Security Compliance Manager
Employee Applicant Privacy Notice
Who we are:
Welcoming, collaborative and having the opportunity to make an impact - is how our employees describe working here. Galileo is a financial technology company that provides innovative and revolutionary software products and services that power some of the world's largest Fintechs. We are the only payments innovator that applies tech and engineering capabilities to empower Fintechs and financial institutions to unleash their full creativity to achieve their most inspired goals. Galileo leads its industry with superior fraud detection, security, decision-making analytics and regulatory compliance functionality combined with customized, responsive and flexible programs to accelerate the success of all payments companies and solve tomorrow's payments challenges today. We hire energetic and creative employees while providing them the opportunity to excel in their careers and make a difference for our clients. Learn more about us and why we work here at https://www.galileo-ft.com/working-at-galileo.
About The Role
The Governance, Risk, and Compliance (GRC) team handles a wide range of cross-functional activities, from security compliance certifications and audits, to risk management, inbound and outbound due diligence, third party risk management, security awareness, policy and procedures, and more.
Each of these ongoing parallel activities entails interpreting and setting requirements, assessing the effectiveness of security controls, risk-based decision making, cross-functional collaboration and communication, and staying up-to-date on security best practices and how changes in the evolving threat landscape need to inform our strategy.
We are seeking an experienced Security Compliance Manager responsible for monitoring and governing security controls in the cloud based on regulatory/compliance requirements and industry standards. Candidate must be able to assimilate knowledge quickly, understand stakeholder’s business challenges/risks, and act as a trusted advisor to lead change, policy adoption and monitor compliance against policies and standards.
Key job responsibilities:
Oversee audit and governance management: optimize year-round compliance, audit and regulatory efforts for SoFi and subsidiaries
Build and maintain an integrated cybersecurity controls framework
Monitor and report on compliance against Information Security policies and standards
Maintain security compliance programs within a GRC or compliance automation solution
Facilitate governance and track remediation within SLA’s for vulnerabilities, gaps, and control deficiencies and work with business stakeholders to establish plans for sustainable resolution
Define and execute existing or new compliance initiatives (i.e. SOC2, PCI, FFIEC CAT, NIST CSF, GLBA)
Work independently to conduct compliance quantitative assessments from beginning to end with minimal supervision, manage key stakeholders relationships
Identify the root cause of control gaps and exceptions and suggest remediation steps
Maintain a cybersecurity risk register
Prioritize and drive cross-functional remediation efforts for identified gaps based on risk impact and criticality
Compile and present compliance posture to senior leadership via metrics and dashboards
Minimum requirements:
BS degree in Computer Information Systems or related field
7+ years of experience with security GRC initiatives
Experience with onboarding and monitoring cybersecurity controls in cloud environments specifically AWS
Experience managing SOC2, PCI DSS, SOX ITGC, GLBA or other compliance standards and framework programs
Strong knowledge of security risk management and running audits/certification programs
Self-starter with strong interpersonal and communication skills
Demonstrate ability to assimilate new knowledge quickly
Comfortable working in a fast-paced, dynamic environment, and managing multiple projects concurrently
Experience with GRC tool implementation
Experience with scanning solutions for policy and technical standards compliance
Preferred qualifications
Big 4, or management/IT consulting experience
Relevant certification (e.g. CISA, CISSP, PCI QSA, AWS certifications) or equivalent expertise
Have knowledge of NIST 800-53/800-37,NIST CSF, SOC 2, PCI, and/or ISO 27001 standards, integrated controls framework, and evaluating design and effectiveness of IT controls working directly with auditors, regulators, investors
Experience in building successful compliance programs for banks or fintech
Experience defining compliance roadmaps based on customer requirements, compliance documentation, and ensuring that committed assessments are delivered on schedule
Technical fluency; comfortable understanding and discussing technology concepts, experience evaluating tradeoffs and new opportunities with technical team members
Galileo Financial Technologies provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion (including religious dress and grooming practices), sex (including pregnancy, childbirth and related medical conditions, breastfeeding, and conditions related to breastfeeding), gender, gender identity, gender expression, national origin, ancestry, age (40 or over), physical or medical disability, medical condition, marital status, registered domestic partner status, sexual orientation, genetic information, military and/or veteran status, or any other basis prohibited by applicable state or federal law.
The Company hires the best qualified candidate for the job, without regard to protected characteristics.
Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.
New York applicants: Notice of Employee Rights
Galileo is committed to embracing diversity. As part of this commitment, Galileo offers reasonable accommodations to candidates with physical or mental disabilities. If you need accommodations to participate in the job application or interview process, please let your recruiter know or email accommodations@sofi.com.
Due to insurance coverage issues, we are unable to accommodate remote work from Hawaii or Alaska at this time.
Galileo Financial Technologies is a robust financial technology platform that delivers core banking, card issuing, and payment processing services. Designed for fintechs, banks, and brands, it empowers them to create innovative financial solutions that enhance customer experiences.
- Founded
- Founded 2000
- Employees
- 500+ employees
- Industry
- Diversified Financial Services
- Total raised
- $77M raised