Envestnet

Lead Security Governance Partner - Risk Management

Envestnet$138K — $173K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years of experience in information security or cybersecurity risk management.
  • Hands-on experience with security assessments and risk evaluation for AI systems.
  • Familiarity with NIST AI RMF and ISO/IEC 42001 frameworks.
  • Proficient in security control frameworks like NIST CSF, NIST SP 800-53.
  • Strong analytical skills with attention to detail.
  • Ability to communicate technical risk findings to non-technical stakeholders.
  • Experience in fast-paced, matrixed environments.

Responsibilities

  • Ensure technology decisions align with business strategy and compliance requirements.
  • Develop and maintain cybersecurity policies and standards for regulatory compliance.
  • Collaborate with cross-functional teams to document and manage security controls.
  • Coordinate legal and compliance efforts for data privacy legislation implementation.
  • Perform Security Risk Assessments across various platforms and technologies.
  • Evaluate and refine security controls based on risk assessment findings.
  • Create risk documentation, reporting metrics, and dashboards for leadership.

Benefits

  • Medical insurance
  • Paid time off (PTO)
  • 401k company match
  • Paid parental leave
  • Education reimbursement
  • Disability coverage
  • Mental health & wellness support
Full Job Description
Description

The application window will close November 1st, 2026

Job Location

The primary work location for this role is Berwyn, PA or our Raleigh, NC office with a hybrid work model.

The Team You'll Join

You'll join Envestnet's Enterprise Cybersecurity team, a collaborative group focused on protecting the organization's technology, data, and clients through effective security governance and risk management. Working closely with partners across Technology, Product, Infrastructure, Architecture, AI/ML Engineering, Legal, Compliance, and Risk & Assurance, the team identifies and evaluates security risks, strengthens controls, and supports informed business decision-making. In this role, you'll help advance a consistent, proactive approach to managing cybersecurity risk across applications, cloud platforms, third-party integrations, and emerging technologies.

How You'll Contribute

Responsible for ensuring that technology decisions align with business strategy, regulatory requirements and client expectations. Encompasses administration of a strategic and comprehensive cybersecurity framework. Identifies, assesses and mitigates technology and information security risks to protect sensitive financial and client data. Establishes policies, controls and oversight to meet regulatory standards for the financial services and wealth management industry. Enables the company to operate securely, responsibly and at scale while maintaining trust with advisors, partners and regulators.

  • Provides Security Governance support and advice companywide.
  • Develops, validates, implements and maintains cybersecurity and related policies, standards, guidelines and procedures to ensure compliance with company and regulatory requirements.
  • Collaborates with cross-functional teams and leaders to ensure security related controls are understood, documented and managed.
  • Coordinates with Legal and across relevant compliance functions to ensure proper implementation of data privacy legislation and disclosure.
  • Establishes and maintains the framework and roadmap for Security Governance documentation.
  • Works with Cyber Security team members and business partners to define risk tolerance and construct risk scenarios.
  • Ensures risk scenarios provide a realistic and relatable view of risks based on business context, system environment and pertinent threats.
  • Perform Security Risk Assessments (SRAs) across applications, infrastructure, cloud platforms, third-party integrations, and AI systems to identify threats, vulnerabilities, and business impact, and determine inherent and residual risk levels using established risk taxonomies, scoring
  • methodologies, and impact criteria aligned to enterprise standards.
  • Evaluate the design and effectiveness of technical, administrative, and operational security controls against identified risks, partnering with technology, product, infrastructure, architecture, and AI/ML engineering teams to design, recommend, and refine controls that mitigate risk to acceptable levels.
  • Operate and leverage continuous risk monitoring tools (e.g., vulnerability management, configuration and cloud posture monitoring) to detect changes in risk posture, and analyze monitoring outputs to identify emerging risks, control degradation, and remediation needs.
  • Own the full lifecycle of identified risks - documentation, remediation planning, validation of corrective actions, and risk closure - and produce clear, actionable risk reporting, metrics, and dashboards that communicate severity, trends, and priority issues to Information Security and technology leadership.
  • Execute firmwide GRC activities such as RCSAs, risk acceptances and exceptions, and policy-driven risk assessments, and maintain accurate and current risk data within enterprise GRC and workflow tooling to support aggregated reporting and second-line oversight.
  • Act as a trusted security risk advisor by translating technical findings into clear business risk context to support risk-informed decision-making, and partner closely with 2nd Line Risk & Assurance functions by providing high-quality risk artifacts and evidence, without performing independent assurance activities.


