Sr Director, Cybersecurity GRC
MoneyGram Β· United States Β· via manual_submit
π Posted: not published by source Β· Found by agent: 2026-08-06 14:00
Application documents
Score breakdown
| Component | Raw | Weight | Contribution | Evidence |
|---|---|---|---|---|
| keywords | 100.0% | 30 | 30.0 | cisocybersecuritycyber risksocincident responsegovernanceregulatoryrisk managementcomplianceinformation security |
| seniority | 80.0% | 25 | 20.0 | Sr Director |
| location | 10.0% | 20 | 2.0 | unrecognized-locationunited states |
| salary | 50.0% | 15 | 7.5 | salary-not-stated |
| company | 100.0% | 10 | 10.0 | financial servicesfintechpayments |
Telegram alerts
2026-08-07T15:54:16+00:00 β chat 5272237815 Β· sent
Synthesis sent: MoneyGram seeks a Sr Director of Cybersecurity GRC to transform and scale its global governance, risk, compliance, third-party risk, and resilience programs, reporting directly to the CISO. This is a remote, full-time leadership role acting as a trusted advisor to executives, regulators, and auditors while modernizing the GRC operating model with automation.
full message
Resume customization
Variant Lucian_Lipinsky_CV__JPMC__2026.docx engine claude 31202 in / 13825 out tokens β 10/10 review passed
β¬ Download tailored resume (.docx) Β· π What changed (changelog)
Keywords injected / gaps: GRCgovernanceregulatory engagementsecond line of defensepolicy governanceaudit readinessrisk oversight
10-pass quality review
| # | Pass | Status | Detail |
|---|---|---|---|
| 1 | Grammar | APPROVED | Sentences grammatically correct throughout; no errors found. |
| 2 | Spelling | APPROVED | No misspellings detected (proper nouns/acronyms excluded). |
| 3 | Formatting consistency | APPROVED | 1 font(s), 5 size(s), consistent bullets |
| 4 | Logical layout | APPROVED | Section order matches base; logical, no orphaned sections. |
| 5 | LLM-artifact detection | APPROVED | no em dashes or LLM filler phrases detected |
| 6 | Job-description alignment | APPROVED | GRC, governance, policy, audit-readiness terms woven naturally, not stuffed. |
| 7 | Accomplishments emphasis | APPROVED | Key metrics (300+, 150+, $1.7T AUM) surfaced clearly, not buried. |
| 8 | No fabrication | APPROVED | No new employer, title, metric, or date beyond base content. |
| 9 | Consistency with base CV | APPROVED | Titles, dates, employers consistent with base resume. |
| 10 | Human readability | APPROVED | Reads naturally as human-written, professional tone maintained. |
Text preview
Lucian Lipinsky de Orlov lucian@lipinskyllc.com βͺ 914-656-0324 βͺ linkedin.com/in/lipinsky/ Senior cybersecurity GRC executive | financial services & fintech Second-Line Risk Oversight | Regulatory Engagement & Policy Governance Identity, Data & Privacy Risk | Executive Education & Advisory Senior cybersecurity risk and governance executive with 20+ years across global financial institutions and asset managers, including second-line of defense leadership at Citigroup (300+) and American Express (150+) and CISO-level accountability at Franklin Templeton ($1.7T AUM, 45 countries). Professional Experience Highlights American Express - New York, NY Senior Director, Risk & Information Security 2025 - Present Cybersecurity Technology & Resiliency Risk Oversight Senior Director leading American Express' global cybersecurity GRC and risk oversight organization, driving governance, policy, and compliance across data security, privacy, and identity & access management (IAM). Serve as global second-line risk owner for Data Loss Prevention (DLP), providing independent oversight and challenge of the first-line DLP program and directing corrective action across a first-line organization of 150+. Lead global GRC and cyber risk governance for data protection, privacy, and identity security across enterprise platforms, cloud, and third-party ecosystems. Advise senior executives on cyber risk exposure, control effectiveness, and practical risk-reduction actions impacting customers, employees, and business operations. Translate complex cybersecurity, privacy, and IAM risks into clear, practical guidance to support executive decision-making and risk awareness among non-technical stakeholders. Partner with technology, legal, privacy, and business leadership to align cyber risk governance and compliance programs with regulatory expectations and business objectives. Lead, coach, and set standards for a global team of senior cyber risk professionals. Citigroup - New York, NY Senior Vice President, Cyber Operational Risk Officer 2023 - 2025 Provided second-line independent risk oversight of Citi's Fusion Center, directing first-line teams (300+) on corrective action across threat intelligence, monitoring, and coordinated response capabilities. Senior GRC and cyber risk leader within Citi's Second Line of Defense, providing independent governance oversight and challenge across vulnerability management, incident response, threat intelligence, security operations, and policy governance. Advised senior leadership on cyber risk exposure, residual