Information Security Risk Management Director
BILLAbout the role
Do the best work of your career as a champion for small and mid-size businesses.
BILL is a leader in financial automation software for small and midsize businesses (SMBs). As a champion of SMBs, we are dedicated to automating the future of finance so businesses can thrive. Hundreds of thousands of businesses trust BILL solutions to manage financial workflows, including payables, receivables, and spend and expense management. With BILL, businesses are connected to a network of millions of members, so they can pay or get paid faster. Through our automated solutions, we help SMBs simplify and control their finances, so they can confidently manage their businesses, and succeed on their terms.
BILL is a trusted partner of leading U.S. financial institutions, accounting firms, and accounting software providers. We have operations in San Jose, CA, Draper, UT, Houston, TX and are continuing to expand into other geographic locations. If you’re looking for a place that helps you do the best work of your career, look no further than BILL.
Make your impact within a rapidly growing Fintech Company
BILL’s Information Security department is searching for an Information Security Risk Management Director to lead the security strategy for our growing Security Risk Management function, reporting to the Deputy CISO. The ideal candidate will bring a blend of technical acumen and strategic insight, capable of effectively communicating with stakeholders and guiding team members in alignment with our security culture and business priorities. The candidate will possess a strong background in cybersecurity and risk management, with working knowledge and experience in risk management frameworks such as NIST RMF, FAIR, and OWASP. Information Security is looking for a strong leader who is capable of working closely with cross-functional engineering teams and leadership to perform comprehensive security risk assessments, communicate identified risks effectively, and ensure timely remediation from a technical perspective, in addition to enhancing the security risk management program capabilities.
Key Responsibilities:
- Lead the comprehensive cyber risk management program including strategy, framework, process, execution, and continuous maturity
- Conduct security risk assessments to identify potential risks from threats and vulnerabilities within the organization's infrastructure and applications.
- Perform control effectiveness assessment by collaborating with cross-functional teams to understand technical implementations and assess control strength
- Communicate identified security risks and their potential impact to stakeholders, including technical and non-technical audiences.
- Develop and implement strategies for security risk remediation, ensuring alignment with technical, compliance and business requirements.
- Provide expert guidance on security controls and best practices to cross-functional teams and guide risk mitigation
- Maintain up-to-date knowledge of industry standards, regulatory requirements, and emerging threats to inform risk assessment and remediation processes.
- Lead the enhancement of the security risk management program, including policies, procedures, and frameworks.
- Track and report on the status of risk remediation efforts, ensuring timely resolution and compliance with organizational policies.
- Develop and present detailed reports on risk assessments, including identified threats, vulnerabilities, and the effectiveness of implemented mitigation measures. Ensure these reports are understandable to technical and non-technical stakeholders, including senior management
- Demonstrate a process-oriented, results-driven approach to security risk engineering, employing effective problem-solving and communication skills to serve as a subject matter expert and trusted advisor
We’d love to chat if you have:
- Bachelor’s degree in Computer Science, Information Security, or a related field.
- 10+ years of experience in security risk assessment, with a focus on qualitative analysis, or equivalent and relevant security experience.
- Strong technical knowledge of security controls, including but not limited to access controls, encryption, network security, and vulnerability management.
- Demonstrated experience working within a GRC framework, with an understanding of regulatory and compliance requirements (e.g., PCI DSS, SOC).
- Excellent communication skills at all levels, with the ability to articulate complex technical concepts to diverse audiences, including including C-Suite
- Proven ability to work collaboratively with engineering teams to assess and mitigate security risks.
- Experience with security risk remediation programs, including technical implementation and compliance c
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s