Role overview
A senior leadership role reporting to the CISO, owning the security governance, risk, and compliance program within a regulated broker-dealer and embedded fintech environment. The position acts as connective tissue across security, risk, and the executive team, translating deep technical and regulatory risk into business-aligned decisions. It is a builder role focused on maturing frameworks, quantifying enterprise risk, and standing up threat intelligence, incident-response readiness, and third-party due-diligence capabilities.
Responsibilities
- Lead and mature the enterprise GRC program, aligning controls with recognized frameworks such as NIST CSF, NIST 800-53, ISO 27001, SOC 2, and CIS Controls
- Maintain the cybersecurity policy, standard, and procedure library, including annual review cycles, control ownership, exceptions, and waivers
- Operate the information security risk register, conducting risk assessments, defining treatment plans, and tracking residual risk over time
- Ensure compliance with SEC and FINRA obligations such as Regulation S-P (Safeguards & Disposal), Rule 17a-4 recordkeeping, and broader financial-industry security requirements
- Manage external and internal security audits and examinations including SOC 1, SOC 2 Type II, and ISO 27001, coordinating evidence collection and remediation tracking
- Establish control testing and continuous control monitoring, driving remediation of gaps to closure across control owners
- Support cyber threat intelligence, incident-response readiness, and third-party and client cyber due-diligence programs
Requirements
- Significant experience leading security GRC functions within a regulated broker-dealer or comparable financial-services environment
- Deep familiarity with NIST CSF, NIST 800-53, ISO 27001, SOC 2, and CIS Controls
- Working knowledge of SEC, FINRA, and global data-protection regulations such as GDPR, CCPA/CPRA, LGPD, and GLBA
- Demonstrated ability to interface credibly with regulators, auditors, enterprise partners, and executive stakeholders
- Proven track record running risk registers, control testing, and policy lifecycle management
- Strong written and verbal communication skills, with the ability to translate technical risk into clear business decisions
Nice to have
- Experience building threat-intelligence or incident-response programs from earlier stages
- Background coordinating annual security due-diligence reviews with critical partners and vendors
- Comfort operating with autonomy and driving initiatives to completion with minimal supervision
Benefits and work setup
- Compensation package including base, bonus, equity, and 401(k) match, plus heavily subsidized benefits and perks
- Coverage that includes dental, vision, disability, and paid parental leave
- Wellness reimbursement, company-provided phone, and a personal development allowance
- Generous paid time off and observed holidays
Applicants must already hold legal authorization to work in the country where the role is located; visa sponsorship is not currently offered for this position.
#J-18808-LjbffrHead of Security GRC in Location not specified at Unknown Company
This position is listed as full time and onsite.