Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Senior InfoSec & GRC Lead - Remote

$150k - $165k

Silversmith Capital Partners

New York, NY
  • Remote job

Location Remote - United States Job Category Corporate, Information Technology Employee Type FT Exempt Required Degree 4 Year Degree Travel 10% Minimum Experience 5 Years Description Compensation Transparency Salary: $150,000 - $165,000 At Earned, we are committed to fair and transparent compensation. Base salary is market-driven and determined at the time of offer based on benchmarks such as role-specific market data, company stage, and factors such as internal equity, relevant experience, interview performance, location, and level. About Earned Earned is a category-defining, first-in-kind tax-smart financial services firm dedicated to serving doctors, their families, and their practices. Our goal is to be the only financial partner doctors need by seamlessly integrating personal and practice-based solutions to maximize their wealth potential and drive better financial outcomes. We bring together tax, accounting, wealth management, insurance, and legal services under one platform not as a generic one-stop shop, but to deliver better advice through an integrated view of a doctor’s full financial life. Our differentiation is relationship-led, trust-based selling paired with disciplined execution across the ecosystem. Earned manages $3.4B+ in assets, serves more than 20,000 clients , and is one of the fastest-growing doctor-focused platforms in the country. Backed by $200M of committed capital, we are scaling rapidly through acquisitions and organic growth across multiple service lines. We are building this platform from the ground up, leveraging modern technology, data, and AI to simplify the client experience and make it easier for advisors and sales teams to deliver high-quality advice at scale. Operating across multiple service lines, acquired entities, and client entry points requires a highly disciplined yet relationship-driven go-to-market model that can scale without losing trust. Join us as we build the future of financial services for doctors faster, smarter, and at scale. Job Summary Earned is hiring an Information Security Lead to own and operate our security governance, compliance, and risk programs. This is a hands-on individual contributor role focused on building, running, and continuously improving Earned’s security control system. You will take ownership of Earned’s Written Information Security Program (WISP), ensure it is operational in practice, and lead SOC 2 readiness and audits to validate and evidence those controls. You will partner closely with IT, Engineering, Legal, and system owners, and support security governance during acquisitions and system integrations as needed to maintain Earned’s security posture. Key Responsibilities Own the WISP and security policy framework: Own and continuously improve Earned’s Written Information Security Program (WISP), including applicable jurisdiction-specific requirements (e.g., GLBA, SEC Reg S-P, state-level data security obligations), and maintain supporting security and privacy policies, standards, and procedures (access control, data handling, business continuity and incident response governance, intercompany agreements, responsible use of AI). \ Own SOC 2 delivery: Lead SOC 2 Type I readiness and audit, then operate the ongoing program to achieve and maintain SOC 2 Type II, including audit planning, evidence strategy, timelines, and direct interaction with auditors. Partner on control implementation: Work closely with IT and Engineering to define control requirements and verify evidence for technical and operational controls across core platforms (e.g., Microsoft 365 for corporate systems and AWS for product infrastructure), with implementation owned by those teams. Evidence and access reviews (SOC 2 controls): Operate the compliance cadence in Vanta, including evidence collection and periodic access reviews, and define standards for privileged access in partnership with IT. Risk visibility and tracking: Identify and document security and compliance risks, track remediation with control owners, and provide clear visibility into risk status and priorities for leadership. Vendor risk (critical vendors): Personally run security risk assessments for tier-1 vendors, including reviews, risk acceptance, and renewal cadence. CCPA runway: Define the program structure and readiness plan for CCPA as a medium-term initiative and partner with Legal and Operations on execution when prioritized. Key Requirements Bachelor’s degree in a related field 5+ years of hands-on experience in GRC, security compliance, IT audit, or security program management Direct experience delivering or operating a SOC 2 program, including readiness, evidence, and audits Strong ability to translate policies into clear, implementable, and auditable controls Experience operating compliance programs end-to-end, including evidence systems, workflows, and issue tracking Strong written communication and documentation skills Comfortable working independently, prioritizing effectively, and driving progress through influence rather than authority Preferred Requirements Experience in financial services, fintech, or similarly regulated environments Familiarity with GLBA, SEC Reg S-P, NIST CSF, ITGC concepts, and vendor risk practices Experience with Vanta Experience supporting security governance during acquisitions or system integrations Security certifications such as CISA, CRISC, or CISSP are a plus Benefits An attractive total compensation package Employer-sponsored health insurance (medical, dental, vision) 401k + 5% match Earned is committed to offering equal employment opportunity in all employment practices and employment decisions are based on an individual’s job qualifications and abilities. Earned prohibits discrimination based on race, creed, color, religion, national origin, ancestry, sex, gender (including gender identity, gender expression and being transgender), sexual orientation, marital status, registered domestic partner status, citizenship status, age, military and veteran status, medical condition, genetic information, political affiliation, disability, medical condition, or any other basis protected by federal, state, or local law or ordinance or regulation. Earned also prohibits discrimination based on the perception that anyone has any of these characteristics or is associated with a person who has or is perceived as having any of those characteristics. All such discrimination is unlawful. #J-18808-Ljbffr Silversmith Capital Partners

