Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Lead GRC & Security Governance

$500 per month
Full-time

Dave

Dave vs. Goliath. We’re Dave.

Dave is a financial app on a mission to build products that level the financial playing field. It is redefining the financial landscape by leveraging technology to create an affordable, transparent, and user-centric access to liquidity for millions of Americans. As a leading innovator in the U.S. financial services sector, Dave’s digital financial platform offers products designed to meet the credit needs of those underserved by traditional financial institutions. Dave’s offerings include its flagship ExtraCash product, providing members up to $500 within minutes. The company is on track to launch several new product offerings in 2026, including a Buy Now Pay Later (BNPL) option.

Dave is focused on serving Americans who are financially vulnerable or living paycheck to paycheck. Dave is leading the charge in creating a new era of credit products that prioritizes speed, affordability, and accessibility, making it the go-to financial partner for those who need it most.

We’re hiring a Lead, GRC & Security Governance to build and run the governance systems that keep Dave’s technology organization controlled, resilient, and audit-ready. This is a senior individual contributor role with meaningful ownership across technology risk, controls, assurance, incident governance, and business continuity.

The Opportunity

This is a new role with the opportunity to shape how technology governance works at Dave. You’ll build practical systems that give Security, IT, Engineering, and Data teams clear expectations for managing risk and demonstrating that controls work.

You won’t own technical remediation. You’ll define what good looks like, establish accountability, challenge gaps, and make sure material risks reach the right decision-makers.

What You’ll Build and Own

  • Build and operate Dave’s technology governance program across technology and cyber risk, IT controls, change management, incident management, business continuity, and policies.
  • Establish and maintain our technology control inventory, with clear owners, evidence requirements, operating cadence, exceptions, and escalation paths.
  • Own technology assurance and audit readiness across programs including SOX ITGC, PCI, SOC 2, and other applicable frameworks. Coordinate evidence, support testing, identify gaps, and drive remediation accountability through closure.
  • Own the technology and cyber risk register and control exception process. Surface material or sustained risks with clear context and recommendations, including when there’s resistance to escalation.
  • Govern change management, incident management, and business continuity so expectations are practical, consistently followed, tested, and improved over time.
  • Use AI and automation thoughtfully to improve evidence analysis, control mapping, policy maintenance, risk reporting, audit preparation, and remediation tracking while maintaining appropriate human review and data safeguards.

The Impact

Strong governance makes it easier for Dave to move with confidence. Your work will help teams understand risk, strengthen operational resilience, meet our obligations, and build systems that hold up as the company grows.

What We’re Looking For

  • 8+ years of relevant technology experience, including significant ownership in security governance, technology risk, or security assurance.
  • You’ve personally led a SOC 2 Type II, ISO 27001, or equivalent audit through a successful result—not simply supported audit preparation.
  • You’ve built or materially rebuilt a governance, risk, or assurance operating model rather than only administering an established program.
  • Strong technical fluency across environments such as cloud, identity, CI/CD, source control, endpoints, networks, and data platforms. You can turn ambiguous expectations into specific, testable controls and challenge answers that aren’t precise enough.
  • Experience owning accountability while technical teams own remediation. You can influence Engineering, SRE, Security, IT, and Data partners without taking their work over.
  • Sound judgment around risk and materiality, including demonstrated experience escalating meaningful risks when stakeholders disagreed.
  • Experience partnering credibly with Internal Audit and Legal in addition to technical and Security teams.
  • Strong written communication and program management skills. You turn ambiguity into clear owners, decisions, actions, dates, and evidence.

Bonus

Experience with SOX ITGC, PCI DSS, NIST-based programs, AI governance or third-party AI risk, and GRC automation platforms such as Vanta or Drata.

What Makes Someone Successful Here

You take responsibility for outcomes, not just deliverables. You’re comfortable defining the system, asking specific questions, and making thoughtful trade-offs between immediate needs and controls that will hold up over time. When something represents meaningful risk, you have the judgment and conviction to make it visible.

You also know governance works best when technical teams see it as useful rather than bureaucratic. You build credibility with partners, seek context before reaching conclusions, and use feedback to improve the system. When priorities or requirements change, you adjust without losing sight of the underlying risk.

