Lead Security Governance Partner - Assurance

EnvestnetBerwyn, PA

Posted: 2026-09-17

Job Description

{"title":"Lead Security Governance Partner - Assurance","company_name":"Envestnet","location":"United States","via":"Envestnet Careers","job_highlights":[{"title":"Qualifications","items":["Candidates should demonstrate the relevant experience, skills, and capabilities needed to successfully perform in the role","Relevant experience may be gained through current responsibilities, prior roles, project work, leadership opportunities, or other comparable experiences","Employees must have achieved a performance rating of \"Meets Expectations\" or higher in the most recent appraisal cycle","Experience in a regulated financial services environment (wealth management, banking, insurance, payments, technology, or FinTech), with working knowledge of cybersecurity controls, data protection, IAM, cloud security, incident response, security monitoring, and AI-related risk considerations","Familiarity with industry frameworks such as NIST CSF, NIST SP 800-53, NIST AI RMF, SOC 1/SOC 2, CIS Critical Security Controls, SEC Regulation S-P, and applicable privacy requirements","Strong cross-functional communication and analytical skills — able to influence without direct authority, translate risk/control concepts for technical and non-technical audiences, and produce clear assessment summaries, evidence requests, findings, and remediation tracking materials","8–10 years of experience in information security, security governance, technology risk, cybersecurity assurance, internal audit, compliance, security operations, privacy, or related risk management functions","2–4 years of experience supporting cybersecurity control assessments, audit readiness, evidence collection, risk assessments, human risk management, security awareness, insider risk, or data protection activities","CISSP, CISM, CRISC, CISA, Certified Fraud Examiner, GCFA, GCIH, GCFE, or related GIAC certification","Familiar with the Insider Threat Matrix framework concepts, including motive, means, preparation activities, infringement techniques, and anti-forensics as an investigative taxonomy","Knowledge of SaaS service architecture frameworks, cloud security services (Azure, AWS) and cyber defense tools"]},{"title":"Benefits","items":["This role offers a base salary range of $138,000 to $170,000","The range listed represents a good-faith estimate of base salary compensation for this position and does not include incentive compensation, equity or benefits","Individual pay will be determined based on factors including, but not limited to, relevant experience, skills, education, certifications, and geographic location, in accordance with applicable pay transparency laws. This role is eligible for an additional incentive component as part of the total rewards package.","We provide a comprehensive suite of benefits - subject to Envestnet’s plan eligibility rules - that support your overall well-being including, medical insurance, paid time off (PTO), 401k company match, paid parental leave, education reimbursement, disability coverage and mental health & wellness support","Our investment in you means supporting you professionally, financially, and personally at every stage of your journey with us"]},{"title":"Responsibilities","items":["You’ll join Envestnet’s Enterprise Cybersecurity team, partnering closely with Security Operations, Technology, Legal, People & Culture, Privacy, Compliance, and business leaders to strengthen the company’s security governance and assurance programs","The team works across the organization to assess and mitigate technology and information security risks, maintain effective policies and controls, support regulatory and audit requirements, and promote responsible security practices","In this role, you’ll contribute to key initiatives spanning human and insider risk, cybersecurity investigations, control assurance, security awareness, and emerging areas such as AI governance, helping Envestnet operate securely and maintain the trust of its clients, partners, and regulators","Responsible for ensuring that technology decisions align with business strategy, regulatory requirements and client expectations","Encompasses administration of a strategic and comprehensive cybersecurity framework","Identifies, assesses and mitigates technology and information security risks to protect sensitive financial and client data","Establishes policies, controls and oversight to meet regulatory standards for the financial services and wealth management industry","Enables the company to operate securely, responsibly and at scale while maintaining trust with advisors, partners and regulators","Provides Security Governance support and advice companywide","Develops, validates, implements and maintains cybersecurity and related policies, standards, guidelines