🎯 Job Search Agent

← all jobs

Sr Director, Cybersecurity GRC

MoneyGram Β· United States Β· via manual_submit

πŸ—“ Posted: not published by source  Β·  Found by agent: 2026-08-06 14:00

70% match
β€”salary (not stated)
n/a applicants
archivedstatus

Open posting β†—

Application documents

Generated draft resume
⬇ Download .docx Β· changes
Cover letter
Your uploaded resume

Score breakdown

ComponentRawWeightContributionEvidence
keywords100.0%30 30.0 cisocybersecuritycyber risksocincident responsegovernanceregulatoryrisk managementcomplianceinformation security
seniority80.0%25 20.0 Sr Director
location10.0%20 2.0 unrecognized-locationunited states
salary50.0%15 7.5 salary-not-stated
company100.0%10 10.0 financial servicesfintechpayments

Telegram alerts

2026-08-07T15:54:16+00:00 β†’ chat 5272237815 Β· sent

Synthesis sent: MoneyGram seeks a Sr Director of Cybersecurity GRC to transform and scale its global governance, risk, compliance, third-party risk, and resilience programs, reporting directly to the CISO. This is a remote, full-time leadership role acting as a trusted advisor to executives, regulators, and auditors while modernizing the GRC operating model with automation.

full message
πŸ‘€ Sr Director, Cybersecurity GRC
🏒 MoneyGram Β· πŸ“ United States

Match: 70%
πŸ’° Salary: not stated in posting
πŸ‘₯ Applicants: n/a β€” not published by manual_submit

MoneyGram seeks a Sr Director of Cybersecurity GRC to transform and scale its global governance, risk, compliance, third-party risk, and resilience programs, reporting directly to the CISO. This is a remote, full-time leadership role acting as a trusted advisor to executives, regulators, and auditors while modernizing the GRC operating model with automation.

Key requirements
β€’ 15+ years in cybersecurity/risk/compliance, with 7+ years leading large GRC or risk organizations.
β€’ Proven experience transforming enterprise GRC programs within fintech, banking, or regulated financial services.
β€’ Hands-on expertise implementing GRC platforms like Vanta, ServiceNow GRC, Archer, AuditBoard, or OneTrust.
β€’ Deep knowledge of frameworks (NIST CSF, ISO 27001, PCI DSS, SOC) and multi-jurisdiction regulatory examinations.
β€’ Bachelor's degree required; CISSP/CISM/CRISC or similar certifications preferred; no visa sponsorship offered.

➑️ Apply
πŸ“„ Tailored resume (.docx)
πŸ“ What changed

Resume customization

Variant Lucian_Lipinsky_CV__JPMC__2026.docx engine claude 31202 in / 13825 out tokens βœ“ 10/10 review passed

⬇ Download tailored resume (.docx)  Β·  πŸ“ What changed (changelog)

Keywords injected / gaps: GRCgovernanceregulatory engagementsecond line of defensepolicy governanceaudit readinessrisk oversight

10-pass quality review
#PassStatusDetail
1Grammar APPROVED Sentences grammatically correct throughout; no errors found.
2Spelling APPROVED No misspellings detected (proper nouns/acronyms excluded).
3Formatting consistency APPROVED 1 font(s), 5 size(s), consistent bullets
4Logical layout APPROVED Section order matches base; logical, no orphaned sections.
5LLM-artifact detection APPROVED no em dashes or LLM filler phrases detected
6Job-description alignment APPROVED GRC, governance, policy, audit-readiness terms woven naturally, not stuffed.
7Accomplishments emphasis APPROVED Key metrics (300+, 150+, $1.7T AUM) surfaced clearly, not buried.
8No fabrication APPROVED No new employer, title, metric, or date beyond base content.
9Consistency with base CV APPROVED Titles, dates, employers consistent with base resume.
10Human readability APPROVED Reads naturally as human-written, professional tone maintained.
Text preview
Lucian Lipinsky de Orlov
lucian@lipinskyllc.com  β–ͺ  914-656-0324  β–ͺ  linkedin.com/in/lipinsky/
	
	
Senior cybersecurity GRC executive | financial services & fintech
Second-Line Risk Oversight | Regulatory Engagement & Policy Governance
Identity, Data & Privacy Risk | Executive Education & Advisory
Senior cybersecurity risk and governance executive with 20+ years across global financial institutions and asset managers, including second-line of defense leadership at Citigroup (300+) and American Express (150+) and CISO-level accountability at Franklin Templeton ($1.7T AUM, 45 countries).
			
