Head of Security GRC
About the role
The Head of Security GRC is responsible for leading the organization's governance, risk, and compliance program across a regulated broker-dealer environment. The role ensures alignment with SEC/FINRA obligations, global data-protection laws, and leading cybersecurity frameworks, while actively reducing enterprise risk.
Responsibilities
- Own and mature the enterprise GRC program, aligning controls to recognized frameworks including NIST CSF, NIST 800-53, ISO 27001, SOC 2, and CIS Controls.
- Maintain and organize the cybersecurity policy, standard, and procedure library, running the annual review cycle and managing control ownership, exceptions, and waivers.
- Operate the information security risk register: conduct risk assessments, define treatment plans, facilitate risk-acceptance workflows, and track residual risk over time.
- Ensure compliance with SEC/FINRA requirements, including Regulation S-P (Safeguards & Disposal), Rule 17a-4 recordkeeping, and financial-industry security obligations.
- Manage external and internal security audits and examinations, including SOC 1, SOC 2 Type II, and ISO 27001, coordinating auditors, evidence collection, and remediation tracking.
- Establish and run control testing and continuous control monitoring, driving remediation of gaps to closure across control owners.
- Establish procedures for annual security due-diligence reviews with critical partners and vendors.
- Maintain and enforce compliance with global data-protection laws, including GDPR, CCPA/CPRA, LGPD, and GLBA.
- Interpret and operationalize evolving SEC cybersecurity risk-management and incident-disclosure obligations relevant to registrants and broker-dealers.
- Assess and manage applicability of NYDFS 500, PCI DSS, and state breach-notification requirements to the platform's control environment.
- Partner with Legal, Privacy, and Compliance teams to ensure end-to-end regulatory adherence.
- Design and maintain a security metrics, KPI, and KRI framework that measures control effectiveness, risk posture, and program maturity.
- Build and deliver executive dashboards and board-level reporting, translating technical risk into clear business and financial impact for the CISO, audit committee, and board.
- Track and report remediation SLAs, risk-trend lines, control-maturity progression, and audit-finding closure.
- Continuously refine metrics so leadership can make risk-informed investment and prioritization decisions.
- Stand up and operate a cyber threat-intelligence capability tuned to financial services, broker-dealers, and embedded-finance ecosystems.
- Produce strategic, operational, and tactical threat reporting for technical teams and executive stakeholders.
- Integrate intelligence into risk assessments, control decisions, and incident-response readiness, ensuring emerging threats drive prioritized action.
- Monitor for threats to partners and the broader supply chain that could create downstream client or platform risk.
- Own, maintain, and regularly test the Incident Response Plan (IRP), ensuring it reflects the current threat landscape and regulatory obligations.
- Develop and maintain incident runbooks / playbooks for high-priority scenarios (e.g., ransomware, business email compromise, account takeover, data exposure, and third-party or partner breach).
- Plan and facilitate tabletop exercises across security, engineering, legal, compliance, and executive leadership.
- Map response procedures to regulatory and contractual notification requirements, including SEC incident disclosure, Reg S-P breach notification, state laws, and partner SLAs.
- Lead post-incident reviews and lessons-learned, translating findings into control and process improvements.
- Own the end-to-end vendor risk lifecycle: intake, risk tiering, security due diligence, contractual security terms, ongoing monitoring, and secure offboarding.
- Partner with Legal, Procurement, IT, and Compliance on the TPRA process and security controls embedded in vendor evaluations.
- Assess concentration, fourth-party, and SaaS supply-chain risk, escalating material exposures to the CISO.
- Maintain the vendor inventory and reassessment cadence, ensuring critical suppliers are reviewed on a defined schedule.
- Establish and enforce minimum security requirements for vendors handling regulated or sensitive data.
- Own responses to inbound security questionnaires, RFPs, and enterprise-client due-diligence requests, serving as the security SME during partner evaluations.
- Partner with Sales, Partnerships, and Legal to translate client security requirements into commitments the platform can meet and evidence.
- Establish standardized due-diligence procedures and scoring so client and partner assessments are consistent, repeatable, and defensible.
- Act as a key liaison between internal business units, regulators, and external partners on security matters.
- Communicate effectively with senior leadership, providing regular updates on security posture, risk, and compliance.
- Represent the company in regulatory discussions, industry panels, and security conferences as needed.
- Provide expert guidance on security frameworks, standards, and industry best practices, and mentor teammates on GRC practices.
Requirements
15+ years of experience in information security, risk management, or cybersecurity roles, with significant time in a regulated financial-services environment and prior ownership of a GRC function.
Strong, practical understanding of SEC/FINRA regulations applicable to broker-dealers (e.g., Reg S-P, Rule 17a-4, cyber disclosure obligations).
Expertise in global data-protection laws (GDPR, CCPA/CPRA, LGPD) and their operational impact.
Demonstrated ownership of SOC 1, SOC 2, and ISO 27001 examinations and compliance audits.
Experience building security KPIs/KRIs and executive or board-level reporting.
Working knowledge of threat intelligence, incident-response planning, and runbook development.
Proven third-party risk management and client/partner security due-diligence.
Excellent communication and leadership skills, with the ability to work independently and drive to completion.
Special Knowledge (Nice to Have, But Not Required):
- Experience at a broker-dealer, fintech, or embedded-finance / brokerage-as-a-service.
- Exposure to multi-jurisdiction / cross-border regulatory and privacy environments.
- Familiarity with MITRE ATT&CK, FS-ISAC, and financial-sector threat landscapes.
- Hands-on experience with GRC/IRM and TPRM platforms and reporting/BI tooling.
- Relevant certifications: CISM, CISSP, CRISC, CISA, or ISO 27001 Lead Auditor (highly preferred).