and procedures to ensure compliance with company and regulatory requirements","Collaborates with cross-functional teams and leaders to ensure security related controls are understood, documented and managed","Coordinates with Legal and across relevant compliance functions to ensure proper implementation of data privacy legislation and disclosure","Establishes and maintains the framework and roadmap for Security Governance documentation","Works with Cyber Security team members and business partners to define risk tolerance and construct risk scenarios","Ensures risk scenarios provide a realistic and relatable view of risks based on business context, system environment and pertinent threats","Human Risk Program Design and Governance: Support human risk and insider risk governance — including risk assessments, playbooks, and monitoring reviews — in partnership with Security Operations, HR, Legal, Privacy, and Compliance","Investigations and Incident Response: Lead or coordinate insider threat investigations (fraud, data exfiltration, policy violations, misuse of privileged access), following sound evidentiary and forensic practices and escalating appropriately to Legal, HR, and executive stakeholders","Second Line Risk Management and Regulatory Compliance: Translate regulatory and framework requirements into practical control assessments, track remediation, and prepare risk summaries for audit, regulatory, and management reporting","Information Security Assurance and Attestation: Support control assessments and evidence collection for internal assurance, external audits, and customer due diligence, documenting findings and control gaps clearly","Awareness, Training, and Culture: Develop role-based security awareness content and training, and help build a culture of early reporting and responsible security behavior","Metrics and Continuous Improvement: Track assessment and remediation metrics, and recommend improvements to assurance processes based on trends and lessons learned","AI Governance and Risk Management: Assess and secure AI/ML systems, agentic ecosystems, and AI-assisted development across the software lifecycle — including AI platforms (e.g., AWS Bedrock, Claude, Copilot), agent/orchestration frameworks, and RAG/LLM integrations — while identifying and mitigating AI-specific risks such as prompt injection, jailbreaking, data poisoning, and model exfiltration, in alignment with NIST AI RMF and ISO 42001","What You’ll Need to Bring"]}],"share_link":"https://www.google.com/search?ibp=htl;jobs&q=Security&htidocid=73QFIlnUpN9Ar4sHAAAAAA%3D%3D&hl=en-US&shem=epsd1,rimspwouoe&shndl=37&shmd=H4sIAAAAAAAA_x2OsQrCQBBEsc0npNpaSE4EG61ERBALQazD3rkkJ3E33G5C_Bm_1dNmiuExb4rPojhcCB9wozCmaG84yUSJkQPBFZMxJahgrzqmf1fBWTwoYQodCGdc2p7KXWc26NY51b5u1dBiqIO8nDB5md1TvP6i0Q4TDT0aNevNaq4HbpflkSfSrDKIDHeORvlQ3iD9AkeBbiShAAAA&shmds=v1_ARwrE21-DJz_Zw8GSZUw9nrolVd_cUc6R3lOwQL9dOfX1aFyFQ&source=sh/x/job/li/m1/1#fpstate=tldetail&htivrt=jobs&htiq=Security&htidocid=73QFIlnUpN9Ar4sHAAAAAA%3D%3D","thumbnail":"https://serpapi.com/searches/6ab11d3612eb1406217923d0/images/fjObHozxXQPe6xAypE_ANFtBGZ4H-Ivf9pWfbeJJAXQ.jpeg","extensions":["4 days ago","Full-time","No degree mentioned","Dental insurance","Health insurance","Paid time off"],"detected_extensions":{"posted_at":"4 days ago","schedule_type":"Full-time","qualifications":"No degree mentioned"},"source_link":"https://careers.envestnet.com/jobs/18257876-lead-security-governance-partner-assurance","job_title":"Lead Security Governance Partner - Assurance","description":"Description \n\n The application window will close November 1, 2026 \n\nJob Location   \n\nThe primary work location for this role is Berwyn, PA or Remote with either a hybrid work or remote model. \n\nAbout Envestnet  \n\nEnvestnet is an adaptive WealthTech company that is redefining the future of wealth management by helping advisors meet the moment with its comprehensive technology, actionable insights, and industry leading support. Backed by over 25 years of experience and approximately $7.0 trillion in platform assets, Envestnet is trusted by over one third of financial advisors across leading banks, wealth managers, brokerages, and RIAs.   \n\nFor a deeper look at how Envestnet is shaping the future of financial advice, visit www.envestnet.com.   \n\n   \n\nThe Team You’ll Join  \n\nYou’ll join Envestnet’s Enterprise Cybersecurity team, partnering closely with Security Operations, Technology, Legal, People & Culture, Privacy, Compliance, and business leaders to strengthen the company’s security governance and assurance programs. The team works across the organization to assess and mitigate technology and information security risks, maintain effective policies and controls, support regulatory and audit requirements, and promote responsible security practices. In this role, you’ll contribute to key initiatives spanning human and insider risk, cybersecurity investigations, control assurance, security awareness, and emerging areas such as AI governance, helping Envestnet operate securely and maintain the trust of its clients, partners, and regulators.