risk, and prioritization across global financial services operations. Translated technical findings into executive decision briefs for non-technical leadership. Served as regulatory liaison on cybersecurity governance, resilience, and remediation strategy across global operations, supporting audit and examination readiness. Oversaw global adversarial emulation exercises with focus on preparedness, judgment, and executive response readiness. Led governance efforts to review and modernize cybersecurity policies, standards, and guidelines to meet regulatory expectations and audit readiness. Franklin Templeton Investments - New York, NY Global Director of Security and Risk (CISO) 2019 - 2023 Advised UHNW individuals and family offices within Franklin Templeton's Fiduciary Trust subsidiary on personal and family office cybersecurity risks, including digital assets, privacy exposure, identity compromise, and secure handling of sensitive financial information. Executive accountable for global cybersecurity and risk management across 45 countries supporting $1.7T AUM. Advised executive leadership on cyber risk tradeoffs, investment decisions, and incident preparedness. Led incident response planning, executive tabletop exercises, and crisis simulations to strengthen organizational resilience and regulatory readiness. Architectural advisor to the world's first SEC-approved tokenized government money fund, advising on blockchain, cryptography, and operational risk. QuSecure - San Mateo, CA Board Advisor (Quantum Security) 2020 - 2023 Provided technical guidance on post-quantum cryptography architecture and applicability in regulated financial services environments. Translated complex quantum and cryptographic concepts into clear, credible narratives for executive leadership, potential investors, and media. Citihub - New York, NY Partner, CISO-for-Hire 2008 - 2015 Served as trusted cybersecurity advisor to C-suite executives across financial services and other industries. Delivered executive briefings, tabletop exercises, and strategic cyber guidance aligned to business risk. Deloitte Consulting - New York, NY Senior Manager, Security SME 2003 - 2008 Advised capital markets, wealth management, and retail banking clients on technology and security risk. Led large-scale regulatory and security initiatives and delivered C-level presentations. Private Bank Relevance Identity compromise, privacy exposure, fraud, and digital asset risk are primary cyber threats to UHNW individuals and family offices. Career experience translating institutional cyber risk into practical, personal, and reputational impact considerations applicable to Private Bank clients. Thought Leadership & Education Fordham University - Three Minute Thesis (3MT) Competition First Place Winner (2018) Recognized for delivering advanced cybersecurity research on AI-driven threat detection to a non-technical audience in under three minutes, demonstrating exceptional clarity, discipline, and executive communication. Fordham University - Lincoln Center, New York, NY Adjunct Professor, Center for Cybersecurity 2019 - Present Teach undergraduate and graduate courses in computer security systems, encryption, operating system vulnerabilities, and disaster recovery. Program designated by NSA/DHS as a National Center of Academic Excellence in Cyber Defense Education. Education MS in Cybersecurity Fordham University, Graduate School of Arts and Sciences, New York, NY NSA and DHS National Center of Academic Excellence in Cyber Defense Education Certified MS in Advanced Technology, Specialization in Computer Science Thomas J. Watson School of Engineering, Applied Science, and Technology Graduated School of State University of New York, Binghamton, NY BS in Computer Science State University of New York, Binghamton, NY Certification & Training ISACA CRISC - PMI Project Management Professional (PMP) - ITIL Foundation Certified - Certified Disciplined Agilist - Enterprise Lean Six Sigma Green Belt - CISSP (Candidate) - IBM Certified Professional - Project Management - New York State Notary Public
Full description (11147 chars)
Open source posting βCompany logo for, MoneyGram. MoneyGram Sr Director, Cybersecurity GRC United States Β· 1 day ago Β· Over 100 people clicked apply Promoted by hirer Β· Responses managed off LinkedIn Remote Full-time Apply Save Use AI to assess how you fit Show match details Tailor my resume Create cover letter Help me stand out People you can reach out to Company alumni from American Express Show all About the job At MoneyGram, we're combining the strength of a trusted global brand with the agility of a tech-forward, growth driven culture. With 80+ years of experience and a presence in more than 200 countries and territories, we've built a foundation of stability and trust to help millions of people around the world send funds quickly, securely, and affordably. We're looking for bold thinkers, builders, technologists, and sellers who want real ownership of their work, thrive in collaborative environments, and