• Skip to primary navigation
  • Skip to main content
  • Skip to footer

Side Hustles

Side Hustles

Side Hustles For All

  • Best Side Hustles
    • Woman sitting on a pile of coins and working on a laptop surrounded by icons representing different side hustle ideas

      31 Best Side Hustles to Earn Extra Money in 2026

    • Bicycle courier delivering food for their side hustle.

      What Is a Side Hustle?

    • Remote worker sitting at his desk making money from home

      18 Ways to Make Money from Home (Online and Offline Jobs)

    • By Category
      • Arts & Crafts
      • Business Services
      • Caregiving
      • Creative Services
      • Digital Freelance Services
      • View All
    • By Lifestyle
      • I’m introverted
      • I’m a man
      • I’m a woman
      • I’m a stay-at-home mom
      • I’m unique
      • View All
    • By Profession
      • Artists & Creatives
      • Musicians
      • Nurses
      • Physicians
      • Teachers
      • View All
    • By Age Group
      • College Students
      • Teens
      • Age 50+
      • Seniors
      • View All
    • By Skills & Interests
      • Get Paid to Lose Weight
      • Get Paid to Play Games
      • Get Paid to Read
      • Get Paid to Sleep
      • Get Paid to Travel
      • View All
  • Best Gig Apps
    • Freelance worker popping out of a phone screen and considering gig apps on the App Store and Google Play

      Top 6 Gig Apps to Make Real Cash in 2026

    • Smartphone surrounded by the icons of different money-making apps

      Top 10 Best Money-Making Apps to Try in 2026

    • two teenagers using job apps on a phone and laptop

      19 Job Apps for Teens to Find Jobs and Make Money

    • By Gig Type
      • Cashback
      • Data Entry
      • Delivery
      • Games
      • Product Testing
      • View All
    • By Payment Method
      • Bingo Games that Pay to Cash App
      • Games that Pay Real Money
      • Games that Pay to Cash App
      • Games that Pay via PayPal
      • Surveys that Pay to Cash App
      • View All
    • By Benefits
      • $20 Signup Bonuses
      • $25 Signup Bonuses
      • $50 Signup Bonuses
      • Best Signup Bonuses
      • Instant Signup Bonuses
      • View All
    • By Skills & Interests
      • Driving
      • Losing Weight
      • Playing Games
      • Product Testing
      • Watching Ads
      • View All
  • Job Hunting
    • Freelance worker browsing a job post on a freelance job board.

      23 Job Boards You Can Use to Find Remote Work

    • Freelance writer sitting at her laptop working on a project

      15 Best Remote Jobs That Require No Paid Work Experience

    • Teenager sitting at laptop working an online job

      14 Online Jobs for Teens (With No Experience)

    • Freelancing
      • Freelance Writing Sites
      • Freelance Writing Job Boards
      • Freelance Writing Platforms
      • View More
    • Gig & Shift Work
      • Gig Work Apps
      • On-Demand Work Apps
      • Shift Work Apps
      • View More
    • GPT (Get Paid To)
      • Microtasking
      • Product Testing
      • Survey Taking
      • View More
    • Remote Working
      • Best Remote Job Boards
      • Top 15 Remote Jobs
      • View More
  • Job Board
    • Work Schedule
      • Part-Time Jobs
      • Per-Diem Jobs
      • Go Search
    • Work Environment
      • Hybrid Jobs
      • Remote Jobs
      • Go Search
    • Employment Type
      • Contractor Jobs
      • Internship Jobs
      • Temporary Jobs
      • Go Search
    • Job Title
      • Accounting Jobs
      • Data Entry Jobs
      • Nursing Jobs
      • Online Teaching Jobs
      • Software Engineer Jobs
      • Go Search
    • State
      • California Jobs
      • Florida Jobs
      • New York Jobs
      • Pennsylvania Jobs
      • Texas Jobs
      • Go Search
    • City
      • Chicago, IL
      • Houston, TX
      • Los Angeles, CA
      • New York City, NY
      • Phoenix, AZ
      • Go Search

Home Flexible Job Board Head of Security GRC

$270,000–290,000/yr 9d ago

Head of Security GRC

Boost your chances before you apply.

  • ✨ Apply 10x Faster Free

    It takes 30+ tailored applications to land jobs like this one. We'll help you get that done in 1 hour.

    No Credit Card Required

  • Proceed to Application Go directly to the company's job page to apply.
Logo

DriveWealth

Austin, TX, US

Full-time Permanent Remote

✨ Apply 10x Faster

Analyze your resume for missing keywords, then one-click optimize it. Don't be anything less than a 100% match candidate.

