VP, Cybersecurity Governance, Risk and Compliance
Listed on 2026-09-04
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Vice President Of Cybersecurity Governance, Risk & Compliance
A global fintech leader, Acrisure empowers millions of ambitious businesses and individuals with the right solutions to grow boldly forward. Bringing cutting-edge technology and top-tier human support together, we connect clients with customized solutions across a range of insurance, reinsurance, payroll, benefits, cybersecurity, mortgage services – and more.
In the last twelve years, Acrisure has grown in revenue from $38 million to almost $5 billion and employs over 19,000 colleagues in more than 20 countries. Acrisure was built on entrepreneurial spirit. Prioritizing leadership, accountability, and collaboration, we equip our teams to work at the highest levels possible.
We are seeking an experienced Vice President of Cybersecurity Governance, Risk & Compliance to build and lead Acrisure's global cybersecurity governance, risk, and regulatory assurance function, establishing the operating model that translates cybersecurity risk into clear executive decisions and board-level visibility. In this role, you will set and operate the cyber governance model for a fast growing, highly acquisitive international fintech organization, ensuring risks are clearly identified, prioritized, and communicated to executive leadership and the board.
You will own cybersecurity governance, enterprise board-level management, regulatory readiness, audit, and examination response, IT general controls alignment, and security awareness and phishing resilience programs. Working closely with leaders across Cybersecurity, Technology, Legal (privacy), Operations, and Enterprise Risk Management, you will establish a scalable, defensible control environment that meets increasing regulatory and audit expectations while enabling business growth.
This role reports directly to the CISO, operates with enterprise‑level decision authority, and serves as a core member of the cybersecurity leadership team. Success requires deep expertise in cybersecurity risk and compliance within regulated environments, strong executive presence, and the ability to lead through influence in a complex, global, and rapidly evolving organization.
Responsibilities:
- Own the operating cadence for the Cybersecurity Governance Committee (Cyber Gov), including agenda development, pre-read preparation, meeting facilitation, and follow through with decisions and action items. Ensure Cyber Gov functions as an active governance vehicle.
- Own the cybersecurity governance operating model, including policy lifecycle management, standards hierarchy, exception governance, and evidence of adoption.
- Translate executive approved cybersecurity policies into clear, enforceable standards and operating procedures that scale globally.
- Partner with IT and business leaders to ensure cybersecurity standards are embedded into core operating processes.
- Own the enterprise cybersecurity risk management program, including risk identification, scoring, treatment, acceptance, and reporting.
- Maintain the cybersecurity risk register and ensure risks are translated into clear decisions, prioritized remediation plans, and executive ready reporting.
- Partner with Enterprise Risk Management to integrate cyber risk appropriately into broader enterprise risk routines.
- Translate enterprise risk appetite into actionable cybersecurity decision frameworks and risk thresholds.
- Lead cybersecurity compliance readiness across applicable regulatory regimes and expectations, including NYDFS 500, FCA/DORA, and a trajectory toward SOX and SEC audit readiness.
- Continuously monitor regulatory and supervisory changes and drive corresponding enhancements to the cybersecurity program.
- Ensure global consistency in cyber controls while accounting for regional regulatory differences.
- Own the end-to-end cybersecurity audit and examination operating model, including intake, scoping, evidence management, response coordination, issue remediation, and closure.
- Serve as the single point of accountability for all cybersecurity audits and examinations (internal and external).
- Ensure audit outcomes drive sustained control and process improvement.
- Define and align…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).