Lead GRC & Security Governance
$174k - $224kjobgether
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Lead GRC & Security Governance based in the United States.
Overview
We are seeking an experienced Lead GRC & Security Governance professional to build and lead the governance frameworks that strengthen technology risk management, security assurance, and operational resilience. In this senior individual contributor role, you will establish practical, scalable systems that help Security, IT, Engineering, and Data teams manage risk, demonstrate control effectiveness, and maintain audit readiness. You will take ownership of technology risk registers, control inventories, compliance programs, and governance processes spanning change management, incident response, and business continuity. Working closely with technical leaders, Legal, Internal Audit, and external assessors, you will translate complex requirements into clear responsibilities, measurable controls, and actionable risk decisions. You will also explore AI and automation to streamline governance workflows while maintaining appropriate oversight and data protection. This is an opportunity to build a new governance function within a growing, publicly traded financial technology environment. The ideal candidate combines strong technical understanding, sound risk judgment, and the confidence to influence stakeholders while balancing business agility with effective controls.
Accountabilities
- Build and lead the technology governance program: Establish and operate a comprehensive governance framework covering technology and cybersecurity risk, IT controls, change management, incident management, business continuity, and security policies.
- Develop and maintain the control inventory: Define and manage a centralized inventory of technology controls, including control owners, evidence requirements, operating schedules, exception processes, and escalation pathways.
- Own audit readiness and assurance: Lead technology assurance activities across SOC 2, SOX IT General Controls (ITGC), PCI, and other applicable compliance frameworks. Coordinate evidence collection, support control testing, identify deficiencies, and maintain accountability for remediation through resolution.
- Manage technology and cybersecurity risks: Own the technology and cyber risk register, assess risk exposure and materiality, document control exceptions, and communicate significant or persistent risks to the appropriate decision-makers with clear context and recommendations.
- Strengthen control accountability: Establish clear expectations for control owners and technical teams while ensuring remediation responsibilities remain with the teams best positioned to address identified issues.
- Govern change and incident management: Define practical policies and oversight processes for technology changes, security incidents, and operational disruptions, ensuring procedures are consistently followed, tested, and improved.
- Oversee business continuity and resilience: Establish and maintain governance requirements that support operational continuity, preparedness, and effective recovery from technology or business disruptions.
- Leverage AI and automation: Identify and implement appropriate AI-assisted and automated workflows for evidence analysis, control mapping, policy maintenance, risk reporting, audit preparation, and remediation tracking, with suitable human review and data safeguards.
- Partner across technical and business functions: Collaborate with Security, IT, Engineering, Site Reliability Engineering (SRE), Data, Compliance, Legal, Internal Audit, and external assessors to align governance requirements with operational realities.
- Escalate material risks effectively: Exercise independent judgment to identify significant control weaknesses, challenge insufficient responses, and ensure material risks receive appropriate visibility and timely decisions, even when stakeholders disagree.
- Build scalable governance processes: Develop clear documentation, reporting structures, decision records, action plans, and performance indicators that support accountability and adapt as the organization grows.
- Drive continuous improvement: Evaluate the effectiveness of governance processes, incorporate stakeholder feedback, and refine the operating model to ensure controls remain practical, proportionate, and sustainable.
Requirements
- Extensive technology experience: At least eight years of relevant technology experience, including substantial responsibility for security governance, technology risk management, security assurance, or related disciplines.
- Proven audit leadership: Direct experience leading a SOC 2 Type II, ISO 27001, or equivalent audit through a successful outcome, rather than solely supporting audit preparation or evidence collection.
- Governance program development: Demonstrated experience creating or materially redesigning a governance, risk, or assurance operating model, including defining control frameworks, ownership structures, and accountability mechanisms.
- Strong technical fluency: A solid understanding of modern technology environments, including cloud infrastructure, identity and access management, CI/CD pipelines, source control, endpoints, networks, and data platforms.
- Control design and assessment expertise: The ability to translate ambiguous security or compliance requirements into precise, testable controls, evaluate evidence objectively, and challenge incomplete or insufficient responses.
- Risk management and escalation judgment: Experience assessing risk severity and materiality, managing exceptions, communicating exposure, and escalating significant issues when stakeholders disagree or remediation is delayed.
- Cross-functional leadership and influence: The ability to establish credibility with Engineering, SRE, Security, IT, and Data teams while maintaining accountability for governance outcomes without assuming ownership of technical remediation.
- Audit and legal stakeholder management: Experience working effectively with Internal Audit, Legal, Compliance, security teams, and external auditors or assessors.
- Excellent written communication: Strong documentation and reporting skills, with the ability to turn complex requirements and ambiguous situations into clear decisions, responsibilities, actions, deadlines, and evidence.
- Program management capabilities: Demonstrated ability to organize complex initiatives, coordinate multiple stakeholders, manage competing priorities, and maintain progress toward measurable outcomes.
- Independent ownership and adaptability: A proactive, practical approach to problem-solving, with the confidence to establish new processes, make informed trade-offs, and adapt governance practices as business priorities and requirements evolve.
