Head of Information Security and GRC

Stott and May

New York (NY)

On-site

USD 250,000 - 350,000

Full time

7 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Equity

Job summary

Stott and May is recruiting a Head of Information Security / GRC in New York to establish and scale a global IT security governance and compliance capability. You will own security strategy, risk management and regulatory compliance while partnering with Legal, HR, Finance and Customer Success.

This leadership role balances robust controls with speed, driving a secure, scalable technology foundation for an internationally expanding workforce.

Qualifications

  • Proven IT leadership in a high-growth SaaS or technology business.
  • Deep expertise in identity, endpoints, enterprise systems and cloud platforms.
  • Hands-on leadership of SOC 2, ISO 27001, audits and risk programmes.
  • Experience in enterprise B2B SaaS, AI or fintech environments.
  • Knowledge of GDPR and global privacy requirements, AWS or Azure, zero-trust.
  • Strong communication, stakeholder leadership and commercial judgement.
  • A pragmatic mindset balancing security, scalability and velocity.

Responsibilities

  • Set and deliver the global IT strategy, roadmap, budget and operating model.
  • Own identity and access management, endpoint management, hardware, software, onboarding and offboarding.
  • Scale secure, reliable systems across regions and offices.
  • Lead security governance, risk management, business continuity and vendor assurance.
  • Maintain SOC 2 and ISO 27001 compliance.
  • Partner with Engineering on vulnerability management, security awareness and incident response.
  • Lead enterprise security reviews, due diligence and customer audits.
  • Build, mentor and lead a global IT team.
  • Drive automation, improve employee experience and reduce risk.

Skills

IT leadership
IAM
SOC 2
ISO27001
GDPR
Zero-trust
AWS/Azure
Stakeholder mgmt
Commercial judgment

Job description

Head of Information Security / GRC

GRC, Compliance, Information Security, ISO27001, DDQ's

New York

$250k-$350k plus equity

Do you want to build a business-critical Security & Compliance function from the ground up?

Would you like to influence senior stakeholders and shape the technology and security foundations of a company scaling internationally?

If you're ready to combine strategic leadership with hands-on impact, we'd like to hear from you.

We're hiring a strategic technology leader to build and scale the global IT, security governance and compliance capability for a fast-growing enterprise technology business. This is a high-impact opportunity to own the roadmap, shape the operating model and create a secure, seamless technology experience for a rapidly expanding international workforce.

You'll take full ownership of Information Security Governance and Compliance. Partnering with Engineering, Legal, HR, Finance and Customer Success, you'll balance robust controls with the pace and pragmatism needed in a high-growth environment.

Key Skills:

  • Proven IT leadership experience in a high-growth SaaS or technology business.
  • Deep expertise in identity, endpoints, enterprise systems and cloud productivity platforms.
  • Hands-on leadership of SOC 2, ISO 27001, audits, risk and compliance programmes.
  • Experience in enterprise B2B SaaS, AI or fintech environments.
  • Knowledge of GDPR, global privacy requirements, AWS or Azure and modern zero-trust architectures.
  • Strong communication, stakeholder leadership and commercial judgement.
  • A pragmatic mindset that balances security, scalability and business velocity

Duties and responsibilities:

  • Set and deliver the global IT strategy, roadmap, budget and operating model.
  • Own identity and access management, endpoint management, hardware, software, onboarding, offboarding and IT support.
  • Scale secure, reliable systems across multiple regions and international offices.
  • Lead security governance, risk management, business continuity, disaster recovery and vendor assurance.
  • Maintain and strengthen SOC 2 and ISO 27001 compliance.
  • Partner with Engineering on vulnerability management, privileged access, security awareness and incident response.
  • Lead enterprise security reviews, due diligence and customer audits.
  • Build, mentor and lead a high-performing global IT team.
  • Drive automation, improve employee experience and reduce operational risk.

Within the first year your challenge will be to create a robust Security and Compliance function that will be able to support exponential growth

Your main goals will be.

  • Strengthen security maturity while maintaining key compliance standards.
  • Deliver a fast, reliable and automated employee technology experience.
  • Reduce operational risk through clear governance, controls and metrics.
  • Build trust with enterprise customers through confident security leadership.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Head of Security
Head of Security

TriHire Solutions • San Francisco (CA)

On-site
USD 180,000 - 240,000
Global InfoSec & GRC Leader — Scale Security & Compliance
Global InfoSec & GRC Leader — Scale Security & Compliance

Stott and May • New York (NY)

On-site
USD 250,000 - 350,000
Equity
Information Security Lead
Information Security Lead

United States Digital Space LLC • United States

Remote
USD 140,000 - 200,000
Remote work
Equity package
Development budget
+5
Manager Security Compliance and Risk Management
Manager Security Compliance and Risk Management

LexisNexis • Raleigh (NC)

On-site
USD 118,000 - 220,000
Head of Information Security - GRC & AI-Driven Security
Head of Information Security - GRC & AI-Driven Security

Unlimit • United States

On-site
USD 180,000 - 320,000
Relocation to Belgrade, Serbia
Annual performance bonus
Comprehensive benefits package
Director, Governance, Risk & Compliance
Director, Governance, Risk & Compliance

Anomali • Redwood City (CA)

Hybrid
USD 180,000 - 230,000
Chief Information Security Officer
Chief Information Security Officer

Glocomms • Charlotte (NC)

On-site
USD 150,000 - 200,000
Information Technology Security Analyst
Information Technology Security Analyst

The Phoenix Group • Charlotte (NC)

Hybrid
USD 95,000 - 116,000
Hybrid work model
Relocation assistance
Certification sponsorship
Manager of Information Security and Compliance
Manager of Information Security and Compliance

iboss • United States

On-site
USD 100,000 - 130,000
Health, Vision, Dental
401(k) with company match
Unlimited Paid Time Off
+1
Security Operations & GRC Lead
Security Operations & GRC Lead

Pasona N A, Inc. • United States

On-site
USD 150,000 - 200,000