ForgeApply · Job listing
VP, Cybersecurity Governance, Risk and Compliance
Acrisure
See all 202 open roles at Acrisure →
Tailor your resume for this Acrisure job in about a minute.
ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for Acrisure's site. Free trial, no card required.
About this role
About Acrisure: A global fintech leader, Acrisure empowers millions of ambitious businesses and individuals with the right solutions to grow boldly forward. Bringing cutting-edge technology and top-tier human support together, we connect clients with customized solutions across a range of insurance, reinsurance, payroll, benefits, cybersecurity, mortgage services – and more.
In the last twelve years, Acrisure has grown in revenue from $38 million to almost $5 billion and employs over 19,000 colleagues in more than 20 countries. Acrisure was built on entrepreneurial spirit. Prioritizing leadership, accountability, and collaboration, we equip our teams to work at the highest levels possible.
Job Summary: We are seeking an experienced Vice President of Cybersecurity Governance, Risk & Compliance to build and lead Acrisure’s global cybersecurity governance, risk, and regulatory assurance function, establishing the operating model that translates cybersecurity risk into clear executive decisions and board-level visibility. In this role, you will set and operate the cyber governance model for a fast growing, highly acquisitive international fintech organization, ensuring risks are clearly identified, prioritized, and communicated to executive leadership and the board.
You will own cybersecurity governance, enterprise board-level management, regulatory readiness, audit, and examination response, IT general controls alignment, and security awareness and phishing resilience programs. Working closely with leaders across Cybersecurity, Technology, Legal (privacy), Operations, and Enterprise Risk Management, you will establish a scalable, defensible control environment that meets increasing regulatory and audit expectations while enabling business growth.
This role reports directly to the CISO, operates with enterprise‑level decision authority, and serves as a core member of the cybersecurity leadership team. Success requires deep expertise in cybersecurity risk and compliance within regulated environments, strong executive presence, and the ability to lead through influence in a complex, global, and rapidly evolving organization.
Responsibilities:
Cyber Governance, Policy, and Standards • Own the operating cadence for the Cybersecurity Governance Committee (CyberGov), including agenda development, pre-read preparation, meeting facilitation, and follow through with decisions and action items. Ensure CyberGov functions as an active governance vehicle. • Own the cybersecurity governance operating model, including policy lifecycle management, standards hierarchy, exception governance, and evidence of adoption. • Translate executive approved cybersecurity policies into clear, enforceable standards and operating procedures that scale globally. • Partner with IT and business leaders to ensure cybersecurity standards are embedded into core operating processes.
Cyber Risk Management • Own the enterprise cybersecurity risk management program, including risk identification, scoring, treatment, acceptance, and reporting. • Maintain the cybersecurity risk register and ensure risks are translated into clear decisions, prioritized remediation plans, and executive ready reporting. • Partner with Enterprise Risk Management to integrate cyber risk appropriately into broader enterprise risk routines. • Translate enterprise risk appetite into actionable cybersecurity decision frameworks and risk thresholds.
Regulatory Readiness & Compliance • Lead cybersecurity compliance readiness across applicable regulatory regimes and expectations, including NYDFS 500, FCA/DORA, and a trajectory toward SOX and SEC audit readiness. • Continuously monitor regulatory and supervisory changes and drive corresponding enhancements to the cybersecurity program. • Ensure global consistency in cyber controls while accounting for regional regulatory differences.
Audit & Examination Leadership • Own the end-to-end cybersecurity audit and examination operating model, including intake, scoping, evidence management, response coordination, issue remediation, and closure. • Serve as the single point of accountability for all cybersecurity audits and examinations (internal and external). • Ensure audit outcomes drive sustained control and process improvement.
IT General Controls & Control Assurance • Define and align cyber-relevant IT General Controls with IT and Operations, including access governance, change management, logging and monitoring, vulnerability and patch governance, and backup and recovery. • Establish a sustainable approach to control assurance and evidence production aligned to audit and regulatory expectations.
M&A Cybersecurity Support • Lead cybersecurity due diligence and provide clear, decision-ready risk assessments for mergers and acquisitions. • Partner with IT and integration teams to ensure visibility and accountability for post-acquisition cybersecurity uplift toward company standards. • Own a repeatable M&A cyber due diligence playbook and drive cybersecurity into the deal team process.
Security Awareness & Phishing Resilience • Own the enterprise security awareness and training program, including role-based training, completion discipline, and effectiveness measurement. • Own the phishing simulation and resilience program, using results to drive targeted risk reduction. • Promote a culture where cybersecurity is embedded into how the business operates.
Metrics, Reporting, and Executive Communication • Develop and maintain a concise set of cybersecurity KPIs and KRIs that reflect risk posture, control health, remediation velocity, and audit readiness. • Deliver clear, consistent, and decision-oriented reporting to executive leadership, Cyber Governance, and other senior forums. • Provide global visibility across regions while maintaining consistent definitions and expectations.
GRC Automation and AI Enablement • Define and execute a GRC modernization roadmap that reduces manual process dependency, acceler
Salary insight
This posting doesn't disclose pay. Across 689 Atlanta jobs with disclosed salaries on ForgeApply, the median is $135k.
See full Security Engineer salary data for Atlanta →
Based on live postings with disclosed pay on ForgeApply; refreshed daily. Not an estimate of this employer's offer.
Tailor your resume for this Acrisure role before you apply.
Tailor my resume for this jobSimilar jobs
- Director of Cybersecurity Governance, Risk and Compliance — The University of Texas at Austin · UT MAIN CAMPUS
- Vice President, IT Governance, Risk & Compliance — Northwestern Mutual · Milwaukee, WI Corporate
- SR. Manager, Cybersecurity Governance — Jabil · St. Petersburg/Tampa, FL
- Director, Global Cybersecurity - Governance, Risk, Compliance & Identity — Donaldson · Bloomington, MN (USA)
- VP, Security & Compliance — Dynata · Remote
- Vice President, Information Security - Identity, Governance, and Cyber Risk — P&G · CINCINNATI GENERAL OFFICES
- Senior Engineer, Global Cybersecurity Governance, Risk and Compliance — Donaldson · Bloomington, MN (USA)
- Senior Director, IT Governance, Risk and Compliance — Wwecorp · Remote
More like this: Security & Cybersecurity Jobs · Security & Cybersecurity Jobs in Atlanta · Browse all jobs
Free ATS checker · No Salary on the Job Posting? How to Find the Number Before You Interview