Garry Costin-Davis

I help organisations strengthen technology governance, operational resilience, and digital control environments.
With over a decade of experience across Big 4 consulting and global enterprises, I specialise in IT risk, cloud transformation assurance, SOX and ITGC frameworks, and embedding control into complex service operations. My focus is simple, protect value, meet compliance, enable innovation, and ensure technology risk is understood, not feared, at board level.
I'm especially interested in mission-led organisations, education, and roles with meaningful social impact.

Highlights

Risk, controls & assurance in complex environments

Leadership across IT controls (including SOX/ITGC), audit readiness, and governance, communicating risk clearly and helping teams deliver compliant, reliable services.

SOX / ITGC Governance Assurance

ITGC and Security controls embedded in a cloud migration

SOX compliance stream leadership for ITGC & Security on a Google Cloud Platform migration ~ embedding, assessing and mitigating controls for access, change management, operations and data security.

Cloud Access Change Security

Technology Risk & Digital Assurance

ITGC & SOX governance, operational resilience, cloud risk oversight, digital audit analytics, and enterprise-wide control optimisation aligned to strategic risk and board reporting.

ITGC / SOX Operational Resilience Cloud Risk Digital Audit Board Reporting

Sector direction: education & social impact

I am moving intentionally toward roles where governance and operational reliability support vulnerable communities, particularly in education, charity, and non-profit, while remaining open to high-impact commercial environments.

Education Charity / Non-profit Safeguarding aware

How I work

Calm delivery, high documentation standards, risk based approach, simplification of complex output, and practical problem solving. I value environments that take accountability seriously and support staff to contribute to community impact.

Clarity Reliability Delivery

Current focus

What I am looking for

A role with real world value, ideally in education, charity; or a mission-led organisation where I can support governance, risk, operational coordination, and high-quality delivery.

Where I'll hedge

I am also open to demanding, tech focused roles where CSR and community engagement aren't just marketing and where the organisation makes space for staff volunteering, pro-bono work, or structured community contribution.

If you're hiring for IT Risk Assurance, structured thinking, careful documentation, and delivery discipline in complex settings, you're likely in the right place.