What to Expect

You’ll have significant autonomy to shape a new function, but you won’t work in isolation. You’ll partner closely with Security, IT, Engineering, Data, Internal Audit, Legal, Compliance, and external assessors to build a governance model that works in practice—not just on paper.

Why Join Dave

Dave is building financial products that give everyday Americans better access to their money without predatory fees. This role offers the chance to build foundational governance systems at a growing public fintech, influence how technology teams manage risk, and create an operating model that can scale with the business.

Ready to build for the underdog? Reports to: Sr. Director, Security & IT Don’t let imposter syndrome get in the way of an incredible opportunity. We’re looking for people who can help us achieve our mission and vision, not just check off the boxes. If you’re excited about this role, we encourage you to apply. You may just be the right candidate for this or other roles. Why you’ll love working here:

At Dave, our people are just as important as our product. Our culture reflects the values that guide who we are, how we work, and what we aspire to be. Daves are member-centric, helpful, transparent, persistent, and better together. We strive to create an environment where all Daves feel valued, heard, and empowered to do their best work. As a virtual-first company, team members can live and work anywhere in the United States, except Hawaii.

A few of our benefits & perks :

Opportunity to tackle tough challenges, learn and grow from fellow top talent, and help millions of people reach their personal financial goals

Flexible hours and virtual-first work culture with a home office stipend

Premium Medical, Dental, and Vision Insurance plans

Generous paid parental and caregiver leave

401(k) savings plan with matching contributions

Financial advisor and financial wellness support

️ Flexible PTO and generous company holidays, including Juneteenth and Winter Break

All-company in-person events once or twice a year and virtual events throughout to connect with your team members and leadership team

Dave Operating LLC is proud to be an Equal Employment Opportunity employer and is dedicated to cultivating a diverse and inclusive workplace. We will consider for employment all qualified applicants and do not discriminate on any basis protected by federal, state, or local law, including the City of Los Angeles’ Fair Chance Initiative for Hiring Ordinance relating to an applicant's criminal history.

#LI-REMOTE

Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Lead GRC & Security Governance in United States vacancy
  • $174k - $224k

     ...position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Lead GRC & Security Governance based in the United States. Overview We are seeking an experienced Lead GRC & Security Governance professional to... 
    Suggested
    Full time
    Remote work
    Home office
    Flexible hours

    jobgether

    United States
    2 days ago
  • MSIG USA, the US-based subsidiary of MS&AD Insurance Group, is seeking a Lead, Governance, Risk & Compliance (GRC) to mature security governance, risk management, and compliance activities. This role focuses on hands-on execution, regulatory compliance, audits, and policy... 
    Suggested

    Kalepa Corporation

    Eastern, KY
    3 days ago
  •  ...Emergent Software in Hartford, CT is seeking a senior Cyber Security & GRC Engineer to lead an enterprise-wide security, governance, risk, and compliance program. You will own the Vanta platform, implement NIST CSF 2.0, GDPR, and SOX ITGC controls, and report to executives... 
    Suggested

    Jobleads-US

    Hartford, CT
    1 day ago
  • Workday in Pleasanton, CA, is seeking a senior GRC leader to drive governance, risk, and compliance across Security, Cloud Operations, IT, Development, and Compliance. You will assess security gaps, communicate impacts to executives, and drive remediation timelines to... 
    Suggested

    Workday

    Pleasanton, CA
    3 days ago
  •  ...position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Lead GRC & Security Governance based in the United States. Overview We are seeking an experienced Lead GRC & Security Governance professional to build... 
    Suggested
    Full time

    Jobgether

    Remote
    1 day ago
  •  ...Stratolaunch is seeking a dynamic Facility Security Officer (FSO) to implement and maintain a comprehensive security program across our sites. You will drive governance, risk, and compliance efforts aligned with NIST SP 800-171, DoD 5220.22, and NISPOM, while coordinating... 
    For contractors

    Jobleads-US

    Mojave, CA
    2 days ago
  • $114.5k - $188.9k

     ...capabilities that make Information Security easier to understand, adopt,...  ...Information Security governance to improve visibility into security...  ...across the enterprise. As the Lead, Information Security Library...  ...Governance, Risk, and Compliance (GRC) tooling. Experience... 
    Full time
    Part time
    Work at office
    Remote work
    3 days per week