Free

No Credit Card Required

Summary

Lead the organization's governance, risk, and compliance program within a regulated broker-dealer environment to ensure alignment with SEC/FINRA and global data laws. The role also manages security metrics, threat intelligence, incident response readiness, and third-party cyber due diligence.

Job Description

About Us

DriveWealth is on a mission to make investing easier. We believe that everyone should have the ability to control their financial future, and that access to financial markets should not be limited by geography, wealth, or legacy systems. We are a global B2B financial technology organization dedicated to democratizing access to financial independence around the world. Our mission is realized through an API-based platform, empowering our partners to offer seamless investing and trading experiences to clients worldwide, all from their mobile devices. Our technology provides partners with a modern, extensible toolkit, enabling traditional investment workflows and innovative techniques like fractional share ownership. DriveWealth has evolved into a global platform offering trading of US equities, mutual funds, ETFs, fixed income, and options.

There’s never been a better time to build a category-defining business and there has rarely been a team better positioned for this opportunity. Our culture blends the pace and agility of a fintech start-up with the impact, stability, and discipline of Wall Street. We encourage creativity and experimentation while ensuring institutional-grade execution and regulatory compliance in everything we do. Join us and help build the future of global investing!

About The Team

As a FINRA-member, SEC-registered broker-dealer powering brokerage-as-a-service and embedded investing for fintech partners around the world, DriveWealth operates where high-velocity technology meets one of the most heavily regulated industries on the planet. Every partner we onboard, every API we expose, and every trade that flows through our platform carries regulatory, client-trust, and operational-risk weight.

We are seeking an experienced, hands-on leader to serve as the connective tissue of our security program—owning governance and risk operations while also acting as a trusted advisor to the CISO and a credible voice with regulators, auditors, and enterprise partners. This is a builder's role: you will mature frameworks, quantify and report risk to executives and the board, stand up threat-intelligence and incident-response capabilities, and run third-party and client due diligence. The ideal candidate thrives with autonomy, drives initiatives to completion with minimal supervision, and can translate deep technical risk into clear business decisions.

About the Role 

Reporting directly to the CISO, the Head of Security GRC is responsible for leading the organization's governance, risk, and compliance program across a regulated broker-dealer environment. The role ensures alignment with SEC/FINRA obligations, global data-protection laws, and leading cybersecurity frameworks, while actively reducing enterprise risk. Beyond traditional GRC, this position owns security metrics and executive/board reporting, cyber threat intelligence, incident-response readiness, and third-party and client cyber due diligence. Success requires an independent, proactive leader who can drive cross-departmental initiatives, interface effectively with regulators and partners, and align security outcomes with business objectives.

What You'll Do

Governance, Risk & Compliance (GRC)

  • Own and mature the enterprise GRC program, aligning controls to recognized frameworks including NIST CSF, NIST 800-53, ISO 27001, SOC 2, and CIS Controls.
  • Maintain and organize the cybersecurity policy, standard, and procedure library, running the annual review cycle and managing control ownership, exceptions, and waivers.
  • Operate the information security risk register: conduct risk assessments, define treatment plans, facilitate risk-acceptance workflows, and track residual risk over time.
  • Ensure compliance with SEC/FINRA requirements, including Regulation S-P (Safeguards & Disposal), Rule 17a-4 recordkeeping, and financial-industry security obligations.
  • Manage external and internal security audits and examinations, including SOC 1, SOC 2 Type II, and ISO 27001, coordinating auditors, evidence collection, and remediation tracking.
  • Establish and run control testing and continuous control monitoring, driving remediation of gaps to closure across control owners.
  • Establish procedures for annual security due-diligence reviews with critical partners and vendors.

Regulatory & Data Protection Compliance

  • Maintain and enforce compliance with global data-protection laws, including GDPR, CCPA/CPRA, LGPD, and GLBA.
  • Interpret and operationalize evolving SEC cybersecurity risk-management and incident-disclosure obligations relevant to registrants and broker-dealers.
  • Assess and manage applicability of NYDFS 500, PCI DSS, and state breach-notification requirements to the platform's control environment.
  • Serve as subject-matter expert (SME) for security compliance, providing guidance to business units, product, and engineering.
  • Partner with Legal, Privacy, and Compliance teams to ensure end-to-end regulatory adherence.

KPI, Metrics & Executive / Board Reporting

  • Design and maintain a security metrics, KPI, and KRI framework that measures control effectiveness, risk posture, and program maturity.
  • Build and deliver executive dashboards and board-level reporting, translating technical risk into clear business and financial impact for the CISO, audit committee, and board.
  • Track and report remediation SLAs, risk-trend lines, control-maturity progression, and audit-finding closure
  • Produce reporting packages that support regulatory exams, partner assurance, and internal governance committees.
  • Continuously refine metrics so leadership can make risk-informed investment and prioritization decisions.

