- Location
- 999 Peachtree Street Northeast, Suite 2750 - ATLANTA, GA, United States of America
- Type
- Full-time
- Department
- IT
- Seniority
- VP
- Experience
- 10+ years
- Education
- Master
- Source
- Workday
Description
About Acrisure:
A global fintech leader, Acrisure empowers millions of ambitious businesses and individuals with the right solutions to grow boldly forward. Bringing cutting-edge technology and top-tier human support together, we connect clients with customized solutions across a range of insurance, reinsurance, payroll, benefits, cybersecurity, mortgage services – and more.
In the last twelve years, Acrisure has grown in revenue from $38 million to almost $5 billion and employs over 19,000 colleagues in more than 20 countries. Acrisure was built on entrepreneurial spirit. Prioritizing leadership, accountability, and collaboration, we equip our teams to work at the highest levels possible.
Job Summary:
We are seeking an experienced Vice President of Cybersecurity Governance, Risk & Compliance to build and lead Acrisure’s global cybersecurity governance, risk, and regulatory assurance function, establishing the operating model that translates cybersecurity risk into clear executive decisions and board-level visibility. In this role, you will set and operate the cyber governance model for a fast growing, highly acquisitive international fintech organization, ensuring risks are clearly identified, prioritized, and communicated to executive leadership and the board.
You will own cybersecurity governance, enterprise board-level management, regulatory readiness, audit, and examination response, IT general controls alignment, and security awareness and phishing resilience programs. Working closely with leaders across Cybersecurity, Technology, Legal (privacy), Operations, and Enterprise Risk Management, you will establish a scalable, defensible control environment that meets increasing regulatory and audit expectations while enabling business growth.
This role reports directly to the CISO, operates with enterprise‑level decision authority, and serves as a core member of the cybersecurity leadership team. Success requires deep expertise in cybersecurity risk and compliance within regulated environments, strong executive presence, and the ability to lead through influence in a complex, global, and rapidly evolving organization.
Responsibilities:
Cyber Governance, Policy, and Standards
- Own the operating cadence for the Cybersecurity Governance Committee (CyberGov), including agenda development, pre-read preparation, meeting facilitation, and follow through with decisions and action items. Ensure CyberGov functions as an active governance vehicle.
- Own the cybersecurity governance operating model, including policy lifecycle management, standards hierarchy, exception governance, and evidence of adoption.
- Translate executive approved cybersecurity policies into clear, enforceable standards and operating procedures that scale globally.
- Partner with IT and business leaders to ensure cybersecurity standards are embedded into core operating processes.
Cyber Risk Management
- Own the enterprise cybersecurity risk management program, including risk identification, scoring, treatment, acceptance, and reporting.
- Maintain the cybersecurity risk register and ensure risks are translated into clear decisions, prioritized remediation plans, and executive ready reporting.
- Partner with Enterprise Risk Management to integrate cyber risk appropriately into broader enterprise risk routines.
- Translate enterprise risk appetite into actionable cybersecurity decision frameworks and risk thresholds.
Regulatory Readiness & Compliance
- Lead cybersecurity compliance readiness across applicable regulatory regimes and expectations, including NYDFS 500, FCA/DORA, and a trajectory toward SOX and SEC audit readiness.
- Continuously monitor regulatory and supervisory changes and drive corresponding enhancements to the cybersecurity program.
- Ensure global consistency in cyber controls while accounting for regional regulatory differences.
Audit & Examination Leadership
- Own the end-to-end cybersecurity audit and examination operating model, including intake, scoping, evidence management, response coordination, issue remediation, and closure.
- Serve as the single point of accountability for all cybersecurity audits and examinations (internal and external).
- Ensure audit outcomes drive sustained control and process improvement.
IT General Controls & Control Assurance
- Define and align cyber-relevant IT General Controls with IT and Operations, including access governance, change management, logging and monitoring, vulnerability and patch governance, and backup and recovery.
- Establish a sustainable approach to control assurance and evidence production aligned to audit and regulatory expectations.
M&A Cybersecurity Support
- Lead cybersecurity due diligence and provide clear, decision-ready risk assessments for mergers and acquisitions.
- Partner with IT and integration teams to ensure visibility and accountability for post-acquisition cybersecurity uplift toward company standards.
- Own a repeatable M&A cyber due diligence playbook and drive cybersecurity into the deal team process.
Security Awareness & Phishing Resilience
- Own the enterprise security awareness and training program, including role-based training, completion discipline, and effectiveness measurement.
