SAP Security and GRC Manager / Engineering Manager II Our Deloitte Cyber team helps organizations address cybersecurity challenges across complex technology environments. Join the team to deliver ...
SAP Security and GRC Manager / Engineering Manager II Our Deloitte Cyber team helps organizations address cybersecurity challenges across complex technology environments. Join the team to deliver ...
Cybersecurity Professional
Raleigh, NC · On-site
... GRC) metrics. • Examines design and operational effectiveness of security controls. Coordinates audit engagements led by Internal Audit, Regulator, or external audit firm. • Supports assessment ...
Cybersecurity Professional
Raleigh, NC · On-site
... GRC) metrics. • Examines design and operational effectiveness of security controls. Coordinates audit engagements led by Internal Audit, Regulator, or external audit firm. • Supports assessment ...
Cybersecurity Professional
Raleigh, NC · On-site
Cybersecurity Professional - Raleigh, NC; Reading, PA; Tanner, AL Primary Responsibilities for the ... Routinely publishes Governance, Risk, and Compliance (GRC) metrics. * Examines design and ...
Cybersecurity Professional
Raleigh, NC · On-site
Cybersecurity Professional - Raleigh, NC; Reading, PA; Tanner, AL Primary Responsibilities for the ... Routinely publishes Governance, Risk, and Compliance (GRC) metrics. * Examines design and ...
Cybersecurity Professional - Raleigh, NC; Reading, PA; Tanner, AL Primary Responsibilities for the ... Routinely publishes Governance, Risk, and Compliance (GRC) metrics. * Examines design and ...
Cybersecurity Professional - Raleigh, NC; Reading, PA; Tanner, AL Primary Responsibilities for the ... Routinely publishes Governance, Risk, and Compliance (GRC) metrics. * Examines design and ...
... GRC) team. The ideal candidate will focus on Third-Party (TP) Cybersecurity & Risk Management. In ... this role, you will conduct cybersecurity and risk management activities focused on third-party ...
... GRC) team. The ideal candidate will focus on Third-Party (TP) Cybersecurity & Risk Management. In ... this role, you will conduct cybersecurity and risk management activities focused on third-party ...
Cyber Security Engineering, Sr Staff Engineer - 17316
Morrisville, NC · On-site
$161K/yr
Partnering with GRC, audit, and compliance teams to ensure identity and secrets controls align with ... Minimum of 5 years' experience in cybersecurity, identity and access management or related field ...
Cyber Security Engineering, Sr Staff Engineer - 17316
Morrisville, NC · On-site
$161K/yr
Partnering with GRC, audit, and compliance teams to ensure identity and secrets controls align with ... Minimum of 5 years' experience in cybersecurity, identity and access management or related field ...
Drive timely identification, escalation, and resolution of cybersecurity risks and issues across ... Deep, hands-on knowledge of GRC disciplines across risk management, compliance, and control ...
Drive timely identification, escalation, and resolution of cybersecurity risks and issues across ... Deep, hands-on knowledge of GRC disciplines across risk management, compliance, and control ...
Drive timely identification, escalation, and resolution of cybersecurity risks and issues across ... Deep, hands-on knowledge of GRC disciplines across risk management, compliance, and control ...
Drive timely identification, escalation, and resolution of cybersecurity risks and issues across ... Deep, hands-on knowledge of GRC disciplines across risk management, compliance, and control ...
Drivetimelyidentification, escalation, and resolution of cybersecurity risks and issues across the ... Deep, hands-on knowledge of GRC disciplines across risk management, compliance, and control ...
Drivetimelyidentification, escalation, and resolution of cybersecurity risks and issues across the ... Deep, hands-on knowledge of GRC disciplines across risk management, compliance, and control ...
Drivetimelyidentification, escalation, and resolution of cybersecurity risks and issues across the ... Deep, hands-on knowledge of GRC disciplines across risk management, compliance, and control ...
Drivetimelyidentification, escalation, and resolution of cybersecurity risks and issues across the ... Deep, hands-on knowledge of GRC disciplines across risk management, compliance, and control ...
Collaborate with cybersecurity analysts, engineers, and stakeholders to translate business needs ... Experience with Microsoft Power Tools, GRC tools, Databricks, Splunk, SharePoint, ServiceNow ticket ...
