Lead GRC & Security Governance
$500 per monthDave
Dave vs. Goliath. We’re Dave.
Dave is a financial app on a mission to build products that level the financial playing field. It is redefining the financial landscape by leveraging technology to create an affordable, transparent, and user-centric access to liquidity for millions of Americans. As a leading innovator in the U.S. financial services sector, Dave’s digital financial platform offers products designed to meet the credit needs of those underserved by traditional financial institutions. Dave’s offerings include its flagship ExtraCash product, providing members up to $500 within minutes. The company is on track to launch several new product offerings in 2026, including a Buy Now Pay Later (BNPL) option.
Dave is focused on serving Americans who are financially vulnerable or living paycheck to paycheck. Dave is leading the charge in creating a new era of credit products that prioritizes speed, affordability, and accessibility, making it the go-to financial partner for those who need it most.
We’re hiring a Lead, GRC & Security Governance to build and run the governance systems that keep Dave’s technology organization controlled, resilient, and audit-ready. This is a senior individual contributor role with meaningful ownership across technology risk, controls, assurance, incident governance, and business continuity.
The Opportunity
This is a new role with the opportunity to shape how technology governance works at Dave. You’ll build practical systems that give Security, IT, Engineering, and Data teams clear expectations for managing risk and demonstrating that controls work.
You won’t own technical remediation. You’ll define what good looks like, establish accountability, challenge gaps, and make sure material risks reach the right decision-makers.
What You’ll Build and Own
- Build and operate Dave’s technology governance program across technology and cyber risk, IT controls, change management, incident management, business continuity, and policies.
- Establish and maintain our technology control inventory, with clear owners, evidence requirements, operating cadence, exceptions, and escalation paths.
- Own technology assurance and audit readiness across programs including SOX ITGC, PCI, SOC 2, and other applicable frameworks. Coordinate evidence, support testing, identify gaps, and drive remediation accountability through closure.
- Own the technology and cyber risk register and control exception process. Surface material or sustained risks with clear context and recommendations, including when there’s resistance to escalation.
- Govern change management, incident management, and business continuity so expectations are practical, consistently followed, tested, and improved over time.
- Use AI and automation thoughtfully to improve evidence analysis, control mapping, policy maintenance, risk reporting, audit preparation, and remediation tracking while maintaining appropriate human review and data safeguards.
The Impact
Strong governance makes it easier for Dave to move with confidence. Your work will help teams understand risk, strengthen operational resilience, meet our obligations, and build systems that hold up as the company grows.
What We’re Looking For
- 8+ years of relevant technology experience, including significant ownership in security governance, technology risk, or security assurance.
- You’ve personally led a SOC 2 Type II, ISO 27001, or equivalent audit through a successful result—not simply supported audit preparation.
- You’ve built or materially rebuilt a governance, risk, or assurance operating model rather than only administering an established program.
- Strong technical fluency across environments such as cloud, identity, CI/CD, source control, endpoints, networks, and data platforms. You can turn ambiguous expectations into specific, testable controls and challenge answers that aren’t precise enough.
- Experience owning accountability while technical teams own remediation. You can influence Engineering, SRE, Security, IT, and Data partners without taking their work over.
- Sound judgment around risk and materiality, including demonstrated experience escalating meaningful risks when stakeholders disagreed.
- Experience partnering credibly with Internal Audit and Legal in addition to technical and Security teams.
- Strong written communication and program management skills. You turn ambiguity into clear owners, decisions, actions, dates, and evidence.
Bonus
Experience with SOX ITGC, PCI DSS, NIST-based programs, AI governance or third-party AI risk, and GRC automation platforms such as Vanta or Drata.
What Makes Someone Successful Here
You take responsibility for outcomes, not just deliverables. You’re comfortable defining the system, asking specific questions, and making thoughtful trade-offs between immediate needs and controls that will hold up over time. When something represents meaningful risk, you have the judgment and conviction to make it visible.
You also know governance works best when technical teams see it as useful rather than bureaucratic. You build credibility with partners, seek context before reaching conclusions, and use feedback to improve the system. When priorities or requirements change, you adjust without losing sight of the underlying risk.
What to Expect
You’ll have significant autonomy to shape a new function, but you won’t work in isolation. You’ll partner closely with Security, IT, Engineering, Data, Internal Audit, Legal, Compliance, and external assessors to build a governance model that works in practice—not just on paper.
Why Join Dave
Dave is building financial products that give everyday Americans better access to their money without predatory fees. This role offers the chance to build foundational governance systems at a growing public fintech, influence how technology teams manage risk, and create an operating model that can scale with the business.
