Senior Governance, Risk, Compliance - Audit Security Advisor
SASAbout the role
Senior Governance, Risk, Compliance - Audit Security Advisor - Hybrid | Cary, NC
Nice to meet you!
We’re a leader in data and AI. Through our software and services, we inspire customers around the world to transform data into intelligence - and questions into answers.
We’re also a debt-free multi-billion-dollar organization on our path to IPO-readiness. If you're looking for a dynamic, fulfilling career coupled with flexibility and world-class employee experience, you'll find it here.
About the job
The Governance, Risk, Compliance – Audit team within SAS Legal Services is looking for an experienced Senior Security Advisor (Individual Contributor role) with banking and /or financial service experience who is agile, adaptable and efficient to help drive regulatory, contractual, and compliance frameworks related to SAS Managed Cloud Services hosted projects, SAS non-hosted internal projects, and SAS software. This role requires an understanding of information technology and security controls and how they are applied to an organization to meet various certification and regulatory compliance frameworks, primarily PCI-DSS.
As a Senior Governance, Risk, Compliance - Audit Security Advisor, you will:
- Maintain an understanding of compliance requirements, standards, guidance, and interpretations and/or best practices, primarily PCI DSS but also may involve HITRUST, ISO 27001, and SOC 1&2.
- Work with internal SAS teams and external third-party assessment organizations to support and evaluate SAS’ technical and organizational measures according to the requirements of regulatory and compliance frameworks, primarily PCI-DSS, but also may involve ISO 27001, HITRUST, and SOC 1 & 2.
- Collaborate with Information Security, IT, and other teams to define and implement security processes and procedures based on industry standard best practices and relevant compliance requirements, which may include efforts related to:
- Identification of control gaps and deficiencies.
- Development of internal compliance programs to remediate the gaps.
- Communication to applicable staff regarding requirements and procedures.
- Conduct scheduled and ad hoc reviews of applicable environments required to maintain compliance and certifications.
- Assist in the development of documentation and artifacts, in collaboration with other teams, to support program development.
- Respond to security questionnaires from, and interact with, customers and prospects related to SAS’ ability to meet security controls.
- Contribute and assist in preparing and maintaining control documentation (e.g., policies, procedures, and narratives).
- Review hosting, security, and audit contract terms and ensure compliance with current policies and processes.
- Must be a self-starter with the ability to work with little supervision, escalating issues, as appropriate.
- Maintain an ability to be flexible with others, to display tact and diplomacy, and to maintain a high degree of confidentiality and integrity.
- Ability to handle multiple projects at the same time and solve problems.
- Perform other duties, as assigned.
Required Qualifications
- Bachelor’s degree in Business Administration, IT, Computer Science or related field.
- 8+ years of functional experience in project management, management consulting, IT, audit/compliance/risk or related field.
- 8+ years of experience in a regulated industry or working with customers in a regulated industry (i.e. banking, financial services). This experience may be concurrent with the above functional experience.
- Equivalent combination of related education, training and experience may be considered in place of the above qualifications.
- Understanding of best practices for information security and data privacy practices and processes.
- Understanding of regulatory standards and assessments: PCI-DSS, SOC 1, SOC 2, ISO 27001, HIPAA/HITRUST.
- Knowledge of IT or quality auditor procedures and tools (not financial/accounting).
- You’re curious, passionate, authentic and accountable. These are our values and influence everything we do.
Preferred Qualifications
- Auditor or security certification, such as CISA, IIA or CISSP, or equivalent professional certification and/or training.
- Previous Internal Security Assessor (ISA) or Qualified Security Assessor (QSA) program participant
- Management consulting experience.
- SAS software implementation or IT hosting experience.
World-Class Benefits
Highlights inc
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s