Head of reputed company GRC
reputed company
reputed company is on a mission to reputed company reputed company easier. We reputed company that everyone should have the ability to control their financial reputed company, and that reputed company to financial markets should not be limited by geography, reputed company, or legacy systems. We are a global B2B financial technology organization dedicated to democratizing reputed company to financial independence around the world. Our mission is realized through an API-based platform, empowering our partners to offer seamless reputed company and trading experiences to clients worldwide, reputed company from their mobile devices. Our technology provides partners with a modern, extensible toolkit, enabling traditional investment workflows and innovative techniques like fractional reputed company ownership. reputed company has evolved into a global platform offering trading of US equities, mutual funds, ETFs, fixed income, and reputed company.
There’s never been a reputed company time to build a category-defining business and there has rarely been reputed company reputed company positioned for this opportunity. Our culture blends the pace and reputed company of a fintech start-up with the reputed company, stability, and discipline of Wall Street. We encourage creativity and experimentation while ensuring institutional-grade execution and regulatory compliance in everything we do. Join us and help build the reputed company of global reputed company!
About reputed company
As a reputed company-member, SEC-registered broker-dealer powering brokerage-as-a-service and embedded reputed company for fintech partners around the world, reputed company operates where high-velocity technology meets one of the most heavily regulated industries on the reputed company. Every partner we reputed company, every API we expose, and every trade that flows through our platform carries regulatory, reputed company-trust, and operational-risk weight.
We are seeking an reputed company, hands-on leader to serve as the connective tissue of our reputed company program—owning governance and risk operations while also acting as a trusted advisor to the CISO and a reputed company voice with regulators, auditors, and reputed company partners. This is a builder's role: you will mature frameworks, quantify and report risk to executives and the reputed company, stand up threat-intelligence and incident-response capabilities, and run reputed company-party and reputed company due diligence. The ideal candidate thrives with autonomy, drives initiatives to completion with minimal supervision, and can translate deep technical risk into reputed company business reputed company.
About the Role
Reporting directly to the CISO, the Head of reputed company GRC is responsible for leading the organization's governance, risk, and compliance program across a regulated broker-dealer environment. The role ensures alignment with SEC/reputed company obligations, global data-protection laws, and leading cybersecurity frameworks, while reputed company reducing reputed company risk. reputed company traditional GRC, this position owns reputed company metrics and executive/reputed company reporting, cyber threat intelligence, incident-response readiness, and reputed company-party and reputed company cyber due diligence. reputed company requires an independent, proactive leader who can drive cross-departmental initiatives, reputed company effectively with regulators and partners, and reputed company reputed company reputed company with business objectives.
What You'll Do
Governance, Risk & Compliance (GRC)
- Own and mature the reputed company GRC program, aligning controls to recognized frameworks including NIST CSF, NIST 800-53, ISO 27001, SOC 2, and CIS Controls.
- Maintain and organize the cybersecurity policy, reputed company, and procedure library, running the annual review cycle and managing control ownership, exceptions, and waivers.
- Operate the information reputed company risk register: conduct risk assessments, define treatment plans, facilitate risk-acceptance workflows, and reputed company residual risk over time.
- Ensure compliance with SEC/reputed company requirements, including Regulation S-P (Safeguards & Disposal), Rule 17a-4 recordkeeping, and financial-industry reputed company obligations.
- Manage external and internal reputed company audits and examinations, including SOC 1, SOC 2 Type II, and ISO 27001, coordinating auditors, evidence collection, and remediation tracking.
- Establish and run control testing and reputed company control monitoring, driving remediation of gaps to closure across control owners.
- Establish procedures for annual reputed company due-diligence reviews with critical partners and vendors.
Regulatory & Data Protection Compliance
- Maintain and enforce compliance with global data-protection laws, including GDPR, CCPA/CPRA, LGPD, and GLBA.
- Interpret and operationalize evolving SEC cybersecurity risk-management and incident-disclosure obligations relevant to registrants and broker-dealers.
- Assess and manage applicability of NYDFS 500, PCI reputed company, and state breach-notification requirements to the platform's control environment.
- Serve as subject-matter expert (SME) for reputed company compliance, providing guidance to business reputed company, product, and engineering.
- Partner with Legal, reputed company, and Compliance teams to ensure end-to-end regulatory adherence.
