Security Operations & GRC Lead

Pasona N A, Inc.

United States

On-site

USD 150,000 - 200,000

Full time

8 days ago
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Pasona N A, Inc. is building a cutting-edge fintech and trust bank focusing on digital payments and asset infrastructure, offering a remote role within the United States.

The Founding Security Operations & GRC Lead will own security operations and governance across cloud, product platforms, and third-party vendors. Ideal candidates bring 7+ years in security operations, GRC, and cloud security, with hands-on AWS experience, SIEM/EDR/MDR familiarity, and strong audit readiness capabilities.

Qualifications

  • 7+ years of experience in security operations, information security, vulnerability management, or GRC.
  • Experience in regulated or audit-sensitive environments.
  • Strong understanding of alert triage, access reviews, vulnerability management, and security documentation.
  • Hands-on experience with AWS security services and cloud security operations.
  • Experience with SIEM, MDR, EDR, identity management, and ticketing platforms.
  • Ability to coordinate across technical teams and stakeholders.
  • Strong documentation and communication skills.

Responsibilities

  • Security Operations: manage day-to-day security operations across cloud and enterprise environments.
  • Governance, Risk & Compliance: maintain security control documentation, audit evidence, and risk registers.
  • Secure Development & Vulnerability Management: support secure SDLC and remediation activities.
  • Regulatory & Examination Readiness: maintain examination-ready evidence and support regulatory readiness.

Skills

Security Operations
GRC / Security Compliance
Vulnerability Management
AWS Security
SIEM / MDR / EDR
Regulated environments
Documentation & communication

Job description

A newly established fintech and trust bank focused on digital payments and digital asset infrastructure.

Location: Remote, U.S.-Based

Employment Type: Full-Time

Compensation: $150,000–$200,000 Base Salary (Depending on Experience)

Position Overview

The Founding Security Operations & GRC Lead will serve as the internal owner of security operations execution and governance activities across cloud infrastructure, enterprise technology, product platforms, and third-party vendors.

The organization leverages specialized security, infrastructure, compliance, and advisory partners for implementation and monitoring activities; however, internal ownership of security findings, remediation tracking, risk management, control evidence, and examination readiness remains critical.

This role is ideal for someone with experience in security operations, cloud security, security governance, technology risk management, audit support, or security compliance within regulated industries.

