
Senior Director, Cybersecurity GRC
Posted Aug 6

Posted Aug 6
This is a fully remote position, open to applicants in United States.
• Enhance and continually develop MoneyGram’s global cybersecurity Governance, Risk, and Compliance (GRC) organization.
• Revamp governance, risk management, compliance, third-party risk, audit, security awareness, and resilience initiatives.
• Create a target operating model, a multi-year modernization strategy, service metrics, key performance indicators (KPIs), and maturity goals.
• Establish and uphold global cybersecurity policies, standards, frameworks, and governance procedures.
• Spearhead enterprise cyber risk identification, assessment, quantification, mitigation planning, metrics, key risk indicators (KRIs), dashboards, and executive reporting.
• Supervise regulatory compliance, examinations, audits, certifications, assessments, remediation, and regulatory interactions across various operating regions.
• Direct the strategy, implementation, adoption, and optimization of GRC technology platforms, including Vanta.
• Streamline evidence collection, control monitoring, risk workflows, policy management, audit readiness, and compliance reporting through automation.
• Manage global third-party cyber risk assessments, vendor evaluations, monitoring, remediation, and security requirements outlined in contracts.
• Oversee initiatives for security awareness, education, culture, and human risk management.
• Ensure readiness for incident response, crisis management, tabletop exercises, and regulatory reporting.
• Counsel executive leadership and represent the cybersecurity function with regulators, auditors, customers, and strategic partners.
• Build and nurture a high-performing GRC organization, establishing performance metrics, development pathways, succession planning, and accountability measures.
• Over 15 years of experience in cybersecurity, information security, risk management, compliance, audit, or related fields.
• At least 7 years of progressive leadership experience in managing extensive cybersecurity, risk, or compliance teams.
• Demonstrated success in transforming and scaling enterprise GRC programs within fintech, payments, banking, financial services, or similarly regulated sectors.
• Proven experience in building and optimizing teams, operational models, and organizational competencies.
• Extensive experience in implementing and operationalizing GRC platforms such as Vanta, ServiceNow GRC, Archer, AuditBoard, OneTrust, or comparable technologies.
• Deep knowledge of cybersecurity governance frameworks, regulatory compliance, audit management, and enterprise risk management.
• Experience leading intricate regulatory examinations and interactions across various jurisdictions.
• Strong familiarity with AWS, Azure, GCP, DevSecOps practices, and contemporary technology architectures.
• Capability to drive large-scale transformation projects while balancing multiple competing priorities.
• Proven track record of influencing executive leadership and functioning effectively within matrixed organizations.
• Excellent communication and presentation skills, including experience interacting with regulators.
• Bachelor’s degree in Cybersecurity, Information Systems, Risk Management, Business, or a related discipline.
• Preferred certifications include CISSP, CISM, CRISC, CCSP, PCI ISA, ISO 27001 Lead Implementer or Lead Auditor.
• Preferred experience across multiple continents and regulatory frameworks, quantitative cyber risk methodologies, AI governance and risk management, publicly traded companies, and initiatives related to automation/process redesign.
• Access to GRC technology and automation tools, including Vanta.
• Opportunities for career development and succession planning.
• Exposure to a global organization and engagement with executives, regulators, auditors, customers, and strategic partners.
OCHIN, Inc.
Dynanet Corporation
Solutions for Information Design, Inc.
Fuze Health
Get handpicked remote jobs straight to your inbox weekly.