Lead GRC & Security Governance
Is this the right opportunity for you?
Explore more jobs, compare advertised salaries and see which skills employers want.
Explore careersSearch for a different role
Skills
Description
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Lead GRC & Security Governance based in the United States.
Overview
We are seeking an experienced Lead GRC & Security Governance professional to build and lead the governance frameworks that strengthen technology risk management, security assurance, and operational resilience. In this senior individual contributor role, you will establish practical, scalable systems that help Security, IT, Engineering, and Data teams manage risk, demonstrate control effectiveness, and maintain audit readiness. You will take ownership of technology risk registers, control inventories, compliance programs, and governance processes spanning change management, incident response, and business continuity. Working closely with technical leaders, Legal, Internal Audit, and external assessors, you will translate complex requirements into clear responsibilities, measurable controls, and actionable risk decisions. You will also explore AI and automation to streamline governance workflows while maintaining appropriate oversight and data protection. This is an opportunity to build a new governance function within a growing, publicly traded financial technology environment. The ideal candidate combines strong technical understanding, sound risk judgment, and the confidence to influence stakeholders while balancing business agility with effective controls.
Accountabilities
- Build and lead the technology governance program: Establish and operate a comprehensive governance framework covering technology and cybersecurity risk, IT controls, change management, incident management, business continuity, and security policies.
- Develop and maintain the control inventory: Define and manage a centralized inventory of technology controls, including control owners, evidence requirements, operating schedules, exception processes, and escalation pathways.
- Own audit readiness and assurance: Lead technology assurance activities across SOC 2, SOX IT General Controls (ITGC), PCI, and other applicable compliance frameworks. Coordinate evidence collection, support control testing, identify deficiencies, and maintain accountability for remediation through resolution.
- Manage technology and cybersecurity risks: Own the technology and cyber risk register, assess risk exposure and materiality, document control exceptions, and communicate significant or persistent risks to the appropriate decision-makers with clear context and recommendations.
- Strengthen control accountability: Establish clear expectations for control owners and technical teams while ensuring remediation responsibilities remain with the teams best positioned to address identified issues.
- Govern change and incident management: Define practical policies and oversight processes for technology changes, security incidents, and operational disruptions, ensuring procedures are consistently followed, tested, and improved.
- Oversee business continuity and resilience: Establish and maintain governance requirements that support operational continuity, preparedness, and effective recovery from technology or business disruptions.
- Leverage AI and automation: Identify and implement appropriate AI-assisted and automated workflows for evidence analysis, control mapping, policy maintenance, risk reporting, audit preparation, and remediation tracking, with suitable human review and data safeguards.
- Partner across technical and business functions: Collaborate with Security, IT, Engineering, Site Reliability Engineering (SRE), Data, Compliance, Legal, Internal Audit, and external assessors to align governance requirements with operational realities.
- Escalate material risks effectively: Exercise independent judgment to identify significant control weaknesses, challenge insufficient responses, and ensure material risks receive appropriate visibility and timely decisions, even when stakeholders disagree.
- Build scalable governance processes: Develop clear documentation, reporting structures, decision records, action plans, and performance indicators that support accountability and adapt as the organization grows.
- Drive continuous improvement: Evaluate the effectiveness of governance processes, incorporate stakeholder feedback, and refine the operating model to ensure controls remain practical, proportionate, and sustainable.
Requirements
- Extensive technology experience: At least eight years of relevant technology experience, including substantial responsibility for security governance, technology risk management, security assurance, or related disciplines.
- Proven audit leadership: Direct experience leading a SOC 2 Type II, ISO 27001, or equivalent audit through a successful outcome, rather than solely supporting audit preparation or evidence collection.
- Governance program development: Demonstrated experience creating or materially redesigning a governance, risk, or assurance operating model, including defining control frameworks, ownership structures, and accountability mechanisms.
- Strong technical fluency: A solid understanding of modern technology environments, including cloud infrastructure, identity and access management, CI/CD pipelines, source control, endpoints, networks, and data platforms.
- Control design and assessment expertise: The ability to translate ambiguous security or compliance requirements into precise, testable controls, evaluate evidence objectively, and challenge incomplete or insufficient responses.
- Risk management and escalation judgment: Experience assessing risk severity and materiality, managing exceptions, communicating exposure, and escalating significant issues when stakeholders disagree or remediation is delayed.
- Cross-functional leadership and influence: The ability to establish credibility with Engineering, SRE, Security, IT, and Data teams while maintaining accountability for governance outcomes without assuming ownership of technical remediation.
- Audit and legal stakeholder management: Experience working effectively with Internal Audit, Legal, Compliance, security teams, and external auditors or assessors.
- Excellent written communication: Strong documentation and reporting skills, with the ability to turn complex requirements and ambiguous situations into clear decisions, responsibilities, actions, deadlines, and evidence.
- Program management capabilities: Demonstrated ability to organize complex initiatives, coordinate multiple stakeholders, manage competing priorities, and maintain progress toward measurable outcomes.
- Independent ownership and adaptability: A proactive, practical approach to problem-solving, with the confidence to establish new processes, make informed trade-offs, and adapt governance practices as business priorities and requirements evolve.
- Business-oriented governance mindset: The ability to create controls that support operational effectiveness and responsible growth without introducing unnecessary bureaucracy.
Additional experience that would be advantageous:
- Experience with SOX ITGC, PCI DSS, or NIST-based security and risk management programs.
- Familiarity with AI governance, AI-related security controls, or third-party AI risk assessments.
- Experience implementing or managing GRC automation platforms such as Vanta or Drata.
- Experience building governance processes within a fintech, financial services, or other regulated technology environment.
- Experience designing scalable governance frameworks for growing organizations with evolving operational and compliance requirements.
Benefits
- Competitive compensation: Annual base salary ranging from $174,000 to $224,000, with equity opportunities. Actual compensation depends on experience, skills, qualifications, and other relevant factors rather than work location.
- Equity opportunities: The opportunity to receive equity and participate in the long-term value created by the business.
- Remote-first flexibility: Work remotely from anywhere in the United States except Hawaii, with flexible working hours and a virtual-first culture.
- Home office support: Receive a home office stipend to help create a productive and comfortable remote workspace.
- Comprehensive healthcare: Access premium medical, dental, and vision insurance plans.
- Retirement savings: Participate in a 401(k) savings plan with matching contributions.
- Family and caregiver support: Benefit from generous paid parental and caregiver leave.
- Flexible paid time off: Enjoy flexible PTO and generous company holidays, including Juneteenth and a company-wide winter break.
- Financial wellness resources: Access financial advisory services and financial wellness support.
- Professional growth: Work alongside experienced professionals, develop your expertise in technology governance and security assurance, and shape a new function with significant ownership.
- Collaborative culture: Participate in company-wide in-person gatherings once or twice a year, along with virtual events that connect employees with colleagues and leadership.
- Meaningful business impact: Help strengthen the security, resilience, and governance of financial technology products designed to improve access to financial services for everyday Americans.
- Autonomy and influence: Establish foundational governance systems, shape risk management practices, and help technical teams operate with greater confidence as the business scales.
How Jobgether works:
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
Why Apply Through Jobgether?
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1
Get similar jobs in United States by email
We'll email you when new jobs similar to this one appear.
Similar jobs
Explore more remote Lead GRC & Security Governance jobs in United States.
Finding similar jobs…