
Director, Cyber GRC
Posted 15 hours ago

Posted 15 hours ago
This is a fully remote position, open to applicants in United States.
• Lead and develop the Cyber GRC function from concept to implementation.
• Formulate and enhance cybersecurity policies while applying control frameworks such as NIST CSF 2.0, CIS Controls v8, and ISO 27001.
• Perform compliance monitoring and ensure audit preparedness for SEC, FINRA, NYDFS, and various state regulations.
• Oversee the third-party vendor risk management program throughout the vendor lifecycle.
• Conduct vendor security evaluations and set stringent contract specifications.
• Collaborate with procurement and AI review teams on integrated risk management strategies.
• Design, refine, and carry out security awareness and training initiatives.
• Create role-specific curricula, phishing simulations, and initiatives to foster a positive culture.
• Lead AI governance within the cybersecurity realm, including policies for acceptable use, risk tiering for use cases, and management of third-party AI tools.
• Build cyber risk management capabilities featuring quantified reporting and dashboards.
• Deliver CISO-level and board-level insights on cyber posture and risk.
• Provide counsel to Security Architecture & Engineering, Monitoring & Response, Legal, and IT governance teams.
• Incorporate GRC into strategic planning, M&A due diligence, product launches, and change management processes.
• Represent Mariner in interactions with regulators, auditors, and third-party evaluators.
• Manage regulatory examinations and responses in collaboration with the CISO.
• 10–12 years of progressive experience in cybersecurity and risk management.
• Proven track record in leading GRC, compliance, or vendor risk teams.
• Demonstrated success in developing and refining security governance programs.
• A background in financial services is strongly preferred.
• In-depth knowledge of highly regulated sectors and examination processes, including banking, insurance, or capital markets.
• Capability to address wealth management-specific requirements related to SEC, FINRA, and NYDFS.
• Practical experience in transforming technology risk, security assurance, or compliance programs.
• Experience in integrating risk management into business operations.
• Data-driven perspective on cybersecurity metrics, risk quantification, and executive-level reporting.
• Ability to convert technical risks into actionable business insights.
• Strong skills in cross-functional leadership, communication, and influence.
• Capacity to collaborate with security, IT, legal, finance, and business teams.
• Preferred certifications include CISM, CRISC, CISA, CGEIT, CISSP, or their equivalents.
• Legally authorized to work in the United States.
• Opportunities for professional growth and advancement.
• A forward-thinking workplace.
• A culture of camaraderie and teamwork.
• Work-life balance support.
• A diverse culture that encourages career aspirations.
• Executive backing and autonomy to develop scalable, impactful programs.
• Continuous opportunities for skill enhancement.
• A chance to lead transformative initiatives.
• Equal employment opportunities.
Coalfire
Thrive Global
Ultragenyx
Neptune Energy
Get handpicked remote jobs straight to your inbox weekly.