Key Responsibilities
  • Security Operations
    • Manage day-to-day security operations across cloud, product, vendor, and enterprise technology environments.
    • Monitor and coordinate remediation of security findings from security tools, cloud monitoring services, and third-party assessments.
    • Review, triage, prioritize, track, and elevate security alerts and security‑related issues.
    • Coordinate security incident response activities, including investigation support, escalation, evidence preservation, communications, and post‑incident review.
    • Support cloud‑security posture management within AWS environments.
    • Maintain cloud‑security documentation and evidence for audits and examinations.
    • Oversee security controls related to: IAM; CloudTrail; AWS Config; Security Hub; GuardDuty; Inspector; Macie; KMS; Secrets Manager; WAF; Backup and recovery controls.
  • Governance, Risk & Compliance (GRC)
    • Maintain security control documentation, audit evidence, risk registers, and security exception records.
    • Support access governance activities, including user access reviews, privileged access certifications, and joiner/mover/leaver processes.
    • Prepare and organize security evidence for internal audits, external audits, regulatory examinations, and third‑party reviews.
    • Assist with ongoing compliance and examination‑readiness initiatives.
    • Coordinate security oversight activities involving critical third‑party providers and security partners.
    • Review vendor security documentation, assessment results, penetration‑test reports, and remediation plans.
    • Track vendor‑related security issues and follow up on corrective actions.
  • Secure Development & Vulnerability Management
    • Partner with engineering and platform teams to support secure SDLC controls.
    • Coordinate remediation activities for findings from: Vulnerability assessments; Penetration tests; Code reviews; SAST tools; Dependency scans; Secrets scanning; Container security reviews.
    • Track remediation progress and ensure timely closure of identified risks.
  • Regulatory & Examination Readiness
    • Maintain organized, accurate, and examination‑ready security evidence.
    • Support regulatory readiness activities and ensure security controls remain properly documented and defensible.
    • Provide regular updates to leadership regarding security risks, incidents, remediation efforts, and control effectiveness.
Qualifications
  • Required
    • 7+ years of experience in one or more of the following areas: Security Operations; Information Security; Vulnerability Management; GRC / Security Compliance.
    • Experience supporting security programs in regulated or audit‑sensitive environments.
    • Strong understanding of: Alert triage; Access reviews; Vulnerability management; Security control documentation.
    • Hands‑on experience with AWS security services and cloud‑security operations.
    • Experience working with SIEM, MDR, EDR, vulnerability management, identity management, and ticketing platforms.
    • Ability to coordinate effectively across technical teams, business stakeholders, and external partners.
    • Strong documentation, communication, and organizational skills.
  • Preferred
    • Experience within: Banking; Fintech; Payments; Trust companies; Digital asset or custody environments.
    • Familiarity with: OCC examination readiness; FFIEC guidance; NIST CSF; NIST 800-53; SOC 2; GLBA; CIS Controls.
    • Experience supporting AWS multi‑account cloud environments.
    • Exposure to digital assets, blockchain, stablecoins, wallets, custody platforms, or regulated payment systems.
    • Experience supporting Microsoft 365, endpoint security, identity governance, EDR, or SASE technologies.
    • Professional certifications such as: CISSP; CISM; CISA; CCSP; AWS Security Specialty; GIAC; Security+
What Makes This Opportunity Unique
  • Founding-level security leadership role with significant visibility and impact
  • Opportunity to help build security operations and governance programs from the ground up
  • Direct interaction with executive leadership, including CTO/CISO
  • Exposure to regulatory, cloud-security, vendor-risk, and audit‑readiness initiatives
  • Collaborative environment supported by specialized security and compliance partners
  • Remote work flexibility within the United States
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Founding Security Operations & GRC Leader
Founding Security Operations & GRC Leader

Pasona N A, Inc. • United States

On-site
USD 150,000 - 200,000
Senior DevSecOps Engineer
Senior DevSecOps Engineer

Greenboard • New York (NY)

Hybrid
USD 165,000 - 240,000
Salary + equity
401(k) match
Medical/Dental/Vision
+3
Head of Information Security and GRC
Head of Information Security and GRC

Stott and May • New York (NY)

On-site
USD 250,000 - 350,000
Equity
Information Security Engineer (CISO track)
Information Security Engineer (CISO track)

Tangible • United States

Remote
GBP 90,000 - 150,000
Ownership of security program
Fully remote
Learning budget
+1
Senior Security Engineer – Hybrid (4649)
Senior Security Engineer – Hybrid (4649)

Hireclout • Los Angeles (CA)

On-site
USD 180,000 - 200,000
Competitive compensation package
Equity participation
100% covered medical, dental, and vision coverage
+5
Security Operations Engineer
Security Operations Engineer

Yellow Card • Tulsa (OK)

On-site
USD 120,000 - 160,000
Senior Security Engineer, Platforms & AI
Senior Security Engineer, Platforms & AI

Spinwheel Solutions Inc. • Oakland (CA)

On-site
USD 140,000 - 190,000
Remote-First
Salary & Equity
Unlimited PTO
+2
Senior Cloud Security Engineer
Senior Cloud Security Engineer

United States Digital Space LLC • Bellevue (NY)

Hybrid
USD 187,000 - 220,000
Challenging, high-impact work to grow
Bonus programs, equity ownership, and
100% paid health insurance for all
+4
Security GRC Specialist
Security GRC Specialist

Profound • New York (NY)

On-site
USD 150,000 - 240,000
Founding Platform & Security Engineer (AWS / DevOps / SOC 2)
Founding Platform & Security Engineer (AWS / DevOps / SOC 2)

IT Recruitment Solutions • New York (NY)

Hybrid
USD 180,000 - 250,000
Equity
Comprehensive healthcare
401(k)
+1