Remote job
Head of Security GRC
Job details
About this role
Role overview
A senior leadership role reporting to the CISO, owning the security governance, risk, and compliance program within a regulated broker-dealer and embedded fintech environment. The position acts as connective tissue across security, risk, and the executive team, translating deep technical and regulatory risk into business-aligned decisions. It is a builder role focused on maturing frameworks, quantifying enterprise risk, and standing up threat intelligence, incident-response readiness, and third-party due-diligence capabilities.
Responsibilities
- Lead and mature the enterprise GRC program, aligning controls with recognized frameworks such as NIST CSF, NIST 800-53, ISO 27001, SOC 2, and CIS Controls - Maintain the cybersecurity policy, standard, and procedure library, including annual review cycles, control ownership, exceptions, and waivers - Operate the information security risk register, conducting risk assessments, defining treatment plans, and tracking residual risk over time - Ensure compliance with SEC and FINRA obligations such as Regulation S-P (Safeguards & Disposal), Rule 17a-4 recordkeeping, and broader financial-industry security requirements - Manage external and internal security audits and examinations including SOC 1, SOC 2 Type II, and ISO 27001, coordinating evidence collection and remediation tracking - Establish control testing and continuous control monitoring, driving remediation of gaps to closure across control owners - Support cyber threat intelligence, incident-response readiness, and third-party and client cyber due-diligence programs
Requirements
- Significant experience leading security GRC functions within a regulated broker-dealer or comparable financial-services environment - Deep familiarity with NIST CSF, NIST 800-53, ISO 27001, SOC 2, and CIS Controls - Working knowledge of SEC, FINRA, and global data-protection regulations such as GDPR, CCPA/CPRA, LGPD, and GLBA - Demonstrated ability to interface credibly with regulators, auditors, enterprise partners, and executive stakeholders - Proven track record running risk registers, control testing, and policy lifecycle management - Strong written and verbal communication skills, with the ability to translate technical risk into clear business decisions
Nice to have
- Experience building threat-intelligence or incident-response programs from earlier stages - Background coordinating annual security due-diligence reviews with critical partners and vendors - Comfort operating with autonomy and driving initiatives to completion with minimal supervision
Benefits and work setup
- Compensation package including base, bonus, equity, and 401(k) match, plus heavily subsidized benefits and perks - Coverage that includes dental, vision, disability, and paid parental leave - Wellness reimbursement, company-provided phone, and a personal development allowance - Generous paid time off and observed holidays - Applicants must already hold legal authorization to work in the country where the role is located; visa sponsorship is not currently offered for this position