Head of Security GRC
Location: Remote
Compensation: To Be Discussed
Reviewed: Tue, Jul 21, 2026
This job expires in: 29 days
Job Summary
Reporting directly to the CISO, the full-time Head of Security GRC will lead the governance, risk, and compliance program for a regulated broker-dealer environment, ensuring alignment with SEC/FINRA obligations and actively reducing enterprise risk while managing security metrics and incident response capabilities.
Key Responsibilities
- Own and mature the enterprise GRC program, aligning controls to recognized frameworks and ensuring compliance with SEC/FINRA requirements
- Design and maintain a security metrics framework, delivering executive dashboards and board-level reporting on risk posture and program maturity
- Lead the incident response planning and maintain incident runbooks, ensuring preparedness for various high-priority scenarios
Required Qualifications
- 15+ years of experience in information security, risk management, or cybersecurity roles, particularly in a regulated financial-services environment
- Strong understanding of SEC/FINRA regulations applicable to broker-dealers and expertise in global data-protection laws
- Hands-on experience leading GRC programs and managing SOC 1, SOC 2, and ISO 27001 compliance audits
- Proven experience in building security KPIs/KRIs and executive or board-level reporting
- Excellent communication and leadership skills, with the ability to work independently and drive initiatives to completion
COMPLETE JOB DESCRIPTION
The job description is available to subscribers. Subscribe today to get the full benefits of a premium membership with Virtual Vocations. We offer the largest remote database online...