Collaborate with cybersecurity analysts, engineers, and stakeholders to translate business needs ... Experience with Microsoft Power Tools, GRC tools, Databricks, Splunk, SharePoint, ServiceNow ticket ...
Customer Success Specialist
Durham, NC · On-site
Over the years, ACA has grown both organically and by acquisition to expand our GRC business and technology solutions. Our services now include GIPS standards verification, cybersecurity and ...
Customer Success Specialist
Durham, NC · On-site
Over the years, ACA has grown both organically and by acquisition to expand our GRC business and technology solutions. Our services now include GIPS standards verification, cybersecurity and ...
Over the years, ACA has grown both organically and by acquisition to expand our GRC business and technology solutions. Our services now include GIPS standards verification, cybersecurity and ...
Over the years, ACA has grown both organically and by acquisition to expand our GRC business and technology solutions. Our services now include GIPS standards verification, cybersecurity and ...
ServiceNow SecOps Technical Consultant - Remote / Telecommute
Cary, NC · Remote
$57 - $62/hr
Collaborate with Cyber Security, SOC, GRC, Infrastructure, and Operations teams to implement security use cases. * Support threat intelligence ingestion, enrichment, and correlation activities.
New
Quick apply
ServiceNow SecOps Technical Consultant - Remote / Telecommute
Cary, NC · Remote
$57 - $62/hr
Collaborate with Cyber Security, SOC, GRC, Infrastructure, and Operations teams to implement security use cases. * Support threat intelligence ingestion, enrichment, and correlation activities.
New
Sr Program Manager, Continuous Monitoring
$108K - $109K/yr
Bachelor's degree in computer science, information systems, risk management, cybersecurity ... Experience using GRC platforms, vulnerability management tools, ticketing systems, evidence ...
Sr Program Manager, Continuous Monitoring
$108K - $109K/yr
Bachelor's degree in computer science, information systems, risk management, cybersecurity ... Experience using GRC platforms, vulnerability management tools, ticketing systems, evidence ...
Sr Program Manager, Continuous Monitoring
Cary, NC · On-site
$108K - $109K/yr
Bachelor's degree in computer science, information systems, risk management, cybersecurity ... Experience using GRC platforms, vulnerability management tools, ticketing systems, evidence ...
Sr Program Manager, Continuous Monitoring
Cary, NC · On-site
$108K - $109K/yr
Bachelor's degree in computer science, information systems, risk management, cybersecurity ... Experience using GRC platforms, vulnerability management tools, ticketing systems, evidence ...
... overall cyber security-related experience. * Ability to manage responsibility for security ... Proficiency in utilizing Governance, Risk, and Compliance (GRC) tools for managing Assessment ...
... overall cyber security-related experience. * Ability to manage responsibility for security ... Proficiency in utilizing Governance, Risk, and Compliance (GRC) tools for managing Assessment ...
... overall cybersecurity-related experience. * Ability to manage responsibility for security ... Demonstrated proficiency in utilizing Governance, Risk, and Compliance (GRC) tools for managing ...
... overall cybersecurity-related experience. * Ability to manage responsibility for security ... Demonstrated proficiency in utilizing Governance, Risk, and Compliance (GRC) tools for managing ...
Experience with governance, risk, and compliance (GRC) programs, risk management, control testing, or compliance strategy * Experience with data protection laws or online safety regulations such as ...
Experience with governance, risk, and compliance (GRC) programs, risk management, control testing, or compliance strategy * Experience with data protection laws or online safety regulations such as ...
... cybersecurity. * Hands-on experience with ISO certification programs, audit coordination, and compliance operations . * Familiarity with GRC tools, policy governance processes, and audit evidence ...
... cybersecurity. * Hands-on experience with ISO certification programs, audit coordination, and compliance operations . * Familiarity with GRC tools, policy governance processes, and audit evidence ...
Cyber Security Grc information
See Raleigh, NC salary details
$39.4K - $51.7K
0% of jobs
$51.7K - $64K
0% of jobs
$64K - $76.4K
4% of jobs
$76.4K - $88.7K
9% of jobs
$100.5K is the 25th percentile. Wages below this are outliers.
$88.7K - $101K
13% of jobs
$101K - $113.3K
20% of jobs
The median wage is $116.6K / yr.
$113.3K - $125.7K
16% of jobs
$135.3K is the 75th percentile. Wages above this are outliers.