Ready to build for the underdog? Reports to: Sr. Director, Security & IT Don’t let imposter syndrome get in the way of an incredible opportunity. We’re looking for people who can help us achieve our mission and vision, not just check off the boxes. If you’re excited about this role, we encourage you to apply. You may just be the right candidate for this or other roles. Why you’ll love working here:At Dave, our people are just as important as our product. Our culture reflects the values that guide who we are, how we work, and what we aspire to be. Daves are member-centric, helpful, transparent, persistent, and better together. We strive to create an environment where all Daves feel valued, heard, and empowered to do their best work. As a virtual-first company, team members can live and work anywhere in the United States, except Hawaii.
A few of our benefits & perks :Opportunity to tackle tough challenges, learn and grow from fellow top talent, and help millions of people reach their personal financial goals
Flexible hours and virtual-first work culture with a home office stipend
Premium Medical, Dental, and Vision Insurance plans
Generous paid parental and caregiver leave
401(k) savings plan with matching contributions
Financial advisor and financial wellness support
️ Flexible PTO and generous company holidays, including Juneteenth and Winter Break
All-company in-person events once or twice a year and virtual events throughout to connect with your team members and leadership team
Dave Operating LLC is proud to be an Equal Employment Opportunity employer and is dedicated to cultivating a diverse and inclusive workplace. We will consider for employment all qualified applicants and do not discriminate on any basis protected by federal, state, or local law, including the City of Los Angeles’ Fair Chance Initiative for Hiring Ordinance relating to an applicant's criminal history.
#LI-REMOTE
$174k - $224k
...position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Lead GRC & Security Governance based in the United States. Overview We are seeking an experienced Lead GRC & Security Governance professional to...SuggestedFull timeRemote workHome officeFlexible hours- MSIG USA, the US-based subsidiary of MS&AD Insurance Group, is seeking a Lead, Governance, Risk & Compliance (GRC) to mature security governance, risk management, and compliance activities. This role focuses on hands-on execution, regulatory compliance, audits, and policy...Suggested
- ...Emergent Software in Hartford, CT is seeking a senior Cyber Security & GRC Engineer to lead an enterprise-wide security, governance, risk, and compliance program. You will own the Vanta platform, implement NIST CSF 2.0, GDPR, and SOX ITGC controls, and report to executives...Suggested
- Workday in Pleasanton, CA, is seeking a senior GRC leader to drive governance, risk, and compliance across Security, Cloud Operations, IT, Development, and Compliance. You will assess security gaps, communicate impacts to executives, and drive remediation timelines to...Suggested
- ...position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Lead GRC & Security Governance based in the United States. Overview We are seeking an experienced Lead GRC & Security Governance professional to build...SuggestedFull time
- ...Stratolaunch is seeking a dynamic Facility Security Officer (FSO) to implement and maintain a comprehensive security program across our sites. You will drive governance, risk, and compliance efforts aligned with NIST SP 800-171, DoD 5220.22, and NISPOM, while coordinating...For contractors
$114.5k - $188.9k
...capabilities that make Information Security easier to understand, adopt,... ...Information Security governance to improve visibility into security... ...across the enterprise. As the Lead, Information Security Library... ...Governance, Risk, and Compliance (GRC) tooling. Experience...Full timePart timeWork at officeRemote work3 days per week- ...of associates with a strong sense of belonging.Learn more about Inclusion & Diversity at PVH here.bout the Role:The Senior Lead, SAP Security, GRC & Compliance will act as a Subject Matter Expert (SME) for SAP Security & GRC including managing multiple SAP GRC instances...Full timeContract workWork at officeLocal area
$180k - $258k
...AI-driven transformation of healthcare payments and eliminate administrative friction for good.Role OverviewWe are seeking a Security GRC Lead to build our first in-house GRC program from the ground up. In this role, you won't just write policies or collect manual screenshots...- ...labor-intensive work in internal audit and governance: testing whether a company's financial,... .... The Opportunity We’re hiring a Security Lead to build and own the security function... ...handling sensitive data, ideally in fintech, GRC, or another regulated space...
$134k - $154.5k
...Practice - CIS - Cloud, Infrastructure, and Security Services About Cloud Infrastructure &... ...We are seeking an experienced Lead GRC Architect – OneTrust to lead the design,... ...implementation, and enhancement of enterprise Governance, Risk, and Compliance (GRC) capabilities...Temporary work- ...Corporation in Santa Clara, CA seeks a Governance, Risk, and Compliance... ...Certifications Engineer to own end-to-end security certifications (ISO 27001, SOC 2, NIST). You will lead planning, execution, and... ...value 8+ years of governance/ GRC experience, cloud security...
- ...Anthropic is seeking an experienced US Public Sector Compliance, Security GRC professional to manage ongoing government authorizations. You will translate regulatory requirements into actionable engineering tasks, perform evidence reviews, and maintain alignment with...