	
Professional Experience Highlights
American Express - New York, NY
Senior Director, Risk & Information Security	2025 - Present
Cybersecurity Technology & Resiliency Risk Oversight
Senior Director leading American Express' global cybersecurity GRC and risk oversight organization, driving governance, policy, and compliance across data security, privacy, and identity & access management (IAM). Serve as global second-line risk owner for Data Loss Prevention (DLP), providing independent oversight and challenge of the first-line DLP program and directing corrective action across a first-line organization of 150+.
Lead global GRC and cyber risk governance for data protection, privacy, and identity security across enterprise platforms, cloud, and third-party ecosystems.
Advise senior executives on cyber risk exposure, control effectiveness, and practical risk-reduction actions impacting customers, employees, and business operations.
Translate complex cybersecurity, privacy, and IAM risks into clear, practical guidance to support executive decision-making and risk awareness among non-technical stakeholders.
Partner with technology, legal, privacy, and business leadership to align cyber risk governance and compliance programs with regulatory expectations and business objectives.
Lead, coach, and set standards for a global team of senior cyber risk professionals.
Citigroup - New York, NY
Senior Vice President, Cyber Operational Risk Officer	2023 - 2025
Provided second-line independent risk oversight of Citi's Fusion Center, directing first-line teams (300+) on corrective action across threat intelligence, monitoring, and coordinated response capabilities. Senior GRC and cyber risk leader within Citi's Second Line of Defense, providing independent governance oversight and challenge across vulnerability management, incident response, threat intelligence, security operations, and policy governance.
Advised senior leadership on cyber risk exposure, residual risk, and prioritization across global financial services operations.
Translated technical findings into executive decision briefs for non-technical leadership.
Served as regulatory liaison on cybersecurity governance, resilience, and remediation strategy across global operations, supporting audit and examination readiness.
Oversaw global adversarial emulation exercises with focus on preparedness, judgment, and executive response readiness.
Led governance efforts to review and modernize cybersecurity policies, standards, and guidelines to meet regulatory expectations and audit readiness.
Franklin Templeton Investments - New York, NY
Global Director of Security and Risk (CISO)	2019 - 2023
Advised UHNW individuals and family offices within Franklin Templeton's Fiduciary Trust subsidiary on personal and family office cybersecurity risks, including digital assets, privacy exposure, identity compromise, and secure handling of sensitive financial information.
Executive accountable for global cybersecurity and risk management across 45 countries supporting $1.7T AUM.
Advised executive leadership on cyber risk tradeoffs, investment decisions, and incident preparedness.
Led incident response planning, executive tabletop exercises, and crisis simulations to strengthen organizational resilience and regulatory readiness.
Architectural advisor to the world's first SEC-approved tokenized government money fund, advising on blockchain, cryptography, and operational risk.
QuSecure - San Mateo, CA
Board Advisor (Quantum Security)	2020 - 2023
Provided technical guidance on post-quantum cryptography architecture and applicability in regulated financial services environments.
Translated complex quantum and cryptographic concepts into clear, credible narratives for executive leadership, potential investors, and media.
Citihub - New York, NY
Partner, CISO-for-Hire	2008 - 2015
Served as trusted cybersecurity advisor to C-suite executives across financial services and other industries.
Delivered executive briefings, tabletop exercises, and strategic cyber guidance aligned to business risk.
Deloitte Consulting - New York, NY
Senior Manager, Security SME	2003 - 2008
Advised capital markets, wealth management, and retail banking clients on technology and security risk.
Led large-scale regulatory and security initiatives and delivered C-level presentations.

	
Private Bank Relevance
Identity compromise, privacy exposure, fraud, and digital asset risk are primary cyber threats to UHNW individuals and family offices.
Career experience translating institutional cyber risk into practical, personal, and reputational impact considerations applicable to Private Bank clients.

	
Thought Leadership & Education
Fordham University - Three Minute Thesis (3MT) Competition
First Place Winner (2018)
Recognized for delivering advanced cybersecurity research on AI-driven threat detection to a non-technical audience in under three minutes, demonstrating exceptional clarity, discipline, and executive communication.
Fordham University - Lincoln Center, New York, NY
Adjunct Professor, Center for Cybersecurity 	2019 - Present
Teach undergraduate and graduate courses in computer security systems, encryption, operating system vulnerabilities, and disaster recovery. Program designated by NSA/DHS as a National Center of Academic Excellence in Cyber Defense Education.


