Search jobs > Washington, DC > Director security risk

Director, Security Risk and Resilience

Robinhood
Washington, DC
$199K-$234K a year
Full-time

Join a leading fintech company that’s democratizing finance for all.

Robinhood Markets was founded on a simple idea : that our financial markets should be accessible to all. With customers at the heart of our decisions, Robinhood and its subsidiaries and affiliates are lowering barriers and providing greater access to financial information.

Together, we are building products and services that help create a financial system everyone can participate in.

With growth as the top priority...

The business is seeking curious, growth-minded thinkers to help shape our vision, structures and systems; playing a key-role as we launch into our ambitious future.

If you’re invigorated by our mission, values, and drive to change the world we’d love to have you apply.

About the team + role

Robinhood’s Security, Privacy and Corporate Engineering organization is seeking an experienced Director of Security Risk Management and Enterprise Resilience to lead our efforts in overseeing security risk management and policy governance, ensuring regulatory compliance, and improving our enterprise resilience.

This pivotal leadership role will coordinate our strategic response to security challenges, lead all aspects of policy and exception management, and ensure robust business continuity and disaster recovery frameworks are in place and operationalized.

As a key member of the leadership team, this role will provide crucial insights surrounding the company’s security risk posture and reports directly to the CSO.

The role is located in the office location(s) listed on this job description which will align with our in-office working environment.

Please connect with your recruiter for more information regarding our in-office philosophy and expectations.

What you’ll do

Security Risk Management :

  • Establish and maintain a comprehensive risk management framework, leading from the front in risk assessment activities and mitigation strategy development.
  • Be responsible for the handling of high-stakes risk mitigation efforts, ensuring alignment with business objectives.
  • Elevate critical risks to the board and senior management, preparing detailed reports and strategic recommendations while leading key discussions.

Regulatory Response & Compliance :

  • Lead a team in developing and implementing the organization’s regulatory response strategy, actively participating in critical discussions and reviews to ensure compliance with legal and regulatory standards.
  • Facilitate cross-functional collaboration among legal, compliance, and operational teams to adapt to regulatory changes and audits efficiently.
  • Champion proactive compliance initiatives, stepping in to guide complex compliance issues and strategic planning sessions.

Policy and Exception Management :

  • Direct the creation and enforcement of security policies, actively engaging in the drafting, vetting, and rollout phases to ensure robustness and applicability.
  • Supervise the policy exception process, with decision making authority in high-risk or high-impact decisions to lead and mitigate potential threats effectively.
  • Cultivate a security-aware culture, providing leadership and direct involvement in training and awareness campaigns.

Enterprise Resilience :

  • Lead the development and continuous improvement of business continuity and disaster recovery plans, actively participating in simulations and drills.
  • Collaborate closely with various department heads to strengthen the resilience of operational and IT systems, directly troubleshooting and strategizing in critical areas.
  • Engage hands-on in the evaluation and enhancement of resilience measures to ensure they meet the evolving needs of the business.

Leadership & Team Management :

  • Lead an impactful risk and resilience team, setting clear goals and expectations while actively supporting their professional development and daily challenges.
  • Create an environment of shared knowledge and mutual support, stepping in to resolve conflicts and facilitate collaboration.
  • Demonstrate leadership through hands-on involvement in critical projects and pivotal initiatives, setting a standard for commitment and excellence.

Board Reporting & Stakeholder Engagement :

  • Develop high-impact security presentations for the board, personally driving the creation of content and essential messaging.
  • Serve as the primary liaison for security matters with internal and external partners, engaging directly in negotiations and critical communications.
  • Lead by example in external engagements, representing the organization in industry forums and regulatory discussions, and forging strong relationships with key partners.

These responsibilities emphasize a balance between strategic leadership and hands-on involvement, ensuring that the Director of Security Risk Management is not only a guiding force but also an active participant in critical activities

What you bring

  • A minimum of 10 years of experience in a senior security role with a strong focus on risk management, policy development, and enterprise resilience.
  • A minimum of 5 years of experience directly engaging with financial regulatory organizations
  • Demonstrated leadership experience with the ability to lead and inspire a team.
  • Consistent track record in developing and implementing comprehensive security risk management and governance programs.
  • Excellent communication and interpersonal skills, capable of working with executive-level stakeholders and board members.
  • Deep understanding of global security regulations, compliance frameworks, and industry standards.
  • Professional certifications such as CISSP, CISM, CRISC, or similar.
  • Experience in a highly regulated environment and / or public companies.
  • Experience with off-the-shelf GRC and program management tools (e.g., Jira)

Base pay for the successful applicant will depend on a variety of job-related factors, which may include education, training, experience, location, business needs, or market demands.

