Senior Manager, Security Risk Management (Fintech)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Senior Manager, Security Risk Management (Fintech): Leading Security Governance and the Security Third-Party Risk Management (TPRM) function with an accent on program strategy, operational maturity, and stakeholder alignment. Focus on setting the security risk posture, tightening governance and fourth-party oversight, and improving tooling and automation adoption.
Location: Remote (Canada)
Salary: $198,000 - $248,000 CAN base pay range per year
Company
is reinventing credit to make it more honest and friendly, giving consumers the flexibility to buy now and pay later without any hidden fees or compounding interest.
What you will do
- Maintain and evolve security policies, standards, and control frameworks (e.g., NIST CSF, ISO 27001).
- Lead the Security TPRM function across vendor lifecycle: intake/onboarding, due diligence, ongoing monitoring, periodic reviews, and offboarding.
- Oversee high-risk vendor decisions and escalations; establish clear RACI for partnership contracts and security acceptance criteria.
- Build, coach, and scale the Governance and TPRM teams: hiring, performance management, career development, and team morale.
- Serve as the security liaison for Internal Audit and external assessments; ensure timely remediation of findings and demonstrable progress.
- Produce regular program health reporting for senior leadership and Board-level stakeholders.
Requirements
- 7+ years in information security, risk management, or GRC roles, with a minimum of 3 years managing teams (or equivalent leadership experience).
- Demonstrated ownership of a TPRM program or security governance program in a regulated or high-growth technology environment (fintech preferred).
- Strong knowledge of security frameworks (NIST, ISO), compliance standards (SOC2, PCI), and vendor risk processes (IRQ/DDQ/SME assessments).
- Hands-on familiarity with TPRM/GRC tooling and observability: AuditBoard (or equivalent), Jira, BI tools (Sigma/Tableau/Looker), and experience with integrations/APIs.
- Excellent stakeholder management across legal, procurement, engineering, product, and executive leadership.
- Certifications such as CISSP, CISM, CRISC, or similar.
Culture & Benefits
- is proud to be a remote-first company! The majority of our roles are remote and you can work almost anywhere within the country of employment.
- Competitive benefits that are anchored to our core value of people come first.
- covers all premiums for all levels of health care coverage for you and your dependents.
- Generous stipends for spending on Technology, Food, various Lifestyle needs, and family forming expenses.
- Competitive vacation and holiday schedules allowing you to take time off to rest and recharge.
- An employee stock purchase plan enabling you to buy shares of at a discount.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →