🎯 Job Search Agent

← all jobs

Vice President, Head of Business Controls – Technology & Cybersecurity

Sofi · CA - San Francisco · via greenhouse

🗓 Posted: 2026-08-21 17:12  ·  Found by agent: 2026-08-21 17:20  ·  Last seen: 2026-08-31 09:22

92% match
—salary (not stated)
n/a applicants
draftstatus

Open posting ↗

Application documents

Generated draft resume
⬇ Download .docx · changes
Cover letter
Your uploaded resume

Score breakdown

ComponentRawWeightContributionEvidence
keywords100.0%30 30.0 cisocybersecuritycyber riskgovernanceregulatoryrisk managementcomplianceinformation security
seniority100.0%25 25.0 Vice President
location100.0%20 20.0 nyc-metronew yorknew york city
salary50.0%15 7.5 salary-not-stated
company100.0%10 10.0 bankfinancial services

Telegram alerts

2026-08-26T17:40:32+00:00 → chat 5272237815 · sent

Synthesis sent: SoFi is hiring a VP-level Head of Business Controls for Technology & Cybersecurity to serve as the 1LOD risk lead for Engineering, InfoSec, Infrastructure, and Data across SoFi's global entities (SoFi Bank, Galileo, Technisys, SoFi Hong Kong). Reports to the Head of Business Controls and acts as direct advisor to the CTO and CISO, leading a team and owning programs like Insider Threat, EUC, and ITAM. Based in SF or NYC.

full message
✅ Vice President, Head of Business Controls – Technology & Cybersecurity
🏢 Sofi · 📍 CA - San Francisco; NY - New York City

Match: 92%
💰 Salary: not stated in posting
👥 Applicants: n/a — not published by greenhouse

SoFi is hiring a VP-level Head of Business Controls for Technology & Cybersecurity to serve as the 1LOD risk lead for Engineering, InfoSec, Infrastructure, and Data across SoFi's global entities (SoFi Bank, Galileo, Technisys, SoFi Hong Kong). Reports to the Head of Business Controls and acts as direct advisor to the CTO and CISO, leading a team and owning programs like Insider Threat, EUC, and ITAM. Based in SF or NYC.

Key requirements
• 15+ years in Risk Management, InfoSec, or Tech Risk; 5+ years in leadership at a regulated financial institution
• Proven experience managing risk across multiple legal entities/international jurisdictions (e.g., LATAM, APAC)
• Deep expertise in NIST, FFIEC, Cloud Security, and SDLC risk frameworks
• Track record building Business Control functions or risk programs (e.g., Insider Threat, EUC) from scratch
• Strong executive communication skills to influence CTO/CISO and Board-level stakeholders; CISA/CISSP/CISM/CRISC preferred

➡️ Apply
📄 Tailored resume (.docx)
📝 What changed

Resume customization

Variant Lucian_Lipinsky_CV__JPMC__2026.docx engine claude 10513 in / 3948 out tokens ✓ 10/10 review passed

⬇ Download tailored resume (.docx)  ·  📝 What changed (changelog)

Keywords injected / gaps: control environmentrisk oversightregulatory examsexecutive advisorymultiple legal entitiesfinancial services

10-pass quality review
#PassStatusDetail
1Grammar APPROVED No grammatical errors found in customized resume.
2Spelling APPROVED No new misspellings; inherited 'Graduated School' typo from base.
3Formatting consistency APPROVED 1 font(s), 5 size(s), consistent bullets
4Logical layout APPROVED Section order unchanged and logical, matches base structure.
5LLM-artifact detection APPROVED no em dashes or LLM filler phrases detected
6Job-description alignment APPROVED Control/regulatory/first-second-line terms align naturally with posting.
7Accomplishments emphasis APPROVED Key metrics ($1.7T AUM, 45 countries) retained and visible.
8No fabrication APPROVED No new employers, titles, dates, or metrics introduced; reframing only.
9Consistency with base CV APPROVED Titles, dates, employers consistent with base resume throughout.
10Human readability APPROVED Reads naturally, professional tone, not robotic or stuffed.
Text preview
Lucian Lipinsky de Orlov
lucian@lipinskyllc.com  ▪  914-656-0324  ▪  linkedin.com/in/lipinsky/
	
	
Senior technology & cybersecurity risk executive | financial services
First & Second Line of Defense Risk Oversight | Regulatory Engagement
Identity, Data & Privacy Risk | Executive Advisory & Communication
Senior technology and cybersecurity risk executive with 20+ years across global financial institutions, spanning both first and second line of defense roles. Deep background in cyber risk oversight, control governance, identity security, and data protection, with direct experience advising CTOs, CISOs, and senior leadership on control effectiveness and risk exposure. Extensive experience engaging regulators and translating complex technical risk into clear, actionable guidance for executive and board audiences. Proven track record building and modernizing risk programs and policies to align with regulatory expectations across large, multi-entity organizations.
			
