Head of Security GRC
Job description
Head of Security GRC at DriveWealth
About the role
DriveWealth is seeking a leader to manage its security governance, risk, and compliance functions. This role is crucial for ensuring adherence to financial industry regulations and safeguarding the company's operations. You will be instrumental in building and refining security frameworks, advising leadership on risk, and interacting with regulatory bodies.
Key facts
What you'll do
Develop and enhance the company's overall governance, risk, and compliance program, aligning with frameworks like NIST CSF, NIST 800-53, ISO 27001, SOC 2, and CIS Controls.
Manage the library of security policies, standards, and procedures, overseeing their review and update cycles, and tracking control ownership, exceptions, and waivers.
Operate the information security risk register, conducting assessments, defining mitigation strategies, managing risk acceptance processes, and monitoring residual risk.
Ensure compliance with SEC and FINRA regulations, including requirements for data safeguards, recordkeeping, and general financial industry security obligations.
Oversee external and internal security audits, such as SOC 1, SOC 2 Type II, and ISO 27001, coordinating with auditors, managing evidence collection, and tracking remediation efforts.
Establish and execute control testing and continuous monitoring procedures, driving the closure of identified gaps with relevant control owners.
Develop and implement procedures for annual security due diligence reviews with key partners and vendors.
Maintain and enforce adherence to global data protection laws, including GDPR, CCPA/CPRA, LGPD, and GLBA.
Interpret and implement evolving SEC cybersecurity risk management and incident disclosure rules applicable to registered broker-dealers.
Assess and manage the applicability of regulations like NYDFS 500, PCI DSS, and state breach notification laws to the platform's control environment.
Act as a subject matter expert for security compliance, providing guidance to business units, product teams, and engineering.
Collaborate with Legal, Privacy, and Compliance departments to ensure comprehensive regulatory adherence.
Design and maintain a framework for security metrics, key performance indicators (KPIs), and key risk indicators (KRIs) to measure control effectiveness, risk posture, and program maturity.
Create and present executive dashboards and board-level reports, translating technical risks into clear business and financial impacts.
Track and report on remediation service level agreements (SLAs), risk trends, control maturity progress, and audit finding closure rates.
Prepare reporting packages to support regulatory examinations, partner assurance requests, and internal governance committees.
Continuously refine metrics to enable leadership to make informed decisions regarding risk and investment priorities.
Establish and operate a cyber threat intelligence capability focused on the financial services, broker-dealer, and embedded finance sectors.
Monitor relevant threat actors, campaigns, and tactics, techniques, and procedures (TTPs) using frameworks like MITRE ATT&CK, and utilize industry sources such as FS-ISAC.
Produce strategic, operational, and tactical threat intelligence reports for technical teams and executive stakeholders.
Integrate threat intelligence into risk assessments, control decisions, and incident response readiness to drive prioritized actions based on emerging threats.
Monitor for threats impacting partners and the broader supply chain that could pose downstream risks to clients or the platform.
Own, maintain, and regularly test the Incident Response Plan (IRP), ensuring it reflects the current threat landscape and regulatory requirements.
Develop and maintain incident response playbooks for critical scenarios, including ransomware, business email compromise, account takeover, data exposure, and third-party breaches.
Organize and facilitate tabletop exercises involving security, engineering, legal, compliance, and executive leadership.
Align response procedures with regulatory and contractual notification obligations, such as SEC incident disclosures, Reg S-P breach notifications, state laws, and partner SLAs.
Lead post-incident reviews and lessons-learned sessions, translating findings into improvements for controls and processes.
Manage the third-party risk management program, including vendor assessments and ongoing monitoring.
Requirements
Minimum of 7 years of experience in information security, with at least 4 years focused on Governance, Risk, and Compliance (GRC) within a regulated financial services environment.
Demonstrated experience in building and maturing GRC programs from the ground up.
Deep understanding of financial industry regulations, including SEC and FINRA rules.
Proficiency with common cybersecurity frameworks such as NIST CSF, NIST 800-53, ISO 27001, SOC 2, and CIS Controls.
Experience managing security audits and examinations.
Proven ability to develop and present security metrics and risk reports to executive leadership and boards.
Experience in establishing and operating a threat intelligence function.
Familiarity with incident response planning and execution.
Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent practical experience.
Nice to have
Experience with cloud security GRC in AWS, Azure, or GCP environments.
Familiarity with security requirements for payment processing (e.g., PCI DSS).
Experience with international data privacy regulations beyond GDPR and CCPA.
Skills & tools
NIST CSF, NIST 800-53, ISO 27001, SOC 2, CIS Controls, MITRE ATT&CK, FS-ISAC, GRC platforms, Risk assessment methodologies, Incident response planning, Threat intelligence platforms.
Practical notes
DriveWealth offers competitive compensation and benefits.
Visa sponsorship is not available for this position.
Applications will be reviewed on a rolling basis.