- Business-oriented governance mindset: The ability to create controls that support operational effectiveness and responsible growth without introducing unnecessary bureaucracy.
Additional experience that would be advantageous:
- Experience with SOX ITGC, PCI DSS, or NIST-based security and risk management programs.
- Familiarity with AI governance, AI-related security controls, or third-party AI risk assessments.
- Experience implementing or managing GRC automation platforms such as Vanta or Drata.
- Experience building governance processes within a fintech, financial services, or other regulated technology environment.
- Experience designing scalable governance frameworks for growing organizations with evolving operational and compliance requirements.
Benefits
- Competitive compensation: Annual base salary ranging from $174,000 to $224,000 , with equity opportunities. Actual compensation depends on experience, skills, qualifications, and other relevant factors rather than work location.
- Equity opportunities: The opportunity to receive equity and participate in the long-term value created by the business.
- Remote-first flexibility: Work remotely from anywhere in the United States except Hawaii, with flexible working hours and a virtual-first culture.
- Home office support: Receive a home office stipend to help create a productive and comfortable remote workspace.
- Comprehensive healthcare: Access premium medical, dental, and vision insurance plans.
- Retirement savings: Participate in a 401(k) savings plan with matching contributions.
- Family and caregiver support: Benefit from generous paid parental and caregiver leave.
- Flexible paid time off: Enjoy flexible PTO and generous company holidays, including Juneteenth and a company-wide winter break.
- Financial wellness resources: Access financial advisory services and financial wellness support.
- Professional growth: Work alongside experienced professionals, develop your expertise in technology governance and security assurance, and shape a new function with significant ownership.
- Collaborative culture: Participate in company-wide in-person gatherings once or twice a year, along with virtual events that connect employees with colleagues and leadership.
- Meaningful business impact: Help strengthen the security, resilience, and governance of financial technology products designed to improve access to financial services for everyday Americans.
- Autonomy and influence: Establish foundational governance systems, shape risk management practices, and help technical teams operate with greater confidence as the business scales.
How Jobgether works:
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
$500 per month
...centric access to liquidity for millions of Americans. As a leading innovator in the U.S. financial services sector, Dave’s... ...partner for those who need it most. We’re hiring a Lead, GRC & Security Governance to build and run the governance systems that keep Dave’s technology...SuggestedFull timeLocal areaImmediate startRemote workWork from homeHome officeFlexible hours- MSIG USA, the US-based subsidiary of MS&AD Insurance Group, is seeking a Lead, Governance, Risk & Compliance (GRC) to mature security governance, risk management, and compliance activities. This role focuses on hands-on execution, regulatory compliance, audits, and policy...Suggested
- ...Emergent Software in Hartford, CT is seeking a senior Cyber Security & GRC Engineer to lead an enterprise-wide security, governance, risk, and compliance program. You will own the Vanta platform, implement NIST CSF 2.0, GDPR, and SOX ITGC controls, and report to executives...Suggested
- ...position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Lead GRC & Security Governance based in the United States. Overview We are seeking an experienced Lead GRC & Security Governance professional to build...SuggestedFull time
- Workday in Pleasanton, CA, is seeking a senior GRC leader to drive governance, risk, and compliance across Security, Cloud Operations, IT, Development, and Compliance. You will assess security gaps, communicate impacts to executives, and drive remediation timelines to...Suggested
- ...Stratolaunch is seeking a dynamic Facility Security Officer (FSO) to implement and maintain a comprehensive security program across our sites. You will drive governance, risk, and compliance efforts aligned with NIST SP 800-171, DoD 5220.22, and NISPOM, while coordinating...For contractors
$180k - $258k
...AI-driven transformation of healthcare payments and eliminate administrative friction for good.Role OverviewWe are seeking a Security GRC Lead to build our first in-house GRC program from the ground up. In this role, you won't just write policies or collect manual screenshots...$114.5k - $188.9k
...capabilities that make Information Security easier to understand, adopt,... ...Information Security governance to improve visibility into security... ...across the enterprise. As the Lead, Information Security Library... ...Governance, Risk, and Compliance (GRC) tooling. Experience...Full timePart timeWork at officeRemote work3 days per week- ...of associates with a strong sense of belonging.Learn more about Inclusion & Diversity at PVH here.bout the Role:The Senior Lead, SAP Security, GRC & Compliance will act as a Subject Matter Expert (SME) for SAP Security & GRC including managing multiple SAP GRC instances...Full timeContract workWork at officeLocal area
- ...labor-intensive work in internal audit and governance: testing whether a company's financial,... .... The Opportunity We’re hiring a Security Lead to build and own the security function... ...handling sensitive data, ideally in fintech, GRC, or another regulated space...
$134k - $154.5k
...Practice - CIS - Cloud, Infrastructure, and Security Services About Cloud Infrastructure &... ...We are seeking an experienced Lead GRC Architect – OneTrust to lead the design,... ...implementation, and enhancement of enterprise Governance, Risk, and Compliance (GRC) capabilities...Temporary work- ...Corporation in Santa Clara, CA seeks a Governance, Risk, and Compliance... ...Certifications Engineer to own end-to-end security certifications (ISO 27001, SOC 2, NIST). You will lead planning, execution, and... ...value 8+ years of governance/ GRC experience, cloud security...
