Head of Security, GRC

Jobtailor

California (MO)

On-site

USD 200,000 - 280,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Jobtailor is seeking a Senior Director of Governance, Risk, and Compliance to lead our GRC program for a regulated financial services environment. You will own security metrics, executive reporting, and alignment with SEC/FINRA obligations and global data protection laws.

You will establish threat intelligence capabilities, manage audits and examinations, oversee vendor risk, and collaborate with regulators and business units to strengthen security across the enterprise.

Qualifications

  • 15+ years in information security or risk management within regulated financial services.
  • Deep understanding of SEC/FINRA regulations for broker-dealers.
  • Experience leading GRC programs and risk initiatives.
  • Proven ability to own SOC 1/2 and ISO 27001 audits.
  • Ability to develop security KPIs/KRIs for executives.

Responsibilities

  • Lead governance, risk, and compliance program.
  • Ensure alignment with SEC/FINRA and data-protection laws.
  • Own security metrics and executive reporting.
  • Establish cyber threat intelligence capabilities.
  • Manage internal and external security audits.
  • Maintain Incident Response Plan (IRP).
  • Oversee vendor risk management.
  • Engage regulators and partners on security.
  • Serve as security compliance SME.

Skills

GRC Leadership
SEC/FINRA Regulations
Global Data Privacy
Threat Intelligence
Incident Response Planning
Third-Party Risk Management
Executive Reporting
Security Audits
Communication & Leadership

Job description

  • Lead the organization's governance, risk, and compliance program
  • Ensure alignment with SEC/FINRA obligations and global data-protection laws
  • Own security metrics and executive or board reporting
  • Establish and run cyber threat intelligence capabilities
  • Manage internal and external security audits and examinations
  • Own and maintain the Incident Response Plan (IRP)
  • Oversee vendor risk management processes
  • Engage with internal business units, regulators, and external partners on security matters
  • Act as subject-matter expert for security compliance
Requirements
  • 15+ years of experience in information security, risk management, or cybersecurity roles in a regulated financial-services environment
  • Strong understanding of SEC/FINRA regulations applicable to broker-dealers
  • Expertise in global data-protection laws (GDPR, CCPA/CPRA, LGPD)
  • Hands-on experience leading GRC programs and risk-management initiatives
  • Ownership of SOC 1, SOC 2, and ISO 27001 examinations and compliance auditsExperience building security KPIs/KRIs and executive or board-level reporting
  • Knowledge of threat intelligence, incident-response planning, and runbook development
  • Proven third-party risk management and client/partner security due-diligence
  • Excellent communication and leadership skills
Core Competencies

Demonstrates extensive expertise in leading governance, risk, and compliance programs within regulated financial services, ensuring alignment with SEC/FINRA regulations and global data-protection laws. Proven ability to manage security audits, incident response planning, and vendor risk management while effectively communicating with stakeholders.

Highest-signal resume keywords
  • Governance, Risk, And Compliance (GRC)
  • SEC/FINRA Regulations
  • Global Data-Protection Laws
  • Incident Response Planning
  • Third-Party Risk Management
ATS Optimization Keywords
Hard Skills
  • Information Security
  • Risk Management
  • Cybersecurity
  • Security Audits
  • Security Metrics
  • Threat Intelligence
  • KPI/KRI Development
  • SOC 1 Compliance
  • SOC 2 Compliance
  • ISO 27001 Compliance
Soft Skills
  • Excellent Communication
  • Leadership Skills
Industry Keywords
  • Financial Services
  • Regulated Environment
  • Data-Protection Laws
  • Cyber Threat Intelligence
  • Vendor Risk Management
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Associate, Cyber Strategy, Risk & Compliance
Senior Associate, Cyber Strategy, Risk & Compliance

Jobtailor • Washington

On-site
USD 75,000 - 110,000
Lead Security Analyst
Lead Security Analyst

Jobtailor • Town of Florida (NY)

On-site
USD 180,000 - 240,000
Cyber GRC Specialist
Cyber GRC Specialist

Jobtailor • Washington

On-site
USD 90,000 - 130,000
Senior IT Risk and Compliance Engineer
Senior IT Risk and Compliance Engineer

Jobtailor • Hartford (CT)

On-site
USD 120,000 - 180,000
Senior Third Party Cybersecurity GRC Analyst
Senior Third Party Cybersecurity GRC Analyst

Jobtailor • Indianapolis (IN)

On-site
USD 95,000 - 130,000
Senior Technical Compliance Analyst
Senior Technical Compliance Analyst

Jobtailor • Kansas

On-site
USD 70,000 - 90,000
Lead Security Analyst
Lead Security Analyst

Jobtailor • Illinois

On-site
USD 90,000 - 120,000
Chief Information Security Officer
Chief Information Security Officer

Jobtailor • Kentucky

On-site
USD 180,000 - 240,000
Security GRC Specialist
Security GRC Specialist

Jobtailor • South San Francisco (CA)

On-site
USD 170,000 - 210,000
Information Security Specialist – Regulatory Exam Management Lead
Information Security Specialist – Regulatory Exam Management Lead

Jobtailor • Fort Lauderdale (FL)

On-site
USD 120,000 - 180,000