\n\n \n\nHow You’ll Contribute   \n\nResponsible for ensuring that technology decisions align with business strategy, regulatory requirements and client expectations. Encompasses administration of a strategic and comprehensive cybersecurity framework. Identifies, assesses and mitigates technology and information security risks to protect sensitive financial and client data. Establishes policies, controls and oversight to meet regulatory standards for the financial services and wealth management industry. Enables the company to operate securely, responsibly and at scale while maintaining trust with advisors, partners and regulators. \n\nProvides Security Governance support and advice companywide. Develops, validates, implements and maintains cybersecurity and related policies, standards, guidelines and procedures to ensure compliance with company and regulatory requirements. Collaborates with cross-functional teams and leaders to ensure security related controls are understood, documented and managed. Coordinates with Legal and across relevant compliance functions to ensure proper implementation of data privacy legislation and disclosure. Establishes and maintains the framework and roadmap for Security Governance documentation. Works with Cyber Security team members and business partners to define risk tolerance and construct risk scenarios. Ensures risk scenarios provide a realistic and relatable view of risks based on business context, system environment and pertinent threats. Human Risk Program Design and Governance: Support human risk and insider risk governance — including risk assessments, playbooks, and monitoring reviews — in partnership with Security Operations, HR, Legal, Privacy, and Compliance.Investigations and Incident Response: Lead or coordinate insider threat investigations (fraud, data exfiltration, policy violations, misuse of privileged access), following sound evidentiary and forensic practices and escalating appropriately to Legal, HR, and executive stakeholders.Second Line Risk Management and Regulatory Compliance: Translate regulatory and framework requirements into practical control assessments, track remediation, and prepare risk summaries for audit, regulatory, and management reporting.Information Security Assurance and Attestation: Support control assessments and evidence collection for internal assurance, external audits, and customer due diligence, documenting findings and control gaps clearly.Awareness, Training, and Culture: Develop role-based security awareness content and training, and help build a culture of early reporting and responsible security behavior.Metrics and Continuous Improvement: Track assessment and remediation metrics, and recommend improvements to assurance processes based on trends and lessons learned.AI Governance and Risk Management: Assess and secure AI/ML systems, agentic ecosystems, and AI-assisted development across the software lifecycle — including AI platforms (e.g., AWS Bedrock, Claude, Copilot), agent/orchestration frameworks, and RAG/LLM integrations — while identifying and mitigating AI-specific risks such as prompt injection, jailbreaking, data poisoning, and model exfiltration, in alignment with NIST AI RMF and ISO 42001. \n\nWhat You’ll Need to Bring  \n\nCandidates should demonstrate the relevant experience, skills, and capabilities needed to successfully perform in the role. Relevant experience may be gained through current responsibilities, prior roles, project work, leadership opportunities, or other comparable experiences.Employees must have achieved a performance rating of \"Meets Expectations\" or higher in the most recent appraisal cycle.Experience in a regulated financial services environment (wealth management, banking, insurance, payments, technology, or FinTech), with working knowledge of cybersecurity controls, data protection, IAM, cloud security, incident response, security monitoring, and AI-related risk considerations. \nFamiliarity with industry frameworks such as NIST CSF, NIST SP 800-53, NIST AI RMF, SOC 1/SOC 2, CIS Critical Security Controls, SEC Regulation S-P, and applicable privacy requirements. Strong cross-functional communication and analytical skills — able to influence without direct authority, translate risk/control concepts for technical and non-technical audiences, and produce clear assessment summaries, evidence requests, findings, and remediation tracking materials. \n\nNice-to-Haves  \n\n8–10 years of experience in information security, security governance, technology risk, cybersecurity assurance, internal audit, compliance, security operations, privacy, or related risk