Vice President, Head of Business Controls – Technology & Cybersecurity
Sofi · CA - San Francisco · via greenhouse
🗓 Posted: 2026-08-21 17:12 · Found by agent: 2026-08-21 17:20 · Last seen: 2026-08-31 09:22
Application documents
Score breakdown
| Component | Raw | Weight | Contribution | Evidence |
|---|---|---|---|---|
| keywords | 100.0% | 30 | 30.0 | cisocybersecuritycyber riskgovernanceregulatoryrisk managementcomplianceinformation security |
| seniority | 100.0% | 25 | 25.0 | Vice President |
| location | 100.0% | 20 | 20.0 | nyc-metronew yorknew york city |
| salary | 50.0% | 15 | 7.5 | salary-not-stated |
| company | 100.0% | 10 | 10.0 | bankfinancial services |
Telegram alerts
2026-08-26T17:40:32+00:00 → chat 5272237815 · sent
Synthesis sent: SoFi is hiring a VP-level Head of Business Controls for Technology & Cybersecurity to serve as the 1LOD risk lead for Engineering, InfoSec, Infrastructure, and Data across SoFi's global entities (SoFi Bank, Galileo, Technisys, SoFi Hong Kong). Reports to the Head of Business Controls and acts as direct advisor to the CTO and CISO, leading a team and owning programs like Insider Threat, EUC, and ITAM. Based in SF or NYC.
full message
Resume customization
Variant Lucian_Lipinsky_CV__JPMC__2026.docx engine claude 10513 in / 3948 out tokens ✓ 10/10 review passed
⬇ Download tailored resume (.docx) · 📝 What changed (changelog)
Keywords injected / gaps: control environmentrisk oversightregulatory examsexecutive advisorymultiple legal entitiesfinancial services
10-pass quality review
| # | Pass | Status | Detail |
|---|---|---|---|
| 1 | Grammar | APPROVED | No grammatical errors found in customized resume. |
| 2 | Spelling | APPROVED | No new misspellings; inherited 'Graduated School' typo from base. |
| 3 | Formatting consistency | APPROVED | 1 font(s), 5 size(s), consistent bullets |
| 4 | Logical layout | APPROVED | Section order unchanged and logical, matches base structure. |
| 5 | LLM-artifact detection | APPROVED | no em dashes or LLM filler phrases detected |
| 6 | Job-description alignment | APPROVED | Control/regulatory/first-second-line terms align naturally with posting. |
| 7 | Accomplishments emphasis | APPROVED | Key metrics ($1.7T AUM, 45 countries) retained and visible. |
| 8 | No fabrication | APPROVED | No new employers, titles, dates, or metrics introduced; reframing only. |
| 9 | Consistency with base CV | APPROVED | Titles, dates, employers consistent with base resume throughout. |
| 10 | Human readability | APPROVED | Reads naturally, professional tone, not robotic or stuffed. |
Text preview
Lucian Lipinsky de Orlov lucian@lipinskyllc.com ▪ 914-656-0324 ▪ linkedin.com/in/lipinsky/ Senior technology & cybersecurity risk executive | financial services First & Second Line of Defense Risk Oversight | Regulatory Engagement Identity, Data & Privacy Risk | Executive Advisory & Communication Senior technology and cybersecurity risk executive with 20+ years across global financial institutions, spanning both first and second line of defense roles. Deep background in cyber risk oversight, control governance, identity security, and data protection, with direct experience advising CTOs, CISOs, and senior leadership on control effectiveness and risk exposure. Extensive experience engaging regulators and translating complex technical risk into clear, actionable guidance for executive and board audiences. Proven track record building and modernizing risk programs and policies to align with regulatory expectations across large, multi-entity organizations. Professional Experience Highlights American Express - New York, NY Senior Director, Risk & Information Security 2025 - Present Cybersecurity Technology & Resiliency Risk Oversight Senior Director within American Express' global cyber risk oversight organization, leading a distributed team focused on data security, privacy, and identity & access management (IAM). Lead global risk oversight and control assessment for data protection, privacy, and identity security across enterprise platforms, cloud environments, and third-party ecosystems. Advise senior executives on cyber risk exposure, control effectiveness, and remediation actions impacting customers, employees, and business operations. Translate complex cybersecurity, privacy, and IAM risks into clear, practical guidance to support executive decision-making and risk awareness among non-technical stakeholders. Partner with technology, legal, privacy, and business leadership to align cyber risk posture with regulatory expectations and business objectives. Lead, coach, and set standards for a global team of senior cyber risk professionals. Citigroup - New York, NY Senior Vice President, Cyber Operational Risk Officer 2023 - 2025 Senior cyber risk leader within Citi's Second Line of Defense providing independent challenge and control oversight across vulnerability management, incident response, threat intelligence, security operations, and policy governance. Advised senior leadership on cyber risk exposure, residual risk, and prioritization across global financial services operations. Translated technical findings into executive decision briefs for non-technical leadership. Served as key liaison with global regulators on cybersecurity posture, control environment, and remediation strategy during exams