{"id":25681,"date":"2026-07-09T18:29:38","date_gmt":"2026-07-09T18:29:38","guid":{"rendered":"https:\/\/www.pasona.com\/job\/062626\/"},"modified":"2026-07-09T18:29:38","modified_gmt":"2026-07-09T18:29:38","slug":"062626","status":"publish","type":"job_listing","link":"https:\/\/www.pasona.com\/en\/job\/062626\/","title":{"rendered":"Founding Security Operations &amp; GRC Lead"},"content":{"rendered":"<p>Founding Security Operations &amp; GRC Lead<\/p>\n<p>A newly established fintech and trust bank focused on digital payments and digital asset infrastructure.<\/p>\n<p><\/p>\n<p>Confidential Search<\/p>\n<p>\u00a0Location: Remote, U.S.-Based<\/p>\n<p>\u00a0Employment Type: Full-Time<\/p>\n<p>\u00a0Compensation: $140,000\u2013$190,000 Base Salary (Depending on Experience)<\/p>\n<p><\/p>\n<p><\/p>\n<p>Position Overview<\/p>\n<p><\/p>\n<p>The Founding Security Operations &amp; GRC Lead will serve as the internal owner of security operations execution and governance activities across cloud infrastructure, enterprise technology, product platforms, and third-party vendors.<\/p>\n<p><\/p>\n<p>The organization leverages specialized security, infrastructure, compliance, and advisory partners for implementation and monitoring activities; however, internal ownership of security findings, remediation tracking, risk management, control evidence, and examination readiness remains critical.<\/p>\n<p><\/p>\n<p>This role is ideal for someone with experience in security operations, cloud security, security governance, technology risk management, audit support, or security compliance within regulated industries.<\/p>\n<p><\/p>\n<p><strong>Key Responsibilities<\/strong><\/p>\n<p>Security Operations<\/p>\n<p>Manage day-to-day security operations across cloud, product, vendor, and enterprise technology environments.<\/p>\n<p>Monitor and coordinate remediation of security findings from security tools, cloud monitoring services, and third-party assessments.<\/p>\n<p>Review, triage, prioritize, track, and escalate security alerts and security-related issues.<\/p>\n<p>Coordinate security incident response activities, including investigation support, escalation, evidence preservation, communications, and post-incident review.<\/p>\n<p>Cloud Security<\/p>\n<p>Support cloud-security posture management within AWS environments.<\/p>\n<p><u>Oversee security controls related to:<\/u><\/p>\n<p>IAM<\/p>\n<p>CloudTrail<\/p>\n<p>AWS Config<\/p>\n<p>Security Hub<\/p>\n<p>GuardDuty<\/p>\n<p>Inspector<\/p>\n<p>Macie<\/p>\n<p>KMS<\/p>\n<p>Secrets Manager<\/p>\n<p>WAF<\/p>\n<p>Backup and recovery controls<\/p>\n<p>Maintain cloud-security documentation and evidence for audits and examinations.<\/p>\n<p>Governance, Risk &amp; Compliance (GRC)<\/p>\n<p>Maintain security control documentation, audit evidence, risk registers, and security exception records.<\/p>\n<p>Support access governance activities, including user access reviews, privileged access certifications, and joiner\/mover\/leaver processes.<\/p>\n<p>Prepare and organize security evidence for internal audits, external audits, regulatory examinations, and third-party reviews.<\/p>\n<p>Assist with ongoing compliance and examination-readiness initiatives.<\/p>\n<p>Vendor Risk &amp; Oversight<\/p>\n<p>Coordinate security oversight activities involving critical third-party providers and security partners.<\/p>\n<p>Review vendor security documentation, assessment results, penetration-test reports, and remediation plans.<\/p>\n<p>Track vendor-related security issues and follow up on corrective actions.<\/p>\n<p>Secure Development &amp; Vulnerability Management<\/p>\n<p>Partner with engineering and platform teams to support secure SDLC controls.<\/p>\n<p><u>Coordinate remediation activities for findings from:<\/u><\/p>\n<p>Vulnerability assessments<\/p>\n<p>Penetration tests<\/p>\n<p>Code reviews<\/p>\n<p>SAST tools<\/p>\n<p>Dependency scans<\/p>\n<p>Secrets scanning<\/p>\n<p>Container security reviews<\/p>\n<p>Track remediation progress and ensure timely closure of identified risks.<\/p>\n<p>Regulatory &amp; Examination Readiness<\/p>\n<p>Maintain organized, accurate, and examination-ready security evidence.<\/p>\n<p>Support regulatory readiness activities and ensure security controls remain properly documented and defensible.