VP, Cybersecurity Governance, Risk and Compliance

AcrisureAtlanta, GA
Onsite

About The Position

Acrisure is a global fintech leader that empowers businesses and individuals with customized solutions across insurance, reinsurance, payroll, benefits, cybersecurity, and mortgage services. With a history of rapid growth, Acrisure employs over 19,000 colleagues in more than 20 countries. This role is responsible for building and leading Acrisure’s global cybersecurity governance, risk, and regulatory assurance function. The objective is to establish an operating model that translates cybersecurity risk into clear executive decisions and provides board-level visibility. The VP will set and operate the cyber governance model for a fast-growing, highly acquisitive international fintech organization, ensuring risks are identified, prioritized, and communicated. Key areas of ownership include cybersecurity governance, enterprise board-level management, regulatory readiness, audit and examination response, IT general controls alignment, and security awareness and phishing resilience programs. The role requires close collaboration with leaders across Cybersecurity, Technology, Legal (privacy), Operations, and Enterprise Risk Management to establish a scalable, defensible control environment that meets increasing regulatory and audit expectations while enabling business growth. This position reports directly to the CISO, operates with enterprise-level decision authority, and is a core member of the cybersecurity leadership team. Success depends on deep expertise in cybersecurity risk and compliance within regulated environments, strong executive presence, and the ability to lead through influence in a complex, global, and rapidly evolving organization.

Requirements

  • Bachelor's degree required
  • 10+ years of experience across cybersecurity governance, risk management, compliance, audit, or assurance in regulated industries
  • 5+ years of experience leading teams and influencing senior executives
  • Demonstrated ability to build scalable governance, risk, and assurance programs in high growth or acquisitive environments
  • Strong executive communication skills including board level writing and presentations
  • Strong knowledge of cybersecurity and control frameworks such as NIST, ISO 27001, SOC, and financial regulatory environments
  • Experience managing audits, regulatory exams, and enterprise risk or control frameworks
  • Exceptional communication, stakeholder management, and problem-solving skills
  • Proven ability to lead projects and influence across a matrixed organization

Nice To Haves

  • CISSP, CISM, or CRISC strongly preferred
  • Master's degree a plus
  • Experience with GRC tools (e.g., OneTrust, Archer, LogicGate, ServiceNow GRC) preferred

Responsibilities

  • Own the operating cadence for the Cybersecurity Governance Committee (CyberGov), including agenda development, pre-read preparation, meeting facilitation, and follow through with decisions and action items.
  • Own the cybersecurity governance operating model, including policy lifecycle management, standards hierarchy, exception governance, and evidence of adoption.
  • Translate executive approved cybersecurity policies into clear, enforceable standards and operating procedures that scale globally.
  • Partner with IT and business leaders to ensure cybersecurity standards are embedded into core operating processes.
  • Own the enterprise cybersecurity risk management program, including risk identification, scoring, treatment, acceptance, and reporting.
  • Maintain the cybersecurity risk register and ensure risks are translated into clear decisions, prioritized remediation plans, and executive ready reporting.
  • Partner with Enterprise Risk Management to integrate cyber risk appropriately into broader enterprise risk routines.
  • Translate enterprise risk appetite into actionable cybersecurity decision frameworks and risk thresholds.
  • Lead cybersecurity compliance readiness across applicable regulatory regimes and expectations, including NYDFS 500, FCA/DORA, and a trajectory toward SOX and SEC audit readiness.
  • Continuously monitor regulatory and supervisory changes and drive corresponding enhancements to the cybersecurity program.
  • Ensure global consistency in cyber controls while accounting for regional regulatory differences.
  • Own the end-to-end cybersecurity audit and examination operating model, including intake, scoping, evidence management, response coordination, issue remediation, and closure.
  • Serve as the single point of accountability for all cybersecurity audits and examinations (internal and external).
  • Ensure audit outcomes drive sustained control and process improvement.
  • Define and align cyber-relevant IT General Controls with IT and Operations, including access governance, change management, logging and monitoring, vulnerability and patch governance, and backup and recovery.
  • Establish a sustainable approach to control assurance and evidence production aligned to audit and regulatory expectations.
  • Lead cybersecurity due diligence and provide clear, decision-ready risk assessments for mergers and acquisitions.
  • Partner with IT and integration teams to ensure visibility and accountability for post-acquisition cybersecurity uplift toward company standards.
  • Own a repeatable M&A cyber due diligence playbook and drive cybersecurity into the deal team process.
  • Own the enterprise security awareness and training program, including role-based training, completion discipline, and effectiveness measurement.
  • Own the phishing simulation and resilience program, using results to drive targeted risk reduction.
  • Promote a culture where cybersecurity is embedded into how the business operates.
  • Develop and maintain a concise set of cybersecurity KPIs and KRIs that reflect risk posture, control health, remediation velocity, and audit readiness.
  • Deliver clear, consistent, and decision-oriented reporting to executive leadership, Cyber Governance, and other senior forums.
  • Provide global visibility across regions while maintaining consistent definitions and expectations.
  • Define and execute a GRC modernization roadmap that reduces manual process dependency, accelerates audit evidence cycles, and improves executive risk visibility.
  • Drive adoption of AI-assisted workflows across risk identification, control assurance, and issue tracking.
  • Establish measurable baselines and report progress against them.
  • Lead and scale a global Cybersecurity GRC organization.
  • Set a high bar for clarity, accountability, and execution.
  • Build strong cross functional partnerships and lead effectively in a decentralized, fast-moving environment.

Benefits

  • Comprehensive medical insurance
  • Dental insurance
  • Vision insurance
  • Life and disability insurance
  • Fertility benefits
  • Wellness resources
  • Paid sick time
  • Generous paid time off and holidays
  • Employee Assistance Program (EAP)
  • Complimentary Calm app subscription
  • Immediate vesting in a 401(k) plan
  • Health Savings Account (HSA) and Flexible Spending Account (FSA) options
  • Commuter benefits
  • Employee discount programs
  • Paid maternity leave
  • Paid paternity leave (including for adoptive parents)
  • Legal plan options
  • Pet insurance coverage
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service