Senior Cybersecurity Governance, Risk & Compliance Specialist (OCaml Experience)
LOCATION
NYC
DEPARTMENT
Cybersecurity
TEAM
Cybersecurity
Jane Street Group, LLC has multiple openings for the position of Senior Cybersecurity Governance, Risk & Compliance Specialist in New York, NY.
The position duties are as follows: Lead strategic cybersecurity vendor risk management initiatives to enhance the firm's vendor risk posture and regulatory compliance framework. Day-to-day job duties include:
- Architect and implement comprehensive cybersecurity vendor risk governance frameworks that align with regulatory requirements and establish enterprise-wide vendor risk tolerance thresholds.
- Provide strategic leadership in vendor security risk analysis, mentoring junior team members, and establishing standardized methodologies for vendor due diligence, security assessments, and ongoing monitoring that integrate into the organization's overall enterprise risk management strategy.
- Partner with procurement, legal, and business stakeholders to lead vendor assessments across the vendor lifecycle—from initial due diligence and onboarding through periodic reassessments, continuous monitoring, incident response coordination, and offboarding—designing risk mitigation solutions that balance business enablement with regulatory compliance.
- Oversee vendor incident management and breach response protocols, establishing clear escalation procedures and coordinating with vendors during security events to ensure timely remediation and appropriate stakeholder communication.
- Lead operational efficiency initiatives by implementing automated vendor compliance monitoring solutions, transforming manual assessment processes into scalable governance workflows, and establishing key risk indicators and dashboards that enable proactive risk management and decision-making.
The position requires a 3 or 4 year Bachelor's degree in Finance, Engineering, Computer Science, or a related scientific or quantitative field or foreign equivalent plus three (3) years of progressively responsible experience as a cybersecurity GRC analyst, or similar occupation at a financial services or technology firm. Experience must include:
- Two (2) years of experience applying knowledge of vendor-related regulatory requirements related to global regulatory bodies - including FCA, DORA, SEBI, SEC, and Finra - to the vendor assessment and onboarding process;
- One (1) year of experience managing vendor risk governance programs, including stakeholder management across technical and business teams;
- One (1) year of experience developing vendor risk frameworks and conducting risk assessments of third-party integrations;
- One (1) year of experience leading vendor security assessments and determining appropriate evaluation scope based on factors such as data sensitivity, system criticality, and operational dependencies; and
- One (1) year of experience conducting vendor assessments for a trading environment built primarily in OCaml and Python.
- All technical requirements for this role may be subject to employer conducted testing to assess minimum proficiency.
Part time telecommuting may be permitted with manager approval.
Ref. SCGRCS26
Base salary is $200,000 - $250,000. Base salary is only one part of Jane Street total compensation, which includes an annual discretionary bonus.
Jane Street is an Equal Opportunity Employer