    PGIM

    Newark, NJ
    3 days ago
  •  ...of associates with a strong sense of belonging.Learn more about Inclusion & Diversity at PVH here.bout the Role:The Senior Lead, SAP Security, GRC & Compliance will act as a Subject Matter Expert (SME) for SAP Security & GRC including managing multiple SAP GRC instances... 
    Full time
    Contract work
    Work at office
    Local area

    PVH

    Bridgewater, NJ
    3 days ago
  • $180k - $258k

     ...AI-driven transformation of healthcare payments and eliminate administrative friction for good.Role OverviewWe are seeking a Security GRC Lead to build our first in-house GRC program from the ground up. In this role, you won't just write policies or collect manual screenshots... 

    Candid Health

    San Francisco, CA
    4 days ago
  •  ...labor-intensive work in internal audit and governance: testing whether a company's financial,...  .... The Opportunity We’re hiring a Security Lead to build and own the security function...  ...handling sensitive data, ideally in fintech, GRC, or another regulated space... 

    Petual

    San Francisco, CA
    4 days ago
  • $134k - $154.5k

     ...Practice - CIS - Cloud, Infrastructure, and Security Services About Cloud Infrastructure &...  ...We are seeking an experienced Lead GRC Architect – OneTrust to lead the design,...  ...implementation, and enhancement of enterprise Governance, Risk, and Compliance (GRC) capabilities... 
    Temporary work

    Cognizant

    Washington DC
    1 day ago
  •  ...Corporation in Santa Clara, CA seeks a Governance, Risk, and Compliance...  ...Certifications Engineer to own end-to-end security certifications (ISO 27001, SOC 2, NIST). You will lead planning, execution, and...  ...value 8+ years of governance/ GRC experience, cloud security... 

    Jobleads-US

    Kentucky
    1 day ago
  •  ...Anthropic is seeking an experienced US Public Sector Compliance, Security GRC professional to manage ongoing government authorizations. You will translate regulatory requirements into actionable engineering tasks, perform evidence reviews, and maintain alignment with... 

    Jobleads-US

    San Francisco, CA
    3 days ago
  • $144.12k - $240.2k

    ## Lead, System SecurityApply: Remote: Full time: Posted Today: JR...  ...of Cybersecurity to own security and security compliance across...  ...DO** **Security strategy and governance.** Define Slate's cybersecurity...  ...single function such as SOC, GRC, or AppSec.* Hands-on leadership... 
    Permanent employment
    Full time
    Contract work
    Remote work

    Jobleads-US

    Kentucky
    1 day ago
  • Monarch Money is seeking a Senior Security GRC Analyst to join our Security team. You will own the day-to-day of our compliance program and customer security assurance while maturing the GRC program across the organization. You'll work cross-functionally with People, Legal... 
    Remote job

    Monarch Money

    New York, NY
    5 days ago
  • Mariner Wealth Advisors seeks a Director, Cyber GRC to lead governance, vendor risk, and security awareness across the organization. You will shape policies, drive risk management efforts, and ensure compliance with SEC, FINRA, and NYDFS requirements while partnering with... 
    Remote job

    Mariner Wealth Advisors

    New York, NY
    5 days ago
  • Job Summary:The IT Governance, Risk, and Compliance (GRC) Lead Analyst serves as a subject matter expert responsible for leading the design, implementation...  ...in IT Governance, Risk, and Compliance, Information Security, IT Audit, or related disciplines.Bachelor's degree in... 
    Full time
    Work at office
    3 days per week

    Westfield Insurance

    Westfield Center, OH
    3 days ago
  •  ...industries ensures our services are customized to meet specific needs. For more details please visit our website Job Description SAP Security & GRC Additional Information All your information will be kept confidential according to EEO guidelines.... 
    Permanent employment
    Full time
    Temporary work

    Epro Consulting

    Stamford, CT
    more than 2 months ago
  • Whatnot is seeking an experienced Governance, Risk & Compliance Analyst to join its Security GRC team. You will focus on security governance, risk management, and regulatory compliance across cloud environments and partner ecosystems. With 5+ years in a tech startup or... 

