Lead Security Governance Partner
Berwyn, United States · Hybrid · Full-time
- Posted 3w ago
- From Envestnet’s careers page
- Location
- Berwyn, United States
- Work mode
- Hybrid
- Type
- Full-time
- Level
- Lead
- Experience
- 8+ years
- Department
- Information Technology
Opens the listing on careers.envestnet.com
Let the right jobs find you
In your inbox every Wednesday and SaturdayPersonalised suggestions from verified career pages, matched to your role, location, level and skills.
About the role
Description
The application window will close November 1, 2026
Job Location
The primary work location for this role is Berwyn, PA or Remote with either a hybrid work or remote model.
The Team You’ll Join
You’ll join Envestnet’s Enterprise Cybersecurity team, partnering closely with Security Operations, Technology, Legal, People & Culture, Privacy, Compliance, and business leaders to strengthen the company’s security governance and assurance programs. The team works across the organization to assess and mitigate technology and information security risks, maintain effective policies and controls, support regulatory and audit requirements, and promote responsible security practices. In this role, you’ll contribute to key initiatives spanning human and insider risk, cybersecurity investigations, control assurance, security awareness, and emerging areas such as AI governance, helping Envestnet operate securely and maintain the trust of its clients, partners, and regulators.
How You’ll Contribute
Responsible for ensuring that technology decisions align with business strategy, regulatory requirements and client expectations. Encompasses administration of a strategic and comprehensive cybersecurity framework. Identifies, assesses and mitigates technology and information security risks to protect sensitive financial and client data. Establishes policies, controls and oversight to meet regulatory standards for the financial services and wealth management industry. Enables the company to operate securely, responsibly and at scale while maintaining trust with advisors, partners and regulators.
- Provides Security Governance support and advice companywide.
- Develops, validates, implements and maintains cybersecurity and related policies, standards, guidelines and procedures to ensure compliance with company and regulatory requirements.
- Collaborates with cross-functional teams and leaders to ensure security related controls are understood, documented and managed.
- Coordinates with Legal and across relevant compliance functions to ensure proper implementation of data privacy legislation and disclosure.
- Establishes and maintains the framework and roadmap for Security Governance documentation.
- Works with Cyber Security team members and business partners to define risk tolerance and construct risk scenarios.
- Ensures risk scenarios provide a realistic and relatable view of risks based on business context, system environment and pertinent threats.
- Human Risk Program Design and Governance: Support human risk and insider risk governance — including risk assessments, playbooks, and monitoring reviews — in partnership with Security Operations, HR, Legal, Privacy, and Compliance.
- Investigations and Incident Response: Lead or coordinate insider threat investigations (fraud, data exfiltration, policy violations, misuse of privileged access), following sound evidentiary and forensic practices and escalating appropriately to Legal, HR, and executive stakeholders.
- Second Line Risk Management and Regulatory Compliance: Translate regulatory and framework requirements into practical control assessments, track remediation, and prepare risk summaries for audit, regulatory, and management reporting.
- Information Security Assurance and Attestation: Support control assessments and evidence collection for internal assurance, external audits, and customer due diligence, documenting findings and control gaps clearly.
- Awareness, Training, and Culture: Develop role-based security awareness content and training, and help build a culture of early reporting and responsible security behavior.
- Metrics and Continuous Improvement: Track assessment and remediation metrics, and recommend improvements to assurance processes based on trends and lessons learned.
- AI Governance and Risk Management: Assess and secure AI/ML systems, agentic ecosystems, and AI-assisted development across the software lifecycle — including AI platforms (e.g., AWS Bedrock, Claude, Copilot), agent/orchestration frameworks, and RAG/LLM integrations — while identifying and mitigating AI-specific risks such as prompt injection, jailbreaking, data poisoning, and model exfiltration, in alignment with NIST AI RMF and ISO 42001.
What You’ll Need to Bring
Candidates should demonstrate the relevant experience, skills, and capabilities needed to successfully perform in the role. Relevant experience may be gained through current responsibilities, prior roles, project work, leadership opportunities, or other comparable experiences.
- Experience in a regulated financial services environment (wealth management, banking, insurance, payments, technology, or FinTech), with working knowledge of cybersecurity controls, data protection, IAM, cloud security, incident response, security monitoring, and AI-related risk considerations.
- Familiarity with industry frameworks such as NIST CSF, NIST SP 800-53, NIST AI RMF, SOC 1/SOC 2, CIS Critical Security Controls, SEC Regulation S-P, and applicable privacy requirements.
- Strong cross-functional communication and analytical skills — able to influence without direct authority, translate risk/control concepts for technical and non-technical audiences, and produce clear assessment summaries, evidence requests, findings, and remediation tracking materials.
Nice-to-Haves
- 8–10 years of experience in information security, security governance, technology risk, cybersecurity assurance, internal audit, compliance, security operations, privacy, or related risk management functions.
- 2–4 years of experience supporting cybersecurity control assessments, audit readiness, evidence collection, risk assessments, human risk management, security awareness, insider risk, or data protection activities.
- CISSP, CISM, CRISC, CISA, Certified Fraud Examiner, GCFA, GCIH, GCFE, or related GIAC certification.
- Familiar with the Insider Threat Matrix framework concepts, including motive, means, preparation activities, infringement techniques, and anti-forensics as an investigative taxonomy.
- Knowledge of SaaS service architecture frameworks, cloud security services (Azure, AWS) and cyber defense tools.
Skills they ask for
Pick one to see other roles that ask for it.
About Envestnet
Wealth technology for financial advisorsEnvestnet provides wealth management technology and services that help financial advisors support clients and manage investments.
See all 44 roles at EnvestnetMore roles at Envestnet
See all 44- Associate Solutions ArchitectThiruvananthapuram · Entry Level · HybridInformation Technology · Entry Level · HybridThiruvananthapuram, India2w
- Lead Software Development EngineerThiruvananthapuram · Lead · HybridSoftware Development · Lead · HybridThiruvananthapuram, India2w
- Senior Data Intelligence AdvisorThiruvananthapuram · Senior · HybridData and Analytics · Senior · HybridThiruvananthapuram, India2w
- Client Service AssociateRaleigh · HybridCustomer Service · HybridRaleigh, United States2w
Let the right jobs find you
In your inbox every Wednesday and SaturdayPersonalised suggestions from verified career pages, matched to your role, location, level and skills.