Jobs and Careers
CO

Director of Cybersecurity Governance, Risk & Compliance

Coastal Community Bank
Untied States, United Statesfull_timeVerifiedPosted 15 Dec 2025
💰 $230,000/yr($195,217/yr$230,000/yr)

About the role

Description

ABOUT US 

  

Coastal is at the forefront of modern banking, combining strong financial infrastructure with cutting-edge Banking-as-a-Service (BaaS) and fintech enablement strategies. We support not only individuals with their personal banking needs; we also empower businesses by integrating modern banking technology that drives growth, flexibility, and innovation.


At Coastal, we think and move like entrepreneurs; focused on impact, speed, and continuous improvement. We believe in working smart, collaborating deeply, and building solutions that unlock real potential. If you're someone who thrives in a fast-moving environment, loves solving complex problems, and wants to help shape the future of banking, we’d love to meet you.


Check out our video here!


OVERVIEW 


The Director of Cybersecurity Governance, Risk & Compliance leads the Security Governance, Risk & Compliance (GRC) function and owns the overall health and maturity of Coastal’s Security Program. You will manage a small team and directly oversee Third Party Risk Management, security governance for BaaS and fintech programs, control definition and internal testing aligned to the NIST CSF, CRI Profile, and FFIEC IT Examination Handbooks, Business Continuity Management (BCM), security reviews of fintech partners, and identity and access certification campaigns. This role blends hands-on technical and GRC capability with strategic leadership. You’ll partner with Security Engineering, IT, Business Lines, Enterprise Risk, Internal Audit, Compliance, and fintech partners to translate regulatory expectations into auditable, automated, and durable controls that reduce risk and enable the business. 


RESPONSIBILITIES TO INCLUDE 


Leadership & Strategy 

  • Lead the Security GRC team responsible for Third Party Risk Management, control governance and testing, Business Continuity Management, and access governance. 
  • Set the vision, roadmap, and priorities for the Security Program in partnership with the CISO, other Security & IT functions, and Enterprise Risk Management. 
  • Mentor and develop team members. Define clear goals, performance expectations, and development plans. 
  • Act as a key advisor to security and business leadership on cyber and technology risk posture, tradeoffs, and remediation priorities. 

Security Program Ownership, Governance, and Execution 

  • Own the Security Program and ensure that regulatory, contractual, and internal security requirements are satisfied across the enterprise and BaaS/fintech ecosystem. 
  • Define and maintain the enterprise control baseline mapped to the NIST CSF, CRI Profile, and FFIEC IT Examination Handbooks, aligning with GLBA, SOX, and PCI-DSS where applicable. 
  • Author and approve control narratives, RACI, evidence requirements, testing procedures, and control objectives. Author and maintain cybersecurity governance documents, such as policies and standards. 
  • Work with technical control owners to implement processes and automations aligned to written controls, policies, and standards. 
  • Champion “policy as code” and guardrails (e.g., identity, configuration, network segmentation, logging/monitoring) in partnership with Security Engineering and IT. 
  • Oversee targeted cyber/IT risk assessments for technology changes, third parties, products, and fintech programs and ensure clear articulation of inherent and residual risk. 
  • Maintain a centralized log of issues, control gaps, and remediation plans; ensure sustainable fixes and prevent recurrences by updating baselines, standards, and automation. 
  • Partner with Enterprise Risk Management on risk acceptance, watch lists, and aggregation of security risks into enterprise risk reporting. 
  • Own the design and execution of access certification campaigns across key systems and applications (e.g., core banking, identity platforms, cloud, fintech partner integrations). 

Third Party Risk Management & Fintech Partner Security Reviews 

  • Own the Third Party Risk Management (TPRM) program for vendors who provide services to the Bank. 
  • Define and maintain risk-based onboarding, due diligence, and ongoing monitoring processes for third parties. 
  • Lead cybersecurity reviews of fintech partners, including evaluation of controls, data flows, architecture, and shared-responsibility models. 
  • Partner with Procurement, Legal, and Business Lines to ensure contracts and SLAs reflect appropriate security, privacy, and resilience requirements. 
  • Track remediation of vendor and fintech security issues and report status and residual risk

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Coastal Community Bank

View company profile →