Senior Information Security Risk Manager - GRC & Audit

Sas

Cary (NC)

Hybrid

USD 140,000 - 180,000

Full time

6 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Comprehensive medical, prescription, –
401k plan
Tuition Assistance Program
Paid holidays
Winter Wellness Break
Volunteer Time Off
Parental leave
Generous childcare benefits

Job summary

SAS in Cary, North Carolina, seeks a hands-on Manager, Information Security Risk – Governance, Risk, Compliance – Audit. You will lead the risk program across SAS and third parties, mentor a team, and drive risk analysis, remediation, and continuous improvement in a dynamic, hybrid environment.

This role requires deep knowledge of NIST CSF, ERM, and regulatory requirements, with strong leadership and collaboration across business, technology, and procurement.

Qualifications

  • Bachelor’s or Master’s degree in a related field.
  • 4–8 years of demonstrated success in risk management.
  • Strong management and leadership skills.
  • Familiarity with GRC tooling such as ServiceNow IRM.
  • Ability to manage multiple projects and train staff.

Responsibilities

  • Lead and mature information security risk management programs and third-party risk assessments.
  • Partner with stakeholders to identify, assess, monitor, and manage information security risks.
  • Monitor regulatory and industry requirements and integrate them into program practices.
  • Perform risk assessments and document threats, vulnerabilities, controls, and residual risks.
  • Oversee risk treatment plans with clear ownership and timely remediation.
  • Define and communicate risk metrics, KRIs, dashboards, and senior leadership reports.

Skills

Information security
Risk management
GRC
Leadership
Regulatory awareness

Education

Bachelor’s or Master’s degree in Business, IT, Cybersecurity, Project Management or related field

Tools

ServiceNowIRM

Job description

SAS in Cary, North Carolina, seeks a hands-on Manager, Information Security Risk – Governance, Risk, Compliance – Audit. You will lead the risk program across SAS and third parties, mentor a team, and drive risk analysis, remediation, and continuous improvement in a dynamic, hybrid environment.

This role requires deep knowledge of NIST CSF, ERM, and regulatory requirements, with strong leadership and collaboration across business, technology, and procurement.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Manager, GRC-A (Information Security Risk)
Manager, GRC-A (Information Security Risk)

Sas • Cary (NC)

On-site
USD 140,000 - 180,000
Comprehensive medical, prescription, –
401k plan
Tuition Assistance Program
+5
Senior Program Manager, Continuous Monitoring & Compliance
Senior Program Manager, Continuous Monitoring & Compliance

SAS • Cary (NC)

Hybrid
USD 120,000 - 160,000
Health benefits
401k plan
Tuition assistance
+3
InfoSec GRC Senior Manager: Security Governance & Risk
InfoSec GRC Senior Manager: Security Governance & Risk

BlackBerry Inc. • MacGregor Park (NC)

Hybrid
USD 180,000 - 230,000
Health, Life & Disability
401k with Company Contributions
Employee Stock Purchase Plan
Information Security GRC Lead - Policy & Risk Management
Information Security GRC Lead - Policy & Risk Management

NorthMark Compute & Cloud • Dallas (TX)

On-site
USD 90,000 - 120,000
Lunch stipend
Medical benefits
Dental & Vision
+7
Senior GRC & Security Leader: Risk & Compliance
Senior GRC & Security Leader: Risk & Compliance

ABB Inc. • Cary (NC)

Hybrid
USD 180,000 - 260,000
Health benefits
401k with company match
Paid holidays
Senior Security Compliance & Risk Leader
Senior Security Compliance & Risk Leader

LexisNexis Risk Solutions • Raleigh (NC)

Hybrid
USD 118,300 - 219,800
Remote Security GRC Analyst: Risk & Compliance Lead
Remote Security GRC Analyst: Risk & Compliance Lead

NEPSE Trading • United States

On-site
USD 70,000 - 77,000
Health insurance
401(k) plan with company match
Pension plan
+1
Senior Information Security GRC Analyst
Senior Information Security GRC Analyst

CareSource • United States

On-site
USD 94,000 - 165,000
Bonus potential
Total rewards package
Senior GRC & Information Security Lead
Senior GRC & Information Security Lead

Dorsey & Whitney LLP • Phoenix (AZ)

On-site
USD 140,000 - 180,000
Health benefits
Paid time off
Parental leave
Senior GRC & Privacy Leader: Risk, Compliance & Security
Senior GRC & Privacy Leader: Risk, Compliance & Security

O'Neil Digital Solutions, LLC • Plano (TX)

On-site
USD 150,000 - 190,000