management functions.2–4 years of experience supporting cybersecurity control assessments, audit readiness, evidence collection, risk assessments, human risk management, security awareness, insider risk, or data protection activities.CISSP, CISM, CRISC, CISA, Certified Fraud Examiner, GCFA, GCIH, GCFE, or related GIAC certification.Familiar with the Insider Threat Matrix framework concepts, including motive, means, preparation activities, infringement techniques, and anti-forensics as an investigative taxonomy.Knowledge of SaaS service architecture frameworks, cloud security services (Azure, AWS) and cyber defense tools. \n\nWhy You’ll Enjoy Working at Envestnet  \n\nHelp shape the future of WealthTech. At Envestnet you’ll gain hands-on experience and collaborate with some of the industry’s brightest minds to deliver meaningful, innovative solutions that make a real difference. \n\n \n\nWe value flexibility in how and where work gets done, and we recognize strong performance with meaningful rewards—because your contributions should drive both business success and your own personal growth. If you’re looking for a place where your work has impact, your development is supported, and your contributions are truly valued, Envestnet is where you can build your future. \n\n \n\nThe opportunity is now!  \n\n Sponsorship \n\nThis position is not open to candidates requiring visa sponsorship \n\n Our Investment in You \n\nThis role offers a base salary range of $138,000 to $170,000. The range listed represents a good-faith estimate of base salary compensation for this position and does not include incentive compensation, equity or benefits. Individual pay will be determined based on factors including, but not limited to, relevant experience, skills, education, certifications, and geographic location, in accordance with applicable pay transparency laws.  This role is eligible for an additional incentive component as part of the total rewards package.   \n\nWe provide a comprehensive suite of benefits - subject to Envestnet’s plan eligibility rules - that support your overall well-being including, medical insurance, paid time off (PTO), 401k company match, paid parental leave, education reimbursement, disability coverage and mental health & wellness support. Our investment in you means supporting you professionally, financially, and personally at every stage of your journey with us. Please visit our benefits page on our career site to learn more.   \n\n   \n\nOur Commitment to Inclusion & Belonging  \n\nEnvestnet is an Equal Opportunity Employer and is committed to creating an inclusive environment for all employees and applicants. We welcome and value individuals of all backgrounds and do not discriminate based on race, color, religion, creed, sex (including pregnancy or related medical conditions), gender identity or expression, sexual orientation, national origin, ancestry, age, disability, genetic information, military or veteran status, citizenship status, or any other status protected by applicable law. We encourage individuals from all backgrounds to apply.   \n\nWe strive to provide an inclusive application and interview process. If you are a candidate with a disability and require reasonable accommodation, please contact us at  careers@envestnet.com. Please include your full name, the title of the role you are applying for, and the accommodation necessary to assist you with the recruiting process.       \n\nRecruitment Fraud \n\nAt Envestnet, safeguarding the trust and safety of job seekers is a top priority. We are aware that scammers may impersonate Envestnet recruiters or create fake job opportunities to deceive candidates. Review the information on our recruitment fraud awareness page to help you recognize and avoid recruitment fraud.","apply_options":[{"title":"Envestnet Careers","link":"https://careers.envestnet.com/jobs/18257876-lead-security-governance-partner-assurance?utm_campaign=google_jobs_apply&utm_source=google_jobs_apply&utm_medium=organic"},{"title":"Indeed","link":"https://www.indeed.com/viewjob?jk=b8c8d6ab5f699c32&utm_campaign=google_jobs_apply&utm_source=google_jobs_apply&utm_medium=organic"}],"job_id":"eyJqb2JfdGl0bGUiOiJMZWFkIFNlY3VyaXR5IEdvdmVybmFuY2UgUGFydG5lciAtIEFzc3VyYW5jZSIsImNvbXBhbnlfbmFtZSI6IkVudmVzdG5ldCIsImh0aWRvY2lkIjoiNzNRRklsblVwTjlBcjRzSEFBQUFBQT09IiwidXVsZSI6IncrQ0FJUUlDSU5WVzVwZEdWa0lGTjBZWFJsY3ciLCJnbCI6InVzIiwiaGwiOiJlbiIsImZjIjoiRXN3QkNvd0JRVXBwVkRSMFNYUnlPVWh3YkZSRmQyVm9jV1pEUVRjelYyUmlaRUpaVnpoS1lYRkNXWHBXUVRsTmIzSjVPR2hyWlVsSllVMUxlazVUY0RkRFgyVkVOM1UzVlcxWmRGbDFiRzR3VkdKWFNUbHFXVjlaUVc1dVYxODFNbXBITW14UFJEVnlRM05pVURKM1RHRTRia1p4VVZrM1pqYzFObHAzYWw5QmVGSlNWWEl4ZW1KM1VFeG5aRmR5YjNNU0YxSm9NbmhoYzBSRFRWOURiSEYwYzFBeFNreExORUZGR2lKQlJITnlPV1pSZWpSSlVrbHJNbmR6YVZaVE16VlRVMHRMVTIxR1VVcHJUSEJCIiwiZmN2IjoiMyIsImZjX2lkIjoiNzNRRklsblVwTjlBcjRzSEFBQUFBQT09In0="}

View job and apply