Description The application window will close November 1, 2026
Job Location The primary work location for this role is Berwyn, PA or Remote with either a hybrid work or remote model.
The Team You'll Join You'll join Envestnet's Enterprise Cybersecurity team, partnering closely with Security Operations, Technology, Legal, People & Culture, Privacy, Compliance, and business leaders to strengthen the company's security governance and assurance programs. The team works across the organization to assess and mitigate technology and information security risks, maintain effective policies and controls, support regulatory and audit requirements, and promote responsible security practices. In this role, you'll contribute to key initiatives spanning human and insider risk, cybersecurity investigations, control assurance, security awareness, and emerging areas such as AI governance, helping Envestnet operate securely and maintain the trust of its clients, partners, and regulators.
How You'll Contribute Responsible for ensuring that technology decisions align with business strategy, regulatory requirements and client expectations. Encompasses administration of a strategic and comprehensive cybersecurity framework. Identifies, assesses and mitigates technology and information security risks to protect sensitive financial and client data. Establishes policies, controls and oversight to meet regulatory standards for the financial services and wealth management industry. Enables the company to operate securely, responsibly and at scale while maintaining trust with advisors, partners and regulators.
- Provides Security Governance support and advice companywide.
- Develops, validates, implements and maintains cybersecurity and related policies, standards, guidelines and procedures to ensure compliance with company and regulatory requirements.
- Collaborates with cross-functional teams and leaders to ensure security related controls are understood, documented and managed.
- Coordinates with Legal and across relevant compliance functions to ensure proper implementation of data privacy legislation and disclosure.
- Establishes and maintains the framework and roadmap for Security Governance documentation.
- Works with Cyber Security team members and business partners to define risk tolerance and construct risk scenarios.
- Ensures risk scenarios provide a realistic and relatable view of risks based on business context, system environment and pertinent threats.
- Human Risk Program Design and Governance: Support human risk and insider risk governance - including risk assessments, playbooks, and monitoring reviews - in partnership with Security Operations, HR, Legal, Privacy, and Compliance.
- Investigations and Incident Response: Lead or coordinate insider threat investigations (fraud, data exfiltration, policy violations, misuse of privileged access), following sound evidentiary and forensic practices and escalating appropriately to Legal, HR, and executive stakeholders.
- Second Line Risk Management and Regulatory Compliance: Translate regulatory and framework requirements into practical control assessments, track remediation, and prepare risk summaries for audit, regulatory, and management reporting.
- Information Security Assurance and Attestation: Support control assessments and evidence collection for internal assurance, external audits, and customer due diligence, documenting findings and control gaps clearly.
- Awareness, Training, and Culture: Develop role-based security awareness content and training, and help build a culture of early reporting and responsible security behavior.
- Metrics and Continuous Improvement: Track assessment and remediation metrics, and recommend improvements to assurance processes based on trends and lessons learned.
- AI Governance and Risk Management: Assess and secure AI/ML systems, agentic ecosystems, and AI-assisted development across the software lifecycle - including AI platforms (e.g., AWS Bedrock, Claude, Copilot), agent/orchestration frameworks, and RAG/LLM integrations - while identifying and mitigating AI-specific risks such as prompt injection, jailbreaking, data poisoning, and model exfiltration, in alignment with NIST AI RMF and ISO 42001.
What You'll Need to Bring - Candidates should demonstrate the relevant experience, skills, and capabilities needed to successfully perform in the role. Relevant experience may be gained through current responsibilities, prior roles, project work, leadership opportunities, or other comparable experiences.
- Employees must have achieved a performance rating of "Meets Expectations" or higher in the most recent appraisal cycle.
- Experience in a regulated financial services environment (wealth management, banking, insurance, payments, technology, or FinTech), with working knowledge of cybersecurity controls, data protection, IAM, cloud security, incident response, security monitoring, and AI-related risk considerations.
Familiarity with industry frameworks such as NIST CSF, NIST SP 800-53, NIST AI RMF, SOC 1/SOC 2, CIS Critical Security Controls, SEC Regulation S-P, and applicable privacy requirements. - Strong cross-functional communication and analytical skills - able to influence without direct authority, translate risk/control concepts for technical and non-technical audiences, and produce clear assessment summaries, evidence requests, findings, and remediation tracking materials.
Nice-to-Haves - 8-10 years of experience in information security, security governance, technology risk, cybersecurity assurance, internal audit, compliance, security operations, privacy, or related risk management functions.
- 2-4 years of experience supporting cybersecurity control assessments, audit readiness, evidence collection, risk assessments, human risk management, security awareness, insider risk, or data protection activities.
- CISSP, CISM, CRISC, CISA, Certified Fraud Examiner, GCFA, GCIH, GCFE, or related GIAC certification.
- Familiar with the Insider Threat Matrix framework concepts, including motive, means, preparation activities, infringement techniques, and anti-forensics as an investigative taxonomy.
- Knowledge of SaaS service architecture frameworks, cloud security services (Azure, AWS) and cyber defense tools.
Sponsorship This position is not open to candidates requiring visa sponsorship
Our Investment in You This role offers a base salary range of $138,000 to $170,000. The range listed represents a good-faith estimate of base salary compensation for this position and does not include incentive compensation, equity or benefits. Individual pay will be determined based on factors including, but not limited to, relevant experience, skills, education, certifications, and geographic location, in accordance with applicable pay transparency laws. This role is eligible for an additional incentive component as part of the total rewards package.
We provide a comprehensive suite of benefits - subject to Envestnet's plan eligibility rules - that support your overall well-being including, medical insurance, paid time off (PTO), 401k company match, paid parental leave, education reimbursement, disability coverage and mental health & wellness support. Our investment in you means supporting you professionally, financially, and personally at every stage of your journey with us. Please visit our benefits page on our career site to learn more.