Featured Job

Staff Security Engineer

Austin, TX Full-time Hybrid 10/01/2026 Job ID: 000312
Apply Now
Cyber Governance, Risk & Compliance (GRC) Regulatory readiness Policy management Control assurance Third‑party cyber risk oversight

Summary

What you’ll impact

The Vice President of Cyber Governance, Risk & Compliance leads the cyber GRC function, defining strategy, operating model, and maturity targets while overseeing risk governance, regulatory readiness, and third‑party risk. In addition, as Deputy CISO, the executive supports the CISO in enterprise cybersecurity strategy, represents the CISO in executive and Board forums, and provides leadership continuity during CISO absences.

Responsibilities

What you'll do

  • Lead the cyber GRC function and define strategic roadmap, operating model, and maturity targets.
  • Maintain governance structures supporting cyber risk decision-making, escalation, and executive oversight.
  • Drive cyber risk appetite, exception management, and risk acceptance processes.
  • Oversee cyber and technology risk assessment methodologies and execution.
  • Develop and maintain executive and Board-level cyber risk reporting and metrics.
  • Lead preparation and coordination for regulatory exams, internal/external audits, and customer assessments related to cybersecurity.
  • Oversee control framework management, evidence programs, and issue remediation governance.
  • Own lifecycle management of security policies, standards, and governance documentation.
  • Oversee cyber due diligence and ongoing risk monitoring for third-party vendors, partners, and strategic providers.
  • Build, mentor, and scale a high-performing GRC team.
  • Support the CISO in defining and executing the enterprise cybersecurity strategy.
  • Serve as a strategic advisor to the CISO on cybersecurity risk, organizational priorities, investment decisions, regulatory matters, and emerging threats.
  • Represent the CISO in designated executive, Board, business, technology, regulatory, risk, and governance forums.
  • Help coordinate strategy, priorities, dependencies, and execution across cybersecurity functions.
  • Promote integration among Security Operations, GRC, IAM, Security Engineering, Architecture, Application Security, Threat Intelligence, Incident Response, Fraud, and other relevant capabilities.
  • Participate in cybersecurity strategic planning, budgeting, workforce planning, investment prioritization, and organizational design.
  • Assist in preparing and delivering Board and executive-level cybersecurity reporting.
  • Represent cybersecurity during significant regulatory examinations and interactions when delegated by the CISO.
  • Identify cross-functional gaps and organizational risks and drive accountability for their resolution.
  • Provide leadership continuity for the cybersecurity organization during periods when the CISO is unavailable.
  • Assume additional CISO responsibilities and authorities when specifically delegated.
  • Foster a culture of transparency, accountability, constructive challenge, collaboration, and continuous improvement.
  • Build trusted relationships across Technology, Operations, Product, Legal, Compliance, Risk, Internal Audit, and business leadership

Requirements

What you’ll bring

  • Bachelor’s degree required; advanced degree preferred.
  • 15+ years of experience in cybersecurity, technology risk, audit, compliance, or governance roles.
  • 7+ years of people leadership experience with increasing organizational scope.
  • Proven experience building, transforming, or materially uplifting cyber GRC programs in financial services or similarly regulated industries.
  • Deep knowledge of cybersecurity governance, financial services regulatory expectations, security/control frameworks, audit/regulatory exams, and third-party cyber risk programs.
  • Experience interacting directly with senior executives, Boards, regulators, auditors, and risk committees.
  • Demonstrated understanding of cybersecurity beyond GRC, including security operations, identity, application security, cloud security, incident response, security engineering, architecture, and emerging technology risk.
  • Demonstrated ability to translate cybersecurity and technology risks into business terms and actionable executive decisions.
  • Possesses at least one of the following professional credentials (or other industry-related credential): CISSP, CRISC, CISM, CISA
  • Executive presence and sound judgment
  • Strategic and enterprise-level thinking
  • Strong knowledge of cybersecurity and technology risk
  • Regulatory fluency
  • Transformation and change leadership
  • Ability to influence across organizational boundaries
  • Exceptional executive communication
  • Strong people leadership and organizational development skills
  • Ability to balance appropriate risk governance with business enablement
  • Willingness and ability to challenge constructively while maintaining trusted relationships

Ready to Move Forward?

Apply now and our recruiting team will reach out with next steps, interview guidance, and client insights tailored to this role.