Threat Intelligence & Reporting

  • Stand up and operate a cyber threat-intelligence capability tuned to financial services, broker-dealers, and embedded-finance ecosystems.
  • Track relevant threat actors, campaigns, and TTPs using frameworks such as MITRE ATT&CK, and leverage sector sources including FS-ISAC.
  • Produce strategic, operational, and tactical threat reporting for technical teams and executive stakeholders.
  • Integrate intelligence into risk assessments, control decisions, and incident-response readiness, ensuring emerging threats drive prioritized action.
  • Monitor for threats to partners and the broader supply chain that could create downstream client or platform risk.

Incident Response Planning & Runbooks

  • Own, maintain, and regularly test the Incident Response Plan (IRP), ensuring it reflects the current threat landscape and regulatory obligations.
  • Develop and maintain incident runbooks / playbooks for high-priority scenarios (e.g., ransomware, business email compromise, account takeover, data exposure, and third-party or partner breach).
  • Plan and facilitate tabletop exercises across security, engineering, legal, compliance, and executive leadership.
  • Map response procedures to regulatory and contractual notification requirements, including SEC incident disclosure, Reg S-P breach notification, state laws, and partner SLAs.
  • Lead post-incident reviews and lessons-learned, translating findings into control and process improvements.

Third-Party / Vendor Risk Management (TPRM)

  • Own the end-to-end vendor risk lifecycle: intake, risk tiering, security due diligence, contractual security terms, ongoing monitoring, and secure offboarding.
  • Partner with Legal, Procurement, IT, and Compliance on the TPRA process and security controls embedded in vendor evaluations.
  • Assess concentration, fourth-party, and SaaS supply-chain risk, escalating material exposures to the CISO.
  • Maintain the vendor inventory and reassessment cadence, ensuring critical suppliers are reviewed on a defined schedule.
  • Establish and enforce minimum security requirements for vendors handling regulated or sensitive data.

Client & Partner Cyber Due Diligence

  • Own responses to inbound security questionnaires, RFPs, and enterprise-client due-diligence requests, serving as the security SME during partner evaluations.
  • Build and maintain a reusable security trust package (SOC 2 report, penetration-test summaries, questionnaire libraries, and security whitepaper) to accelerate sales and partnership cycles.
  • Partner with Sales, Partnerships, and Legal to translate client security requirements into commitments the platform can meet and evidence.
  • Establish standardized due-diligence procedures and scoring so client and partner assessments are consistent, repeatable, and defensible.

Security Leadership & Stakeholder Engagement

  • Act as a key liaison between internal business units, regulators, and external partners on security matters.
  • Communicate effectively with senior leadership, providing regular updates on security posture, risk, and compliance.
  • Represent the company in regulatory discussions, industry panels, and security conferences as needed.
  • Provide expert guidance on security frameworks, standards, and industry best practices, and mentor teammates on GRC practices.

You Bring

  • 15+ years of experience in information security, risk management, or cybersecurity roles, with significant time in a regulated financial-services environment and prior ownership of a GRC function.
  • Strong, practical understanding of SEC/FINRA regulations applicable to broker-dealers (e.g., Reg S-P, Rule 17a-4, cyber disclosure obligations).
  • Expertise in global data-protection laws (GDPR, CCPA/CPRA, LGPD) and their operational impact.
  • Hands-on experience leading GRC programs and risk-management initiatives end to end.
  • Demonstrated ownership of SOC 1, SOC 2, and ISO 27001 examinations and compliance audits.
  • Experience building security KPIs/KRIs and executive or board-level reporting.
  • Working knowledge of threat intelligence, incident-response planning, and runbook development.
  • Proven third-party risk management and client/partner security due-diligence
  • Excellent communication and leadership skills, with the ability to work independently and drive to completion.

Special Knowledge (Nice to Have, But Not Required)

  • Experience at a broker-dealer, fintech, or embedded-finance / brokerage-as-a-service
  • Exposure to multi-jurisdiction / cross-border regulatory and privacy environments.
  • Familiarity with MITRE ATT&CK, FS-ISAC, and financial-sector threat landscapes.
  • Hands-on experience with GRC/IRM and TPRM platforms and reporting/BI tooling.
  • Relevant certifications: CISM, CISSP, CRISC, CISA, or ISO 27001 Lead Auditor (highly preferred).

Location

This role is open to candidates in the following locations: New York City, Chicago, Austin, Dallas, Denver, Miami, San Francisco Bay Area, or Seattle. 

  • If based in New York or Chicago: This role is expected to come into the office on a cadence set by the Hiring Manager/Team.
  • If based in Austin, Dallas, Denver, Miami, San Francisco, or Seattle: This is a fully remote role, though you may need to visit our onsite offices from time to time.
  • If you're not based in one of the locations listed above, this role is not a fit, and we cannot accommodate remote work outside these locations.
  • Applicants must be authorized to work for any employer in the U.S. DriveWealth does not sponsor or take over sponsorship of an employment visa at this time.

