Vice President, Cyber Governance, Risk & Compliance and Deputy CISO
Austin, TX - USA
Job Summary
We are seeking a seasoned Vice President of Cyber Governance Risk & Compliance to lead the strategy execution and continuous maturation of our cybersecurity governance risk and compliance program. Reporting to the Chief Information Security Officer this leader will oversee the frameworks processes and teams responsible for cyber risk governance regulatory readiness policy management control assurance third-party cyber risk oversight and related GRC capabilities.
In addition to leading Cyber GRC this executive will serve as Deputy CISO for Western Union supporting the CISO in the leadership and execution of the broader enterprise cybersecurity strategy. The Deputy CISO will represent the CISO in designated executive Board regulatory business and technology forums; help coordinate priorities across cybersecurity functions; provide leadership during significant cyber incidents; and assume delegated CISO responsibilities as required.
The successful candidate will combine deep GRC and financial services expertise with the executive presence business acumen cybersecurity knowledge and leadership capabilities necessary to operate across the full breadth of the cybersecurity organization.
Role Responsibilities (GRC):
- Lead the cyber GRC function and define strategic roadmap operating model and maturity targets.
- Maintain governance structures supporting cyber risk decision-making escalation and executive oversight.
- Drive cyber risk appetite exception management and risk acceptance processes.
- Oversee cyber and technology risk assessment methodologies and execution.
- Develop and maintain executive and Board-level cyber risk reporting and metrics.
- Lead preparation and coordination for regulatory exams internal/external audits and customer assessments related to cybersecurity.
- Oversee control framework management evidence programs and issue remediation governance.
- Own lifecycle management of security policies standards and governance documentation.
- Oversee cyber due diligence and ongoing risk monitoring for third-party vendors partners and strategic providers.
- Build mentor and scale a high-performing GRC team.
Role Responsibilities (Deputy CISO):
- Support the CISO in defining and executing the enterprise cybersecurity strategy.
- Serve as a strategic advisor to the CISO on cybersecurity risk organizational priorities investment decisions regulatory matters and emerging threats.
- Represent the CISO in designated executive Board business technology regulatory risk and governance forums.
- Help coordinate strategy priorities dependencies and execution across cybersecurity functions.
- Promote integration among Security Operations GRC IAM Security Engineering Architecture Application Security Threat Intelligence Incident Response Fraud and other relevant capabilities.
- Participate in cybersecurity strategic planning budgeting workforce planning investment prioritization and organizational design.
- Assist in preparing and delivering Board and executive-level cybersecurity reporting.
- Represent cybersecurity during significant regulatory examinations and interactions when delegated by the CISO.
- Identify cross-functional gaps and organizational risks and drive accountability for their resolution.
- Provide leadership continuity for the cybersecurity organization during periods when the CISO is unavailable.
- Assume additional CISO responsibilities and authorities when specifically delegated.
- Foster a culture of transparency accountability constructive challenge collaboration and continuous improvement.
- Build trusted relationships across Technology Operations Product Legal Compliance Risk Internal Audit and business leadership
Role Requirements:
- Bachelors degree required; advanced degree preferred.
- 15 years of experience in cybersecurity technology risk audit compliance or governance roles.
- 7 years of people leadership experience with increasing organizational scope.
- Proven experience building transforming or materially uplifting cyber GRC programs in financial services or similarly regulated industries.
- Deep knowledge of cybersecurity governance financial services regulatory expectations security/control frameworks audit/regulatory exams and third-party cyber risk programs.
- Experience interacting directly with senior executives Boards regulators auditors and risk committees.
- Demonstrated understanding of cybersecurity beyond GRC including security operations identity application security cloud security incident response security engineering architecture and emerging technology risk.
- Demonstrated ability to translate cybersecurity and technology risks into business terms and actionable executive decisions.
- Possesses at least one of the following professional credentials (or other industry-related credential):CISSP CRISC CISM CISA
The successful candidate will demonstrate:
- Executive presence and sound judgment
- Strategic and enterprise-level thinking
- Strong knowledge of cybersecurity and technology risk
- Regulatory fluency
- Transformation and change leadership
- Ability to influence across organizational boundaries
- Exceptional executive communication
- Strong people leadership and organizational development skills
- Ability to balance appropriate risk governance with business enablement
- Willingness and ability to challenge constructively while maintaining trusted relationships
What Success Looks Like. Within the first 1218 months this executive will:
- Complete a comprehensive assessment of Cyber GRC capabilities and maturity.
- Establish and begin executing a multi-year GRC transformation roadmap.
- Improve enterprise visibility into cybersecurity and technology risk.
- Strengthen executive and Board-level cybersecurity risk reporting.
- Improve regulatory and audit readiness and reduce recurring control issues.
- Mature policy governance exception management risk acceptance and issue-management processes.
- Strengthen first-line accountability for cybersecurity risk.
- Improve integration among Cyber GRC and other cybersecurity functions.
- Become a trusted advisor and strategic partner to the CISO.
- Effectively represent the CISO with executives regulators and governance bodies when required.
- Demonstrate the leadership breadth necessary to provide continuity for the CISO function and assume broader cybersecurity responsibilities when delegated.
Work Shift - HYBRID
Benefits
You will also have access to short-term incentives multiple health insurance options accident and life insurance and access to best-in-class development platforms to name a few. Please see the benefits below specific to your country. If applicable additional role-specific benefits will be mentioned during your interview process or in an offer of employment.
Your United States specific benefits include:
- Parental Leave
- Family First Programs
- Medical Dental and Life Insurance
- Tuition Repayment Assistance Program
For residents of Colorado California Connecticut Delaware Minnesota and Pennsylvania: Please do not respond to any questions on this initial application that may seek age-identifying information such as age date of birth or dates of school attendance or graduation. You may also redact this information from any materials you submit during the application process. You will not be penalized for redacting or removing this information.
Other Details
As part of the application process all applicants are required to take assessments. Western Union has partnered with a 3rd party provider to administer these tests. Applicants will need to provide their name and email address in order to process the assessments. If you have any questions you may reach out to .
We are passionate about honoring our employees identity and fostering a feeling of belonging. Our commitment is to provide an inclusive culture that celebrates the unique backgrounds and perspectives of our global teams while reflecting the communities we serve. We do not discriminate based on race color national origin religion political affiliation sex (including pregnancy) sexual orientation gender identity age disability marital status or veteran status. The company will provide accommodation to applicants including those with disabilities during the recruitment process following applicable laws.
Estimated Job Posting End Date:
This application window is a good-faith estimate of the time that this posting will remain open. This posting will be promptly updated if the deadline is extended or the role is filled.
Required Experience:
Exec