$125.7K - $138K
17% of jobs
$138K - $150.3K
12% of jobs
$150.3K - $162.6K
6% of jobs
$162.6K - $175K
3% of jobs
$39.4K
$119.5K
$175K
How much do cyber security grc jobs pay per year?
Is cyber security GRC a good job?
What are some common challenges faced by Cyber Security GRC professionals, and how do they typically overcome them?
Cyber Security GRC professionals often face the challenge of keeping up with evolving regulations, adapting controls for new technologies, and coordinating between security teams and business units. To overcome these challenges, professionals stay current with industry standards, participate in ongoing training, and actively communicate policy changes and risk assessments to stakeholders across the organization. They also leverage robust GRC tools to streamline compliance processes and documentation. Working collaboratively with IT, legal, and compliance teams allows them to better identify risks and implement effective, practical security controls. This approach ensures a well-integrated and proactive risk management posture for the organization.
What is a Cyber Security GRC?
A Cyber Security GRC (Governance, Risk, and Compliance) job focuses on ensuring an organization's security policies, risk management strategies, and regulatory compliance. Professionals in this role develop and enforce security policies, assess risks, and ensure adherence to industry regulations like GDPR, HIPAA, or ISO 27001. They collaborate with different teams to mitigate cybersecurity threats while aligning security practices with business goals. This role is critical for maintaining an organization's security posture and reducing potential risks.
Is cyber security GRC in high demand?
What are the key skills and qualifications needed to thrive in the Cyber Security GRC position?
To thrive as a Cyber Security GRC professional, a solid understanding of information security frameworks, risk management, and regulatory compliance is essential, often supported by a degree in information security or a related field. Familiarity with GRC platforms (such as Archer, ServiceNow, or LogicGate), and certifications like CISSP, CISM, or CRISC, are highly valued. Excellent analytical skills, attention to detail, and the ability to communicate complex risks to non-technical stakeholders are critical soft skills. These capabilities ensure organizations remain secure, compliant, and able to effectively manage evolving cyber risks.

Other
Re-posted 8 days ago
Deloitte rating
8.2
Based on 92 frontline employees who took The Breakroom Quiz
46th of 150 rated financial services
Job description
SAP Security and GRC Manager / Engineering Manager II
Our Deloitte Cyber team helps organizations address cybersecurity challenges across complex technology environments. Join the team to deliver solutions that help clients navigate evolving threats, strengthen resilience, and support secure business transformation. In this role, you will help organizations manage SAP security and governance, risk, and compliance requirements across implementation and transformation programs.
Recruiting for this role ends on 12/31/2026.
Work you'll do
As an Engineering Manager II on the Enterprise Security team, you will be responsible for supporting SAP security and GRC implementations, assessments, and transformation initiatives across client environments.
- Lead SAP ECC and SAP S/4HANA security assessments, design, and implementation activities across complex business and technology environments
- Design, build, test, and deploy end-user and IT support security roles across SAP platforms, including Fiori, Ariba, Integrated Business Planning, Business Technology Platform, and Business Data Cloud
- Configure and implement SAP GRC Access Control capabilities, including Access Risk Analysis, Access Request Management, Emergency Access Management, and Business Role Management
- Support SAP GRC Process Control design and configuration, including controls, risks, subprocesses, organizations, assignments, and continuous control monitoring capabilities
- Manage project workstreams, client stakeholders, and delivery teams while providing recommendations on SAP security role design, segregation of duties, vulnerability findings, and regulatory control requirements
A successful candidate would possess these skills:
- Ability to work independently and collaborate as part of a team
- Effective written and verbal communication skills
- Meticulous attention to detail and quality of work product
- Ability to build and sustain professional relationships
- Ability to lead projects or workstreams
- Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
- Strong interpersonal skills and professional demeanor
- Ability to meet deadlines
- Ability to mentor and provide clear guidance to others
The team
Deloitte's Enterprise Security Offering helps clients embed security across digital transformation initiatives by securing core technology environments while enabling business change. The team supports work spanning security architecture, secure development and deployment, cyber cloud capabilities, application security, and security for emerging technologies and connected products.
