Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Senior Manager, Security GRC image - Rise Careers
Job details

Senior Manager, Security GRC

OppFi is a mission-driven specialty finance platform seeking a Senior Manager for Cybersecurity Governance, Risk, and Compliance to enhance security policies and reduce cybersecurity risks.

Skills

  • Information Security
  • IT Risk Management
  • IT Audit
  • Security frameworks
  • Policy development

Responsibilities

  • Partner with the CISO to develop the information security program
  • Lead the information security risk management process
  • Develop and maintain security policies and guidelines
  • Manage cybersecurity audits and vendor security reviews
  • Ensure compliance with IT security policies
  • Develop and mature enterprise cybersecurity awareness program
  • Lead and mentor a team of Security Analysts

Education

  • Bachelor's degree in Information Technology or related field

Benefits

  • 401(k) matching program
  • Generous paid time off
  • Medical, dental, vision coverage
  • Tuition reimbursement
  • Lifestyle benefits platform
To read the complete job description, please click on the ‘Apply’ button
OppFi Glassdoor Company Review
2.9 Glassdoor star iconGlassdoor star icon Glassdoor star icon Glassdoor star iconGlassdoor star icon
OppFi DE&I Review
No rating Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
CEO of OppFi
OppFi CEO photo
Todd Schwartz
Approve of CEO

Average salary estimate

$154000 / YEARLY (est.)
min
max
$123200K
$184800K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Senior Manager, Security GRC, OppFi

At OppFi, we are on a mission to reshape the financial landscape, ensuring that credit access is a reality for everyone, especially those who often feel overlooked by traditional banks. We are excited to welcome a dynamic Senior Manager, Security GRC to our incredible team. This remote role is pivotal in strengthening our cyber risk management and compliance strategies, directly impacting how we protect our customers and their data. You'll be at the forefront of integrating security policies and industry best practices into our operations, ensuring that we not only comply with regulations but exceed them. As you partner closely with our Chief Information Security Officer, you will lead a talented team of Security Analysts in implementing robust security governance programs. Your work will involve conducting thorough risk assessments, managing audits, and developing awareness programs that foster a culture of security across the organization. With a focus on innovation and collaboration, you will help us drive continuous improvement, ensuring our cybersecurity measures are as effective as they can be. If you’re an experienced IT professional with a passion for information security and compliance, and you possess at least ten years of related experience, this role could be a wonderful opportunity for you to make a significant impact at OppFi. Join us in our commitment to enhancing financial inclusivity—together, we can create a safer, more equitable financial system for all.

Frequently Asked Questions (FAQs) for Senior Manager, Security GRC Role at OppFi
What are the primary responsibilities of a Senior Manager, Security GRC at OppFi?

The Senior Manager, Security GRC at OppFi is responsible for leading the development and execution of cyber risk management and compliance programs. This includes overseeing risk assessments, managing third-party security reviews, conducting audits, and developing security awareness initiatives. The role also includes ensuring that security policies align with regulatory requirements and industry best practices while collaborating with cross-functional teams.

Join Rise to see the full answer
What qualifications are required to apply for the Senior Manager, Security GRC position at OppFi?

To qualify for the Senior Manager, Security GRC position at OppFi, candidates typically need a bachelor's degree in Information Technology, Computer Information Systems, or a related field. Additionally, extensive experience in Information Security, IT Risk Management, or IT Audit is essential, alongside familiarity with compliance frameworks such as FFIEC, NIST, and ISO standards. A minimum of ten years in IT, with at least two years in a leadership role focused on compliance, is also required.

Join Rise to see the full answer
How does OppFi foster a security-first culture for its employees in the Senior Manager, Security GRC role?

At OppFi, fostering a security-first culture starts with effective communication and training. The Senior Manager, Security GRC will implement an enterprise cybersecurity awareness program that educates employees about security practices. This initiative promotes proactive behavior regarding data protection and compliance, ensuring that security is a shared responsibility across all levels of the organization.

Join Rise to see the full answer
What is the work environment like for the Senior Manager, Security GRC at OppFi?

The work environment for a Senior Manager, Security GRC at OppFi is fully remote, promoting flexibility and work-life balance. OppFi embraces a collaborative culture, encouraging open communication and innovation among team members regardless of their physical location. This environment empowers employees to contribute ideas and solutions freely while being part of a mission-driven team.

Join Rise to see the full answer
What benefits can the Senior Manager, Security GRC expect at OppFi?

OppFi values its employees and offers a comprehensive benefits package for the Senior Manager, Security GRC role, including competitive compensation, performance-based bonuses, equity grants, and a 401(k) matching program. Additional perks include flexible work options, generous paid time off, medical, dental, and vision coverage, as well as lifestyle benefits through various vendor partnerships.

Join Rise to see the full answer
Common Interview Questions for Senior Manager, Security GRC
Can you describe your experience with cybersecurity frameworks relevant to the Senior Manager, Security GRC position?

When answering this question, highlight specific frameworks like NIST, ISO, and COBIT that you have worked with. Discuss how you have applied these frameworks to assess risks, manage compliance, and implement security policies effectively in your past roles.

Join Rise to see the full answer
How do you manage a team focused on cybersecurity compliance and risk management?

Focus on leadership strategies you've employed. Include your approach to mentoring, team dynamics, and how you facilitate collaboration within the team. Discuss any specific successes or improvements your team achieved under your guidance.

Join Rise to see the full answer
What strategies would you implement at OppFi to enhance its security governance?

