Jobs and Careers
VA

Head of Security GRC

Valon
UKRemotefull_timeVerifiedPosted 14 May 2026
💰 $250,000/yr($190,000/yr$250,000/yr)

About the role

About the Company

Valon is building the AI-native operating system for regulated finance, starting with mortgage servicing.

We're a Series C company backed by a16z, transforming industries that others have written off as too complex to innovate.

Rather than build on top of broken legacy systems, we took a different approach: we built and operate our own mortgage servicing business managing $110+ billion in loans. This wasn't the end goal, it was how we deeply understood the complexity needed to build software that actually works in regulated industries.

The results speak for themselves. We've transformed mortgage servicing from a 0% margin business into 60%+ margins while dramatically improving customer experience. Major enterprise contracts are now deploying across the industry.

ValonOS is our unified platform that makes every process structured and programmable and it is perfectly positioned for the AI era. When everything flows through one system with rich data, AI agents don't just automate tasks, they continuously improve entire operations. Mortgage servicing is just the beginning of our vision to transform regulated industries and beyond.

Security at Valon

Our customers entrust us with some of their most sensitive and personal financial information, and it is the ultimate mission of Valon’s Security team to ensure we have sound programs, processes, and automation in place to safeguard our customers’ data. The Security team protects the infrastructure and data for processing billions of dollars of mortgage loans.

In addition to protecting Valon’s internal systems, the Security team partners closely with Product and Engineering to design and deliver secure, scalable, and trustworthy capabilities for ValonOS. As AI becomes central to how Valon builds and operates, our team is responsible for securing AI-powered systems and pipelines while also leveraging AI tools to optimize security and defense capabilities. We work cross-functionally across all teams at Valon to enable security throughout the organization. We engage with external security auditors, pentesting firms, and partners to continuously evaluate Valon’s security posture.

Valon offices are located in New York City and San Francisco, but we fully support remote work!

About the Role

We are seeking an experienced Head of Security Governance, Risk & Compliance (GRC) to lead Valon's governance, risk, and compliance practices. In this role, you'll own the frameworks, governance processes, and cross-functional relationships that keep Valon secure, risk-informed, and compliant with the regulatory and customer requirements of a modern fintech provider. You'll work closely with Engineering, IT, Legal, and executive leadership to translate security, data and resilience requirements into actionable controls and communicate risk posture clearly across the organization. Your work will directly enable Valon to deliver the security guarantees that protect our customers and their data — and position us to meet the rigorous due diligence requirements of institutional partners and regulated financial entities.

Responsibilities

  • Manage and expand Valon's security and privacy compliance program across key frameworks and regulations (e.g., SOC 2, NYDFS Cybersecurity Regulation, FTC Safeguards Rule, CCPA and evolving regulations)

  • Build and scale modern Security GRC capabilities that leverage AI-enabled tools and processes, reducing manual overhead while optimizing risk and compliance operations

  • Support AI security standards development and risk processes

  • Design, develop and monitor technical security controls

  • Lead audit preparation and management

  • Maintain and evolve Valon's risk management practices; facilitate risk assessments across teams and track remediation of identified issues to closure

  • Develop, publish, and maintain security policies, standards, and procedures in partnership with IT, Engineering and Legal

  • Build and mature Valon's Data Governance program including secure data handling practices

  • Enhance BC/DR risk management practices and processes

  • Partner with Engineering and Product to assess security compliance implications of new features, infrastructure changes, and data flows

  • Manage security compliance, regulatory requirements, and customer-facing due diligence, while supporting operational security activities including advisory reviews, incident management, and issue remediation

Ideal Background

  • Proven experience owning a security GRC program at a tech or fintech organization

  • Strong experience designing, develo

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Valon

View company profile →