Senior Director, Cybersecurity GRC
Posted 4hrs ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Senior cybersecurity GRC leader modernizing governance, risk, compliance, and resilience programs at MoneyGram. Scaling automation and global teams for a regulated fintech organization.
Responsibilities:
- Transform and continuously mature MoneyGram’s global cybersecurity GRC organization
- Modernize governance, risk management, compliance, third-party risk, audit, security awareness, and resilience programs
- Develop a target-state operating model, multi-year modernization roadmap, service metrics, KPIs, and maturity targets
- Define and maintain global cybersecurity policies, standards, frameworks, and governance processes
- Lead enterprise cyber risk identification, assessment, quantification, mitigation planning, metrics, KRIs, dashboards, and executive reporting
- Oversee regulatory compliance, examinations, audits, certifications, assessments, remediation, and regulatory engagements across operating regions
- Own the strategy, implementation, adoption, and optimization of GRC technology platforms including Vanta
- Automate evidence collection, control monitoring, risk workflows, policy management, audit readiness, and compliance reporting
- Lead global third-party cyber risk management, vendor assessments, monitoring, remediation, and contractual security requirements
- Oversee security awareness, education, culture, and human risk management initiatives
- Maintain incident response preparedness, crisis management, tabletop exercises, and regulatory reporting readiness
- Advise executive leadership and represent cybersecurity with regulators, auditors, customers, and strategic partners
- Lead and develop a high-performing GRC organization and establish performance, development, succession, and accountability programs
Requirements:
- 15+ years of experience in cybersecurity, information security, risk management, compliance, audit, or related disciplines
- Minimum 7+ years of progressive leadership experience managing large cybersecurity, risk, or compliance organizations
- Proven experience transforming and scaling enterprise GRC programs within fintech, payments, banking, financial services, or similarly regulated industries
- Experience building and optimizing teams, operating models, and organizational capabilities
- Significant experience implementing and operationalizing GRC platforms such as Vanta, ServiceNow GRC, Archer, AuditBoard, OneTrust, or similar technologies
- Deep expertise in cybersecurity governance frameworks, regulatory compliance, audit management, and enterprise risk management
- Experience leading complex regulatory examinations and engagements across multiple jurisdictions
- Strong understanding of AWS, Azure, GCP, DevSecOps practices, and modern technology architectures
- Ability to drive large-scale transformation initiatives while managing multiple competing priorities
- Demonstrated success influencing executive leadership and operating effectively within matrixed organizations
- Exceptional communication and presentation skills, including regulator-facing experience
- Bachelor's degree in Cybersecurity, Information Systems, Risk Management, Business, or related field
- Preferred certifications: CISSP, CISM, CRISC, CCSP, PCI ISA, ISO 27001 Lead Implementer or Lead Auditor
- Preferred experience across multiple continents and regulatory regimes, quantitative cyber risk methodologies, AI governance and AI risk management, publicly traded companies, and automation/process redesign initiatives
Benefits:
- GRC technology and automation capabilities, including Vanta
- Career development pathways and succession plans
- Global organization exposure and executive, regulator, auditor, customer, and strategic partner engagement


















