Sr Director, Cybersecurity GRC

MoneyGram
Remote

About The Position

At MoneyGram, we're combining the strength of a trusted global brand with the agility of a tech-forward, growth driven culture. With 80+ years of experience and a presence in more than 200 countries and territories, we've built a foundation of stability and trust to help millions of people around the world send funds quickly, securely, and affordably. We're looking for bold thinkers, builders, technologists, and sellers who want real ownership of their work, thrive in collaborative environments, and are energized by solving complex challenges. Here, you'll have the opportunity to make a measurable impact - fast. If you're eager to shape the future of cross-border payments and financial services, join us as we transform how the world moves money. At MoneyGram, we connect the world by making cross-border money transfers seamless, affordable, and secure for everyone. We are seeking a Senior Director of Cybersecurity Governance, Risk and Compliance (GRC) for our global organization. This role is responsible for transforming, scaling, and operationalizing the global cybersecurity GRC function. This leader will drive modernization of governance, risk management, compliance, third-party risk, audit, security awareness, and resilience programs while building a highly efficient, technology-enabled operating model capable of supporting a rapidly evolving global fintech organization. Reporting directly to the Chief Information Security Officer (CISO), this role serves as a trusted advisor to executive leadership, regulators, auditors, and business stakeholders. The ideal candidate is an experienced cybersecurity leader with a proven track record of building and maturing GRC organizations, driving operational excellence, implementing automation at scale, and leading high-performing global teams. This role requires a strategic thinker who can simultaneously manage multiple complex initiatives, influence senior stakeholders, navigate regulatory environments across multiple jurisdictions, and execute with a strong bias for action.

Requirements

  • 15+ years of experience in cybersecurity, information security, risk management, compliance, audit, or related disciplines.
  • Minimum 7+ years of progressive leadership experience managing large cybersecurity, risk, or compliance organizations.
  • Proven track record transforming and scaling enterprise GRC programs within fintech, payments, banking, financial services, or similarly regulated industries.
  • Demonstrated experience building and optimizing teams, operating models, and organizational capabilities.
  • Significant experience implementing and operationalizing GRC platforms such as Vanta, ServiceNow GRC, Archer, AuditBoard, OneTrust, or similar technologies.
  • Deep expertise in cybersecurity governance frameworks, regulatory compliance, audit management, and enterprise risk management.
  • Experience leading complex regulatory examinations and engagements across multiple jurisdictions.
  • Strong understanding of cloud environments (AWS, Azure, GCP), DevSecOps practices, and modern technology architectures.
  • Proven ability to drive large-scale transformation initiatives while managing multiple competing priorities.
  • Demonstrated success influencing executive leadership and operating effectively within matrixed organizations.
  • Exceptional communication and presentation skills, including regulator-facing experience.
  • Bachelor's degree in Cybersecurity, Information Systems, Risk Management, Business, or related field.

Nice To Haves

  • Experience leading cybersecurity governance and compliance programs across multiple continents and regulatory regimes.
  • Experience applying quantitative cyber risk methodologies.
  • Familiarity with AI governance, AI risk management, and emerging regulatory requirements related to artificial intelligence.
  • Experience in publicly traded companies.
  • Proven history of improving operational efficiency through automation, process redesign, and technology modernization initiatives.

Responsibilities

  • Lead the transformation and continuous maturation of the global GRC organization, including governance, risk management, compliance, third-party risk, audit management, security awareness, and resilience programs.
  • Assess organizational effectiveness and develop a target-state operating model that improves efficiency, scalability, accountability, and business alignment.
  • Drive process optimization, simplification, and automation initiatives across the GRC portfolio.
  • Establish measurable service delivery metrics, operational KPIs, and maturity targets to continuously improve program effectiveness.
  • Build and execute a multi-year roadmap for GRC modernization aligned to business objectives and regulatory expectations.
  • Define and maintain global cybersecurity policies, standards, frameworks, and governance processes aligned with NIST CSF, ISO 27001, PCI DSS, SOC, and applicable financial services regulations.
  • Ensure governance structures effectively support executive decision-making and risk-based prioritization.
  • Drive consistent application of security requirements and controls across products, platforms, and regions.
  • Lead the enterprise cyber risk management program, including risk identification, assessment, quantification, mitigation planning, and executive reporting.
  • Develop meaningful risk metrics, KRIs, and executive dashboards that support business-informed risk decisions.
  • Advance quantitative risk analysis capabilities using existing risk models or similar methodologies where appropriate.
  • Partner with technology and business leaders to embed risk management into strategic planning and operational processes.
  • Oversee compliance with regulatory, legal, and contractual cybersecurity requirements across all operating regions.
  • Lead regulatory engagements, examinations, and responses with financial services regulators and external assessors.
  • Ensure readiness for audits, certifications, and assessments, including PCI DSS, SOC, ISO 27001, privacy regulations, and emerging cybersecurity requirements.
  • Drive timely remediation and sustainable resolution of audit and regulatory findings.
  • Own the strategy, implementation, adoption, and continuous optimization of GRC technology platforms, including Vanta and related compliance automation capabilities.
  • Lead and execute the roadmap to automate evidence collection, control monitoring, risk workflows, policy management, audit readiness, and compliance reporting.
  • Establish governance and operational processes that maximize platform value while reducing manual effort and audit burden.
  • Evaluate and implement additional technologies that improve visibility, efficiency, and program scalability.
  • Lead the global third-party cyber risk management program, including vendor assessments, continuous monitoring, risk remediation, and contractual security requirements.
  • Partner with Procurement, Legal, Compliance, and Business stakeholders to ensure consistent third-party risk governance.
  • Drive maturity of continuous monitoring and risk-based vendor oversight capabilities.
  • Oversee enterprise security awareness, education, and culture initiatives.
  • Develop programs that strengthen employee resilience against evolving cyber threats, fraud, social engineering, and emerging AI-enabled attacks.
  • Establish measurable outcomes that demonstrate reductions in human-related risk.
  • Partner with Cyber Operations and Business teams to maintain incident response preparedness, crisis management processes, tabletop exercises, and regulatory reporting readiness.
  • Ensure governance and oversight mechanisms support operational resilience objectives and regulatory expectations.
  • Serve as a trusted advisor to executive leadership on cybersecurity governance, risk, compliance, and resilience matters.
  • Represent the cybersecurity organization during interactions with regulators, auditors, customers, and strategic partners.
  • Lead and develop a high-performing GRC organization focused on accountability, collaboration, operational excellence, and business partnership.
  • Assess organizational structure, capabilities, and talent to ensure alignment with business objectives and future growth requirements.
  • Establish clear performance expectations, career development pathways, succession plans, and leadership accountability.
  • Drive a culture of ownership, execution, continuous improvement, and customer-focused service delivery.

Benefits

  • Remote first flexibility
  • Generous PTO
  • 13 Paid Holidays
  • Medical / Dental / Vision Insurance
  • Life, Disability, and other benefits
  • 401k with competitive Employer Match
  • Community Service Days
  • Generous Parental Leave
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service