Onsite Health Care Center
+6
Senior SDET: Remote/Hybrid, Build Scalable Test Frameworks
Senior SDET: Remote/Hybrid, Build Scalable Test Frameworks

SAS • Cary (NC)

On-site