$144.12k - $240.2k
## Lead, System SecurityApply: Remote: Full time: Posted Today: JR... ...of Cybersecurity to own security and security compliance across... ...DO** **Security strategy and governance.** Define Slate's cybersecurity... ...single function such as SOC, GRC, or AppSec.* Hands-on leadership...Permanent employmentFull timeContract workRemote work- Monarch Money is seeking a Senior Security GRC Analyst to join our Security team. You will own the day-to-day of our compliance program and customer security assurance while maturing the GRC program across the organization. You'll work cross-functionally with People, Legal...Remote job
- Mariner Wealth Advisors seeks a Director, Cyber GRC to lead governance, vendor risk, and security awareness across the organization. You will shape policies, drive risk management efforts, and ensure compliance with SEC, FINRA, and NYDFS requirements while partnering with...Remote job
- Job Summary:The IT Governance, Risk, and Compliance (GRC) Lead Analyst serves as a subject matter expert responsible for leading the design, implementation... ...in IT Governance, Risk, and Compliance, Information Security, IT Audit, or related disciplines.Bachelor's degree in...Full timeWork at office3 days per week
- ...industries ensures our services are customized to meet specific needs. For more details please visit our website Job Description SAP Security & GRC Additional Information All your information will be kept confidential according to EEO guidelines....Permanent employmentFull timeTemporary work
- Whatnot is seeking an experienced Governance, Risk & Compliance Analyst to join its Security GRC team. You will focus on security governance, risk management, and regulatory compliance across cloud environments and partner ecosystems. With 5+ years in a tech startup or...
- ...empowers clients to build a healthier and more financially secure workforce by unifying the benefits ecosystem across... ...! Learn more at careers.alight.com. The AI Enablement & Governance - Security & Controls Lead enables secure, responsible, and scalable AI adoption by...Work at officeLocal areaRemote workWork from homeWorldwideFlexible hours
$143.32k - $273.93k
..., our mission is to empower our members to achieve financial security through highly competitive products, exceptional service and... ...business needs.The OpportunityAs the Data Policy and Regulatory Governance Lead you will lead the development, implementation, and ongoing...Full timeH1bWork at officeRemote workHome officeRelocation packageFlexible hours$120k - $202.5k
Location: Boston/Quincy, Massachusetts, United States Who we are looking for State Street is seeking a Security Platform Governance & Resilience Lead for our Security Platforms team, which is part of the State Street Cyber Fusion Center. The Security Platforms team designs...Full timeTemporary workFlexible hours$135k - $150k
...we looking for? As our Applied AI Lead, you'll be the person who makes AI real... ...the team, and you'll set the standards, governance, and direction for how the organization... ...You'll partner with Legal and IT on the security and data-privacy questions that AI-built...Work at officeImmediate start$156.5k - $191.2k
...Title: CI Team Lead Belong. Connect. Grow. with KBR! KBR’s National Security Solutions team provides high-end engineering and advanced technology solutions to... ...supporting the Chief Information Office (CIO) at a government customer in the Northern Virginia area by assisting...Contract workTemporary workFor contractorsFor subcontractorWork at officeLocal areaWorldwideRelocation packageFlexible hours- ...Opportunity A growing SaaS technology organization is seeking a Group Product Manager to help lead the strategy and continued evolution of its Governance, Risk & Compliance (GRC) product portfolio. This is not a traditional execution-focused Product Management role....Full timeLocal area
$160k - $180k
...connect across an organization while respecting enterprise-grade security, governance, permissions, and ethical walls.Innovation is only part of... ....What You’ll Do NetDocuments is seeking an execution-focused Lead Product Manager to drive the build and delivery of our next-...Work at officeImmediate startFlexible hours- ...Any resume submitted outside of an active job posting will not be considered for employment.What You'll Do:The Lead Associate Principal, Security Governance supports the Security Services Department and will regularly liaise with Compliance, Operational Risk Management...Full timeWork experience placementRemote work2 days per week
- Job DescriptionADP is Hiring a Senior Lead Product Manager - FraudJob SummaryThe Fraud... ...supports the development, execution, governance, and continuous enhancement of ADP's enterprise... ...Fraud Strategy, Analytics, Engineering, Security, Operations, and business stakeholders,...
- ...in your technical career. Join us. As a Lead Architect at JPMorganChase within the Corporate... ...Sector,enterprise architecture and governance function, you will lead architecture... ...delivery speed while strengthening resilience, security, and regulatory readiness.You will shape...
$95.1k - $146.3k
...healthcare and other large enterprises.The Lead OneStream Application Administrator... ...administration, configuration, technical governance, application controls, and technical support... ..., integrations, business rules, security, reporting objects, and production release...Full timeWork experience placementLocal area
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Lead GRC & Security Governance. Be the first to apply!