Vacancy posted 4 days ago
Similar jobs that could be interesting for youBased on the Senior InfoSec & GRC Lead - Remote in New York, NY vacancy
  •  ...Thoropass is seeking a Senior Manager, InfoSec Solutions, to lead the execution of SOC audits and manage a high-performing team. You will drive innovation in audit technology and ensure exceptional service delivery for emerging technology companies. This role requires... 
    Remote work
    Senior
    Work from home
    Flexible hours

    Thoropass

    New York, NY
    3 days ago
  •  ...A leading consulting firm seeks a Governance, Risk, and Compliance (GRC) leader to advance their programs. This remote role requires 5–7 years of experience in GRC with relevant certifications like CISSP or CISM. The successful candidate will lead policy development,... 
    Remote work
    Senior

    Franklin Fitch

    New York, NY
    4 days ago
  •  ...Docker, Inc is looking for a Senior GRC Analyst to lead the company's risk management program. This role requires experience in Information Security...  ...performing risk assessments. The position offers flexible remote work, competitive compensation, and multiple benefits... 
    Remote work
    Senior
    Flexible hours

    Docker

    New Bremen, OH
    6 days ago
  • $100k - $125k

    Senior GRC Analyst (InfoSec) job at loanDepot. Plano, TX. Description Position at loanDepot Position Summary : The Senior InfoSec GRC Analyst is responsible...  ...and supports risk management activities. Responsibilities: Leads the development and implementation of comprehensive... 
    Senior
    Local area

    Itlearn360

    Plano, TX
    4 days ago
  •  ...candidate will have over 6 years of experience with Workiva GRC implementations, lead project delivery, and manage client communications...  ...implementation support. The position offers a flexible hybrid or remote working model as well as a comprehensive benefits package,... 
    Remote job
    Senior
    Flexible hours

    Clearsulting

    Columbus, OH
    3 days ago
  • Oura is seeking a Senior Governance, Risk, Compliance (GRC) Analyst to join the Security Team in New York City. This role involves leading GRC initiatives, managing compliance policies, and performing...  ..., health insurance, and a flexible remote work model for East Coast... 
    Remote work
    Senior
    Flexible hours

    Itlearn360

    New York, NY
    21 hours ago
  • $153.6k - $192k

     ...expertise with technical execution. As a Senior GRC Engineer, you will drive critical GRC...  ...have up to four weeks per year of fully remote work! Responsibilities Manage and scale...  ...partners by producing documentation and leading training sessions Evangelize best practices... 
    Remote work
    Senior
    Work at office
    Immediate start
    Work from home
    3 days per week

    Brex

    New York, NY
    4 days ago
  •  ...A technology consulting firm is seeking an Infosec or GRC Leader to implement and manage Information Security Management Systems and coordinate...  ..., and supporting supply chain risk management. The role is available remotely for a duration of 6+ months. #J-18808-Ljbffr... 
    Remote work

