Lead GRC & Security Governance
Job Description
Dave vs. Goliath. We’re Dave.
Dave is a financial app on a mission to build products that level the financial playing field. It is redefining the financial landscape by leveraging technology to create an affordable, transparent, and user-centric access to liquidity for millions of Americans. As a leading innovator in the U.S. financial services sector, Dave’s digital financial platform offers products designed to meet the credit needs of those underserved by traditional financial institutions. Dave’s offerings include its flagship ExtraCash product, providing members up to $500 within minutes. The company is on track to launch several new product offerings in 2026, including a Buy Now Pay Later (BNPL) option.
Dave is focused on serving Americans who are financially vulnerable or living paycheck to paycheck. Dave is leading the charge in creating a new era of credit products that prioritizes speed, affordability, and accessibility, making it the go-to financial partner for those who need it most.
We’re hiring a Lead, GRC & Security Governance to build and run the governance systems that keep Dave’s technology organization controlled, resilient, and audit-ready. This is a senior individual contributor role with meaningful ownership across technology risk, controls, assurance, incident governance, and business continuity.
The Opportunity
This is a new role with the opportunity to shape how technology governance works at Dave. You’ll build practical systems that give Security, IT, Engineering, and Data teams clear expectations for managing risk and demonstrating that controls work.
You won’t own technical remediation. You’ll define what good looks like, establish accountability, challenge gaps, and make sure material risks reach the right decision-makers.
What You’ll Build and Own
• Build and operate Dave’s technology governance program across technology and cyber risk, IT controls, change management, incident management, business continuity, and policies.
• Establish and maintain our technology control inventory, with clear owners, evidence requirements, operating cadence, exceptions, and escalation paths.
• Own technology assurance and audit readiness across programs including SOX ITGC, PCI, SOC 2, and other applicable frameworks. Coordinate evidence, support testing, identify gaps, and drive remediation accountability through closure.
• Own the technology and cyber risk register and control exception process. Surface material or sustained risks with clear context and recommendations, including when there’s resistance to escalation.
• Govern change management, incident management, and business continuity so expectations are practical, consistently followed, tested, and improved over time.
• Use AI and automation thoughtfully to improve evidence analysis, control mapping, policy maintenance, risk reporting, audit preparation, and remediation tracking while maintaining appropriate human review and data safeguards.
The Impact
Strong governance makes it easier for Dave to move with confidence. Your work will help teams understand risk, strengthen operational resilience, meet our obligations, and build systems that hold up as the company grows.
What We’re Looking For
• 8+ years of relevant technology experience, including significant ownership in security governance, technology risk, or security assurance.
• You’ve personally led a SOC 2 Type II, ISO 27001, or equivalent audit through a successful result—not simply supported audit preparation.
• You’ve built or materially rebuilt a governance, risk, or assurance operating model rather than only administering an established program.
• Strong technical fluency across environments such as cloud, identity, CI/CD, source control, endpoints, networks, and data platforms. You can turn ambiguous expectations into specific, testable controls and challenge answers that aren’t precise enough.
• Experience owning accountability while technical teams own remediation. You can influence Engineering, SRE, Security, IT, and Data partners without taking their work over.
• Sound judgment around risk and materiality, including demonstrated experience escalating meaningful risks when stakeholders disagreed.
• Experience partnering credibly with Internal Audit and Legal in addition to technical and Security teams.
• Strong written communication and program management skills. You turn ambiguity into clear owners, decisions, actions, dates, and evidence.
Bonus
Experience with SOX ITGC, PCI DSS, NIST-based programs, AI governance or third-party AI risk, and GRC automation platforms such as Vanta or Drata.
What Makes Someone Successful Here
You take responsibility for outcomes, not just deliverables. You’re comfortable defining the system, asking specific questions, and making thoughtful trade-offs between immediate needs and controls that will hold up over time. When something represents meaningful risk, you have the judgment and conviction to make it visible.
You also know governance works best when technical teams see it as useful rather than bureaucratic. You build credibility with partners, seek context before reaching conclusions, and use feedback to improve the system. When priorities or requirements change, you adjust without losing sight of the underlying risk.
What to Expect
You’ll have significant autonomy to shape a new function, but you won’t work in isolation. You’ll partner closely with Security, IT, Engineering, Data, Internal Audit, Legal, Compliance, and external assessors to build a governance model that works in practice—not just on paper.
Why Join Dave
Dave is building financial products that give everyday Americans better access to their money without predatory fees. This role offers the chance to build foundational governance systems at a growing public fintech, influence how technology teams manage risk, and create an operating model that can scale with the business.
Ready to build for the underdog?
Reports to: Sr. Director, Security & IT
Don’t let imposter syndrome get in the way of an incredible opportunity. We’re looking for people who can help us achieve our mission and vision, not just check off the boxes. If you’re excited about this role, we encourage you to apply. You may just be the right candidate for this or other roles.
Why you’ll love working here:
At Dave, our people are just as important as our product. Our culture reflects the values that guide who we are, how we work, and what we aspire to be. Daves are member-centric, helpful, transparent, persistent, and better together. We strive to create an environment where all Daves feel valued, heard, and empowered to do their best work. As a virtual-first company, team members can live and work anywhere in the United States, except Hawaii.
A few of our benefits & perks:
💚 Opportunity to tackle tough challenges, learn and grow from fellow top talent, and help millions of people reach their personal financial goals
💻 Flexible hours and virtual-first work culture with a home office stipend
🏥 Premium Medical, Dental, and Vision Insurance plans
👶 Generous paid parental and caregiver leave
💰 401(k) savings plan with matching contributions
📈 Financial advisor and financial wellness support
🏖️ Flexible PTO and generous company holidays, including Juneteenth and Winter Break
🎉 All-company in-person events once or twice a year and virtual events throughout to connect with your team members and leadership team
Dave Operating LLC is proud to be an Equal Employment Opportunity employer and is dedicated to cultivating a diverse and inclusive workplace. We will consider for employment all qualified applicants and do not discriminate on any basis protected by federal, state, or local law, including the City of Los Angeles’ Fair Chance Initiative for Hiring Ordinance relating to an applicant's criminal history.
#LI-REMOTE
Requirements
Department: Engineering
Team: Security & IT