    Whatnot

    Los Angeles, CA
    1 day ago
  •  ...empowers clients to build a healthier and more financially secure workforce by unifying the benefits ecosystem across...  ...! Learn more at careers.alight.com. The AI Enablement & Governance - Security & Controls Lead enables secure, responsible, and scalable AI adoption by... 
    Work at office
    Local area
    Remote work
    Work from home
    Worldwide
    Flexible hours

    Alight Solutions

    Springfield, IL
    4 days ago
  • $143.32k - $273.93k

     ..., our mission is to empower our members to achieve financial security through highly competitive products, exceptional service and...  ...business needs.The OpportunityAs the Data Policy and Regulatory Governance Lead you will lead the development, implementation, and ongoing... 
    Full time
    H1b
    Work at office
    Remote work
    Home office
    Relocation package
    Flexible hours

    USAA - United Services Automobile Association

    San Antonio, TX
    3 days ago
  • $120k - $202.5k

    Location: Boston/Quincy, Massachusetts, United States Who we are looking for State Street is seeking a Security Platform Governance & Resilience Lead for our Security Platforms team, which is part of the State Street Cyber Fusion Center. The Security Platforms team designs... 
    Full time
    Temporary work
    Flexible hours

    State Street Bank

    Quincy, MA
    3 days ago
  • $135k - $150k

     ...we looking for? As our Applied AI Lead, you'll be the person who makes AI real...  ...the team, and you'll set the standards, governance, and direction for how the organization...  ...You'll partner with Legal and IT on the security and data-privacy questions that AI-built... 
    Work at office
    Immediate start

    ATG (Auction Technology Group)

    United, PA
    21 hours ago
  • $156.5k - $191.2k

     ...Title: CI Team Lead Belong. Connect. Grow. with KBR! KBR’s National Security Solutions team provides high-end engineering and advanced technology solutions to...  ...supporting the Chief Information Office (CIO) at a government customer in the Northern Virginia area by assisting... 
    Contract work
    Temporary work
    For contractors
    For subcontractor
    Work at office
    Local area
    Worldwide
    Relocation package
    Flexible hours

    KBR Careers

    Chantilly, Loudoun County, VA
    1 day ago
  •  ...Opportunity A growing SaaS technology organization is seeking a Group Product Manager to help lead the strategy and continued evolution of its Governance, Risk & Compliance (GRC) product portfolio. This is not a traditional execution-focused Product Management role.... 
    Full time
    Local area

    Juno Search Partners

    United States
    2 days ago
  • $160k - $180k

     ...connect across an organization while respecting enterprise-grade security, governance, permissions, and ethical walls.Innovation is only part of...  ....What You’ll Do NetDocuments is seeking an execution-focused Lead Product Manager to drive the build and delivery of our next-... 
    Work at office
    Immediate start
    Flexible hours

    NetDocuments

    Lehi, UT
    15 hours ago
  •  ...Any resume submitted outside of an active job posting will not be considered for employment.What You'll Do:The Lead Associate Principal, Security Governance supports the Security Services Department and will regularly liaise with Compliance, Operational Risk Management... 
    Full time
    Work experience placement
    Remote work
    2 days per week

    The Options Clearing Corporation

    Chicago, IL
    4 days ago
  • Job DescriptionADP is Hiring a Senior Lead Product Manager - FraudJob SummaryThe Fraud...  ...supports the development, execution, governance, and continuous enhancement of ADP's enterprise...  ...Fraud Strategy, Analytics, Engineering, Security, Operations, and business stakeholders,... 

    ADP - Automatic Data Processing

    Roseland, NJ
    4 days ago
  •  ...in your technical career. Join us. As a Lead Architect at JPMorganChase within the Corporate...  ...Sector,enterprise architecture and governance function, you will lead architecture...  ...delivery speed while strengthening resilience, security, and regulatory readiness.You will shape... 

    JP Morgan Chase

    Plano, TX
    15 hours ago
  • $95.1k - $146.3k

     ...healthcare and other large enterprises.The Lead OneStream Application Administrator...  ...administration, configuration, technical governance, application controls, and technical support...  ..., integrations, business rules, security, reporting objects, and production release... 
    Full time
    Work experience placement
    Local area

    Zayo Group

    Denver, CO
    15 hours ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Lead GRC & Security Governance. Be the first to apply!