DriveWealth

Head of Security Governance, Risk, and Compliance (GRC)

DriveWealth

United States (Hybrid) · Full Time

Be the first to apply

Experience
15+ yrs
Salary
USD 270,000 – USD 290,000 / year
Openings
1
Posted
6 days ago
Work mode
Hybrid
Eligibility
Candidates must be legally authorized to work in the United States without current or future visa sponsorship and reside within specified metropolitan areas. This role cannot support remote work from other locations.
Resume
Required to apply

Where you'll work

Job description

Company Overview

DriveWealth is dedicated to simplifying investing by empowering individuals globally to manage their financial futures regardless of geography or wealth status. As a fintech leader offering API-driven platforms for seamless investing and trading, DriveWealth enables partners to provide mobile-first access to US equities, mutual funds, ETFs, fixed income, and options. Combining a fintech startup agility with the rigor of Wall Street, we prioritize innovation, creativity, and strict regulatory compliance.

Team Context

Operating as a FINRA-member, SEC-registered broker-dealer, DriveWealth navigates high-velocity technology within intensely regulated financial environments. The security program is crucial for managing regulatory risk and building trusted partnerships worldwide.

Role Summary

The Head of Security GRC leads the governance, risk, and compliance efforts across the regulated broker-dealer landscape, reporting directly to the CISO. This position is responsible for maturing security frameworks, risk management, compliance with SEC/FINRA regulations and global data-protection laws, and championing security metrics and reporting at executive and board levels. The role also develops threat intelligence, incident response readiness, and oversees third-party and client security due diligence.

Primary Responsibilities

  • Lead and improve the enterprise GRC program, aligning policies and controls to standards such as NIST CSF, NIST 800-53, ISO 27001, SOC 2, and CIS Controls.
  • Manage the cybersecurity policy documents, including annual review, control ownership, exceptions, and waivers.
  • Maintain information security risk registers by conducting assessments, defining treatment plans, and tracking residual risks.
  • Ensure adherence to SEC/FINRA security obligations including Regulation S-P and recordkeeping rules.
  • Coordinate for internal and external audits such as SOC 1, SOC 2 Type II, and ISO 27001, including evidence gathering and remediation.
  • Implement continuous control monitoring and testing to close compliance gaps effectively.
  • Oversee annual security due diligence for key partners and vendors.
  • Maintain compliance with global privacy laws like GDPR, CCPA/CPRA, LGPD, and GLBA; interpret and implement evolving SEC cybersecurity risk and disclosure obligations.
  • Evaluate and address regulatory requirements such as NYDFS 500, PCI DSS, and state breach laws relevant to platform controls.
  • Provide security compliance expertise and collaborate across Legal, Privacy, and Compliance teams.
  • Develop security KPIs, KRIs, and reporting frameworks to measure risk and control effectiveness for leadership and board presentations.
  • Deliver clear, actionable executive dashboards and regulatory reporting that aids governance and risk-informed decisions.
  • Develop and operate cyber threat intelligence capabilities tailored to financial services and broker-dealer threats using frameworks like MITRE ATT&CK and sector sources.
  • Maintain incident response plans and runbooks for critical scenarios, lead tabletop exercises, and ensure compliance with notification regulations.
  • Administer third-party risk management processes including security assessments, contract security terms, ongoing monitoring, and offboarding.
  • Lead client and partner security due diligence efforts, managing questionnaires, RFP responses, and maintaining reusable trust packages.
  • Serve as key liaison among internal teams, regulators, and external partners, and represent DriveWealth in relevant industry forums.

Candidate Profile

  • 15+ years of experience in information security, risk management, or cybersecurity, particularly within regulated financial services sectors.
  • In-depth knowledge of SEC/FINRA regulations affecting broker-dealers, such as Reg S-P, Rule 17a-4, and cyber risk disclosure mandates.
  • Proficient understanding of global data-protection legislation and its application in operational contexts.
  • Proven track record in independently managing a GRC function and executing risk management programs.
  • Experienced with SOC 1, SOC 2, and ISO 27001 compliance and certification efforts.
  • Strong background in developing and communicating security performance metrics to high-level stakeholders.
  • Familiar with threat intelligence practices and incident response planning and execution.
  • Skilled in managing third-party risk and client cyber due diligence procedures.
  • Excellent communication and leadership skills with the ability to work autonomously and drive initiatives to completion.

Preferred Qualifications

  • Background in broker-dealer, fintech, embedded finance, or brokerage-as-a-service settings.
  • Experience with cross-border regulatory and privacy frameworks.
  • Familiarity with MITRE ATT&CK, FS-ISAC, and industry-specific threat environments.
  • Hands-on use of GRC/IRM platforms and business intelligence tools.
  • Certifications such as CISM, CISSP, CRISC, CISA, or ISO 27001 Lead Auditor are highly valued.

Location & Work Arrangement

This position is open to applicants located in New York City, Chicago, Austin, Dallas, Denver, Miami, San Francisco Bay Area, or Seattle. Candidates in New York or Chicago are expected to work in-office intermittently, while those in other locations will work fully remotely with occasional office visits. Applicants must be authorized to work in the U.S. with no visa sponsorship provided by the company.

Compensation & Benefits

The annual salary range for this role is $270,000 to $290,000 USD. DriveWealth offers competitive pay, equity opportunities, 401(k) matching, comprehensive medical, dental, vision, and disability insurance, paid parental leave, wellness reimbursements, a company phone, professional development allowances, and generous paid time off alongside observed holidays.

Work Authorization

Applicants must have valid authorization to work legally in the United States at the time of application and employment commencement. DriveWealth does not provide visa sponsorship or transfer services.

Leave it if you'd like a reply — we won't use it for anything else.

Click to browse, drag & drop, or paste a screenshot

PNG, JPG, GIF, MP4, WebM, MOV · Max 20MB each · Up to 5 files

🤖
Online · instant AI help