are energized by solving complex challenges. Here, you'll have the opportunity to make a measurable impact - fast. If you're eager to shape the future of cross-border payments and financial services, join us as we transform how the world moves money. At MoneyGram, we connect the world by making cross-border money transfers seamless, affordable, and secure for everyone. We are seeking a Senior Director of Cybersecurity Governance, Risk and Compliance (GRC) for our global organization. This role is responsible for transforming, scaling, and operationalizing the global cybersecurity GRC function. This leader will drive modernization of governance, risk management, compliance, third-party risk, audit, security awareness, and resilience programs while building a highly efficient, technology-enabled operating model capable of supporting a rapidly evolving global fintech organization. Reporting directly to the Chief Information Security Officer (CISO), this role serves as a trusted advisor to executive leadership, regulators, auditors, and business stakeholders. The ideal candidate is an experienced cybersecurity leader with a proven track record of building and maturing GRC organizations, driving operational excellence, implementing automation at scale, and leading high-performing global teams. This role requires a strategic thinker who can simultaneously manage multiple complex initiatives, influence senior stakeholders, navigate regulatory environments across multiple jurisdictions, and execute with a strong bias for action. What You Will Get To Do Cybersecurity Program Transformation & Operational Excellence Lead the transformation and continuous maturation of the global GRC organization, including governance, risk management, compliance, third-party risk, audit management, security awareness, and resilience programs. Assess organizational effectiveness and develop a target-state operating model that improves efficiency, scalability, accountability, and business alignment. Drive process optimization, simplification, and automation initiatives across the GRC portfolio. Establish measurable service delivery metrics, operational KPIs, and maturity targets to continuously improve program effectiveness. Build and execute a multi-year roadmap for GRC modernization aligned to business objectives and regulatory expectations. Governance & Policy Management Define and maintain global cybersecurity policies, standards, frameworks, and governance processes aligned with NIST CSF, ISO 27001, PCI DSS, SOC, and applicable financial services regulations. Ensure governance structures effectively support executive decision-making and risk-based prioritization. Drive consistent application of security requirements and controls across products, platforms, and regions. Enterprise Cyber Risk Management Lead the enterprise cyber risk management program, including risk identification, assessment, quantification, mitigation planning, and executive reporting. Develop meaningful risk metrics, KRIs, and executive dashboards that support business-informed risk decisions. Advance quantitative risk analysis capabilities using existing risk models or similar methodologies where appropriate. Partner with technology and business leaders to embed risk management into strategic planning and operational processes. Regulatory Compliance & Assurance Oversee compliance with regulatory, legal, and contractual cybersecurity requirements across all operating regions. Lead regulatory engagements, examinations, and responses with financial services regulators and external assessors. Ensure readiness for audits, certifications, and assessments, including PCI DSS, SOC, ISO 27001, privacy regulations, and emerging cybersecurity requirements. Drive timely remediation and sustainable resolution of audit and regulatory findings. GRC Technology, Automation & Vanta Ownership Own the strategy, implementation, adoption, and continuous optimization of GRC technology platforms, including Vanta and related compliance automation capabilities. Lead and execute the roadmap to automate evidence collection, control monitoring, risk workflows, policy management, audit readiness, and compliance reporting. Establish governance and operational processes that maximize platform value while reducing manual effort and audit burden. Evaluate and implement additional technologies that improve visibility, efficiency, and program scalability. Third-Party Risk Management Lead the global third-party cyber risk management program, including vendor assessments, continuous monitoring, risk remediation, and contractual security requirements. Partner with Procurement, Legal, Compliance, and Business stakeholders to ensure consistent third-party risk governance. Drive maturity of continuous monitoring and risk-based vendor oversight capabilities. Security Awareness & Human Risk Management Oversee enterprise security awareness, education, and culture initiatives. Develop programs that strengthen employee resilience against evolving cyber