Qualifications
Required:
- Bachelor's degree
- 8+ years of experience with SAP S/4HANA security and SAP Governance, Risk, and Compliance (GRC) Access Control
- 8+ years of hands-on experience implementing security for SAP S/4HANA, Fiori, Ariba, Integrated Business Planning (IBP), Business Technology Platform (BTP), and Business Data Cloud (BDC), including requirement gathering, security design, and deployment
- Demonstrated delivery of 3+ full-cycle SAP GRC Access Control implementation projects, SAP S/4HANA security implementations, and 2+ SAP GRC Process Control implementations
- 5+ years of experience designing, configuring, and implementing SAP GRC Access Risk Analysis (ARA), Access Request Management (ARM), Emergency Access Management (EAM), and Business Role Management (BRM)
- Ability to travel 50%, on average, based on the work you do and the clients and industries/sectors you serve.
- Limited immigration sponsorship may be available.
Preferred:
- Previous consulting experience
- Professional certification such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), or Certified Information Systems Auditor (CISA)
- Experience with SAP identity and access governance
- Experience with cloud security and cloud migrations
- Experience with SAP business process controls and data protection tools such as NextLabs
- Experience with vulnerability management tools such as Onapsis
The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $134,500 to $265,100.
You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.
Qualifications:SAP Security and GRC Manager / Engineering Manager II
Our Deloitte Cyber team helps organizations address cybersecurity challenges across complex technology environments. Join the team to deliver solutions that help clients navigate evolving threats, strengthen resilience, and support secure business transformation. In this role, you will help organizations manage SAP security and governance, risk, and compliance requirements across implementation and transformation programs.
Recruiting for this role ends on 12/31/2026.
Work you'll do
As an Engineering Manager II on the Enterprise Security team, you will be responsible for supporting SAP security and GRC implementations, assessments, and transformation initiatives across client environments.
- Lead SAP ECC and SAP S/4HANA security assessments, design, and implementation activities across complex business and technology environments
- Design, build, test, and deploy end-user and IT support security roles across SAP platforms, including Fiori, Ariba, Integrated Business Planning, Business Technology Platform, and Business Data Cloud
- Configure and implement SAP GRC Access Control capabilities, including Access Risk Analysis, Access Request Management, Emergency Access Management, and Business Role Management
- Support SAP GRC Process Control design and configuration, including controls, risks, subprocesses, organizations, assignments, and continuous control monitoring capabilities
- Manage project workstreams, client stakeholders, and delivery teams while providing recommendations on SAP security role design, segregation of duties, vulnerability findings, and regulatory control requirements
A successful candidate would possess these skills:
- Ability to work independently and collaborate as part of a team
- Effective written and verbal communication skills
- Meticulous attention to detail and quality of work product
- Ability to build and sustain professional relationships
- Ability to lead projects or workstreams
- Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
- Strong interpersonal skills and professional demeanor
- Ability to meet deadlines
- Ability to mentor and provide clear guidance to others
The team
Deloitte's Enterprise Security Offering helps clients embed security across digital transformation initiatives by securing core technology environments while enabling business change. The team supports work spanning security architecture, secure development and deployment, cyber cloud capabilities, application security, and security for emerging technologies and connected products.
Qualifications
Required:
- Bachelor's degree
- 8+ years of experience with SAP S/4HANA security and SAP Governance, Risk, and Compliance (GRC) Access Control
- 8+ years of hands-on experience implementing security for SAP S/4HANA, Fiori, Ariba, Integrated Business Planning (IBP), Business Technology Platform (BTP), and Business Data Cloud (BDC), including requirement gathering, security design, and deployment
- Demonstrated delivery of 3+ full-cycle SAP GRC Access Control implementation projects, SAP S/4HANA security implementations, and 2+ SAP GRC Process Control implementations
- 5+ years of experience designing, configuring, and implementing SAP GRC Access Risk Analysis (ARA), Access Request Management (ARM), Emergency Access Management (EAM), and Business Role Management (BRM)
- Ability to travel 50%, on average, based on the work you do and the clients and industries/sectors you serve.
- Limited immigration sponsorship may be available.
Preferred:
- Previous consulting experience
- Professional certification such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), or Certified Information Systems Auditor (CISA)
- Experience with SAP identity and access governance
- Experience with cloud security and cloud migrations
- Experience with SAP business process controls and data protection tools such as NextLabs
- Experience with vulnerability management tools such as Onapsis
The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $134,500 to $265,100.
You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.
Education:Bachelor's DegreeEmployment Type: