VP, Security Engineering Programs & Controls
SynchronyAbout the role
Job Description:
Role Summary/Purpose:
The VP, Security Engineering Programs & Controls will lead modernization of the Information Security Engineering control landscape, ensuring a complete vision for control coverage and standardization across all Security Engineering functions. The ideal candidate will have tactical and strategic experience in organizing and driving technology programs, and demonstrate a keen ability to integrate Governance, Risk, and Compliance (GRC) deliverables into program execution. The ideal candidate will have a working awareness of information security technologies, excellent organizational skills, and the ability to influence without direct authority to advance key security objectives.
Our Way of Working
We’re proud to offer you flexibility. At Synchrony, our way of working allows you to have the option to work from home near one of our Hubs or come into one of our offices. Occasionally you will be required to commute or travel for in person engagement activities such as business or team meetings, training and culture events.
*Field Sales and some Commercial team roles may have varied location requirements based upon partner obligations or preferences.
Essential Responsibilities:
Assess and create a vision for strengthening the GRC practices of Security Engineering including but not limited to publication of security controls, authoring and/or revision of ancillary documentation (e.g., Synchrony Policies, Standards, and Procedures), and evidence-gathering practices
Advocate for and facilitate the integration of GRC into Security Engineering programs
Partner with Risk Managers and Governance personnel to ensure organizational alignment
Build and maintain a Security Engineering control library mapped to enterprise risks and frameworks (e.g., NIST/FFIEC/PCI as applicable).
Standardize evidence requirements, retention, and automation opportunities (e.g., GRC tooling, CI/CD artifacts, logging sources).
Partner on control testing/assurance activities (design/operating effectiveness), including periodic reviews and control health metrics.
Prioritize and align security objectives with the controls necessary for risk mitigation and operational efficiency
Lead and manage cross-functional information security engineering initiatives
Provide executive-ready communications and influence decisions through data and risk-based narratives.
Coordinate project planning, resource allocation, risk management, and stakeholder engagement to ensure program milestones are met. Establish and run a Security Engineering program governance cadence (steering, RAID, milestone reviews).
Drive consistent delivery artifacts: charters, business cases (as needed), integrated plans, RAID logs, comms plans.
Build strong collaborative relationships with security engineers, architects, compliance teams, and business partners to drive program success.
Act as a key liaison between technical teams and business units, <
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s