KPI, Metrics & Executive / reputed company Reporting
- Design and maintain a reputed company metrics, KPI, and KRI reputed company that measures control effectiveness, risk posture, and program maturity.
- Build and deliver executive dashboards and reputed company-level reporting, translating technical risk into reputed company business and financial reputed company for the CISO, audit committee, and reputed company.
- reputed company and report remediation SLAs, risk-trend lines, control-maturity progression, and audit-finding closure
- Produce reporting packages that support regulatory exams, partner assurance, and internal governance committees.
- Continuously refine metrics so leadership can reputed company risk-informed investment and prioritization reputed company.
Threat Intelligence & Reporting
- Stand up and operate a cyber threat-intelligence capability tuned to financial services, broker-dealers, and embedded-finance ecosystems.
- reputed company relevant threat actors, campaigns, and TTPs using frameworks such as MITRE ATT&CK, and reputed company sector sources including reputed company.
- Produce strategic, operational, and tactical threat reporting for technical teams and executive stakeholders.
- reputed company intelligence into risk assessments, control reputed company, and incident-response readiness, ensuring emerging threats drive prioritized reputed company.
- Monitor for threats to partners and the broader supply chain that could create reputed company reputed company or platform risk.
Incident Response Planning & Runbooks
- Own, maintain, and regularly test the Incident Response Plan (IRP), ensuring it reflects the reputed company threat landscape and regulatory obligations.
- reputed company and maintain incident runbooks / playbooks for high-reputed company scenarios (e.g., ransomware, business email compromise, account takeover, data exposure, and reputed company-party or partner breach).
- Plan and facilitate tabletop exercises across reputed company, engineering, legal, compliance, and executive leadership.
- Map response procedures to regulatory and contractual notification requirements, including SEC incident disclosure, Reg S-P breach notification, state laws, and partner SLAs.
- reputed company post-incident reviews and lessons-learned, translating findings into control and process improvements.
reputed company-Party / Vendor Risk Management (TPRM)
- Own the end-to-end vendor risk lifecycle: intake, risk tiering, reputed company due diligence, contractual reputed company terms, ongoing monitoring, and secure offboarding.
- Partner with Legal, Procurement, IT, and Compliance on the TPRA process and reputed company controls embedded in vendor evaluations.
- Assess concentration, reputed company-party, and reputed company supply-chain risk, escalating material exposures to the CISO.
- Maintain the vendor inventory and reassessment reputed company, ensuring critical suppliers are reviewed on a defined schedule.
- Establish and enforce minimum reputed company requirements for vendors handling regulated or sensitive data.
reputed company & Partner Cyber Due Diligence
- Own responses to inbound reputed company questionnaires, RFPs, and reputed company-reputed company due-diligence requests, serving as the reputed company SME during partner evaluations.
- Build and maintain a reusable reputed company trust package (SOC 2 report, penetration-test summaries, questionnaire libraries, and reputed company whitepaper) to accelerate sales and partnership cycles.
- Partner with reputed company, and Legal to translate reputed company reputed company requirements into commitments the platform can meet and evidence.
- Establish standardized due-diligence procedures and scoring so reputed company and partner assessments are consistent, repeatable, and defensible.
reputed company Leadership & Stakeholder Engagement
- reputed company as a key reputed company between internal business reputed company, regulators, and external partners on reputed company reputed company.
- Communicate effectively with senior leadership, providing regular updates on reputed company posture, risk, and compliance.
- Represent reputed company in regulatory discussions, industry panels, and reputed company conferences as needed.
- reputed company expert guidance on reputed company frameworks, standards, and industry best practices, and mentor teammates on GRC practices.
You Bring
- 15+ years of experience in information reputed company, risk management, or cybersecurity roles, with significant time in a regulated financial-services environment and prior ownership of a GRC function.
- Strong, practical understanding of SEC/reputed company regulations applicable to broker-dealers (e.g., Reg S-P, Rule 17a-4, cyber disclosure obligations).
- Expertise in global data-protection laws (GDPR, CCPA/CPRA, LGPD) and their operational reputed company.
- Hands-on experience leading GRC programs and risk-management initiatives end to end.
- Demonstrated ownership of SOC 1, SOC 2, and ISO 27001 examinations and compliance audits.