	
Professional Experience Highlights
American Express - New York, NY
Senior Director, Risk & Information Security	2025 - Present
Cybersecurity Technology & Resiliency Risk Oversight
Senior Director within American Express' global cyber risk oversight organization, leading a distributed team focused on data security, privacy, and identity & access management (IAM).
Lead global risk oversight and control assessment for data protection, privacy, and identity security across enterprise platforms, cloud environments, and third-party ecosystems.
Advise senior executives on cyber risk exposure, control effectiveness, and remediation actions impacting customers, employees, and business operations.
Translate complex cybersecurity, privacy, and IAM risks into clear, practical guidance to support executive decision-making and risk awareness among non-technical stakeholders.
Partner with technology, legal, privacy, and business leadership to align cyber risk posture with regulatory expectations and business objectives.
Lead, coach, and set standards for a global team of senior cyber risk professionals.
Citigroup - New York, NY
Senior Vice President, Cyber Operational Risk Officer	2023 - 2025
Senior cyber risk leader within Citi's Second Line of Defense providing independent challenge and control oversight across vulnerability management, incident response, threat intelligence, security operations, and policy governance.
Advised senior leadership on cyber risk exposure, residual risk, and prioritization across global financial services operations.
Translated technical findings into executive decision briefs for non-technical leadership.
Served as key liaison with global regulators on cybersecurity posture, control environment, and remediation strategy during exams and reviews.
Oversaw global adversarial emulation exercises with focus on preparedness, judgment, and executive response readiness.
Reviewed and modernized cybersecurity policies, standards, and guidelines to align the control environment with regulatory expectations.
Franklin Templeton Investments - New York, NY
Global Director of Security and Risk (CISO)	2019 - 2023
Advised UHNW individuals and family offices within Franklin Templeton's Fiduciary Trust subsidiary on personal and family office cybersecurity risks, including digital assets, privacy exposure, identity compromise, and secure handling of sensitive financial information.
Executive accountable for global cybersecurity and risk management across 45 countries and multiple legal entities, supporting $1.7T AUM.
Advised executive leadership on cyber risk tradeoffs, investment decisions, and incident preparedness.
Led incident response planning, executive tabletop exercises, and crisis simulations.
Architectural advisor to the world's first SEC-approved tokenized government money fund, advising on blockchain, cryptography, and operational risk.
QuSecure - San Mateo, CA
Board Advisor (Quantum Security)	2020 - 2023
Provided technical guidance on post-quantum cryptography architecture and applicability in regulated financial services environments.
Translated complex quantum and cryptographic concepts into clear, credible narratives for executive leadership, potential investors, and media.
Citihub - New York, NY
Partner, CISO-for-Hire	2008 - 2015
Served as trusted cybersecurity advisor to C-suite executives across financial services and other industries.
Delivered executive briefings, tabletop exercises, and strategic cyber guidance aligned to business risk.
Deloitte Consulting - New York, NY
Senior Manager, Security SME	2003 - 2008
Advised capital markets, wealth management, and retail banking clients on technology and security risk.
Led large-scale regulatory and security initiatives and delivered C-level presentations.


	
Thought Leadership & Education
Fordham University - Three Minute Thesis (3MT) Competition
First Place Winner (2018)
Recognized for delivering advanced cybersecurity research on AI-driven threat detection to a non-technical audience in under three minutes, demonstrating exceptional clarity, discipline, and executive communication.
Fordham University - Lincoln Center, New York, NY
Adjunct Professor, Center for Cybersecurity 	2019 - Present
Teach undergraduate and graduate courses in computer security systems, encryption, operating system vulnerabilities, and disaster recovery. Program designated by NSA/DHS as a National Center of Academic Excellence in Cyber Defense Education.


Education
MS in Cybersecurity
Fordham University, Graduate School of Arts and Sciences, New York, NY
NSA and DHS National Center of Academic Excellence in Cyber Defense Education Certified
MS in Advanced Technology, Specialization in Computer Science
Thomas J. Watson School of Engineering, Applied Science, and Technology
	Graduated School of State University of New York, Binghamton, NY	
BS in Computer Science
State University of New York, Binghamton, NY
Certification & Training
ISACA CRISC - PMI Project Management Professional (PMP) - ITIL Foundation Certified - Certified Disciplined Agilist - Enterprise Lean Six Sigma Green Belt - CISSP (Candidate) - IBM Certified Professional - Project Management - New York State Notary Public 

Full description (7403 chars)

Open source posting ↗
Employee Applicant Privacy Notice

Who we are:

Shape a brighter financial future with us.

Together with our members, we’re changing the way people think about and interact with personal finance.

We’re a next-generation financial services company and national bank using innovative, mobile-first technology to help our millions of members reach their goals. The industry is going through an unprecedented transformation, and we’re at the forefront. We’re proud to come to work every day knowing that what we do has a direct impact on people’s lives, with our core values guiding us every step of the way. Join us to invest in yourself, your career, and the financial world.

The Role:

Positioned in the first line of defense (1LOD) and reporting to the Head of Business Controls, this experienced executive will act as the Business Controls Lead for SoFi’s Technology and Cybersecurity organizations. This includes comprehensive coverage of Engineering, Information Security, Infrastructure, and Data across the full SoFi Legal structure: SoFi Inc., SoFi Bank, Galileo, Technisys, and SoFi Hong Kong.

