Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Head of Security GRC

$190k - $250k

Valon

Head Of Security Governance, Risk & Compliance (Grc)

We are seeking an experienced Head Of Security Governance, Risk & Compliance (Grc) to lead Valon's governance, risk, and compliance practices. In this role, you'll own the frameworks, governance processes, and cross-functional relationships that keep Valon secure, risk-informed, and compliant with the regulatory and customer requirements of a modern fintech provider. You'll work closely with Engineering, It, Legal, and executive leadership to translate security, data and resilience requirements into actionable controls and communicate risk posture clearly across the organization. Your work will directly enable Valon to deliver the security guarantees that protect our customers and their data — and position us to meet the rigorous due diligence requirements of institutional partners and regulated financial entities.

Valon offices are located in New York City and San Francisco, but we fully support remote work!

Responsibilities
  • Manage and expand Valon's security and privacy compliance program across key frameworks and regulations (e.g., Soc 2, Nydfs Cybersecurity Regulation, Ftc Safeguards Rule, Ccpa and evolving regulations)

  • Build and scale modern Security Grc capabilities that leverage Ai-enabled tools and processes, reducing manual overhead while optimizing risk and compliance operations

  • Support Ai security standards development and risk processes

  • Design, develop and monitor technical security controls

  • Lead audit preparation and management

  • Maintain and evolve Valon's risk management practices; facilitate risk assessments across teams and track remediation of identified issues to closure

  • Develop, publish, and maintain security policies, standards, and procedures in partnership with It, Engineering and Legal

  • Build and mature Valon's Data Governance program including secure data handling practices

  • Enhance Bc/Dr risk management practices and processes

  • Partner with Engineering and Product to assess security compliance implications of new features, infrastructure changes, and data flows

  • Manage security compliance, regulatory requirements, and customer-facing due diligence, while supporting operational security activities including advisory reviews, incident management, and issue remediation

Ideal Background
  • Proven experience owning a security Grc program at a tech or fintech organization

  • Strong experience designing, developing and implementing technical security and privacy controls

  • Deep familiarity with Soc, Nydfs Part 500, Ftc Safeguards Rule, and Ccpa; experience with nist Csf, Iso 27001 and related frameworks

  • Hands-on experience building or maturing a data governance program, including classification frameworks, retention policies, and data subject rights workflows

  • Knowledge of Bc/Dr controls - bia, Rto/Rpo, recovery playbooks, and tabletop exercises

  • Strong track record managing external audits end-to-end — scoping, evidence coordination, findings remediation

  • Familiarity with Ai governance and risk frameworks, including assessing security risks introduced by Llm and agentic systems

  • Experience applying Ai tools to security and/or Grc processes

  • Ability to translate technical security controls into clear compliance narratives for auditors, customers, and executives

  • Applied knowledge with industry security and compliance frameworks (nist, cis, Soc 2/Iso 27001 concepts)

  • Hands-on in both developing and operating security processes day-to-day (builder and operator)

  • Excellent communication and collaboration skills, including the ability to explain complex security concepts to both technical and non-technical stakeholders

  • Experience working in high-growth or startup environments is a plus

Minimum Qualifications
  • 7+ years in a progressive security management roles leading security focused technical Grc, compliance, and/or risk management programs

  • Bachelor's degree in Information Security, Computer Science, Technology or related field

  • Relevant security certifications (e.g., Cissp, Cism, Crisc, Cisa or similar)

  • Hands-on experience managing compliance audits such as Soc 2, Iso 27001 and others

  • Experience driving risk management and assessment practices at scale

  • Applied knowledge of data governance processes and standards

Benefits
  • Base Compensation Band: $190k - $250k. Base salary offered is determined by a number of factors including the candidate's experience, qualifications, and skills

  • Compensation: Competitive salary with a meaningful stake in the company via equity, and 401k plan

  • Health & well-being: We'll invest in your physical and mental well-being with comprehensive medical, dental, & vision benefits

  • Commuter benefits: We offer pre-tax deductions for public transportation, rideshare services, and parking expenses to make your commute more affordable and convenient

  • Grow together: Company wide orientation for you to successfully onboard and other learning & development opportunities including regular review cycles that feature 360 degree feedback

  • Play together: Quarterly budgets for team and company outings. Use it for team swag, cooking classes, or team dinners!