$144.12k - $240.2k
## Lead, System SecurityApply: Remote: Full time: Posted Today: JR... ...of Cybersecurity to own security and security compliance across... ...DO** **Security strategy and governance.** Define Slate's cybersecurity... ...single function such as SOC, GRC, or AppSec.* Hands-on leadership...Permanent employmentFull timeContract workRemote work- ...Anthropic is seeking an experienced US Public Sector Compliance, Security GRC professional to manage ongoing government authorizations. You will translate regulatory requirements into actionable engineering tasks, perform evidence reviews, and maintain alignment with...
- Monarch Money is seeking a Senior Security GRC Analyst to join our Security team. You will own the day-to-day of our compliance program and customer security assurance while maturing the GRC program across the organization. You'll work cross-functionally with People, Legal...Remote job
- Mariner Wealth Advisors seeks a Director, Cyber GRC to lead governance, vendor risk, and security awareness across the organization. You will shape policies, drive risk management efforts, and ensure compliance with SEC, FINRA, and NYDFS requirements while partnering with...Remote job
- Job Summary:The IT Governance, Risk, and Compliance (GRC) Lead Analyst serves as a subject matter expert responsible for leading the design, implementation... ...in IT Governance, Risk, and Compliance, Information Security, IT Audit, or related disciplines.Bachelor's degree in...Full timeWork at office3 days per week
- ...industries ensures our services are customized to meet specific needs. For more details please visit our website Job Description SAP Security & GRC Additional Information All your information will be kept confidential according to EEO guidelines....Permanent employmentFull timeTemporary work
- Whatnot is seeking an experienced Governance, Risk & Compliance Analyst to join its Security GRC team. You will focus on security governance, risk management, and regulatory compliance across cloud environments and partner ecosystems. With 5+ years in a tech startup or...
- ...empowers clients to build a healthier and more financially secure workforce by unifying the benefits ecosystem across... ...! Learn more at careers.alight.com. The AI Enablement & Governance - Security & Controls Lead enables secure, responsible, and scalable AI adoption by...Work at officeLocal areaRemote workWork from homeWorldwideFlexible hours
$143.32k - $273.93k
..., our mission is to empower our members to achieve financial security through highly competitive products, exceptional service and... ...business needs.The OpportunityAs the Data Policy and Regulatory Governance Lead you will lead the development, implementation, and ongoing...Full timeH1bWork at officeRemote workHome officeRelocation packageFlexible hours$120k - $202.5k
Location: Boston/Quincy, Massachusetts, United States Who we are looking for State Street is seeking a Security Platform Governance & Resilience Lead for our Security Platforms team, which is part of the State Street Cyber Fusion Center. The Security Platforms team designs...Full timeTemporary workFlexible hours$135k - $150k
...we looking for? As our Applied AI Lead, you'll be the person who makes AI real... ...the team, and you'll set the standards, governance, and direction for how the organization... ...You'll partner with Legal and IT on the security and data-privacy questions that AI-built...Work at officeImmediate start$156.5k - $191.2k
...Title: CI Team Lead Belong. Connect. Grow. with KBR! KBR’s National Security Solutions team provides high-end engineering and advanced technology solutions to... ...supporting the Chief Information Office (CIO) at a government customer in the Northern Virginia area by assisting...Contract workTemporary workFor contractorsFor subcontractorWork at officeLocal areaWorldwideRelocation packageFlexible hours- ...opportunity, job satisfaction, and job security for our people. Providing superior long... .... This role works closely with the IT Lead - AI Management Lead and all of our business... ...architectures aligned with enterprise governance standards and approved technology stack...
- ...Opportunity A growing SaaS technology organization is seeking a Group Product Manager to help lead the strategy and continued evolution of its Governance, Risk & Compliance (GRC) product portfolio. This is not a traditional execution-focused Product Management role....Full timeLocal area
$160k - $180k
...connect across an organization while respecting enterprise-grade security, governance, permissions, and ethical walls.Innovation is only part of... ....What You’ll Do NetDocuments is seeking an execution-focused Lead Product Manager to drive the build and delivery of our next-...Work at officeImmediate startFlexible hours- ...in your technical career. Join us. As a Lead Architect at JPMorganChase within the Corporate... ...Sector,enterprise architecture and governance function, you will lead architecture... ...delivery speed while strengthening resilience, security, and regulatory readiness.You will shape...
$95.1k - $146.3k
...healthcare and other large enterprises.The Lead OneStream Application Administrator... ...administration, configuration, technical governance, application controls, and technical support... ..., integrations, business rules, security, reporting objects, and production release...Full timeWork experience placementLocal area- ...Any resume submitted outside of an active job posting will not be considered for employment.What You'll Do:The Lead Associate Principal, Security Governance supports the Security Services Department and will regularly liaise with Compliance, Operational Risk Management...Full timeWork experience placementRemote work2 days per week
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Lead GRC & Security Governance. Be the first to apply!