For this question, emphasize a proactive approach. Discuss how you would begin by assessing the current security posture, identifying gaps, and recommending improvements. Mention strategies like increased risk assessments, security awareness training, and revising security policies to align with evolving threats.

Join Rise to see the full answer
Can you give an example of a major cybersecurity risk you identified and how you addressed it?

Share a specific instance where you successfully identified a significant risk. Explain your methodology, the steps you took to mitigate the risk, the stakeholders involved, and the outcome. This shows your analytical skills and ability to implement effective solutions.

Join Rise to see the full answer
How do you ensure compliance with industry regulations in cybersecurity?

Explain your strategy for staying up to date with industry regulations and how you implement compliance measures within an organization. Focus on developing robust policies, conducting regular training, and implementing continual monitoring practices to ensure ongoing compliance.

Join Rise to see the full answer
What role does communication play in your approach to cybersecurity management?

Discuss the importance of clear communication in educating and aligning employees on security policies. Emphasize collaboration with different departments to create a unified approach to security that incorporates all aspects of compliance and governance.

Join Rise to see the full answer
How do you handle audits and ensure readiness in a cybersecurity context?

Talk about your process for preparing for audits, such as conducting internal assessments, validating documentation, and ensuring all security controls are enforced. Provide examples of your experience leading successful audits and any lessons learned.

Join Rise to see the full answer
How do you cultivate a culture of security awareness among employees?

Share your strategies for promoting security awareness, such as developing training programs, creating engaging content, and utilizing real-life examples to underscore the importance of cybersecurity. Mention any successful initiatives you have led in past positions.

Join Rise to see the full answer
What metrics do you track to measure the effectiveness of your cybersecurity programs?

Identify key metrics such as incident response times, employee training completion rates, and risk assessment results. Discuss how you would utilize these metrics to assess ongoing performance and make data-driven decisions to enhance security practices.

Join Rise to see the full answer
What do you believe is the biggest challenge facing cybersecurity today?

Discuss current trends in cybersecurity, such as the rise of sophisticated cyber attacks or challenges with remote work security. Offer insights into potential solutions and how you would address these issues in your role as Senior Manager, Security GRC at OppFi.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User

Join OppFi as a Senior Associate in Issue Resolution, where you will leverage your analytical skills to enhance customer experiences and drive operational efficiency.

Photo of the Rise User
Sopra Steria I2S Remote No location specified
Posted yesterday

Join Sopra Steria as a Cybersecurity Analyst and leverage your expertise in a dynamic, hybrid working environment.

Photo of the Rise User
Posted 14 days ago

Seeking a motivated intern to assist in crafting detection rules for emerging threats while gaining hands-on experience in cybersecurity.

UBC Hybrid UBC Vancouver Campus
Posted 8 days ago

The UBC Sauder School of Business is looking for a Business Technology Analyst to enhance their business processes through technology-driven solutions.

Photo of the Rise User
Posted 12 days ago

Elevate your career as a Business Systems Administrator by streamlining our project management tools for enhanced organizational efficiency.

Photo of the Rise User

AbbVie is looking for a Senior Information Security Architect to lead secrets management strategies in a fully remote role.

Children’s Mercy is looking for a Security Engineering Manager to join a dedicated team making a positive impact on children's health.

Posted 10 days ago

Join SMU as the Director of Web Application Services, where you will oversee a critical web platform and lead a talented team.

Posted 12 days ago

Join Delaware Nation Industries as a Cloud Engineer and help support vital Air Force operations through innovative cloud solutions.

To facilitate safe, simple and more affordable credit access to the 60 million² everyday Americans who currently lack traditional options while rebuilding their financial health.

12 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
SALARY RANGE
$123,200/yr - $184,800/yr
EMPLOYMENT TYPE
Full-time, remote
DATE POSTED
March 28, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!
LATEST ACTIVITY
Photo of the Rise User
Someone from OH, Delaware just viewed Practice Group Manager at LifeStance Health
Photo of the Rise User
51 people applied to Cyber Crime Analyst at TEKsystems
S
13 people applied to SOC Intern at SHEIN
Photo of the Rise User
8 people applied to Security Analyst at Maximus
Photo of the Rise User
7 people applied to Junior Security Engineer at Epic
Photo of the Rise User
6 people applied to Salesforce Administrator at AHEAD
Photo of the Rise User
Someone from OH, Avon Lake just viewed Advancement Specialist at Sierra Club
Photo of the Rise User
Someone from OH, Sidney just viewed Database Engineer Principal at Sagent
Photo of the Rise User
Someone from OH, North Canton just viewed Manager, Customer Success at impact.com
Photo of the Rise User
43 people applied to IT Intern at USAA
Photo of the Rise User
Someone from OH, Columbus just viewed Customer Experience Representative at MYOB
Photo of the Rise User
Someone from OH, Lakewood just viewed Production Scheduling Supervisor at Shearer's Foods
Photo of the Rise User
Someone from OH, Hilliard just viewed General Manager at Super Soccer Stars
Photo of the Rise User
Someone from OH, West Chester just viewed Independent Living Ambassador at Otterbein SeniorLife
Photo of the Rise User
Someone from OH, Cincinnati just viewed Strategic Sourcing Specialist (US) at Fictiv
Photo of the Rise User
Someone from OH, Cincinnati just viewed Global Supply Manager, Hardware - Asia at Block
Photo of the Rise User
Someone from OH, Springfield just viewed [ Choose Your Own Role ] at Rad AI