Head of Security & Risk

M0

New York (NY)

On-site

USD 150,000 - 210,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Jobtailor is seeking an experienced information security and GRC leader in New York to build and own the enterprise risk program across security, regulatory, and vendor risk. You will drive audits, policy, and awareness training, ensuring audit-ready operations for all entities.

You will own SOC 2, ISO 27001, and related frameworks, coordinate auditors and third-party assessments, and design incident response and ISMS documentation. A strong track record in fintech or B2B SaaS is preferred.

Qualifications

  • 7–10 years of information security, risk, GRC, or compliance operations with ownership.
  • Hands-on knowledge of compliance frameworks (SOC 2, ISO 27001, and others).
  • Experience implementing and managing GRC automation tools and audits.

Responsibilities

  • Build M0’s enterprise risk program from scratch across security, operational, regulatory, and counterparty risk.
  • Own M0's compliance posture across SOC 2, ISO 27001, and other frameworks—drive policy, audits, and vendor risk.
  • Design and maintain incident response, ISMS docs, and security policies; manage external security vendor relationships.
  • Coordinate security due diligence for partners and respond to questionnaires with reusable documentation.
  • Design and own security awareness training; foster a proactive security culture across teams.

Skills

Information security
GRC
Compliance operations
Risk management
Audits
Security controls
BCP/DR planning
Vendor risk
ISO 27001
SOC 2

Tools

Vanta
Drata
AWS

Job description

  • Build M0’s enterprise risk program from scratch. Cover security, operational, regulatory, and counterparty risk, including the risk register, annual assessments, scenario analyses, and escalation framework across all entities.
  • Own M0's compliance posture across SOC 2, ISO 27001, and other applicable frameworks — driving all non-technical workstreams (policy writing, auditor coordination, vendor risk, access reviews, third-party SaaS vendor evaluations) and keeping the organization audit-ready at all times.
  • Design and maintain M0's incident response framework, ISMS documentation, and security policies — own external security vendor relationships, facilitate tabletop exercises covering IR, BCP, and DR scenarios, and drive the selection of a security advisory firm for on-call support.
  • Serve as M0's primary point of contact for institutional partner security due diligence and inbound security questionnaires, build and maintain the reusable documentation package for responding to partner requests, and coordinate with Senior Counsel on information security representations in commercial agreements.
  • Design and own M0's security awareness training program, ensure all employees understand their security obligations, and build a proactive security culture across engineering, operations, legal, and business teams.
Requirements
  • 7–10 years of experience in information security, risk, GRC, or compliance operations, with meaningful ownership and a preference for fintech, crypto infrastructure, or B2B SaaS backgrounds.
  • Demonstrated track record of building a compliance certification program from scratch, in-depth knowledge of compliance and regulatory frameworks, including hands‑on implementation of SOC 2, ISO 27001, CMMC, HIPAA, GDPR, NIST 800-53, etc.
  • Hands‑on experience with GRC automation platforms (Vanta, Drata, or equivalent), cloud security environments (AWS preferred), and BCP/DR program design.
  • Proven experience managing external audit relationships end‑to‑end (including auditors, penetration testing firms, and compliance vendors) and navigating evidence collection and report production.
  • Working understanding of AWS, GCP, and Azure, including embedding security controls into DevOps workflows and Infrastructure as a Service (IaaS) deployments.
  • Preferred certifications: Cloud+, CySA+, CISSP, or CISM.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Chief Security & Risk Architect
Chief Security & Risk Architect

M0 • United States

Hybrid
USD 150,000 - 200,000
Comprehensive healthcare coverage
Flexible remote work option
Professional development budget
Head of Security & Risk
Head of Security & Risk

M0 • United States

On-site
USD 150,000 - 200,000
Comprehensive healthcare coverage
Flexible remote work option
Professional development budget
Head of Security & Risk
Head of Security & Risk

M0 • New York (NY)

Hybrid
USD 120,000 - 160,000
Comprehensive healthcare insurance
Wellbeing allowance and gym membership
Annual development budget
Security & Risk Leader for FinTech & Crypto
Security & Risk Leader for FinTech & Crypto

M0 • New York (NY)

Hybrid
USD 120,000 - 160,000
Comprehensive healthcare insurance
Wellbeing allowance and gym membership
Annual development budget
Senior Manager of Risk and Compliance
Senior Manager of Risk and Compliance

PTR Global • United States

On-site
USD 100,000 - 130,000
Information Security Program Lead
Information Security Program Lead

MSA - The Safety Company • Cranberry Township

On-site
USD 120,000 - 180,000
Manager Security Compliance and Risk Management
Manager Security Compliance and Risk Management

RELX • Raleigh (NC)

On-site
USD 118,000 - 220,000
Annual incentive bonus
Technical Security Manager
Technical Security Manager

Cambium Learning Group • United States

On-site
USD 120,000 - 180,000
Information Security Program Lead
Information Security Program Lead

MSA, The Safety Company • Cranberry Township

On-site
USD 120,000 - 180,000
Compliance Project Manager
Compliance Project Manager

M3 Technology Consultants • Fairfax (VA)

On-site
USD 80,000 - 115,000
Very competitive compensation package
Annual paid training for continuing.
Collaborative team environment
+4