- Own the phishing simulation and resilience program, using results to drive targeted risk reduction.
- Promote a culture where cybersecurity is embedded into how the business operates.
Metrics, Reporting, and Executive Communication
- Develop and maintain a concise set of cybersecurity KPIs and KRIs that reflect risk posture, control health, remediation velocity, and audit readiness.
- Deliver clear, consistent, and decision-oriented reporting to executive leadership, Cyber Governance, and other senior forums.
- Provide global visibility across regions while maintaining consistent definitions and expectations.
GRC Automation and AI Enablement
- Define and execute a GRC modernization roadmap that reduces manual process dependency, accelerates audit evidence cycles, and improves executive risk visibility.
- Drive adoption of AI-assisted workflows across risk identification, control assurance, and issue tracking. Establish measurable baselines and report progress against them.
Leadership & Talent Development
- Lead and scale a global Cybersecurity GRC organization
- Set a high bar for clarity, accountability, and execution.
- Build strong cross functional partnerships and lead effectively in a decentralized, fast-moving environment.
Leadership Approach
- Operates as a trusted peer within Acrisure’s enterprise risk ecosystem, partnering closely with Legal, Privacy, Internal Audit, Finance, and ERM to represent cybersecurity risk with credibility and authority.
- Leads with a cyber‑first, enterprise‑minded, and pragmatic approach; decisive, accountable, and focused on outcomes over unnecessary complexity.
- Establishes and runs a clear, disciplined GRC function with visible risks, managed audits, effective remediation tracking, and actionable reporting for senior leadership.
- Comfortable operating in ambiguity, bringing structure and clarity while aligning to broader enterprise risk and security priorities.
Education/Experience:
- Bachelor's degree required; CISSP, CISM, or CRISC strongly preferred; Master's degree a plus.
- 10+ years of experience across cybersecurity governance, risk management, compliance, audit, or assurance in regulated industries.
- 5+ years of experience leading teams and influencing senior executives.
- Demonstrated ability to build scalable governance, risk, and assurance programs in high growth or acquisitive environments.
- Strong executive communication skills including board level writing and presentations.
- Strong knowledge of cybersecurity and control frameworks such as NIST, ISO 27001, SOC, and financial regulatory environments.
- Experience managing audits, regulatory exams, and enterprise risk or control frameworks.
- Exceptional communication, stakeholder management, and problem-solving skills.
- Proven ability to lead projects and influence across a matrixed organization.
- Experience with GRC tools (e.g., OneTrust, Archer, LogicGate, ServiceNow GRC) preferred.
Candidates should be comfortable with an on-site presence to support collaboration, team leadership, and cross-functional partnership.
Why Join Us:
At Acrisure, we’re building more than a business, we’re building a community where people can grow, thrive, and make an impact. Our benefits are designed to support every dimension of your life, from your health and finances to your family and future.
Making a lasting impact on the communities it serves, Acrisure has pledged more than $22 million through its partnerships with Corewell Health Helen DeVos Children's Hospital in Grand Rapids, Michigan, UPMC Children's Hospital in Pittsburgh, Pennsylvania and Blythedale Children's Hospital in Valhalla, New York.
Employee Benefits
We also offer our employees a comprehensive suite of benefits and perks, including:
Physical Wellness: Comprehensive medical insurance, dental insurance, and vision insurance; life and disability insurance; fertility benefits; wellness resources; and paid sick time.
Mental Wellness: Generous paid time off and holidays; Employee Assistance Program (EAP); and a complimentary Calm app subscription.
Financial Wellness: Immediate vesting in a 401(k) plan; Health Savings Account (HSA) and Flexible Spending Account (FSA) options; commuter benefits; and employee discount programs.
Family Care: Paid maternity leave and paid paternity leave (including for adoptive parents); legal plan options; and pet insurance coverage.
… and so much more!
This list is not exhaustive of all available benefits. Eligibility and waiting periods may apply to certain offerings. Benefits may vary based on subsidiary entity and geographic location.
Acrisure is an Equal Opportunity Employer. We consider qualified applicants without regard to race, color, religion, sex, national origin, disability, or protected veteran status. Applicants may request reasonable accommodation by contacting [email protected].
Final candidates will be required to complete post-offer verification processes related to the role and in accordance with applicable laws.
California Residents: Learn more about our privacy practices for applicants by visiting the Acrisure California Applicant Privacy Policy.
Recruitment Fraud: Please visit here to learn more about our Recruitment Fraud Notice.
Welcome, your new opportunity awaits you.