threats, fraud, social engineering, and emerging AI-enabled attacks. Establish measurable outcomes that demonstrate reductions in human-related risk. Incident Preparedness & Resilience Partner with Cyber Operations and Business teams to maintain incident response preparedness, crisis management processes, tabletop exercises, and regulatory reporting readiness. Ensure governance and oversight mechanisms support operational resilience objectives and regulatory expectations. Executive & Regulatory Engagement Serve as a trusted advisor to executive leadership on cybersecurity governance, risk, compliance, and resilience matters. Represent the cybersecurity organization during interactions with regulators, auditors, customers, and strategic partners. Organizational Leadership & Talent Development Lead and develop a high-performing GRC organization focused on accountability, collaboration, operational excellence, and business partnership. Assess organizational structure, capabilities, and talent to ensure alignment with business objectives and future growth requirements. Establish clear performance expectations, career development pathways, succession plans, and leadership accountability. Drive a culture of ownership, execution, continuous improvement, and customer-focused service delivery. Required Qualifications Who you are 15+ years of experience in cybersecurity, information security, risk management, compliance, audit, or related disciplines. Minimum 7+ years of progressive leadership experience managing large cybersecurity, risk, or compliance organizations. Proven track record transforming and scaling enterprise GRC programs within fintech, payments, banking, financial services, or similarly regulated industries. Demonstrated experience building and optimizing teams, operating models, and organizational capabilities. Significant experience implementing and operationalizing GRC platforms such as Vanta, ServiceNow GRC, Archer, AuditBoard, OneTrust, or similar technologies. Deep expertise in cybersecurity governance frameworks, regulatory compliance, audit management, and enterprise risk management. Experience leading complex regulatory examinations and engagements across multiple jurisdictions. Strong understanding of cloud environments (AWS, Azure, GCP), DevSecOps practices, and modern technology architectures. Proven ability to drive large-scale transformation initiatives while managing multiple competing priorities. Demonstrated success influencing executive leadership and operating effectively within matrixed organizations. Exceptional communication and presentation skills, including regulator-facing experience. Bachelor's degree in Cybersecurity, Information Systems, Risk Management, Business, or related field. Preferred Certifications CISSP CISM CRISC CCSP PCI ISA ISO 27001 Lead Implementer or Lead Auditor Preferred Qualifications Experience leading cybersecurity governance and compliance programs across multiple continents and regulatory regimes. Experience applying quantitative cyber risk methodologies. Familiarity with AI governance, AI risk management, and emerging regulatory requirements related to artificial intelligence. Experience in publicly traded companies. Proven history of improving operational efficiency through automation, process redesign, and technology modernization initiatives. The salary/pay rate listed below is a good faith determination that may be offered to a successful applicant for this position at the time of this job advertisement based on the company hiring process and budget for this role and may be modified in the future. Actual compensation may vary from posting based on geographic location, work experience, and/or skill level. Here Are Some Reasons You Will Love Working At MoneyGram! Remote first flexibility Generous PTO 13 Paid Holidays Medical / Dental / Vision Insurance Life, Disability, and other benefits 401k with competitive Employer Match Community Service Days Generous Parental Leave MoneyGram does not sponsor US work authorizations for this job position including H-1Bs, O-1, and TN. MoneyGram also does not hire F-1s working on EAD for this position. About MoneyGram MoneyGram is a global payments network built to move money across borders with speed, simplicity and trust. Its omnichannel platform empowers consumers, developers and agents to transfer cash, fiat and stablecoin however it works best for them. The company serves over 50 million customers a year across 200+ countries and territories, nearly half a million retail locations and a rapidly expanding digital ecosystem reaching billions of devices. As one of the most recognized and trusted names in global payments, MoneyGram continues to reinvent how money moves - helping people around the world support their loved ones and build better futures. MoneyGram is an Equal Opportunity Employer. We consider all qualified applicants for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, disability, genetic information, veteran status, or any other status protected by applicable law.