We are seeking an experienced Lead GRC & Security Governance professional to build and lead the governance frameworks that strengthen technology risk management, security assurance, and operational resilience. In this senior individual contributor role, you will establish practical, scalable systems that help Security, IT, Engineering, and Data teams manage risk, demonstrate control effectiveness, and maintain audit readiness. You will take ownership of technology risk registers, control inventories, compliance programs, and governance processes spanning change management, incident response, and business continuity. Working closely with technical leaders, Legal, Internal Audit, and external assessors, you will translate complex requirements into clear responsibilities, measurable controls, and actionable risk decisions. You will also explore AI and automation to streamline governance workflows while maintaining appropriate oversight and data protection. This is an opportunity to build a new governance function within a growing, publicly traded financial technology environment. The ideal candidate combines strong technical understanding, sound risk judgment, and the confidence to influence stakeholders while balancing business agility with effective controls.
Build and lead the technology governance program: Establish and operate a comprehensive governance framework covering technology and cybersecurity risk, IT controls, change management, incident management, business continuity, and security policies.
Develop and maintain the control inventory: Define and manage a centralized inventory of technology controls, including control owners, evidence requirements, operating schedules, exception processes, and escalation pathways.
Own audit readiness and assurance: Lead technology assurance activities across SOC 2, SOX IT General Controls (ITGC), PCI, and other applicable compliance frameworks. Coordinate evidence collection, support control testing, identify deficiencies, and maintain accountability for remediation through resolution.
Manage technology and cybersecurity risks: Own the technology and cyber risk register, assess risk exposure and materiality, document control exceptions, and communicate significant or persistent risks to the appropriate decision-makers with clear context and recommendations.
Strengthen control accountability: Establish clear expectations for control owners and technical teams while ensuring remediation responsibilities remain with the teams best positioned to address identified issues.
Govern change and incident management: Define practical policies and oversight processes for technology changes, security incidents, and operational disruptions, ensuring procedures are consistently followed, tested, and improved.
Oversee business continuity and resilience: Establish and maintain governance requirements that support operational continuity, preparedness, and effective recovery from technology or business disruptions.
Leverage AI and automation: Identify and implement appropriate AI-assisted and automated workflows for evidence analysis, control mapping, policy maintenance, risk reporting, audit preparation, and remediation tracking, with suitable human review and data safeguards.
Partner across technical and business functions: Collaborate with Security, IT, Engineering, Site Reliability Engineering (SRE), Data, Compliance, Legal, Internal Audit, and external assessors to align governance requirements with operational realities.
Escalate material risks effectively: Exercise independent judgment to identify significant control weaknesses, challenge insufficient responses, and ensure material risks receive appropriate visibility and timely decisions, even when stakeholders disagree.
Build scalable governance processes: Develop clear documentation, reporting structures, decision records, action plans, and performance indicators that support accountability and adapt as the organization grows.
Drive continuous improvement: Evaluate the effectiveness of governance processes, incorporate stakeholder feedback, and refine the operating model to ensure controls remain practical, proportionate, and sustainable.