Security & Risk Leader — Compliance, IR & Strategy

Jobtailor

New York (NY)

On-site

USD 150,000 - 210,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Jobtailor is seeking an experienced information security and GRC leader in New York to build and own the enterprise risk program across security, regulatory, and vendor risk. You will drive audits, policy, and awareness training, ensuring audit-ready operations for all entities.

You will own SOC 2, ISO 27001, and related frameworks, coordinate auditors and third-party assessments, and design incident response and ISMS documentation. A strong track record in fintech or B2B SaaS is preferred.

Qualifications

  • 7–10 years of information security, risk, GRC, or compliance operations with ownership.
  • Hands-on knowledge of compliance frameworks (SOC 2, ISO 27001, and others).
  • Experience implementing and managing GRC automation tools and audits.

Responsibilities

  • Build M0’s enterprise risk program from scratch across security, operational, regulatory, and counterparty risk.
  • Own M0's compliance posture across SOC 2, ISO 27001, and other frameworks—drive policy, audits, and vendor risk.
  • Design and maintain incident response, ISMS docs, and security policies; manage external security vendor relationships.
  • Coordinate security due diligence for partners and respond to questionnaires with reusable documentation.
  • Design and own security awareness training; foster a proactive security culture across teams.

Skills

Information security
GRC
Compliance operations
Risk management
Audits
Security controls
BCP/DR planning
Vendor risk
ISO 27001
SOC 2

Tools

Vanta
Drata
AWS

Job description

Jobtailor is seeking an experienced information security and GRC leader in New York to build and own the enterprise risk program across security, regulatory, and vendor risk. You will drive audits, policy, and awareness training, ensuring audit-ready operations for all entities.

You will own SOC 2, ISO 27001, and related frameworks, coordinate auditors and third-party assessments, and design incident response and ISMS documentation. A strong track record in fintech or B2B SaaS is preferred.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Director of Cybersecurity & GRC Strategy
Director of Cybersecurity & GRC Strategy

Jobtailor • San Francisco (CA)

On-site
USD 180,000 - 240,000
Risk & Compliance Leader - Security GRC & Audits
Risk & Compliance Leader - Security GRC & Audits

Applied Intuition • United States

Hybrid
USD 160,000 - 190,000
Health insurance
Dental insurance
Vision insurance
+6
Senior Security GRC Leader (Risk & Compliance)
Senior Security GRC Leader (Risk & Compliance)

Applied Intuition • Sunnyvale (CA)

On-site
USD 180,000 - 260,000
Head of Information Security and GRC
Head of Information Security and GRC

Stott and May • New York (NY)

On-site
USD 250,000 - 350,000
Equity
Technology Risk Strategist
Technology Risk Strategist

Jobtailor • Alabama

On-site
USD 90,000 - 130,000
GRC Intern: Build Risk, Compliance & Governance
GRC Intern: Build Risk, Compliance & Governance

Jobtailor • Center Square (PA)

On-site
USD 35,000 - 52,000
Chief Compliance & Risk Program Leader
Chief Compliance & Risk Program Leader

Jobtailor • Illinois

On-site
USD 120,000 - 190,000
Enterprise Tech GRC Lead: AI & Data Governance
Enterprise Tech GRC Lead: AI & Data Governance

Jobtailor • California (MO)

On-site
USD 120,000 - 190,000
Senior Cybersecurity Risk Advisor for Financial Services
Senior Cybersecurity Risk Advisor for Financial Services

Jobtailor • California (MO)

On-site
USD 120,000 - 180,000
Strategic GRC Lead - Risk & Compliance Expert
Strategic GRC Lead - Risk & Compliance Expert

Request Technology, LLC • Austin (TX)

On-site
USD 120,000 - 160,000