What You'll Need to Bring

  • Candidates should demonstrate the relevant experience, skills, and capabilities needed to successfully perform in the role. Relevant experience may be gained through current responsibilities, prior roles, project work, leadership opportunities, or other comparable experiences.
  • Hands-on experience evaluating and defining security controls for AI agents, models, and applications, including model risk, data governance, and output-integrity considerations.
  • Familiarity with risk and governance frameworks (e.g., NIST AI RMF, ISO/IEC 42001).
  • Hands-on experience performing Security Risk Assessments and documenting risk scenarios, impacts, controls, and conclusions.
  • Strong understanding of security control frameworks (NIST CSF, NIST SP 800-53) and risk methodologies.
  • Demonstrated experience evaluating control effectiveness and supporting remediation planning.
  • Familiarity with continuous monitoring concepts and tools (e.g., vulnerability management, CSPM, configuration monitoring).
  • Ability to clearly document and communicate security risk to both technical teams and non-technical stakeholders.
  • Strong analytical, writing, and organizational skills with attention to detail.
  • Experience creating dashboards and KPI status from real-time data.
  • Experience operating in fast-paced, matrixed environments with multiple stakeholders.


Nice-to-Haves

  • 7+ years of experience in information security, cybersecurity risk management, or technology risk.
  • Knowledge of Investment Banking or Wealth Management
  • Resourceful and proactive in resolving technical challenges.
  • Experience working within a Three Lines of Defense operating model, particularly in financial services or other regulated environments.
  • Hands-on experience with Jira-based risk workflows or enterprise GRC platforms.
  • Cloud security experience.
  • Experience with generative AI/LLM governance and secure AI development lifecycle practices.
  • Relevant certifications such as CISSP, CISM, CCSP, or equivalent.


Sponsorship

This position is not open to candidates requiring visa sponsorship

Our Investment in You

This role offers a base salary range of $138,500 to $173,100. The range listed represents a good-faith estimate of base salary compensation for this position and does not include incentive compensation, equity or benefits. Individual pay will be determined based on factors including, but not limited to, relevant experience, skills, education, certifications, and geographic location, in accordance with applicable pay transparency laws. This role is eligible for an additional incentive component as part of the total rewards package.

We provide a comprehensive suite of benefits - subject to Envestnet's plan eligibility rules - that support your overall well-being including, medical insurance, paid time off (PTO), 401k company match, paid parental leave, education reimbursement, disability coverage and mental health & wellness support. Our investment in you means supporting you professionally, financially, and personally at every stage of your journey with us. Please visit our benefits page on our career site to learn more.

#LI-AA1

About Envestnet

Envestnet, Inc. is a leading provider of intelligent systems for wealth management and financial wellness. The company's platform provides financial advisors with a range of tools and services to help them manage their clients' investments and financial goals. Envestnet's platform includes a range of features, including portfolio management, financial planning, and data analytics. The company is headquartered in Chicago, Illinois, and has operations in more than 20 countries around the world. Envestnet was founded in 1999 and went public in 2010.
Learn more about Envestnet
Size
4,375 employees
Market Cap
$3.3 billion
Industry
Net Income
-$3.1 million
Founded
1999
5 Year Trend
+15.5%
Revenue
$998.2 million
NASDAQ

Similar Jobs

More Jobs at Envestnet

More Information Technology Jobs

Find similar Lead Security Governance Partner - Risk Management jobs: