Director, Governance, Risk & Compliance

Candescent

Atlanta (GA)

On-site

USD 180,000 - 240,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Hybrid position

Job summary

Candescent is seeking an experienced Director of Governance, Risk, Compliance & Vendor Management to lead audit, compliance, third-party risk management, and vendor governance for banking and fintech clients. This role drives a strong control environment, ensuring regulatory and contractual security obligations are met across internal teams and external partners.

The leader will helm external audits, customer due diligences, and executive reporting, while mentoring a high-performing team and

Qualifications

  • Bachelor's degree in a relevant field and deep experience leading GRC programs.
  • Proven track record delivering SOC 2 Type II and PCI DSS audits.
  • Strong knowledge of US banking regulations and third-party risk governance.

Responsibilities

  • Lead Governance, Risk, Compliance, Third-Party Risk Management, and Vendor Management programs.
  • Oversee SOC 2 Type II, PCI DSS, customer audits, and regulatory examinations.
  • Ensure compliance with banking, security, and privacy requirements (FFIEC/GLBA/PCI).
  • Direct the vendor lifecycle: onboarding, risk assessments, monitoring, contracts, offboarding.
  • Develop executive reporting on audit readiness, vendor risk, and remediation.

Skills

SOC 2 Type II audit
PCI DSS
Vendor risk management
Banking regulations (FFIEC/GLBA)
Leadership
Audits & remediation

Education

Bachelor's degree in Information Systems, Cybersecurity, Finance, Accounting, or related field

Job description

Candescent is a forward-thinking technology company transforming how financial institutions deliver Intelligent Banking experiences. We unite digital banking, account opening, and branch solutions that power and connect digital banking, account opening, and branch solutions—creating seamless engagement across digital, remote, and in-person channels. Our Experience-Led, Intelligence-Driven approach combines human-centered design with data, automation, and cloud-based innovation. Built on an API-first architecture, our extensible ecosystem enables institutions to adapt quickly, integrate easily, and unlock new opportunities for growth—turning every customer interaction into a moment of clarity, confidence, and connection.

Position Summary

Candescent is seeking an experienced Director of Governance, Risk, Compliance & Vendor Management to lead the organization's audit, compliance, third-party risk management (TPRM), and vendor governance functions. This leader will maintain a strong control environment that supports Candescent's banking and financial services customers while ensuring compliance with regulatory, contractual, and industry security requirements. The Director will lead a team responsible for external audits, customer compliance activities, third-party risk assessments, and vendor oversight, with particular focus on SOC 2 Type II, PCI DSS, and banking regulatory expectations.

Key Responsibilities
  • Lead Candescent's Governance, Risk, Compliance, Third-Party Risk Management, and Vendor Management programs.
  • Manage and oversee SOC 2 Type II, PCI DSS, customer audits, and banking regulatory examinations.
  • Ensure compliance with applicable banking, security, and privacy requirements, including FFIEC guidance, GLBA, and PCI DSS.
  • Direct the vendor lifecycle, including onboarding, risk assessments, ongoing monitoring, contract reviews, and offboarding.
  • Partner with Legal, Procurement, Technology, Product, and Operations teams to manage risk and compliance obligations.
  • Develop executive reporting on audit readiness, compliance status, vendor risk, and remediation activities.
  • Lead customer compliance engagements, due diligence reviews, and security assurance activities.
  • Build, mentor, and develop a high-performing team while driving process improvements and operational efficiency.
Required Qualifications
  • Bachelor's degree in Information Systems, Cybersecurity, Business, Finance, Accounting, or a related field.
  • 10+ years of experience in audit, compliance, risk management, vendor management, or information security within banking, fintech, or financial services.
  • 5+ years of leadership experience managing professional teams.
  • Deep expertise leading SOC 2 Type II and PCI DSS audit programs.
  • Strong understanding of US banking regulations and frameworks, including FFIEC and GLBA.
  • Experience with third-party risk management and vendor governance programs.
  • Proven ability to lead audits, manage remediation efforts, and present results to executive leadership and customers.

Hybrid position

Preferred Qualifications
  • CISA, CISM, CRISC, CIA, CTPRP, or equivalent certifications.
  • Experience supporting cloud-based financial technology platforms.
  • Experience interacting with banking regulators, customers, and external auditors.
What Success Looks Like
  • Successful completion of annual SOC 2 Type II and PCI assessments.
  • Strong audit readiness and timely remediation of findings.
  • Effective management of third-party and vendor risk.
  • Positive customer and regulatory audit outcomes.
  • Continued maturation of Candescent's governance and compliance programs.

Candescent offers the opportunity to lead critical governance and compliance functions that protect our customers, strengthen trust, and support the secure delivery of innovative banking technology solutions.

Candescent is the largest non-core digital banking provider. We bring together the transformative technologies that power and connect account opening, digital banking and branch solutions for banks and credit unions of all sizes on any core.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Audit & Compliance Analyst
Audit & Compliance Analyst

Candescent • Atlanta (GA), Northern (KY)

On-site
USD 70,000 - 90,000
Audit & Compliance Analyst
Audit & Compliance Analyst

Candescent (Digital First Holdings LLC) • Atlanta (GA)

Hybrid
USD 95,000 - 145,000
Director, GRC & Vendor Risk (Hybrid)
Director, GRC & Vendor Risk (Hybrid)

Candescent • Atlanta (GA)

Hybrid
USD 180,000 - 240,000
Hybrid position
Manager, Identity & Access Management (IAM)
Manager, Identity & Access Management (IAM)

Candescent • Atlanta (GA), Northern (KY)

Hybrid
USD 120,000 - 180,000
Hybrid Atlanta office
Sr Manager, Area Sales
Sr Manager, Area Sales

Candescent (Digital First Holdings LLC) • Town of Texas (WI)

On-site
USD 120,000 - 160,000
Digital Strategy Executive
Digital Strategy Executive

Capitolis • Colorado

Hybrid
USD 120,000 - 180,000
Digital Strategy Executive
Digital Strategy Executive

Capitolis • Illinois

Hybrid
USD 120,000 - 160,000
Sr Manager, Area Sales
Sr Manager, Area Sales

Candescent • Massachusetts

On-site
USD 140,000 - 210,000
Digital Strategy Executive
Digital Strategy Executive

Candescent • Illinois

Hybrid
USD 120,000 - 190,000
Digital Strategy Executive
Digital Strategy Executive

Candescent • Massachusetts

Hybrid
USD 130,000 - 190,000