Pay Range: $270,000 – $290,000 USD

Working at DriveWealth

We do our best work when we're in the same room. To maintain the speed our partners expect, our New York, Chicago, and Lithuania teams work in office on a hybrid schedule. We've found that being physically side-by-side is the only way to solve complex problems in real-time and stay truly accountable to the products we ship. When you're here, you're working directly with the people making the decisions.

To support that work, we provide competitive compensation, equity, and a 401(k) match. We also offer Medical insurance, Dental insurance, Vision insurance, Disability insurance, and Paid Parental Leave, along with a wellness reimbursement, a company-provided phone, and a personal development allowance. Finally, we value the time you spend away from the office with generous Paid Time Off (PTO) and observed holidays.

Work Authorization

Applicants must possess the legal right to work in the country where the position is located at the time of application. DriveWealth requires all employees to provide original documentation verifying their work authorization on or before their first day of employment.

For US-based roles: Applicants must be currently authorized to work in the United States on a full-time basis without the need for current or future visa sponsorship. DriveWealth does not provide visa sponsorship or support for employment authorization, including transfers, at this time. Offers of employment are strictly contingent upon an individual’s ability to secure and maintain the legal right to work at the Company.

How We Think About AI

We leverage AI to work smarter and move faster. We seek AI-curious talent who are proactive about using emerging tools to increase signal quality, reduce friction, and improve outcomes to deliver products faster, provide better service to our partners, and to streamline processes. Your ability to leverage our internal tools and technology to drive results is as important to us as your core domain expertise.

Compensation

Pay is generally based on the level, complexity, responsibility, location, and job duties/requirements of the specific position. We then source candidates with the requisite skills, expertise, education, training, and experience.  If you are selected for an interview, please feel welcome to speak to a recruiter about our compensation philosophy and other available benefits. This role is eligible for base, bonus, equity, 401(k) match, and heavily subsidized benefits and perks.

Equal Employment Opportunity

To build technology and products that are used and loved by people and solve real-world problems, we need to build a team with many different perspectives and experiences. We are an equal opportunity employer. We do not discriminate based on race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. We encourage candidates from all backgrounds to apply. 

Agency Disclaimer

DriveWealth does not accept agency resumes. Do not forward resumes to our jobs alias, employees, or any other organization location. DriveWealth is not responsible for any fees related to unsolicited resumes.

About the company

DriveWealth

DriveWealth is a global B2B financial technology platform. Our core business is providing Brokerage-as-a-Service, powering the investing and trading experiences for banks, broker dealers, asset managers, digital wallets, and consumer brands. DriveWealth’s APIs provide our Partners with a modern, extensible, and flexible toolkit to develop everything from traditional investment workflows to more innovative techniques such as rounding up purchases into fractional share ownership.

DriveWealth, LLC is a registered broker dealer, member of FINRA and SIPC. Visit legal.drivewealth.com for full disclosures.

Company size

201-500 employees

Industry

Financial Services

Org type

Privately Held

Headquarters

New York, NY

Apply Now

About the company

DriveWealth

DriveWealth is a global B2B financial technology platform. Our core business is providing Brokerage-as-a-Service, powering the investing and trading experiences for banks, broker dealers, asset managers, digital wallets, and consumer brands. DriveWealth’s APIs provide our Partners with a modern, extensible, and flexible toolkit to develop everything from traditional investment workflows to more innovative techniques such as rounding up purchases into fractional share ownership.

DriveWealth, LLC is a registered broker dealer, member of FINRA and SIPC. Visit legal.drivewealth.com for full disclosures.

Company size

201-500 employees

Industry

Financial Services

Org type

Privately Held

Headquarters

New York, NY

Footer

sidehustles.com
Facebook Twitter Instagram LinkedIn Reddit TikTok YouTube

Show Me The Money

  • Side Hustle Basics
  • Side Hustle Job Board (Remote & Part-Time Jobs)
  • Gig App Reviews
  • Job Hunting
  • Manage Your Money
  • The Gig Apple: News & Events

Company

  • About Us
  • Contact Us
  • Become a Contributor
  • Advertising & Sponsorships
  • Partner With Us
  • Editorial Guidelines

Side Hustles © All rights reserved

  • Privacy Policy
  • Terms of Service

Thanks for using our free job board

Your review would mean a lot to us.

If you love that we're just giving away remote jobs for free with no paywall, please spread the word. (You will need to create an account on Trustpilot, for which we'll be eternally grateful.) Good luck out there!

Leave a Review Not yet. Send me to the job post.