Education
MS in Cybersecurity
Fordham University, Graduate School of Arts and Sciences, New York, NY
NSA and DHS National Center of Academic Excellence in Cyber Defense Education Certified
MS in Advanced Technology, Specialization in Computer Science
Thomas J. Watson School of Engineering, Applied Science, and Technology
	Graduated School of State University of New York, Binghamton, NY	
BS in Computer Science
State University of New York, Binghamton, NY
Certification & Training
ISACA CRISC - PMI Project Management Professional (PMP) - ITIL Foundation Certified - Certified Disciplined Agilist - Enterprise Lean Six Sigma Green Belt - CISSP (Candidate) - IBM Certified Professional - Project Management - New York State Notary Public 

Full description (11147 chars)

Open source posting β†—
Company logo for, MoneyGram.
MoneyGram

Sr Director, Cybersecurity GRC

United States Β· 1 day ago Β· Over 100 people clicked apply

Promoted by hirer Β· Responses managed off LinkedIn

Remote
Full-time
Apply

Save
Use AI to assess how you fit
Show match details

Tailor my resume

Create cover letter

Help me stand out

People you can reach out to

Company alumni from American Express

Show all
About the job
At MoneyGram, we're combining the strength of a trusted global brand with the agility of a tech-forward, growth driven culture. With 80+ years of experience and a presence in more than 200 countries and territories, we've built a foundation of stability and trust to help millions of people around the world send funds quickly, securely, and affordably.

We're looking for bold thinkers, builders, technologists, and sellers who want real ownership of their work, thrive in collaborative environments, and are energized by solving complex challenges. Here, you'll have the opportunity to make a measurable impact - fast.

If you're eager to shape the future of cross-border payments and financial services, join us as we transform how the world moves money.

At MoneyGram, we connect the world by making cross-border money transfers seamless, affordable, and secure for everyone. We are seeking a Senior Director of Cybersecurity Governance, Risk and Compliance (GRC) for our global organization. This role is responsible for transforming, scaling, and operationalizing the global cybersecurity GRC function. This leader will drive modernization of governance, risk management, compliance, third-party risk, audit, security awareness, and resilience programs while building a highly efficient, technology-enabled operating model capable of supporting a rapidly evolving global fintech organization.

Reporting directly to the Chief Information Security Officer (CISO), this role serves as a trusted advisor to executive leadership, regulators, auditors, and business stakeholders. The ideal candidate is an experienced cybersecurity leader with a proven track record of building and maturing GRC organizations, driving operational excellence, implementing automation at scale, and leading high-performing global teams.

This role requires a strategic thinker who can simultaneously manage multiple complex initiatives, influence senior stakeholders, navigate regulatory environments across multiple jurisdictions, and execute with a strong bias for action.

What You Will Get To Do

Cybersecurity Program Transformation & Operational Excellence

Lead the transformation and continuous maturation of the global GRC organization, including governance, risk management, compliance, third-party risk, audit management, security awareness, and resilience programs.
Assess organizational effectiveness and develop a target-state operating model that improves efficiency, scalability, accountability, and business alignment.
Drive process optimization, simplification, and automation initiatives across the GRC portfolio.
Establish measurable service delivery metrics, operational KPIs, and maturity targets to continuously improve program effectiveness.
Build and execute a multi-year roadmap for GRC modernization aligned to business objectives and regulatory expectations.

Governance & Policy Management

Define and maintain global cybersecurity policies, standards, frameworks, and governance processes aligned with NIST CSF, ISO 27001, PCI DSS, SOC, and applicable financial services regulations.
Ensure governance structures effectively support executive decision-making and risk-based prioritization.
Drive consistent application of security requirements and controls across products, platforms, and regions.

Enterprise Cyber Risk Management

Lead the enterprise cyber risk management program, including risk identification, assessment, quantification, mitigation planning, and executive reporting.
Develop meaningful risk metrics, KRIs, and executive dashboards that support business-informed risk decisions.
Advance quantitative risk analysis capabilities using existing risk models or similar methodologies where appropriate.
Partner with technology and business leaders to embed risk management into strategic planning and operational processes.

Regulatory Compliance & Assurance

Oversee compliance with regulatory, legal, and contractual cybersecurity requirements across all operating regions.
Lead regulatory engagements, examinations, and responses with financial services regulators and external assessors.
Ensure readiness for audits, certifications, and assessments, including PCI DSS, SOC, ISO 27001, privacy regulations, and emerging cybersecurity requirements.
Drive timely remediation and sustainable resolution of audit and regulatory findings.

GRC Technology, Automation & Vanta Ownership

Own the strategy, implementation, adoption, and continuous optimization of GRC technology platforms, including Vanta and related compliance automation capabilities.
Lead and execute the roadmap to automate evidence collection, control monitoring, risk workflows, policy management, audit readiness, and compliance reporting.
Establish governance and operational processes that maximize platform value while reducing manual effort and audit burden.
Evaluate and implement additional technologies that improve visibility, efficiency, and program scalability.

