Voleon is a technology company that applies state-of-the-art AI and machine learning techniques to real-world problems in finance. For nearly two decades, we have led our industry and worked at the frontier of applying AI/ML to investment management. We have become a multibillion-dollar asset manager, and we have ambitious goals for the future. Your colleagues will include internationally recognized experts in artificial intelligence and machine learning research as well as highly experienced finance and technology professionals. The people who shape our company come from other backgrounds, including concert music performances, humanitarian aid, opera singing, sports writing, and BMX racing. You will be part of a team that loves to succeed together. In addition to our enriching and collegial working environment, we offer highly competitive compensation and benefits packages, technology talks by our experts, a beautiful modern office, daily catered lunches, and more. As a GRC Manager, you will own and operationalize governance, risk, and compliance within the Information Security organization, reporting directly to the CISO. This is a security GRC role — distinct from the firm's trade compliance function — focused on building an information security risk management program from the ground up. You will transform an existing risk assessment framework and methodology into a living program with a formal risk register, policy lifecycle, control inventory, and security compliance posture. This role sits at the intersection of security engineering, operational risk, legal, and investor relations — requiring both the technical depth to engage credibly with a strong InfoSec engineering team and the communication skills to translate complex security posture into business language for leadership, auditors, and investors. This is not a checkbox compliance role. You will need genuine security expertise to write accurate policies grounded in how systems actually work, conduct meaningful risk assessments, and partner with security engineers on control design and gap remediation. You will serve as the primary interface between InfoSec (first line) and the firm's Operational Risk, Internal Audit, Legal, and Compliance functions (second/third line) — owning the three-lines-of-defense relationship on behalf of the CISO organization.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Manager
Education Level
No Education Listed