Lead GRC & Security Governance

JobgetherBrussels (Firmensitz, recherchiert)Job.bozveřejněno 09. 10. 2026
Nutné:CloudDevOpsCI/CDAIFinTechHealthTechSecurityLeadRemote

Accountabilities Build and lead the technology governance program: Establish and operate a comprehensive governance framework covering technology and cybersecurity risk, IT controls, change management, incident management, business continuity, and security policies.

Develop and maintain the control inventory: Define and manage a centralized inventory of technology controls, including control owners, evidence requirements, operating schedules, exception processes, and escalation pathways.

Own audit readiness and assurance: Lead technology assurance activities across SOC 2, SOX IT General Controls (ITGC), PCI, and other applicable compliance frameworks. Coordinate evidence collection, support control testing, identify deficiencies, and maintain accountability for remediation through resolution.

Manage technology and cybersecurity risks: Own the technology and cyber risk register, assess risk exposure and materiality, document control exceptions, and communicate significant or persistent risks to the appropriate decision-makers with clear context and recommendations.

Strengthen control accountability: Establish clear expectations for control owners and technical teams while ensuring remediation responsibilities remain with the teams best positioned to address identified issues.

Govern change and incident management: Define practical policies and oversight processes for technology changes, security incidents, and operational disruptions, ensuring procedures are consistently followed, tested, and improved.

Oversee business continuity and resilience: Establish and maintain governance requirements that support operational continuity, preparedness, and effective recovery from technology or business disruptions.

Leverage AI and automation: Identify and implement appropriate AI-assisted and automated workflows for evidence analysis, control mapping, policy maintenance, risk reporting, audit preparation, and remediation tracking, with suitable human review and data safeguards.

Partner across technical and business functions: Collaborate with Security, IT, Engineering, Site Reliability Engineering (SRE), Data, Compliance, Legal, Internal Audit, and external assessors to align governance requirements with operational realities.

Escalate material risks effectively: Exercise independent judgment to identify significant control weaknesses, challenge insufficient responses, and ensure material risks receive appropriate visibility and timely decisions, even when stakeholders disagree.

Build scalable governance processes: Develop clear documentation, reporting structures, decision records, action plans, and performance indicators that support accountability and adapt as the organization grows.

Drive continuous improvement: Evaluate the effectiveness of governance processes, incorporate stakeholder feedback, and refine the operating model to ensure controls remain practical, proportionate, and sustainable.

Requirements

Extensive technology experience: At least eight years of relevant technology experience, including substantial responsibility for security governance, technology risk management, security assurance, or related disciplines.

Proven audit leadership: Direct experience leading a SOC 2 Type II, ISO 27001, or equivalent audit through a successful outcome, rather than solely supporting audit preparation or evidence collection.

Governance program development: Demonstrated experience creating or materially redesigning a governance, risk, or assurance operating model, including defining control frameworks, ownership structures, and accountability mechanisms.

Strong technical fluency: A solid understanding of modern technology environments, including cloud infrastructure, identity and access management, CI/CD pipelines, source control, endpoints, networks, and data platforms.

Control design and assessment expertise: The ability to translate ambiguous security or compliance requirements into precise, testable controls, evaluate evidence objectively, and challenge incomplete or insufficient responses.

Risk management and escalation judgment: Experience assessing risk severity and materiality, managing exceptions, communicating exposure, and escalating significant issues when stakeholders disagree or remediation is delayed.

Cross-functional leadership and influence: The ability to establish credibility with Engineering, SRE, Security, IT, and Data teams while maintaining accountability for governance outcomes without assuming ownership of technical remediation.

Audit and legal stakeholder management: Experience working effectively with Internal Audit, Legal, Compliance, security teams, and external auditors or assessors.

Excellent written communication: Strong documentation and reporting skills, with the ability to turn complex requirements and ambiguous situations into clear decisions, responsibilities, actions, deadlines, and evidence.

Program management capabilities: Demonstrated ability to organize complex initiatives, coordinate multiple stakeholders, manage competing priorities, and maintain progress toward measurable outcomes.

Independent ownership and adaptability: A proactive, practical approach to problem-solving, with the confidence to establish new processes, make informed trade-offs, and adapt governance practices as business priorities and requirements evolve.

Business-oriented governance mindset: The ability to create controls that support operational effectiveness and responsible growth without introducing unnecessary bureaucracy.

Additional experience that would be advantageous:

Experience with SOX ITGC, PCI DSS, or NIST-based security and risk management programs.

Familiarity with AI governance, AI-related security controls, or third-party AI risk assessments.

Experience implementing or managing GRC automation platforms such as Vanta or Drata.

Experience building governance processes within a fintech, financial services, or other regulated technology environment.

Experience designing scalable governance frameworks for growing organizations with evolving operational and compliance requirements.

Benefits

Competitive compensation: Annual base salary ranging from $174,000 to $224,000 , with equity opportunities. Actual compensation depends on experience, skills, qualifications, and other relevant factors rather than work location.

Equity opportunities: The opportunity to receive equity and participate in the long-term value created by the business.

Remote-first flexibility: Work remotely from anywhere in the United States except Hawaii, with flexible working hours and a virtual-first culture.

Home office support: Receive a home office stipend to help create a productive and comfortable remote workspace.

Comprehensive healthcare: Access premium medical, dental, and vision insurance plans.

Retirement savings: Participate in a 401(k) savings plan with matching contributions.

Family and caregiver support: Benefit from generous paid parental and caregiver leave.

Flexible paid time off: Enjoy flexible PTO and generous company holidays, including Juneteenth and a company-wide winter break.

Financial wellness resources: Access financial advisory services and financial wellness support.

Professional growth: Work alongside experienced professionals, develop your expertise in technology governance and security assurance, and shape a new function with significant ownership.

Collaborative culture: Participate in company-wide in-person gatherings once or twice a year, along with virtual events that connect employees with colleagues and leadership.

Meaningful business impact: Help strengthen the security, resilience, and governance of financial technology products designed to improve access to financial services for everyday Americans.

Autonomy and influence: Establish foundational governance systems, shape risk management practices, and help technical teams operate with greater confidence as the business scales.

How Jobgether works: We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best!  Why Apply Through Jobgether? 

Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.

#LI-CL1