Head of Security GRC
Listed on 2026-07-24
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Head Of Security GRC
Drive Wealth is on a mission to make investing easier. We believe that everyone should have the ability to control their financial future, and that access to financial markets should not be limited by geography, wealth, or legacy systems. We are a global B2B financial technology organization dedicated to democratizing access to financial independence around the world. Our mission is realized through an API-based platform, empowering our partners to offer seamless investing and trading experiences to clients worldwide, all from their mobile devices.
Our technology provides partners with a modern, extensible toolkit, enabling traditional investment workflows and innovative techniques like fractional share ownership. Drive Wealth has evolved into a global platform offering trading of US equities, mutual funds, ETFs, fixed income, and options.
There's never been a better time to build a category-defining business and there has rarely been a team better positioned for this opportunity. Our culture blends the pace and agility of a fintech start-up with the impact, stability, and discipline of Wall Street. We encourage creativity and experimentation while ensuring institutional-grade execution and regulatory compliance in everything we do. Join us and help build the future of global investing!
AboutThe Role
Reporting directly to the CISO, the Head of Security GRC is responsible for leading the organization's governance, risk, and compliance program across a regulated broker-dealer environment. The role ensures alignment with SEC/FINRA obligations, global data-protection laws, and leading cybersecurity frameworks, while actively reducing enterprise risk. Beyond traditional GRC, this position owns security metrics and executive/board reporting, cyber threat intelligence, incident-response readiness, and third-party and client cyber due diligence.
Success requires an independent, proactive leader who can drive cross-departmental initiatives, interface effectively with regulators and partners, and align security outcomes with business objectives.
Governance, Risk & Compliance (GRC)
- Own and mature the enterprise GRC program, aligning controls to recognized frameworks including NIST CSF, NIST 800-53, ISO 27001, SOC 2, and CIS Controls.
- Maintain and organize the cybersecurity policy, standard, and procedure library, running the annual review cycle and managing control ownership, exceptions, and waivers.
- Operate the information security risk register: conduct risk assessments, define treatment plans, facilitate risk-acceptance workflows, and track residual risk over time.
- Ensure compliance with SEC/FINRA requirements, including Regulation S-P (Safeguards & Disposal), Rule 17a-4 recordkeeping, and financial-industry security obligations.
- Manage external and internal security audits and examinations, including SOC 1, SOC 2 Type II, and ISO 27001, coordinating auditors, evidence collection, and remediation tracking.
- Establish and run control testing and continuous control monitoring, driving remediation of gaps to closure across control owners.
- Establish procedures for annual security due-diligence reviews with critical partners and vendors.
Regulatory & Data Protection Compliance
- Maintain and enforce compliance with global data-protection laws, including GDPR, CCPA/CPRA, LGPD, and GLBA.
- Interpret and operationalize evolving SEC cybersecurity risk-management and incident-disclosure obligations relevant to registrants and broker-dealers.
- Assess and manage applicability of NYDFS 500, PCI DSS, and state breach-notification requirements to the platform's control environment.
- Serve as subject-matter expert (SME) for security compliance, providing guidance to business units, product, and engineering.
- Partner with Legal, Privacy, and Compliance teams to ensure end-to-end regulatory adherence.
KPI, Metrics & Executive / Board Reporting
- Design and maintain a security metrics, KPI, and KRI framework that measures control effectiveness, risk posture, and program maturity.
- Build and deliver executive dashboards and board-level reporting, translating technical risk into clear business and financial…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).