- Lead the organization's governance, risk, and compliance program
- Ensure alignment with SEC/FINRA obligations and global data-protection laws
- Own security metrics and executive or board reporting
- Establish and run cyber threat intelligence capabilities
- Manage internal and external security audits and examinations
- Own and maintain the Incident Response Plan (IRP)
- Oversee vendor risk management processes
- Engage with internal business units, regulators, and external partners on security matters
- Act as subject-matter expert for security compliance
Requirements
- 15+ years of experience in information security, risk management, or cybersecurity roles in a regulated financial-services environment
- Strong understanding of SEC/FINRA regulations applicable to broker-dealers
- Expertise in global data-protection laws (GDPR, CCPA/CPRA, LGPD)
- Hands-on experience leading GRC programs and risk-management initiatives
- Ownership of SOC 1, SOC 2, and ISO 27001 examinations and compliance auditsExperience building security KPIs/KRIs and executive or board-level reporting
- Knowledge of threat intelligence, incident-response planning, and runbook development
- Proven third-party risk management and client/partner security due-diligence
- Excellent communication and leadership skills
Core Competencies
Demonstrates extensive expertise in leading governance, risk, and compliance programs within regulated financial services, ensuring alignment with SEC/FINRA regulations and global data-protection laws. Proven ability to manage security audits, incident response planning, and vendor risk management while effectively communicating with stakeholders.
Highest-signal resume keywords
- Governance, Risk, And Compliance (GRC)
- SEC/FINRA Regulations
- Global Data-Protection Laws
- Incident Response Planning
- Third-Party Risk Management
ATS Optimization Keywords
Hard Skills
- Information Security
- Risk Management
- Cybersecurity
- Security Audits
- Security Metrics
- Threat Intelligence
- KPI/KRI Development
- SOC 1 Compliance
- SOC 2 Compliance
- ISO 27001 Compliance
Soft Skills
- Excellent Communication
- Leadership Skills
Industry Keywords
- Financial Services
- Regulated Environment
- Data-Protection Laws
- Cyber Threat Intelligence
- Vendor Risk Management
Head of Security, GRC in california at Unknown Company
This position is listed as full time and onsite.