The expected salary range for this role is based on the location where the work will be performed and is aligned to one of 3 compensation zones.

This role is also eligible to participate in a Robinhood bonus plan and Robinhood’s equity plan. For other locations not listed, compensation can be discussed with your recruiter during the interview process.

Zone 1 (Menlo Park, CA; New York, NY; Bellevue, WA; Washington, DC)$255,000 $300,000 USDZone 2 (Denver, CO; Westlake, TX;

Chicago, IL)$224,000 $264,000 USDZone 3 (Lake Mary, FL)$199,000 $234,000 USD

Click to learn more about available Benefits, which vary by region and Robinhood entity.

We’re looking for more growth-minded and collaborative people to be a part of our journey in democratizing finance for all.

If you’re ready to give 100% in helping us achieve our mission we’d love to have you apply even if you feel unsure about whether you meet every single requirement in this posting.

At Robinhood, we're looking for people invigorated by our mission, values, and drive to change the world, not just those who simply check off all the boxes.

Robinhood embraces a diversity of backgrounds and experiences and provides equal opportunity for all applicants and employees.

We are dedicated to building a company that represents a variety of backgrounds, perspectives, and skills. We believe that the more inclusive we are, the better our work (and work environment) will be for everyone.

Additionally, Robinhood provides reasonable accommodations for candidates on request and respects applicants' privacy rights.

Please review the specific applicable to the country where you are applying.

30+ days ago
Related jobs
Promoted
Enterprise Community Partners
Washington, District of Columbia

Experience conducting climate risk assessments; climate resilience planning; and climate mitigation, resilience, and/or adaptation strategies, especially as they relate to housing and community development and/or land use and zoning. Experience with conducting economic risk assessments and with deve...

Promoted
The Executive Leadership Council
Washington, District of Columbia

Assesses the degree of risk in plans or actions and takes appropriate action to mitigate them or make contingency plans to limit the magnitude of risk, including having the insight and appreciation of organizational needs, priorities, goals and seeing that actions support those goals; demonstrates a...

Action Against Hunger
Washington, District of Columbia

Develop and implement a comprehensive compliance and risk management program to more effectively prevent, detect, respond to and mitigate illegal, unethical, or improper conduct and promote a culture of integrity, compliance, and accountability to both the donors that entrust us with resources and t...

Atlantic Council of the United States
Washington, District of Columbia

The Scowcroft Center for Strategy and Security works to develop sustainable, nonpartisan strategies to address the most important security challenges and opportunities facing the United States and the world. The Director and Senior Fellow will support the Vice President and Senior Director of the Sc...

Gibson, Dunn & Crutcher LLP
Washington, District of Columbia

The Senior Director, Information Security Threat Hunting, Detection & Incident Response advises the Information Security Team on the tactics, techniques and procedures of current threat actors, emerging threats, relevant and timely IOCs and all aspects of threat hunting, detection and analysis. Los ...

BDO
Washington, District of Columbia

Under the direction of the Regional Business Development Director (RBDD), and in collaboration with practice leadership, and the Chief Business Development Officer, the Director of Business Development, Legal, Compliance & Risk, is responsible for driving, monitoring and improving sales performance ...

MEDSTAR HEALTH
Washington, District of Columbia

Reporting to the Assistant Vice President of Quality and High Reliability with matrix reporting to the Vice President for Risk Management Services for MSH, the Director of Risk and Claims Management directs, designs, implements and maintains the Risk Management Program in order to reduce incidence a...

The Executive Leadership Council
Washington, District of Columbia

Assesses the degree of risk in plans or actions and takes appropriate action to mitigate them or make contingency plans to limit the magnitude of risk, including having the insight and appreciation of organizational needs, priorities, goals and seeing that actions support those goals; demonstrates a...

DBA Web Technologies
Washington, District of Columbia

Responsible for planning and implementation of information security and cyber risk policies, procedures, standards, and controls across PeaceHealth. Facilitates cyber risk management activities, security risk assessments, and information security awareness. Provides support for internal and external...

Forrester Research, Inc.
Washington, District of Columbia
Remote

Candidates for this role must understand how NAV solutions round out capabilities and processes within the security operations center (SOC) and the availability of managed security services (MSS) to gain access to additional security expertise, increase security detection and response capabilities, ...