    Avantdigitalnow

    San Francisco, CA
    1 day ago
  •  ...Lynk is seeking a Senior Cybersecurity Compliance Officer (ISSO) to oversee compliance programs aligned with CMMC Level 2, NIST SP 800‑171, and more. This remote position requires 3–6 years in cybersecurity, with a strong focus on governance, risk, and compliance. The... 
    Remote work
    Senior

    Lynk Inc

    New York, NY
    4 days ago
  • Waters Corporation in Milford, MA is looking for a seasoned Sr. Information Security Compliance and Risk Analyst to lead its Governance, Risk, and Compliance (GRC) program. This critical role involves conducting risk assessments, supporting audits, and ensuring compliance... 
    Senior

    Waters Corporation

    Milford, MA
    4 days ago
  •  ...A leading staffing and recruiting firm in Boston is seeking a seasoned cybersecurity compliance professional to strengthen risk management...  ...frameworks and auditing complex systems. The company offers remote work and flexible schedules, fostering a highly innovative... 
    Remote work
    Senior
    Flexible hours

    Expertech

    Boston, MA
    1 day ago
  • A leading technology firm is seeking a Governance, Risk, and Compliance (GRC) Analyst to enhance compliance posture across various standards. Based in Schaumburg, IL or Phoenix, AZ, the ideal candidate will have 2+ years' experience in risk and compliance, managing audits... 
    Senior
    Full time

    Fulcrum Global Technologies

    Schaumburg, IL
    1 day ago
  •  ...Neier Inc. is seeking an Experienced or Senior GRC Analyst to lead cybersecurity and compliance initiatives. This full-time, remote position will focus on risk assessments, developing compliance programs, and mentoring junior analysts. The ideal candidate has over 5 years... 
    Remote work
    Senior
    Full time

    Neier Inc

    New York, NY
    1 day ago
  • $105k - $135k

    Dark Wolf Solutions, LLC is seeking an Information System Security Officer to join our team in Tampa, FL. This hybrid position involves evaluating information system security, conducting vulnerability assessments, and maintaining certification. Candidates should have over...
    Remote job
    Senior

    Dark Wolf Solutions, LLC

    Tampa, FL
    21 hours ago
  • $190k - $215k

    Governance, Risk & Compliance (GRC) Manager Sigma is seeking an experienced GRC Manager to lead and scale our governance, risk, and compliance programs. This role...  ...Experience working in organizations with distributed or remote teams Familiarity with security frameworks such... 
    Remote work
    Senior
    Full time
    Contract work
    Work at office
    Flexible hours

    Sigma Computing Inc.

    San Francisco, CA
    4 days ago
  •  ...is seeking an experienced Information Security & Compliance Manager to oversee security engineering and compliance operations. This remote role involves managing vulnerability responses, designing security controls, and ensuring compliance with frameworks like SOC 2 and... 
    Remote work
    Senior
    Flexible hours

    Jobgether

    Florida, NY
    1 day ago
  • $130k - $160k

     ...Location U.S Remote Employment Type Full time Department Engineering Team & Role As a Senior GRC Analyst at Benepass, you will help operate...  ...operations. Reporting to the Head of Infosec & GRC, you will be a key...  ..., HITRUST CCSFP, ISO 27001 Lead Implementer, ISO 27001 Lead... 
    Remote work
    Senior
    Full time
    Work at office
    Work from home
    Flexible hours

    Benepass

    New York, NY
    2 days ago
  • Centene Corporation is seeking a Security Compliance Lead Information Risk Analyst to take charge of security governance and compliance...  ...relevant field, over six years of auditing experience, and expertise in GRC platforms. Benefits include competitive pay and flexible work... 
    Remote job
    Senior
    Flexible hours

    Centene Corporation

    California, MO
    4 days ago
  •  ...Campus-Umgebungen seiner Kunden. Aufgaben Als Lead Consultant spielen Sie eine bedeutende und...  ...und strategische Weiterentwicklung des GRC-Bereichs Unterstützung des Vertriebs bei...  ...Unternehmen Dienstsitz: Raum Ingolstadt, remote Einstellungsdatum: schnellst möglich Gehalt... 
    Remote work
    Senior
    Flexible hours

