Head of Security GRC

drivewealth

United States

Remote

USD 180,000 - 320,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Base + bonus + equity
401(k) plan with match
Extensive healthcare coverage (dental,
Vision, disability)
Paid time off & holidays
Personal development allowance
Wellness reimbursement
Company-provided phone

Job summary

DriveWealth is seeking a senior security leader to own the governance, risk, and compliance program within a regulated broker-dealer and embedded fintech environment. Reporting to the CISO, this role translates complex regulatory risk into business decisions, matures risk management frameworks, and stands up threat intelligence, incident response readiness, and third-party due-diligence capabilities.

You will work across security, risk, and the executive team to quantify enterprise risk and

Qualifications

  • Experience leading security GRC in regulated financial services.
  • Familiarity with NIST CSF, NIST 800-53, ISO 27001, SOC 2 and CIS Controls.
  • Ability to interface with regulators, auditors, and executives.
  • Knowledge of SEC, FINRA, GDPR/CCPA/GLBA data protections.

Responsibilities

  • Lead enterprise GRC program and align controls with frameworks.
  • Maintain cybersecurity policy library with reviews and ownership.
  • Operate risk register, conduct risk assessments and track residual risk.
  • Ensure SEC and FINRA obligations compliance and recordkeeping.
  • Lead audits (SOC 1/2, ISO 27001) and remediation tracking.
  • Establish testing and continuous monitoring, close gaps with owners.
  • Support threat intelligence, incident readiness, and third-party due-diligence.

Skills

GRC leadership
Regulated financial services
NIST CSF & 800-53
ISO 27001 / SOC 2 knowledge
Regulatory compliance
Risk assessment & treatment
Policy lifecycle management
Stakeholder communication

Job description

Role overview

A senior leadership role reporting to the CISO, owning the security governance, risk, and compliance program within a regulated broker-dealer and embedded fintech environment. The position acts as connective tissue across security, risk, and the executive team, translating deep technical and regulatory risk into business-aligned decisions. It is a builder role focused on maturing frameworks, quantifying enterprise risk, and standing up threat intelligence, incident-response readiness, and third-party due-diligence capabilities.

Responsibilities
  • Lead and mature the enterprise GRC program, aligning controls with recognized frameworks such as NIST CSF, NIST 800-53, ISO 27001, SOC 2, and CIS Controls
  • Maintain the cybersecurity policy, standard, and procedure library, including annual review cycles, control ownership, exceptions, and waivers
  • Operate the information security risk register, conducting risk assessments, defining treatment plans, and tracking residual risk over time
  • Ensure compliance with SEC and FINRA obligations such as Regulation S-P (Safeguards & Disposal), Rule 17a-4 recordkeeping, and broader financial-industry security requirements
  • Manage external and internal security audits and examinations including SOC 1, SOC 2 Type II, and ISO 27001, coordinating evidence collection and remediation tracking
  • Establish control testing and continuous control monitoring, driving remediation of gaps to closure across control owners
  • Support cyber threat intelligence, incident-response readiness, and third-party and client cyber due-diligence programs
Requirements
  • Significant experience leading security GRC functions within a regulated broker-dealer or comparable financial-services environment
  • Deep familiarity with NIST CSF, NIST 800-53, ISO 27001, SOC 2, and CIS Controls
  • Working knowledge of SEC, FINRA, and global data-protection regulations such as GDPR, CCPA/CPRA, LGPD, and GLBA
  • Demonstrated ability to interface credibly with regulators, auditors, enterprise partners, and executive stakeholders
  • Proven track record running risk registers, control testing, and policy lifecycle management
  • Strong written and verbal communication skills, with the ability to translate technical risk into clear business decisions
Nice to have
  • Experience building threat-intelligence or incident-response programs from earlier stages
  • Background coordinating annual security due-diligence reviews with critical partners and vendors
  • Comfort operating with autonomy and driving initiatives to completion with minimal supervision
Benefits and work setup
  • Compensation package including base, bonus, equity, and 401(k) match, plus heavily subsidized benefits and perks
  • Coverage that includes dental, vision, disability, and paid parental leave
  • Wellness reimbursement, company-provided phone, and a personal development allowance
  • Generous paid time off and observed holidays

Applicants must already hold legal authorization to work in the country where the role is located; visa sponsorship is not currently offered for this position.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Information Security Governance, Risk & Compliance Manager
Information Security Governance, Risk & Compliance Manager

JustMarkets • United States

Remote
USD 120,000 - 190,000
20 vacation days
10 sick leave days
Public holidays per policy
+5
Chief Security & GRC Officer
Chief Security & GRC Officer

DriveWealth Holdings, Inc. • Austin (TX)

Remote
USD 270,000 - 290,000
Medical insurance
401(k) match
Paid Parental Leave
+2
Staff Security Analyst - GRC
Staff Security Analyst - GRC

harnessinc • United States

Remote
USD 150,000 - 164,000
Monthly internet reimbursement
Security GRC Lead: Risk, Compliance & Strategy
Security GRC Lead: Risk, Compliance & Strategy

drivewealth • United States

Remote
USD 180,000 - 320,000
Base + bonus + equity
401(k) plan with match
Extensive healthcare coverage (dental,
+5
VP of Governance, Risk & Compliance
VP of Governance, Risk & Compliance

Tiro Security • Los Angeles (CA)

On-site
USD 200,000 - 280,000
Senior Engineer, Information Security GRC
Senior Engineer, Information Security GRC

ICE Clear Europe Limited • Atlanta (GA)

On-site
USD 120,000 - 180,000
Senior Analyst, Cyber Governance, Risk and Compliance (GRC)
Senior Analyst, Cyber Governance, Risk and Compliance (GRC)

H.I.G. Capital • Coral Gables (FL)

On-site
USD 120,000 - 170,000
Staff Security Analyst - GRC
Staff Security Analyst - GRC

Jobgether • United States

Hybrid
USD 150,000 - 164,000
Remote work within the United States
Hybrid option with designated offices
Governance, Risk, & Compliance (GRC) Analyst
Governance, Risk, & Compliance (GRC) Analyst

Districttechgroup • Washington

On-site
USD 80,000 - 100,000
Fully remote work environment
Competitive salary and performance bonuses
Health, dental, and vision insurance
+2
Manager, Information Security Governance, Risk & Compliance (GRC)
Manager, Information Security Governance, Risk & Compliance (GRC)

Burtch Works • United States

Remote
USD 140,000 - 170,000
Health and wellness benefits
Remote, US-based work