Mariner
VP Cyber GRC, Vendor Management & Awareness
United States · Vp
Sponsorship not specifiedDetected 26 days ago
CybersecurityComplianceM&AVendor ManagementProcurementLeadership
About the role
- Experience designing and implementing security metrics programs, risk quantification frameworks, and executive-level reporting to link cybersecurity performance with business outcomes; ability to translate technical risks for board and senior leadership.
- We welcome your interest in being a part of our firm.
Responsibilities
- Build and enhance the enterprise security awareness and training program, incorporating phishing simulations, role-based training, security culture assessments, and executive initiatives to measurably reduce human-related security risks.
- Lead AI governance strategy in cybersecurity, including acceptable use policies, model risk analysis, risk tiering of use cases, and oversight of third-party AI tools to meet emerging regulatory standards and support digital workforce initiatives.
- Develop a cyber risk management capability that produces quantified risk posture reporting, key risk indicator dashboards, and board-level cyber risk intelligence connecting program performance to business strategy and investment priorities.
- Collaborate with Security Architecture & Engineering, Monitoring & Response, Legal, and enterprise IT governance to integrate cyber GRC into strategic planning, mergers & acquisitions, product launches, and change management.
- Represent the cybersecurity organization to regulators, auditors, and third-party assessors; support examination management, regulatory response, and supervisory engagement in partnership with the CISO.
- Establish and lead the Cyber GRC function, including the development of cybersecurity policies, implementation of control frameworks (NIST CSF 2.0, CIS Controls v8, ISO 27001), compliance monitoring, and audit readiness aligned with SEC, FINRA, and state regulatory requirements (e.g., NYDFS).
- Proven ability to lead at the executive level and build mature security programs from the ground up.
- Demonstrated success building and maturing technology risk management, security assurance, and compliance programs at scale; experience launching new security functions and revitalizing underperforming programs.
- Strong strategic advisory skills and cross-functional leadership, with the ability to collaborate with CISOs, CIOs, and business executives to align security strategy with business goals, and to influence across engineering, legal, finance, and operational teams.
Requirements
- 15+ years of progressive cybersecurity and risk management experience in leadership roles within large, complex enterprises-particularly in financial services, insurance, technology, or media.
- Direct experience in financial services required
- experience launching new security functions and revitalizing underperforming programs.
- Experience designing and implementing security metrics programs, risk quantification frameworks, and executive-level reporting to link cybersecurity performance with business outcomes
- ability to translate technical risks for board and senior leadership.
- Required License/Certification:
Nice to have
- CISSP, CISM, CRISC, CISA, CGEIT, or equivalent.
- We believe in giving associates progressive opportunities, actively nurturing professional growth and giving back to the community.
- Relevant certifications preferred: CISSP, CISM, CRISC, CISA, CGEIT, or equivalent.
Benefits
- Required Education and Experience:
Apply directly at Mariner →Create a free account for alerts like thisView Mariner immigration profile
This listing is sourced directly from Mariner's careers page and normalized into a canonical job model.