Third-Party Risk Management

Lead the global third-party cyber risk management program, including vendor assessments, continuous monitoring, risk remediation, and contractual security requirements.
Partner with Procurement, Legal, Compliance, and Business stakeholders to ensure consistent third-party risk governance.
Drive maturity of continuous monitoring and risk-based vendor oversight capabilities.

Security Awareness & Human Risk Management

Oversee enterprise security awareness, education, and culture initiatives.
Develop programs that strengthen employee resilience against evolving cyber threats, fraud, social engineering, and emerging AI-enabled attacks.
Establish measurable outcomes that demonstrate reductions in human-related risk.

Incident Preparedness & Resilience

Partner with Cyber Operations and Business teams to maintain incident response preparedness, crisis management processes, tabletop exercises, and regulatory reporting readiness.
Ensure governance and oversight mechanisms support operational resilience objectives and regulatory expectations.

Executive & Regulatory Engagement

Serve as a trusted advisor to executive leadership on cybersecurity governance, risk, compliance, and resilience matters.
Represent the cybersecurity organization during interactions with regulators, auditors, customers, and strategic partners.

Organizational Leadership & Talent Development

Lead and develop a high-performing GRC organization focused on accountability, collaboration, operational excellence, and business partnership.
Assess organizational structure, capabilities, and talent to ensure alignment with business objectives and future growth requirements.
Establish clear performance expectations, career development pathways, succession plans, and leadership accountability.
Drive a culture of ownership, execution, continuous improvement, and customer-focused service delivery.

Required Qualifications

Who you are

15+ years of experience in cybersecurity, information security, risk management, compliance, audit, or related disciplines.
Minimum 7+ years of progressive leadership experience managing large cybersecurity, risk, or compliance organizations.
Proven track record transforming and scaling enterprise GRC programs within fintech, payments, banking, financial services, or similarly regulated industries.
Demonstrated experience building and optimizing teams, operating models, and organizational capabilities.
Significant experience implementing and operationalizing GRC platforms such as Vanta, ServiceNow GRC, Archer, AuditBoard, OneTrust, or similar technologies.
Deep expertise in cybersecurity governance frameworks, regulatory compliance, audit management, and enterprise risk management.
Experience leading complex regulatory examinations and engagements across multiple jurisdictions.
Strong understanding of cloud environments (AWS, Azure, GCP), DevSecOps practices, and modern technology architectures.
Proven ability to drive large-scale transformation initiatives while managing multiple competing priorities.
Demonstrated success influencing executive leadership and operating effectively within matrixed organizations.
Exceptional communication and presentation skills, including regulator-facing experience.
Bachelor's degree in Cybersecurity, Information Systems, Risk Management, Business, or related field.

Preferred Certifications

CISSP
CISM
CRISC
CCSP
PCI ISA
ISO 27001 Lead Implementer or Lead Auditor

Preferred Qualifications

Experience leading cybersecurity governance and compliance programs across multiple continents and regulatory regimes.
Experience applying quantitative cyber risk methodologies.
Familiarity with AI governance, AI risk management, and emerging regulatory requirements related to artificial intelligence.
Experience in publicly traded companies.
Proven history of improving operational efficiency through automation, process redesign, and technology modernization initiatives.

The salary/pay rate listed below is a good faith determination that may be offered to a successful applicant for this position at the time of this job advertisement based on the company hiring process and budget for this role and may be modified in the future. Actual compensation may vary from posting based on geographic location, work experience, and/or skill level.

Here Are Some Reasons You Will Love Working At MoneyGram!

Remote first flexibility
Generous PTO
13 Paid Holidays
Medical / Dental / Vision Insurance
Life, Disability, and other benefits
401k with competitive Employer Match
Community Service Days
Generous Parental Leave

MoneyGram does not sponsor US work authorizations for this job position including H-1Bs, O-1, and TN. MoneyGram also does not hire F-1s working on EAD for this position.

About MoneyGram

MoneyGram is a global payments network built to move money across borders with speed, simplicity and trust. Its omnichannel platform empowers consumers, developers and agents to transfer cash, fiat and stablecoin however it works best for them.

The company serves over 50 million customers a year across 200+ countries and territories, nearly half a million retail locations and a rapidly expanding digital ecosystem reaching billions of devices. As one of the most recognized and trusted names in global payments, MoneyGram continues to reinvent how money moves - helping people around the world support their loved ones and build better futures.

MoneyGram is an Equal Opportunity Employer. We consider all qualified applicants for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, disability, genetic information, veteran status, or any other status protected by applicable law.
✎ Edit & reprocess description