Security GRC Lead
Listed on 2026-01-03
-
IT/Tech
Cybersecurity, Information Security
Bridgewater Associates is a premier asset management firm, focused on delivering unique insight and partnership for the most sophisticated global institutional investors.
Our investment process is driven by a tireless pursuit to understand how the world’s markets and economies work — using cutting edge technology to validate and execute on timeless and universal investment principles.
Founded in 1975, we are a community of independent thinkers who share a commitment to excellence. By fostering a culture of openness, transparency, and inclusion, we strive to unlock the most complex questions in investment strategy, management, and corporate culture.
Explore more information about Bridgewater on our website here .
Our Culture
Our culture is anchored in excellence, meaning constant improvement, and it is deeply tied to our mission.
Because markets are objective, competitive, and getting smarter everyday—we need to keep rapidly improving to have any chance of beating them. Truth is our most essential tool for engaging with the markets and constantly improving.
Because once you know what s true about your problems and opportunities, you can determine how to get better. Valuing truth means being transparent about your decision-making and mistakes, giving and receiving feedback with humility, and fighting for the best answers over hierarchy, ego, or self-interest. Operating this way is hard, it s only possible because we build meaning in our work and relationships.
The meaning comes from the audacity of the mission, and the joy of working alongside people who make you a better version of yourself. The culture, like Bridgewater itself, is always 1997 our founder Ray Dalio wrote down his lessons, starting with aPhilosophy Statement which remains our foundation. This later evolved into a set of 300+ Principles. In 2022, when Ray transitioned the company, we re-underwrote several of those principles and evolved others, with a specific focus on Meritocracy.
Today the culture sits, alongside our people, as our most important edge. When we get it right, it’s the engine that powers everything else.
About the Security Department
The Security Department’s mission is to protect Bridgewater. We secure the investment departments, which manage assets for global institutional clients, as well as all other business operations. We constantly evolve our cyber, physical, and staff security practices to meet the business needs and stay ahead of the changing threat landscape.
About the role:
The Security GRC Lead role at Bridgewater is critical to shaping and executing the company’s oversight and management of security risks. As the senior-most individual contributor on the Technical Risk and Security Governance team, you will be a key player in the overall oversight and execution of how the Security department meets its security compliance responsibilities and practically manages security risk for the company across areas as diverse as cybersecurity, physical security, and staff security.
Additionally, this role will have a significant focus on third party risk, specifically those security risks posed by service providers and other external parties that process Bridgewater information or provide critical services to our investment operations.
As the Security GRC Lead, you will be responsible for managing and ensuring our security risk management program is compliant with global regulatory and client requirements. This role is our senior-most individual contributor for Governance & Risk work streams, requiring independent strategic thinking, planning, and execution across the Security department and in partnership with key stakeholders in our Legal & Regulatory Group, Technology department, and business units.
You’d Click for This Role If You’re Knowledgeable In:
- The many facets (policy, standards, implementation, assurance) of a mature security governance, risk, and compliance (GRC) program. Bonus if your knowledge is derived from experience operating in a U.S. and/or global asset management regulatory context.
- How to conduct due diligence of service provider security programs without an overly rigid or burdensome process – you…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).