SlipstreamJobsFresh Startup & VC-Backed Jobs

Vice President, Head of Business Controls – Technology & Cybersecurity

SoFi - San Francisco, CA, United States - In-office - posted 2026-08-21

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

SoFi is seeking an experienced Vice President to lead Business Controls for its Technology and Cybersecurity organizations. Reporting to the Head of Business Controls, you will serve as the primary first-line-of-defense (1LOD) risk partner for the CTO, CISO, and their senior leadership teams across SoFi's global entities including SoFi Inc., SoFi Bank, Galileo, Technisys, and SoFi Hong Kong. You will lead a team of IT risk and controls professionals responsible for promoting risk awareness and ensuring effective implementation of risk and compliance management programs. Key responsibilities include: • Strategic Leadership: Serve as the primary 1LOD risk partner for Technology and Cybersecurity functions across all domestic and international entities, ensuring consistent application of risk frameworks in diverse regulatory environments. • Program Ownership: Own the strategy, governance, and execution of critical enterprise-wide programs including Insider Threat, End User Computing (EUC), AI Governance, and IT Asset Management (ITAM), ensuring compliance with FFIEC and OCC standards. • Risk Assessment & RCSA: Lead complex initiatives to maintain the Risk and Control Self-Assessment (RCSA) framework, conduct control testing, identify gaps, and develop remediation strategies for operational and cyber risks. • Advisory & Governance: Partner across lines of defense—Compliance, Risk Management, Audit, and Regulators—to support diverse risk and compliance initiatives. Advise senior management and Board Committees on control environment status. • Regulatory Interface: Serve as key interface for Technology and Cyber risk matters during regulatory exams (Federal Reserve, OCC, CFPB) and internal audits. • Framework Alignment: Drive program adherence to industry frameworks such as CoBIT, NIST, and FFIEC guidance. • Risk Identification: Partner with Engineering and Security leaders to identify, measure, monitor, and control existing and emerging risks including software supply chain, cloud security, and legacy system integration. You will be responsible for supporting consistent 1LOD adherence to critical programs, monitoring control effectiveness, and strengthening the overall control environment through data-driven risk assessment and continuous improvement initiatives.

Similar roles