GRC Program Lead
We're the hiring partner for a lean, talent-dense security team at a FinTech company with real household-name potential in the next 3 to 4 years.You'll be joining a security team of ~5 at a company of well under 200 people. Flat structure, no bureaucracy, no legacy tech debt. If you've spent your career watching GRC get bolted on as an afterthought, this is the opposite: you'd be building the program, not inheriting one.The role:You'd own security GRC end-to-end while also standing up third-party and supply chain security from scratch. That means building the vendor risk program, defining security requirements for partner integrations, and thinking hard about software supply chain risk (SBOM, open-source exposure, secure SDLC) in a regulated financial environment. You'd be the primary voice on security matters with auditors and regulatory examiners, translating dense regulatory requirements into programs that actually work.Who thrives here:Builder mentality: You've built or significantly matured a GRC/TPRM program before.AI-Fluency: Genuinely excited about using AI to modernize a function that's historically been slow and manualExecutive presence: comfortable briefing the CISO, leadership, and the BoardStartup-tested (nice to have): thrives building from zero.What's in it for you:Competitive base + meaningful equity (four-year vest) in a company built for an outsized outcomeFull benefits: healthcare, 401(k), unlimited PTO, daily meals coveredVisa sponsorship available (H-1B, etc.)Relocation support availableIf you want to help secure the next generation of FinTech infrastructure, let's talk.