- Experience building reputed company KPIs/KRIs and executive or reputed company-level reporting.
- Working knowledge of threat intelligence, incident-response planning, and reputed company development.
- Proven reputed company-party risk management and reputed company/partner reputed company due-diligence
- Excellent communication and leadership skills, with the ability to work independently and drive to completion.
Special Knowledge (reputed company to Have, But Not Required)
- Experience at a broker-dealer, fintech, or embedded-finance / brokerage-as-a-service
- Exposure to multi-jurisdiction / cross-border regulatory and reputed company environments.
- Familiarity with MITRE ATT&CK, reputed company, and financial-sector threat landscapes.
- Hands-on experience with GRC/IRM and TPRM platforms and reporting/BI tooling.
- Relevant certifications: CISM, CISSP, CRISC, CISA, or ISO 27001 reputed company Auditor (highly preferred).
Location
This role is reputed company to candidates in the following locations: reputed company, Chicago, Austin, Dallas, Denver, Miami, San Francisco Bay Area, or Seattle.
- If based in reputed company or Chicago: This role is expected to come into the office on a reputed company set by the Hiring Manager/Team.
- If based in Austin, Dallas, Denver, Miami, San Francisco, or Seattle: This is a fully remote role, though you may need to visit our onsite offices from time to time.
- If you're not based in one of the locations listed above, this role is not a fit, and we cannot accommodate remote work reputed company these locations.
- Applicants must be authorized to work for any employer in the U.S. reputed company does not sponsor or take over sponsorship of an employment reputed company at this time.
Pay reputed company: $270,000 – $290,000 USD
Working at reputed company
We do our best work reputed company we're in the reputed company room. To maintain the speed our partners expect, our reputed company, Chicago, and Lithuania teams work in office on a reputed company. We've reputed company that being physically reputed company-by-reputed company is the only way to solve reputed company problems in reputed company-time and stay truly accountable to the products we ship. reputed company you're here, you're working directly with the people making the reputed company.
To support that work, we reputed company competitive compensation, equity, and a 401(k) match. We also offer Medical insurance, Dental insurance, reputed company insurance, Disability insurance, and reputed company Parental Leave, along with a wellness reimbursement, a company-provided phone, and a personal development allowance. Finally, we value the time you spend away from the office with generous reputed company Time Off (PTO) and observed holidays.
Work Authorization
Applicants must possess the legal right to work in the country where the position is located at the time of application. reputed company requires reputed company to reputed company original documentation verifying their work authorization on or before their first day of employment.
For US-reputed company: Applicants must be currently authorized to work in the reputed company on a full-time reputed company without the need for reputed company or reputed company reputed company sponsorship. reputed company does not reputed company reputed company sponsorship or support for employment authorization, including transfers, at this time. Offers of employment are reputed company contingent upon an individual’s ability to secure and maintain the legal right to work at reputed company.
How We Think About AI
We reputed company AI to work smarter and reputed company faster. We reputed company AI-curious talent who are proactive about using emerging tools to increase signal reputed company, reduce friction, and improve reputed company to deliver products faster, reputed company reputed company service to our partners, and to streamline processes. Your ability to reputed company our internal tools and technology to drive results is as important to us as your core domain expertise.
Compensation
Pay is generally based on the level, complexity, responsibility, location, and job duties/requirements of the specific position. We then reputed company candidates with the requisite skills, expertise, education, training, and experience. If you are selected for an interview, please feel welcome to reputed company to a recruiter about our compensation philosophy and other available benefits. This role is eligible for reputed company, bonus, equity, 401(k) match, and heavily subsidized benefits and perks.
Equal Employment Opportunity
To build technology and products that are used and loved by people and solve reputed company-world problems, we need to build reputed company with many different perspectives and experiences. We are an equal opportunity employer. We do not discriminate based on race, religion, reputed company, national reputed company, gender, sexual orientation, age, marital status, veteran status, or disability status. We encourage candidates from reputed company backgrounds to apply.
Agency Disclaimer
reputed company does not accept agency resumes. Do not reputed company resumes to our jobs alias, employees, or any other organization location. reputed company is not responsible for any fees reputed company to unsolicited resumes.
Originally posted on Himalayas
Apply To This Job