Garry Costin-Davis

I help organisations strengthen technology governance, operational resilience, and digital control environments.
With over a decade of experience across Big 4 consulting, global enterprises, and independent business operations, I specialise in IT risk, cloud transformation assurance, SOX and ITGC frameworks, systems implementation support, and embedding control into complex service operations. My focus is simple: protect value, meet compliance obligations, enable innovation, and ensure technology risk is understood, not feared, at board level.
I'm especially interested in mission-led organisations, education, and roles with meaningful social impact.

Highlights

Risk, controls & assurance in complex environments

Leadership across IT controls (including SOX/ITGC), audit readiness, and governance, communicating risk clearly and helping teams deliver compliant, reliable services.

SOX / ITGC Governance Assurance

ITGC and Security controls embedded in a cloud migration

SOX compliance stream leadership for ITGC & Security on a Google Cloud Platform migration ~ embedding, assessing and mitigating controls for access, change management, operations and data security.

Cloud Access Change Security

Technology Risk & Digital Assurance

ITGC & SOX governance, operational resilience, cloud risk oversight, digital audit analytics, and enterprise-wide control optimisation aligned to strategic risk and board reporting.

ITGC / SOX Operational Resilience Cloud Risk Digital Audit Board Reporting

Sector direction: education & social impact

I am moving intentionally toward roles where governance and operational reliability support vulnerable communities, particularly in education, charity, and non-profit, while remaining open to high-impact commercial environments.

Education Charity / Non-profit Safeguarding aware

How I work

Calm delivery, high documentation standards, risk based approach, simplification of complex output, and practical problem solving. I value environments that take accountability seriously and support staff to contribute to community impact.

Clarity Reliability Delivery

Current focus

What I am looking for

A role with real world value, ideally in education, charity; or a mission-led organisation where I can support governance, risk, operational coordination, and high-quality delivery.

Where I'll hedge

I am also open to demanding, tech focused roles where CSR and community engagement aren't just marketing and where the organisation makes space for staff volunteering, pro-bono work, or structured community contribution.

If you're hiring for IT Risk Assurance, structured thinking, careful documentation, and delivery discipline in complex settings, you're likely in the right place.