<\/p>\n<p>Provide regular updates to leadership regarding security risks, incidents, remediation efforts, and control effectiveness.<\/p>\n<p>Qualifications<\/p>\n<p><strong>Required<\/strong><\/p>\n<p>7<u>+ years of experience in one or more of the following areas:<\/u><\/p>\n<p>Security Operations<\/p>\n<p>Cloud Security<\/p>\n<p>Information Security<\/p>\n<p>Technology Risk<\/p>\n<p>Incident Response<\/p>\n<p>Vulnerability Management<\/p>\n<p>GRC \/ Security Compliance<\/p>\n<p>Experience supporting security programs in regulated or audit-sensitive environments.<\/p>\n<p><u>Strong understanding of:<\/u><\/p>\n<p>Incident response<\/p>\n<p>Alert triage<\/p>\n<p>Access reviews<\/p>\n<p>Vulnerability management<\/p>\n<p>Risk remediation<\/p>\n<p>Security control documentation<\/p>\n<p>Hands-on experience with AWS security services and cloud-security operations.<\/p>\n<p>Experience working with SIEM, MDR, EDR, vulnerability management, identity management, and ticketing platforms.<\/p>\n<p>Ability to coordinate effectively across technical teams, business stakeholders, and external partners.<\/p>\n<p>Strong documentation, communication, and organizational skills.<\/p>\n<p>Preferred<\/p>\n<p><u>Experience within:<\/u><\/p>\n<p>Banking<\/p>\n<p>Fintech<\/p>\n<p>Payments<\/p>\n<p>Trust companies<\/p>\n<p>Financial services<\/p>\n<p>Digital asset or custody environments<\/p>\n<p>Familiarity with:<\/p>\n<p>OCC examination readiness<\/p>\n<p>FFIEC guidance<\/p>\n<p>NIST CSF<\/p>\n<p>NIST 800-53<\/p>\n<p>SOC 2<\/p>\n<p>GLBA<\/p>\n<p>CIS Controls<\/p>\n<p>Experience supporting AWS multi-account cloud environments.<\/p>\n<p>Exposure to digital assets, blockchain, stablecoins, wallets, custody platforms, or regulated payment systems.<\/p>\n<p>Experience supporting Microsoft 365, endpoint security, identity governance, EDR, or SASE technologies.<\/p>\n<p>Professional certifications such as:<\/p>\n<p>CISSP<\/p>\n<p>CISM<\/p>\n<p>CISA<\/p>\n<p>CCSP<\/p>\n<p>AWS Security Specialty<\/p>\n<p>GIAC<\/p>\n<p>Security+<\/p>\n<p><\/p>\n<p><strong>What Makes This Opportunity Unique<\/strong><\/p>\n<p>Founding-level security leadership role with significant visibility and impact<\/p>\n<p>Opportunity to help build security operations and governance programs from the ground up<\/p>\n<p>Direct interaction with executive leadership, including CTO\/CISO<\/p>\n<p>Exposure to regulatory, cloud-security, vendor-risk, and audit-readiness initiatives<\/p>\n<p>Collaborative environment supported by specialized security and compliance partners<\/p>\n<p>Remote work flexibility within the United States<\/p>\n<p><\/p>\n<p>Interested candidates should possess a hands-on approach, strong ownership mentality, and the ability to thrive in a fast-paced, high-growth environment where security, compliance, and operational excellence are critical to success.<\/p>\n<p><\/p>\n<p>Ro apply, please email your resume to <a href=\"mailto:xjiang@pasona.com\" rel=\"noopener noreferrer\" target=\"_blank\">xjiang@pasona.com<\/a><\/p>\n","protected":false},"author":0,"featured_media":0,"template":"","meta":{"_acf_changed":false,"_promoted":"","_job_location":"","_application":"","_company_name":"","_company_website":"","_company_tagline":"","_company_twitter":"","_company_video":"","_filled":0,"_featured":0,"_remote_position":0,"_job_salary":"","_job_salary_currency":"","_job_salary_unit":""},"job-categories":[],"job-types":[],"class_list":["post-25681","job_listing","type-job_listing","status-publish","hentry"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.pasona.com\/en\/wp-json\/wp\/v2\/job-listings\/25681","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.pasona.com\/en\/wp-json\/wp\/v2\/job-listings"}],"about":[{"href":"https:\/\/www.pasona.com\/en\/wp-json\/wp\/v2\/types\/job_listing"}],"wp:attachment":[{"href":"https:\/\/www.pasona.com\/en\/wp-json\/wp\/v2\/media?parent=25681"}],"wp:term":[{"taxonomy":"job_listing_category","embeddable":true,"href":"https:\/\/www.pasona.com\/en\/wp-json\/wp\/v2\/job-categories?post=25681"},{"taxonomy":"job_listing_type","embeddable":true,"href":"https:\/\/www.pasona.com\/en\/wp-json\/wp\/v2\/job-types?post=25681"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}