and reviews. Oversaw global adversarial emulation exercises with focus on preparedness, judgment, and executive response readiness. Reviewed and modernized cybersecurity policies, standards, and guidelines to align the control environment with regulatory expectations. Franklin Templeton Investments - New York, NY Global Director of Security and Risk (CISO) 2019 - 2023 Advised UHNW individuals and family offices within Franklin Templeton's Fiduciary Trust subsidiary on personal and family office cybersecurity risks, including digital assets, privacy exposure, identity compromise, and secure handling of sensitive financial information. Executive accountable for global cybersecurity and risk management across 45 countries and multiple legal entities, supporting $1.7T AUM. Advised executive leadership on cyber risk tradeoffs, investment decisions, and incident preparedness. Led incident response planning, executive tabletop exercises, and crisis simulations. Architectural advisor to the world's first SEC-approved tokenized government money fund, advising on blockchain, cryptography, and operational risk. QuSecure - San Mateo, CA Board Advisor (Quantum Security) 2020 - 2023 Provided technical guidance on post-quantum cryptography architecture and applicability in regulated financial services environments. Translated complex quantum and cryptographic concepts into clear, credible narratives for executive leadership, potential investors, and media. Citihub - New York, NY Partner, CISO-for-Hire 2008 - 2015 Served as trusted cybersecurity advisor to C-suite executives across financial services and other industries. Delivered executive briefings, tabletop exercises, and strategic cyber guidance aligned to business risk. Deloitte Consulting - New York, NY Senior Manager, Security SME 2003 - 2008 Advised capital markets, wealth management, and retail banking clients on technology and security risk. Led large-scale regulatory and security initiatives and delivered C-level presentations. Thought Leadership & Education Fordham University - Three Minute Thesis (3MT) Competition First Place Winner (2018) Recognized for delivering advanced cybersecurity research on AI-driven threat detection to a non-technical audience in under three minutes, demonstrating exceptional clarity, discipline, and executive communication. Fordham University - Lincoln Center, New York, NY Adjunct Professor, Center for Cybersecurity 2019 - Present Teach undergraduate and graduate courses in computer security systems, encryption, operating system vulnerabilities, and disaster recovery. Program designated by NSA/DHS as a National Center of Academic Excellence in Cyber Defense Education. Education MS in Cybersecurity Fordham University, Graduate School of Arts and Sciences, New York, NY NSA and DHS National Center of Academic Excellence in Cyber Defense Education Certified MS in Advanced Technology, Specialization in Computer Science Thomas J. Watson School of Engineering, Applied Science, and Technology Graduated School of State University of New York, Binghamton, NY BS in Computer Science State University of New York, Binghamton, NY Certification & Training ISACA CRISC - PMI Project Management Professional (PMP) - ITIL Foundation Certified - Certified Disciplined Agilist - Enterprise Lean Six Sigma Green Belt - CISSP (Candidate) - IBM Certified Professional - Project Management - New York State Notary Public
Full description (7403 chars)
Open source posting ↗Employee Applicant Privacy Notice Who we are: Shape a brighter financial future with us. Together with our members, we’re changing the way people think about and interact with personal finance. We’re a next-generation financial services company and national bank using innovative, mobile-first technology to help our millions of members reach their goals. The industry is going through an unprecedented transformation, and we’re at the forefront. We’re proud to come to work every day knowing that what we do has a direct impact on people’s lives, with our core values guiding us every step of the way. Join us to invest in yourself, your career, and the financial world. The Role: Positioned in the first line of defense (1LOD) and reporting to the Head of Business Controls, this experienced executive will act as the Business Controls Lead for SoFi’s Technology and Cybersecurity organizations. This includes comprehensive coverage of Engineering, Information Security, Infrastructure, and Data across the full SoFi Legal structure: SoFi Inc., SoFi Bank, Galileo, Technisys, and SoFi Hong Kong. The Business Controls Lead will act as the direct advisor to the Chief Technology Officer (CTO), Chief Information Security Officer (CISO), and their senior leadership teams. You will lead a team of experienced IT risk & controls team charged with promoting risk awareness and ensure the overall effectiveness of risk and compliance management program implementation and execution across the 1LOD. This role provides support, advisory services, and enables strategic alignment directly to department heads to accelerate and ensure quality execution. You will be responsible for supporting and driving consistent 1LOD adherence to critical programs, such as building and maintaining risk and control self-assessments (RCSAs); identification and evaluation of control