The Business Controls Lead will act as the direct advisor to the Chief Technology Officer (CTO), Chief Information Security Officer (CISO), and their senior leadership teams. You will lead a team of experienced IT risk & controls team charged with promoting risk awareness and ensure the overall effectiveness of risk and compliance management program implementation and execution across the 1LOD. This role provides support, advisory services, and enables strategic alignment directly to department heads to accelerate and ensure quality execution.

You will be responsible for supporting and driving consistent 1LOD adherence to critical programs, such as building and maintaining risk and control self-assessments (RCSAs); identification and evaluation of control effectiveness through control testing; 1LOD risk reporting; and supporting audits and regulatory exams. You will monitor the first line of defense in these assigned functions to minimize risk exposures and strengthen the overall control environment, leveraging risk assessment data to identify and seek improvements.

Crucially, this role holds direct ownership of major 1LOD risk management programs, driving their build, implementation, and sustainment, including Insider Threats, End User Computing (EUC), and IT Asset Management (ITAM).  Additionally, this role drives industry alignment to proven frameworks such as CoBit, NIST, and FFIEC Guidance to name a few.

What You’ll Do:

- Global Strategic Leadership : Serve as the primary 1LOD Risk Partner for the Technology and Cybersecurity functions across all domestic and international entities (SoFi Bank, Galileo, Technisys, SoFi Hong Kong), ensuring consistent application of risk frameworks in diverse regulatory environments.

- Program Ownership : Own the strategy, governance, and execution of critical enterprise-wide risk programs including the Insider Threat Program, End User Computing (EUC), AI Governance, and IT Asset Management (ITAM), ensuring these programs meet regulatory standards (FFIEC, OCC) and internal safety targets.

- Advisory & Governance : Partner and collaborate across lines of defense—including Compliance, Risk Management, Audit, and Regulators—to support a diverse portfolio of risk and compliance-based initiatives.

- Risk Identification & Assessment : Partner with Engineering and Security leaders to ensure existing and emerging risks (e.g., software supply chain, cloud security, legacy system integration) are effectively identified, measured, monitored, and controlled.

- RCSA & Testing : Lead large and complex initiatives to maintain the RCSA framework and conduct control testing; develop strategies to remediate gaps identified and implement processes to effectively manage and mitigate operational and cyber risk.

- Executive Reporting : Create effective 1LOD risk reporting and trend analysis; advise senior management (CTO, CISO, Board Committees) on the status of their control environment. Identify critical areas to monitor and escalate issues/findings to appropriate stakeholders.

- Issue Remediation : Assist with translating control deficiencies into action plans and provide recommendations to enhance governance practices in alignment with risk and compliance frameworks.

- Regulatory Interface : Serve as a key interface for Technology and Cyber risk matters during regulatory exams (Federal Reserve, OCC, CFPB) and internal audits.

- Industry Framework Alignment :  Drive program adherence to proven industry frameworks such as CoBit, NIST, and FFIEC guidance.

What You’ll Need:

- Experience : 15+ years of experience in Risk Management, Information Security, or Technology Risk, with at least 5+ years in a leadership role within a highly regulated financial services environment.

- Global Scope : Proven experience managing risk across multiple legal entities and international jurisdictions (e.g., LATAM, APAC).

- Subject Matter Expertise : Deep understanding of Technology and Cybersecurity risk domains, including NIST frameworks, FFIEC guidelines, Cloud Security, and SDLC.

- Program Building : Direct experience creating and building Business Control functions or specific risk programs (Insider Threat, EUC) from the ground up.

- Communication : Excellent executive communication skills with the ability to influence C-level stakeholders (CTO, CISO) and Board members.

- Certifications : Relevant industry certifications (CISA, CISSP, CISM, CRISC) are highly preferred.

Compensation and Benefits

The base pay range for this role is listed below. Final base pay offer will be determined based on individual factors such as the candidate’s experience, skills, and location.

To view all of our comprehensive and competitive benefits, visit our  Benefits at SoFi   page!

SoFi provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion (including religious dress and grooming practices), sex (including pregnancy, childbirth and related medical conditions, breastfeeding, and conditions related to breastfeeding), gender, gender identity, gender expression, national origin, ancestry, age (40 or over), physical or medical disability, medical condition, marital status, registered domestic partner status, sexual orientation, genetic information, military and/or veteran status, or any other basis prohibited by applicable state or federal law.

The Company hires the best qualified candidate for the job, without regard to protected characteristics.

Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.

New York applicants: Notice of Employee Rights

SoFi is committed to an inclusive culture. As part of this commitment, SoFi offers reasonable accommodations to candidates with physical or mental disabilities. If you need accommodations to participate in the job application or interview process, please let your recruiter know or email accommodations@sofi.com.

Due to insurance coverage issues, we are unable to accommodate remote work from Hawaii or Alaska at this time.

Internal Employees

If you are a current employee, do not apply here - please navigate to our Internal Job Board in Greenhouse to apply to our open roles.
✎ Edit & reprocess description