Candescent is a forward-thinking technology company transforming how financial institutions deliver Intelligent Banking experiences. We unite digital banking, account opening, and branch solutions that power and connect digital banking, account opening, and branch solutions—creating seamless engagement across digital, remote, and in-person channels. Our Experience-Led, Intelligence-Driven approach combines human-centered design with data, automation, and cloud-based innovation. Built on an API-first architecture, our extensible ecosystem enables institutions to adapt quickly, integrate easily, and unlock new opportunities for growth—turning every customer interaction into a moment of clarity, confidence, and connection.
Position Summary
Candescent is seeking an experienced Director of Governance, Risk, Compliance & Vendor Management to lead the organization's audit, compliance, third-party risk management (TPRM), and vendor governance functions. This leader will maintain a strong control environment that supports Candescent's banking and financial services customers while ensuring compliance with regulatory, contractual, and industry security requirements. The Director will lead a team responsible for external audits, customer compliance activities, third-party risk assessments, and vendor oversight, with particular focus on SOC 2 Type II, PCI DSS, and banking regulatory expectations.
Key Responsibilities
- Lead Candescent's Governance, Risk, Compliance, Third-Party Risk Management, and Vendor Management programs.
- Manage and oversee SOC 2 Type II, PCI DSS, customer audits, and banking regulatory examinations.
- Ensure compliance with applicable banking, security, and privacy requirements, including FFIEC guidance, GLBA, and PCI DSS.
- Direct the vendor lifecycle, including onboarding, risk assessments, ongoing monitoring, contract reviews, and offboarding.
- Partner with Legal, Procurement, Technology, Product, and Operations teams to manage risk and compliance obligations.
- Develop executive reporting on audit readiness, compliance status, vendor risk, and remediation activities.
- Lead customer compliance engagements, due diligence reviews, and security assurance activities.
- Build, mentor, and develop a high-performing team while driving process improvements and operational efficiency.
Required Qualifications
- Bachelor's degree in Information Systems, Cybersecurity, Business, Finance, Accounting, or a related field.
- 10+ years of experience in audit, compliance, risk management, vendor management, or information security within banking, fintech, or financial services.
- 5+ years of leadership experience managing professional teams.
- Deep expertise leading SOC 2 Type II and PCI DSS audit programs.
- Strong understanding of US banking regulations and frameworks, including FFIEC and GLBA.
- Experience with third-party risk management and vendor governance programs.
- Proven ability to lead audits, manage remediation efforts, and present results to executive leadership and customers.
Hybrid position
Preferred Qualifications
- CISA, CISM, CRISC, CIA, CTPRP, or equivalent certifications.
- Experience supporting cloud-based financial technology platforms.
- Experience interacting with banking regulators, customers, and external auditors.
What Success Looks Like
- Successful completion of annual SOC 2 Type II and PCI assessments.
- Strong audit readiness and timely remediation of findings.
- Effective management of third-party and vendor risk.
- Positive customer and regulatory audit outcomes.
- Continued maturation of Candescent's governance and compliance programs.
Candescent offers the opportunity to lead critical governance and compliance functions that protect our customers, strengthen trust, and support the secure delivery of innovative banking technology solutions.
Candescent is the largest non-core digital banking provider. We bring together the transformative technologies that power and connect account opening, digital banking and branch solutions for banks and credit unions of all sizes on any core.
#J-18808-LjbffrDirector, Governance, Risk & Compliance in atlanta at Unknown Company
This position is listed as contract and able to be worked remotely.