Head of Security GRC
Ladders · United States · 1 mo ago
RemoteRemoteInformation Technology$270k–$290k/yrFull-time
Responsibilities
- Lead the governance, risk, and compliance (GRC) program and align it with recognized control frameworks
- Maintain the organization's cybersecurity policies, standards, and review cycles
- Conduct risk assessments and manage the information security risk register
- Ensure compliance with complex SEC/FINRA requirements and global data-protection laws
- Manage external audits and examinations related to security compliance
- Establish and run continuous control monitoring and testing to address identified gaps
- Oversee vendor risk management and drive vendor security assessments
Qualifications
- 15+ years of experience in information security, risk management, or cybersecurity roles, particularly in regulated financial services
- Strong understanding of SEC/FINRA regulations applicable to broker-dealers
- Expertise in global data-protection laws, including GDPR, CCPA/CPRA, and LGPD
- Hands-on experience leading governance, risk, and compliance (GRC) programs from inception to execution
- Demonstrated experience with SOC 1, SOC 2, and ISO 27001 compliance audits
- Proven ability to build executive-level KPIs/KRIs and reporting mechanisms
- Excellent communication and leadership skills, capable of operating independently
Benefits
- Competitive compensation package including base salary, equity, and 401(k) match
- Comprehensive medical, dental, and vision insurance
- Generous paid parental leave and wellness reimbursement programs
- Personal development allowance to support continued learning
- Flexible work arrangements with a mix of in-office and remote options