Lead Security Governance Partner - Risk Management
Listed on 2026-09-03
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Description
The application window will close November 1st, 2026
Job LocationThe primary work location for this role is Berwyn, PA or our Raleigh, NC office with a hybrid work model.
About EnvestnetEnvestnet is an adaptive
Wealth
Tech company that is redefining the future of wealth management byhelpingadvisors meet the moment with its comprehensive technology, actionable insights, and industry leading support.
Backed byover
25 years of experience and approximately $7.0 trillion in platform assets, Envestnet is trusted by over one third of financial advisors across leading banks, wealth managers, brokerages, and RIAs.
For a deeper look at how Envestnet is shaping the future of financial advice, visit
The Team You’ll JoinYou’ll join Envestnet’s Enterprise Cybersecurity team, a collaborative group focused on protecting the organization’s technology, data, and clients through effective security governance and risk management. Working closely with partners across Technology, Product, Infrastructure, Architecture, AI/ML Engineering, Legal, Compliance, and Risk & Assurance, the team identifies and evaluates security risks, strengthens controls, and supports informed business decision-making. In this role, you’ll help advance a consistent, proactive approach to managing cybersecurity risk across applications, cloud platforms, third-party integrations, and emerging technologies.
HowYou'll Contribute
Responsible for ensuring that technology decisions align with business strategy, regulatory requirements and client expectations. Encompasses administration of a strategic and comprehensive cybersecurity framework. Identifies, assesses and mitigates technology and information security risks to protect sensitive financial and client data. Establishes policies, controls and oversight to meet regulatory standards for the financial services and wealth management industry. Enables the company to operate securely, responsibly and at scale while maintaining trust with advisors, partners and regulators.
- Provides Security Governance support and advice company wide.
- Develops, validates, implements and maintains cybersecurity and related policies, standards, guidelines and procedures to ensure compliance with company and regulatory requirements.
- Collaborates with cross-functional teams and leaders to ensure security related controls are understood, documented and managed.
- Coordinates with Legal and across relevant compliance functions to ensure proper implementation of data privacy legislation and disclosure.
- Establishes and maintains the framework and roadmap for Security Governance documentation.
- Works with Cyber Security team members and business partners to define risk tolerance and construct risk scenarios.
- Ensures risk scenarios provide a realistic and relatable view of risks based on business context, system environment and pertinent threats.
- Perform Security Risk Assessments (SRAs) across applications, infrastructure, cloud platforms, third-party integrations, and AI systems to identify threats, vulnerabilities, and business impact, and determine inherent and residual risk levels using established risk taxonomies, scoring methodologies, and impact criteria aligned to enterprise standards.
- Evaluate the design and effectiveness of technical, administrative, and operational security controls against identified risks, partnering with technology, product, infrastructure, architecture, and AI/ML engineering teams to design, recommend, and refine controls that mitigate risk to acceptable levels.
- Operate and leverage continuous risk monitoring tools (e.g., vulnerability management, configuration and cloud posture monitoring) to detect changes in risk posture, and analyze monitoring outputs to identify emerging risks, control degradation, and remediation needs.
- Own the full lifecycle of identified risks — documentation, remediation planning, validation of corrective actions, and risk closure — and produce clear, actionable risk reporting, metrics, and dashboards that communicate severity, trends, and priority issues to Information Security and technology leadership.
- Execute firmwide GRC activities such as RCSAs, risk acceptances and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).