effectiveness through control testing; 1LOD risk reporting; and supporting audits and regulatory exams. You will monitor the first line of defense in these assigned functions to minimize risk exposures and strengthen the overall control environment, leveraging risk assessment data to identify and seek improvements. Crucially, this role holds direct ownership of major 1LOD risk management programs, driving their build, implementation, and sustainment, including Insider Threats, End User Computing (EUC), and IT Asset Management (ITAM). Additionally, this role drives industry alignment to proven frameworks such as CoBit, NIST, and FFIEC Guidance to name a few. What You’ll Do: - Global Strategic Leadership : Serve as the primary 1LOD Risk Partner for the Technology and Cybersecurity functions across all domestic and international entities (SoFi Bank, Galileo, Technisys, SoFi Hong Kong), ensuring consistent application of risk frameworks in diverse regulatory environments. - Program Ownership : Own the strategy, governance, and execution of critical enterprise-wide risk programs including the Insider Threat Program, End User Computing (EUC), AI Governance, and IT Asset Management (ITAM), ensuring these programs meet regulatory standards (FFIEC, OCC) and internal safety targets. - Advisory & Governance : Partner and collaborate across lines of defense—including Compliance, Risk Management, Audit, and Regulators—to support a diverse portfolio of risk and compliance-based initiatives. - Risk Identification & Assessment : Partner with Engineering and Security leaders to ensure existing and emerging risks (e.g., software supply chain, cloud security, legacy system integration) are effectively identified, measured, monitored, and controlled. - RCSA & Testing : Lead large and complex initiatives to maintain the RCSA framework and conduct control testing; develop strategies to remediate gaps identified and implement processes to effectively manage and mitigate operational and cyber risk. - Executive Reporting : Create effective 1LOD risk reporting and trend analysis; advise senior management (CTO, CISO, Board Committees) on the status of their control environment. Identify critical areas to monitor and escalate issues/findings to appropriate stakeholders. - Issue Remediation : Assist with translating control deficiencies into action plans and provide recommendations to enhance governance practices in alignment with risk and compliance frameworks. - Regulatory Interface : Serve as a key interface for Technology and Cyber risk matters during regulatory exams (Federal Reserve, OCC, CFPB) and internal audits. - Industry Framework Alignment : Drive program adherence to proven industry frameworks such as CoBit, NIST, and FFIEC guidance. What You’ll Need: - Experience : 15+ years of experience in Risk Management, Information Security, or Technology Risk, with at least 5+ years in a leadership role within a highly regulated financial services environment. - Global Scope : Proven experience managing risk across multiple legal entities and international jurisdictions (e.g., LATAM, APAC). - Subject Matter Expertise : Deep understanding of Technology and Cybersecurity risk domains, including NIST frameworks, FFIEC guidelines, Cloud Security, and SDLC. - Program Building : Direct experience creating and building Business Control functions or specific risk programs (Insider Threat, EUC) from the ground up. - Communication : Excellent executive communication skills with the ability to influence C-level stakeholders (CTO, CISO) and Board members. - Certifications : Relevant industry certifications (CISA, CISSP, CISM, CRISC) are highly preferred. Compensation and Benefits The base pay range for this role is listed below. Final base pay offer will be determined based on individual factors such as the candidate’s experience, skills, and location. To view all of our comprehensive and competitive benefits, visit our Benefits at SoFi page! SoFi provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion (including religious dress and grooming practices), sex (including pregnancy, childbirth and related medical conditions, breastfeeding, and conditions related to breastfeeding), gender, gender identity, gender expression, national origin, ancestry, age (40 or over), physical or medical disability, medical condition, marital status, registered domestic partner status, sexual orientation, genetic information, military and/or veteran status, or any other basis prohibited by applicable state or federal law. The Company hires the best qualified candidate for the job, without regard to protected characteristics. Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records. New York applicants: Notice of Employee Rights SoFi is committed to an inclusive culture. As part of this commitment, SoFi offers reasonable accommodations to candidates with physical or mental disabilities. If you need accommodations to participate in the job application or interview process, please let your recruiter know or email accommodations@sofi.com. Due to insurance coverage issues, we are unable to accommodate remote work from Hawaii or Alaska at this time. Internal Employees If you are a current employee, do not apply here - please navigate to our Internal Job Board in Greenhouse to apply to our open roles.