SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Candescent is a fintech company providing intelligent banking solutions to financial institutions through digital banking, account opening, and branch solutions. The company is seeking an experienced Director of Governance, Risk, Compliance & Vendor Management to lead the organization's audit, compliance, third-party risk management (TPRM), and vendor governance functions.
In this role, you will lead a team responsible for maintaining a strong control environment that supports Candescent's banking and financial services customers while ensuring compliance with regulatory, contractual, and industry security requirements. Key responsibilities include:
• Leading Candescent's Governance, Risk, Compliance, Third-Party Risk Management, and Vendor Management programs
• Managing and overseeing SOC 2 Type II, PCI DSS, customer audits, and banking regulatory examinations
• Ensuring compliance with applicable banking, security, and privacy requirements, including FFIEC guidance, GLBA, and PCI DSS
• Directing the vendor lifecycle, including onboarding, risk assessments, ongoing monitoring, contract reviews, and offboarding
• Partnering with Legal, Procurement, Technology, Product, and Operations teams to manage risk and compliance obligations
• Developing executive reporting on audit readiness, compliance status, vendor risk, and remediation activities
• Leading customer compliance engagements, due diligence reviews, and security assurance activities
• Building, mentoring, and developing a high-performing team while driving process improvements and operational efficiency
Required qualifications include a bachelor's degree in Information Systems, Cybersecurity, Business, Finance, Accounting, or related field; 10+ years of experience in audit, compliance, risk management, vendor management, or information security within banking, fintech, or financial services; 5+ years of leadership experience managing professional teams; deep expertise leading SOC 2 Type II and PCI DSS audit programs; strong understanding of US banking regulations and frameworks including FFIEC and GLBA; experience with third-party risk management and vendor governance programs; and proven ability to lead audits, manage remediation efforts, and present results to executive leadership and customers.
Preferred qualifications include CISA, CISM, CRISC, CIA, CTPRP, or equivalent certifications; experience supporting cloud-based financial technology platforms; and experience interacting with banking regulators, customers, and external auditors.