Unknown Company

Head of Security GRC

Location not specified • Posted 1 weeks ago
Onsite Full Time Management & Operations

Role overview

A senior leadership role reporting to the CISO, owning the security governance, risk, and compliance program within a regulated broker-dealer and embedded fintech environment. The position acts as connective tissue across security, risk, and the executive team, translating deep technical and regulatory risk into business-aligned decisions. It is a builder role focused on maturing frameworks, quantifying enterprise risk, and standing up threat intelligence, incident-response readiness, and third-party due-diligence capabilities.

Responsibilities

  • Lead and mature the enterprise GRC program, aligning controls with recognized frameworks such as NIST CSF, NIST 800-53, ISO 27001, SOC 2, and CIS Controls
  • Maintain the cybersecurity policy, standard, and procedure library, including annual review cycles, control ownership, exceptions, and waivers
  • Operate the information security risk register, conducting risk assessments, defining treatment plans, and tracking residual risk over time
  • Ensure compliance with SEC and FINRA obligations such as Regulation S-P (Safeguards & Disposal), Rule 17a-4 recordkeeping, and broader financial-industry security requirements
  • Manage external and internal security audits and examinations including SOC 1, SOC 2 Type II, and ISO 27001, coordinating evidence collection and remediation tracking
  • Establish control testing and continuous control monitoring, driving remediation of gaps to closure across control owners
  • Support cyber threat intelligence, incident-response readiness, and third-party and client cyber due-diligence programs

Requirements

  • Significant experience leading security GRC functions within a regulated broker-dealer or comparable financial-services environment
  • Deep familiarity with NIST CSF, NIST 800-53, ISO 27001, SOC 2, and CIS Controls
  • Working knowledge of SEC, FINRA, and global data-protection regulations such as GDPR, CCPA/CPRA, LGPD, and GLBA
  • Demonstrated ability to interface credibly with regulators, auditors, enterprise partners, and executive stakeholders
  • Proven track record running risk registers, control testing, and policy lifecycle management
  • Strong written and verbal communication skills, with the ability to translate technical risk into clear business decisions

Nice to have

  • Experience building threat-intelligence or incident-response programs from earlier stages
  • Background coordinating annual security due-diligence reviews with critical partners and vendors
  • Comfort operating with autonomy and driving initiatives to completion with minimal supervision

Benefits and work setup

  • Compensation package including base, bonus, equity, and 401(k) match, plus heavily subsidized benefits and perks
  • Coverage that includes dental, vision, disability, and paid parental leave
  • Wellness reimbursement, company-provided phone, and a personal development allowance
  • Generous paid time off and observed holidays

Applicants must already hold legal authorization to work in the country where the role is located; visa sponsorship is not currently offered for this position.

#J-18808-Ljbffr

Head of Security GRC in Location not specified at Unknown Company

This position is listed as full time and onsite.

Back to Job Search