Security Risk Management Lead
Core
Design, automate, and scale security controls and workflows for third-party risk management, transforming GRC from compliance into an engineering discipline.
Role type
Senior Security Risk Management Lead (Engineering-focused)
Builds
Automated GRC workflows, workflow orchestration integrations, and risk dashboards for third-party security.
Domain
Financial Technology / Third-Party Risk Management / Security Engineering
Deliverable
production ML models | product features | dashboards & analysis | infrastructure
Required skills
Python scripting, agentic coding tools (Cursor, Claude), cloud security (AWS/GCP/Azure), GRC frameworks (NIST, ISO 2700x, SOC1/2, PCI DSS), stakeholder management, process automation, threat modeling basics, SQL/BI tools
Preferred skills
CISSP/CISM/CISA/CRISC certification, experience with low-code platforms, deep cloud architecture knowledge
Technologies
Python, Cursor, Claude, AWS, GCP, Azure, SQL, BI tools, ticketing systems, GRC platforms, identity providers
Responsibilities
Lead and mature the Security Third Party Program; build automation to replace manual GRC tasks; design workflow orchestration across systems; partner with stakeholders to manage third-party risk; translate requirements into scalable solutions; prototype automation tools; drive operational excellence with metrics; evaluate third-party controls and cloud architectures; conduct light threat models; manage complex risk initiatives; develop risk dashboards; advise stakeholders on risk decisions.
Seniority
Senior, hands-on IC with strategy & mentorship