    PSC Pro Search Consulting GmbH Unternehmensberatung

    New Bremen, OH
    2 days ago
  • $153k - $214k

    1Password is seeking a Senior Security Engineer – GRC Controls and Audit to direct compliance audit programs and lead technical audit walkthroughs with external auditors. This role demands over 5 years of experience in the GRC space, particularly strong in SOC 2 Type II... 
    Remote work
    Senior

    1Password

    New York, NY
    1 day ago
  • Lead development efforts within ServiceNow SecOps (GRC, Vulnerability Response, Integrations) Perform code reviews and enforce coding standards Own branch strategy and pull requests Implement DevSecOps best practices
    Remote work
    Senior

    Saxon Global

    United States
    21 hours ago
  • $265k

     ...s central AI teams. The Role: We are looking for a Senior Applied AI Lead who can bridge the gap between Talent's biggest opportunities...  ..., and fairness considerations - partnering with Legal, Infosec, and other teams from the start, not at the end. Partner... 
    Remote work
    Senior
    Hourly pay
    Full time
    Immediate start
    Flexible hours

    Netflix

    United States
    1 day ago
  •  ...Senior Functional Lead - HR and Corporate Services Location: Flexible with 40% Travel Remote Purpose of Role: Weir's global SAP S/4HANA transformation is a once-in-a-generation...  ...-class capabilities spanning HR, HSE, GRC, Facilities, Sustainability, Legal, and... 
    Remote work
    Senior
    Flexible hours

    Weir

    United States
    4 days ago
  •  ...A leading Health-Tech firm in the United States is seeking a Senior Manager for Information Security, Governance, Risk, and Compliance. In this role, you will lead security governance processes and oversee incident response, all while driving the Information Security program... 
    Senior

    Stellar Health

    Richmond, VA
    3 days ago
  •  ...A cutting-edge technology firm in the United States is seeking a Senior GRC Analyst. The role requires 5+ years of experience in risk management, compliance, and governance. You will support the organizations GRC program, maintain security compliance frameworks, and conduct... 
    Remote work
    Senior

    Juniper Square

    United States
    2 days ago
  • $95k - $105k

     ...Subsplash is looking for a GRC Analyst to join its Remote team in the United States. In this role, you'll be a strategic lead in advancing security and risk operations by identifying gaps and implementing best practices. With a salary range of $95,000-$105,000/yr, you... 
    Remote work
    Senior

    Subsplash

    New York, NY
    4 days ago
  • $122.5k - $175k

     ...compliance at their U.S. locations. The successful candidate will enhance compliance tasks through intelligent automation, redesign GRC processes, and mentor junior staff. Ideal applicants will have a strong background in AI/ML architecture and GRC engineering, with a... 
    Senior
    Full time

    Framework Ventures

    New York, NY
    4 days ago
  •  ...To support the organization's security initiatives, the remote Senior Security GRC Analyst will manage the Information Security Program, conduct compliance audits, and collaborate with various stakeholders to enhance security practices and policies. Key responsibilities... 
    Remote work
    Senior

    Virtual Vocations Inc

    United States
    1 day ago
  •  ...A leading cybersecurity company is seeking a Senior Governance, Risk & Compliance Specialist to join their Technology Risk & Compliance team. This remote role, preferred hybrid near San Jose, CA, involves implementing GRC frameworks for FedRAMP and DoD authorizations,... 
    Remote work
    Senior

    Framework Ventures

    New York, NY
    2 days ago
  •  ...Commission on the RSA Archer Governance, Risk, and Compliance (GRC) implementation project. This role is responsible for...  ...excluding State holidays. Work Arrangement: 100% On Site - No Remote Work Air InfoSec, LLC is an Equal Opportunity Employer and does not discriminate... 
    Remote work
    Senior
    Contract work
    Work experience placement
    Monday to Friday

    Airinfosec

    Austin, TX
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Senior InfoSec & GRC Lead - Remote. Be the first to apply!