  • Generous time off: Flexible paid time off, sick days, and 11 company holidays

  • Baby bonding time!: 12 weeks off for both birthing and non-birthing parents - fully paid so you can focus your energy on your newest addition

Throughout the interview process, please remember that emails will only be from valon.com email addresses. We will never ask for any personally identifiable information during the interview process itself. Please reach out to View email address on click.appcast.io if you have any requests to verify the authenticity of an outreach.

Valon is an equal opportunity employer that is committed to diversity and inclusion in the workplace. We prohibit discrimination and harassment of any kind based on race, color, sex, religion, sexual orientation, national origin, disability, genetic information, pregnancy, or any other protected characteristic as outlined by federal, state, or local laws. Valon makes hiring decisions based solely on qualifications, merit, and business needs at the time.

Vacancy posted 13 hours ago
Similar jobs that could be interesting for youBased on the Head of Security GRC in United States vacancy
  • $500 per month

     ...Head Of Information Security (APAC) Remote - APAC Alpaca is a US-headquartered self-clearing broker-dealer and brokerage infrastructure for...  ...years of experience in information security, cybersecurity, or GRC, preferably in fintech or financial services ~ Fluent in... 
    Suggested
    Local area
    Remote work
    Home office

    Alpaca

    United States
    17 hours ago
  •  ...Head Of Information Security Thndr is looking for a head of information security to serve as the company's most senior security leader with full...  ...record leading multi-disciplinary security teams spanning both GRC and technical/engineering domains. ~ Experience... 
    Suggested
    Local area
    Remote work

    Thndr

    United States
    2 days ago
  •  ...Bitdeer Ai Cloud Security Leader For The Americas Bitdeer is a world-leading technology company for AI and Bitcoin mining infrastructure...  ...compliance support interface. Partner with the Singapore GRC Manager to provide the evidence collection and control implementation... 
    Suggested
    Local area

    Bitdeer Technologies Group

    Austin, TX
    3 days ago
  • $138.4k - $235.6k

     ...Overview This role reports to VP, Technology GRC and Deputy CISO and has accountability for maturing SOX ITGC oversight, establishing...  ...Services ~ Serve as a trusted advisor to IT, Information Security and Engineering on technology risk, control design, and... 
    Suggested
    Remote work

    RealPage

    United States
    1 day ago
  • $1,000 per month

     ...Security GRC Manager Credit Genie is a mobile-first financial wellness platform designed to help individuals take control of their financial future. We leverage artificial intelligence to provide personalized insights and are building a financial ecosystem by offering... 
    Suggested
    Temporary work
    Work at office
    Immediate start
    Remote work
    Flexible hours

    Credit Genie

    New York, NY
    20 hours ago
  •  ...A company is looking for a Security GRC Manager to build and oversee security and privacy compliance programs. Key Responsibilities Own and mature the security and privacy compliance program across various frameworks Lead internal and external audits and establish evidence... 

    Virtual Vocations Inc

    United States
    21 hours ago
  • $138.24k

     ...experience for yourself, and a better working world for all. Technology Consulting, Technologies & Platforms, Risk Technology – SAP Security and GRC (Manager) (Multiple Positions) (1710176), Ernst & Young U.S. LLP, Houston, TX. Provide Risk Management services to help... 
    Full time
    Temporary work
    Work experience placement
    Summer holiday
    Immediate start
    Monday to Friday

    EY

    Houston, TX
    3 days ago
  •  ...: Job Level: 7 What does the Sr. Manager, Governance, Risk & Compliance (GRC) - Cybersecurity do at Swire Coca-Cola? Swire Coca-Cola is seeking a Sr. Manager, IT Security - GRC to lead and mature our cybersecurity governance, risk management, and compliance... 
    Visa sponsorship
    Work visa

