JobBobsReal-time global job discoveryLive

Head of Security GRC

Drivewealth · AMER-US-Remote; Austin, Texas, United States; Dallas, Texas, United States; Denver, Colorado, United States; Miami, Florida, United States; San Francisco, California, United States; Seattle, Washington, United States · 2026-07-21

executiveRemote
Apply on the employer's site

About this role

<div class="content-intro"><p><span style="font-family: helvetica, arial, sans-serif;"><strong><span style="font-size: 14pt;">About Us</span></strong></span></p> <p><span style="font-family: helvetica, arial, sans-serif;">DriveWealth is on a mission to make investing easier. We believe that everyone should have the ability to control their financial future, and that access to financial markets should not be limited by geography, wealth, or legacy systems. We are a global B2B financial technology organization dedicated to democratizing access to financial independence around the world. Our mission is realized through an API-based platform, empowering our partners to offer seamless investing and trading experiences to clients worldwide, all from their mobile devices. Our technology provides partners with a modern, extensible toolkit, enabling traditional investment workflows and innovative techniques like fractional share ownership. DriveWealth has evolved into a global platform offering trading of US equities, mutual funds, ETFs, fixed income, and options.</span></p> <p><span style="font-family: helvetica, arial, sans-serif;">There’s never been a better time to build a category-defining business and there has rarely been a team better positioned for this opportunity. Our culture blends the pace and agility of a fintech start-up with the impact, stability, and discipline of Wall Street. We encourage creativity and experimentation while ensuring institutional-grade execution and regulatory compliance in everything we do. Join us and help build the future of global investing!</span></p></div><h3><span style="font-family: helvetica, arial, sans-serif;"><strong>About The Team</strong></span></h3> <p><span style="font-family: helvetica, arial, sans-serif;">As a FINRA-member, SEC-registered broker-dealer powering brokerage-as-a-service and embedded investing for fintech partners around the world, DriveWealth operates where high-velocity technology meets one of the most heavily regulated industries on the planet. Every partner we onboard, every API we expose, and every trade that flows through our platform carries regulatory, client-trust, and operational-risk weight.</span></p> <p><span style="font-family: helvetica, arial, sans-serif;">We are seeking an experienced, hands-on leader to serve as the connective tissue of our security program—owning governance and risk operations while also acting as a trusted advisor to the CISO and a credible voice with regulators, auditors, and enterprise partners. This is a builder's role: you will mature frameworks, quantify and report risk to executives and the board, stand up threat-intelligence and incident-response capabilities, and run third-party and client due diligence. The ideal candidate thrives with autonomy, drives initiatives to completion with minimal supervision, and can translate deep technical risk into clear business decisions.</span></p> <h3><span style="font-family: helvetica, arial, sans-serif;"><strong>About the Role </strong></span></h3> <p><span style="font-family: helvetica, arial, sans-serif;">Reporting directly to the CISO, the Head of Security GRC is responsible for leading the organization's governance, risk, and compliance program across a regulated broker-dealer environment. The role ensures alignment with SEC/FINRA obligations, global data-protection laws, and leading cybersecurity frameworks, while actively reducing enterprise risk. Beyond traditional GRC, this position owns security metrics and executive/board reporting, cyber threat intelligence, incident-response readiness, and third-party and client cyber due diligence. Success requires an independent, proactive leader who can drive cross-departmental initiatives, interface effectively with regulators and partners, and align security outcomes with business objectives.</span></p> <h3><span style="font-family: helvetica, arial, sans-serif;"><strong>What You'll Do</strong></span></h3> <p><span style="font-family: helvetica, arial, sans-serif;"><strong>Governance, Risk & Compliance (GRC)</strong></span></p> <ul> <li style="font-family: helvetica, arial, sans-serif;"><span style="font-family: helvetica, arial, sans-serif;">Own and mature the enterprise GRC program, aligning controls to recognized frameworks including NIST CSF, NIST 800-53, ISO 27001, SOC 2, and CIS Controls.</span></li> <li style="font-family: helvetica, arial, sans-serif;"><span style="font-family: helvetica, arial, sans-serif;">Maintain and organize the cybersecurity policy, standard, and procedure library, running the annual review cycle and managing control ownership, exceptions, and waivers.</span></li> <li style="font-family: helvetica, arial, sans-serif;"><span style="font-family: helvetica, arial, sans-serif;">Operate the information security risk register: conduct risk assessments, define treatment plans, facilitate risk-acceptance workflows, and track residual risk over time.</span></li> <li style="font-family: helvetica, arial, sans-serif;"><span style="font-family: helvetica, arial, sans-serif;">Ensure compliance with SEC/FINRA requirements, including Regulation S-P (Safeguards & Disposal), Rule 17a-4 recordkeeping, and financial-industry security obligations.</span></li> <li style="font-family: helvetica, arial,…

Skills asked for

Apply on the employer's site

Your next role is already in here.

Search live openings from thousands of employers, save the ones worth a second look, and let JobBob keep watch for the rest.