Lead GRC & Security Governance
Dave · United States
About this role
## Lead, GRC & Security Governance **About Dave** Dave is a financial app on a mission to build products that level the financial playing field. Dave is redefining access to liquidity through affordable, transparent, user-centric credit products—serving Americans who are financially vulnerable or living paycheck to paycheck. **The Opportunity** Dave is hiring a **Lead, GRC & Security Governance** to build and run governance systems that keep Dave’s technology organization **controlled, resilient, and audit-ready**. This is a **senior individual contributor** role with meaningful ownership across technology risk, controls, assurance, incident governance, and business continuity. ### What you’ll build and own - **Build and operate** Dave’s technology governance program across technology & cyber risk, IT controls, change management, incident management, business continuity, and policies. - **Establish and maintain** the technology control inventory: owners, evidence requirements, operating cadence, exceptions, and escalation paths. - **Own technology assurance and audit readiness** across programs including **SOX ITGC, PCI, SOC 2,** and other applicable frameworks—coordinate evidence, support testing, identify gaps, and drive remediation accountability through closure. - **Own the technology & cyber risk register** and control exception process—surface material or sustained risks with context and recommendations, including when escalation is resisted. - **Govern change management, incident management, and business continuity** so expectations are practical, consistently followed, tested, and continuously improved. - **Use AI and automation thoughtfully** to improve evidence analysis, control mapping, policy maintenance, risk reporting, audit preparation, and remediation tracking—while maintaining appropriate human review and data safeguards. ### The impact Strong governance helps Dave move with confidence—supporting operational resilience, strengthening risk understanding, meeting obligations, and scaling as the company grows. ### What we’re looking for - **8+ years** of relevant technology experience, including significant ownership in **security governance, technology risk,** or **security assurance**. - You’ve **personally led** a **SOC 2 Type II, ISO 27001,** or equivalent audit through a successful result (not just supported preparation). - You’ve built or materially rebuilt a **governance, risk, or assurance operating model** (not only administered an existing program). - Strong technical fluency across **cloud, identity, CI/CD, source control, endpoints, networks,** and **data platforms**—able to turn ambiguity into specific, testable controls. - Experience owning accountability while technical teams own remediation—able to influence Engineering, SRE, Security, IT, and Data partners without taking their work over. - Sound judgment around **risk and materiality**, including escalating meaningful risks when stakeholders disagreed. - Experience partnering credibly with **Internal Audit and Legal** in addition to technical and Security teams. - Strong written communication and program management—turn ambiguity into clear owners, decisions, actions, dates, and evidence. **Bonus** - Experience with **SOX ITGC, PCI DSS, NIST-based programs, AI governance/third-party AI risk,** and GRC automation platforms such as **Vanta** or **Drata**. ### What to expect You’ll have significant autonomy to shape a new function, while partnering clo
Listing freshness
CronJobs last confirmed this listing 2h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.