    Swire Coca Cola USA

    Draper, UT
    21 hours ago
  •  ...tens of millions of radiology reports by nearly 50%. Rad AI has secured over $140M in funding, including a recently oversubscribed...  ...strategy, and lead a small, high‑leverage team across cybersecurity, GRC, and security operations. You’ll be a critical partner to Sales... 
    Full time
    Flexible hours

    Rad AI

    San Francisco, CA
    1 day ago
  •  ...in the industry. M0 is seeking a sharp, execution-focused Head of Security & Risk to build and own the information security and risk function...  ...~7-10 years of experience in information security, risk, GRC, or compliance operations, with meaningful ownership and a preference... 
    Contract work
    Work at office
    Remote work
    Worldwide

    M0

    United States
    4 days ago
  • $400 per month

     ...the U.S. Help us solve our clients' biggest payment problems.Job DescriptionWe are seeking a detail-oriented and proactive Sr. Security GRC Manager to join our team. This role is responsible for identifying, assessing, and mitigating information technology and information... 
    Contract work
    Remote work
    Work from home
    Flexible hours

    PayNearMe

    Santa Clara, CA
    4 days ago
  • $178k - $307.05k

     ...senior cybersecurity leader and trusted advisor to the CISO, with enterprise accountability for Governance, Risk & Compliance (GRC) and Product Security across DePuy Synthes. The Sr. Director, Deputy CISO will shape and execute cybersecurity strategy that protects patients,... 
    Immediate start

    J&J Family of Companies

    West Palm Beach, FL
    4 days ago
  •  ...Work type: Staff Location: Newark, DE/Hybrid Categories: Information Technology, Legal & Compliance, Full Time The Director of GRC and Security Architecture is a senior leadership role responsible for governing the organization’s information security risk, compliance,... 
    Full time

    University of Delaware

    New York, NY
    4 days ago
  • $182k - $295k

    About the role Hex is looking for our first Security GRC Manager to build, scale, and own our security and privacy compliance programs. This role is pivotal in setting the foundation for how Hex meets regulatory, customer, and industry obligations across frameworks including... 
    Flexible hours

    Hex

    New York, NY
    3 days ago
  •  ...U.S. innovation with Colombian heart A company that listens, invests in you, and celebrates wins together The Senior Manager, Security GRC drives the enterprise security governance framework, shaping risk posture, compliance strategy, and policy architecture across global... 
    Work at office
    Remote work
    Flexible hours

    AspenView Technology Partners, Inc.

    Denver, CO
    3 days ago
  • $212k - $230k

     ...leading healthcare technology company in the United States is seeking a Director of Governance, Risk, and Compliance (GRC) to define and execute security governance strategies. This role requires strong expertise in managing compliance, overseeing third-party risks, and... 
    Remote work

    Clover Health

    New York, NY
    2 days ago
  • $250k - $300k

     ...BetterHelp is committed to being part of the solution. As the Head of Security at BetterHelp, you’ll join a diverse team of licensed...  ...distributed systems, or consumer platforms. Experience partnering with GRC teams The base salary range for this position is $250,000 - $... 
    Full time
    Work experience placement
    Work at office
    Immediate start
    Remote work

    BetterHelp

    United States
    3 days ago
  •  ...8 years of experience in Governance, Risk & Compliance project management. You will manage GRC projects, ensuring compliance with ISO 27001 standards and conducting IT security assessments. The ideal candidate possesses excellent communication skills to interact with both... 

