Head of Security GRC

DriveWealthAustin, TX
$270,000 - $290,000Hybrid

About The Position

DriveWealth is seeking an experienced, hands-on leader to serve as the connective tissue of our security program—owning governance and risk operations while also acting as a trusted advisor to the CISO and a credible voice with regulators, auditors, and enterprise partners. This is a builder's role: you will mature frameworks, quantify and report risk to executives and the board, stand up threat-intelligence and incident-response capabilities, and run third-party and client due diligence. The ideal candidate thrives with autonomy, drives initiatives to completion with minimal supervision, and can translate deep technical risk into clear business decisions. Reporting directly to the CISO, the Head of Security GRC is responsible for leading the organization's governance, risk, and compliance program across a regulated broker-dealer environment. The role ensures alignment with SEC/FINRA obligations, global data-protection laws, and leading cybersecurity frameworks, while actively reducing enterprise risk. Beyond traditional GRC, this position owns security metrics and executive/board reporting, cyber threat intelligence, incident-response readiness, and third-party and client cyber due diligence. Success requires an independent, proactive leader who can drive cross-departmental initiatives, interface effectively with regulators and partners, and align security outcomes with business objectives.

Requirements

  • 15+ years of experience in information security, risk management, or cybersecurity roles, with significant time in a regulated financial-services environment and prior ownership of a GRC function.
  • Strong, practical understanding of SEC/FINRA regulations applicable to broker-dealers (e.g., Reg S-P, Rule 17a-4, cyber disclosure obligations).
  • Expertise in global data-protection laws (GDPR, CCPA/CPRA, LGPD) and their operational impact.
  • Hands-on experience leading GRC programs and risk-management initiatives end to end.
  • Demonstrated ownership of SOC 1, SOC 2, and ISO 27001 examinations and compliance audits.
  • Experience building security KPIs/KRIs and executive or board-level reporting.
  • Working knowledge of threat intelligence, incident-response planning, and runbook development.
  • Proven third-party risk management and client/partner security due-diligence
  • Excellent communication and leadership skills, with the ability to work independently and drive to completion.

Nice To Haves

  • Experience at a broker-dealer, fintech, or embedded-finance / brokerage-as-a-service
  • Exposure to multi-jurisdiction / cross-border regulatory and privacy environments.
  • Familiarity with MITRE ATT&CK, FS-ISAC, and financial-sector threat landscapes.
  • Hands-on experience with GRC/IRM and TPRM platforms and reporting/BI tooling.
  • Relevant certifications: CISM, CISSP, CRISC, CISA, or ISO 27001 Lead Auditor (highly preferred).

Responsibilities

  • Own and mature the enterprise GRC program, aligning controls to recognized frameworks including NIST CSF, NIST 800-53, ISO 27001, SOC 2, and CIS Controls.
  • Maintain and organize the cybersecurity policy, standard, and procedure library, running the annual review cycle and managing control ownership, exceptions, and waivers.
  • Operate the information security risk register: conduct risk assessments, define treatment plans, facilitate risk-acceptance workflows, and track residual risk over time.
  • Ensure compliance with SEC/FINRA requirements, including Regulation S-P (Safeguards & Disposal), Rule 17a-4 recordkeeping, and financial-industry security obligations.
  • Manage external and internal security audits and examinations, including SOC 1, SOC 2 Type II, and ISO 27001, coordinating auditors, evidence collection, and remediation tracking.
  • Establish and run control testing and continuous control monitoring, driving remediation of gaps to closure across control owners.
  • Establish procedures for annual security due-diligence reviews with critical partners and vendors.
  • Maintain and enforce compliance with global data-protection laws, including GDPR, CCPA/CPRA, LGPD, and GLBA.
  • Interpret and operationalize evolving SEC cybersecurity risk-management and incident-disclosure obligations relevant to registrants and broker-dealers.
  • Assess and manage applicability of NYDFS 500, PCI DSS, and state breach-notification requirements to the platform's control environment.
  • Serve as subject-matter expert (SME) for security compliance, providing guidance to business units, product, and engineering.
  • Partner with Legal, Privacy, and Compliance teams to ensure end-to-end regulatory adherence.
  • Design and maintain a security metrics, KPI, and KRI framework that measures control effectiveness, risk posture, and program maturity.
  • Build and deliver executive dashboards and board-level reporting, translating technical risk into clear business and financial impact for the CISO, audit committee, and board.
  • Track and report remediation SLAs, risk-trend lines, control-maturity progression, and audit-finding closure.
  • Produce reporting packages that support regulatory exams, partner assurance, and internal governance committees.
  • Continuously refine metrics so leadership can make risk-informed investment and prioritization decisions.
  • Stand up and operate a cyber threat-intelligence capability tuned to financial services, broker-dealers, and embedded-finance ecosystems.
  • Track relevant threat actors, campaigns, and TTPs using frameworks such as MITRE ATT&CK, and leverage sector sources including FS-ISAC.
  • Produce strategic, operational, and tactical threat reporting for technical teams and executive stakeholders.
  • Integrate intelligence into risk assessments, control decisions, and incident-response readiness, ensuring emerging threats drive prioritized action.
  • Monitor for threats to partners and the broader supply chain that could create downstream client or platform risk.
  • Own, maintain, and regularly test the Incident Response Plan (IRP), ensuring it reflects the current threat landscape and regulatory obligations.
  • Develop and maintain incident runbooks / playbooks for high-priority scenarios (e.g., ransomware, business email compromise, account takeover, data exposure, and third-party or partner breach).
  • Plan and facilitate tabletop exercises across security, engineering, legal, compliance, and executive leadership.
  • Map response procedures to regulatory and contractual notification requirements, including SEC incident disclosure, Reg S-P breach notification, state laws, and partner SLAs.
  • Lead post-incident reviews and lessons-learned, translating findings into control and process improvements.
  • Own the end-to-end vendor risk lifecycle: intake, risk tiering, security due diligence, contractual security terms, ongoing monitoring, and secure offboarding.
  • Partner with Legal, Procurement, IT, and Compliance on the TPRA process and security controls embedded in vendor evaluations.
  • Assess concentration, fourth-party, and SaaS supply-chain risk, escalating material exposures to the CISO.
  • Maintain the vendor inventory and reassessment cadence, ensuring critical suppliers are reviewed on a defined schedule.
  • Establish and enforce minimum security requirements for vendors handling regulated or sensitive data.
  • Own responses to inbound security questionnaires, RFPs, and enterprise-client due-diligence requests, serving as the security SME during partner evaluations.
  • Build and maintain a reusable security trust package (SOC 2 report, penetration-test summaries, questionnaire libraries, and security whitepaper) to accelerate sales and partnership cycles.
  • Partner with Sales, Partnerships, and Legal to translate client security requirements into commitments the platform can meet and evidence.
  • Establish standardized due-diligence procedures and scoring so client and partner assessments are consistent, repeatable, and defensible.
  • Act as a key liaison between internal business units, regulators, and external partners on security matters.
  • Communicate effectively with senior leadership, providing regular updates on security posture, risk, and compliance.
  • Represent the company in regulatory discussions, industry panels, and security conferences as needed.
  • Provide expert guidance on security frameworks, standards, and industry best practices, and mentor teammates on GRC practices.

Benefits

  • Competitive compensation
  • Equity
  • 401(k) match
  • Medical insurance
  • Dental insurance
  • Vision insurance
  • Disability insurance
  • Paid Parental Leave
  • Wellness reimbursement
  • Company-provided phone
  • Personal development allowance
  • Generous Paid Time Off (PTO)
  • Observed holidays
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service