About the job
About Us
At DriveWealth, we are dedicated to revolutionizing the investment landscape. Our vision is to empower individuals to take charge of their financial destinies, ensuring that access to financial markets is universally available, regardless of location, wealth, or outdated systems. As a leading global B2B financial technology firm, we strive to democratize financial independence through our innovative API-based platform. This enables our partners to provide seamless investing and trading experiences to their clients globally, all from their mobile devices. Our state-of-the-art technology equips partners with a versatile toolkit that supports both traditional investment workflows and cutting-edge strategies like fractional share ownership. DriveWealth is at the forefront of a global trading platform, facilitating transactions in US equities, mutual funds, ETFs, fixed income, and options.
Now is an exciting time to join a trailblazing business that is poised for significant growth. Our culture uniquely combines the dynamism of a fintech startup with the rigor, impact, and stability of Wall Street. We foster an environment that encourages innovation and experimentation while ensuring that we uphold the highest standards of execution and regulatory compliance in all our endeavors. Come and be part of shaping the future of global investing!
About the Role
As the Chief Information Security Officer, you will spearhead and enhance our entire security framework across four critical areas: Governance, Risk & Compliance (GRC), Offensive Security (Red Team), Defensive Security (Blue Team), and Security Engineering & Architecture. You will be responsible for strategic leadership, process improvements, budget management, and team development to meet our ambitious growth targets. The CISO will also serve as the security representative to senior leadership and the board, ensuring compliance with industry standards and readiness for regulatory examinations.
What You’ll Do
- Enhance and oversee policy frameworks and regulatory compliance programs (e.g., SOC, ISO27001, GDPR)
- Conduct and refine security monitoring, incident response, and threat hunting activities
- Lead penetration testing and manage vendor relationships
- Direct the engineering of secure network and identity management systems in cloud environments
- Build, mentor, and grow a proficient security team, particularly in GRC and Blue Team areas
- Engage with industry communities, prepare compliance reports, and present findings to company leadership
- Facilitate readiness for public company listing and support ongoing business expansion