    Cloud Hybrid Technologies, LLC

    Dallas, TX
    3 days ago
  •  ...Product Manager in Washington, DC to support the Governance, Risk, and Compliance (GRC) team. The role requires over 5 years of product management experience and at least 2 years in security and risk management. Responsibilities include gathering requirements, developing... 
    Contract work

    System One

    Washington DC
    1 day ago
  • Product Manager - IT Security (GRC) Washington, DC - ONSITE Must be able to work in the U.S. without sponsorship. Must be able to obtain Public Trust clearance. Type: Multi-year Contract. Open to W2 and C2C. Deadline to apply: May, 15th. We are seeking a Product Manager... 
    Contract work
    Temporary work
    Local area

    System One

    Washington DC
    1 day ago
  •  ...conversational AI firm in San Francisco is seeking a Compliance Manager to secure customer trust and manage compliance programs. This role...  ...ensure security standards. Candidates should have 3-5 years of GRC experience, strong project management skills, and a background... 

    Decagon

    San Francisco, CA
    13 hours ago
  •  ...experienced Project Manager specializing in Governance, Risk Compliance (GRC). The ideal candidate will have over 12 years of project...  ...a strong understanding of ISO 27K controls, and expertise in IT security assessment processes. Effective communication skills are... 

    Robotics Prcocess Automation, LLC

    Atlanta, GA
    4 days ago
  • $90k - $110k

     ...The Opportunity We are hiring our Senior Director of Security to build and lead TrackVia's security function. This is a hands-...  ...integrating AI tools into security workflows (detection, response, GRC, code review) * CISSP, CISM, CCSP, or equivalent Team & Reporting... 
    Part time
    Work at office
    Remote work

    TrackVia

    Denver, CO
    21 hours ago
  •  ...One mission. One team. That’s OneStudyTeam. The Director of Security leads enterprise security strategy and execution across governance...  ..., compliance, and security engineering. This role manages the GRC and Security Engineering teams, partners with technology and business... 
    Contract work
    For contractors
    For subcontractor
    Work at office
    Remote work
    Visa sponsorship
    Work visa

    OneStudyTeam, Inc.

    United States
    1 day ago
  • $175k - $190k

     ...Job Summary The Head of Regional Security - Americas provides strategic leadership and operational oversight for all regional security programs and operates within the matrix structure of the Head of Group Security - Regions organization. This role is accountable... 
    Permanent employment
    Local area
    3 days per week

    Fresenius

    Lake Zurich, IL
    13 hours ago
  •  ...Director of Information Security Duration: Full-Time Location: Remote About BigRio : BigRio is a Digital Transformation...  ...support compliance efforts. Governance, Risk & Compliance (GRC) Establish and manage a robust enterprise security governance... 
    Full time
    Remote work

    Saviance

    Boston, MA
    4 days ago
  •  ...care. One mission. One team. That’s OneStudyTeam. The Director of Security leads enterprise security strategy and execution across...  ...risk, compliance, and security engineering. This role manages the GRC and Security Engineering teams, partners with technology and business... 
    Contract work
    For contractors
    For subcontractor
    Work at office
    Remote work
    Visa sponsorship
    Work visa

    OneStudyTeam, Inc.

    New York, NY
    2 days ago
  •  ...Head of Security Architecture & Assurance Publication Date: May 22, 2026 Ref. No: 547025 Location: Remote Home, GB About Atos Group Atos Group is a global leader in digital transformation with c. 56,000 employees and annual revenue of c. €7.2 billion (at the go-... 
    Remote work
    Flexible hours

    World Grid

    United States
    5 days ago
  •  ...are required Role Overview The Director of Information Security is responsible for leading and advancing IntegriChain's information...  ...working with globally distributed teams. Experience with GRC tools, such as OneTrust, AuditBoard, or similar. Additional Information... 
    Work at office
    Remote work
    Visa sponsorship
    Flexible hours

    IntegriChain

    United States
    3 days ago
  • $190k - $240k

    Home Depot is seeking a qualified candidate for the Offensive Security Leader role in Atlanta, Georgia. This position focuses on leading security capabilities, overseeing investigations, and implementing strategies against advanced cyber threats. Ideal candidates will... 

    Home Depot

    Atlanta, GA
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Head of Security GRC. Be the first to apply!