Senior Cybersecurity Governance, Risk & Compliance Specialist (OCaml Experience)

Jane Street
New York, NY
Hybrid

Who this role is best for

Geared toward candidates with vendor risk expertise and a background in trading environments, comfortable with OCaml and Python.

Best fit for

  • Candidates with vendor risk governance experience and a quantitative or technical background
    — “Bachelor's degree in Finance, Engineering, Computer Science, or a related scientific or quantitative field
  • Individuals familiar with global financial regulations and third-party risk frameworks
    — “vendor-related regulatory requirements related to global regulatory bodies - including FCA, DORA, SEBI, SEC, and Finra
  • Candidates who can lead and mentor teams while managing complex vendor risk workflows
    — “mentoring junior team members, and establishing standardized methodologies

Things to consider

  • OCaml and Python expertise is specifically required for assessing trading environments
    — “conducting vendor assessments for a trading environment built primarily in OCaml and Python
  • The role demands a strong grasp of both technical and business stakeholder needs
    — “stakeholder management across technical and business teams

How to stand out

  • Highlight experience in balancing business enablement with regulatory compliance
    — “designing risk mitigation solutions that balance business enablement with regulatory compliance
  • Demonstrate leadership in developing standardized vendor risk methodologies
    — “establishing standardized methodologies for vendor due diligence, security assessments
  • Emphasize experience with automated compliance monitoring tools and dashboards
    — “implementing automated vendor compliance monitoring solutions
  • Showcase prior work with vendor lifecycle management from due diligence to offboarding
    — “vendor lifecycle—from initial due diligence and onboarding through periodic reassessments
Pace · SteadyCollaboration · MediumAutonomy · MediumDecision Impact · Team

Derived from job-description analysis by Serendipath's career intelligence engine.

What success looks like

  • enhanced vendor risk posture
  • established enterprise-wide vendor risk tolerance thresholds
  • implemented automated vendor compliance monitoring solutions
Typical background
3+ years of experience in cybersecurity governance, risk, and compliance

Skills & requirements

Required

Cybersecurity GovernanceRisk ManagementCompliance FrameworksVendor Risk AnalysisRegulatory RequirementsOcaml

Preferred

Python

Stack & domain

OcamlPythonVendor Risk ManagementRegulatory ComplianceLeadershipMentoringStakeholder ManagementCybersecurityFinanceEngineeringComputer Science

About the role

Original posting from Jane Street

Jane Street Group, LLC  has multiple openings for the position of Senior Cybersecurity Governance, Risk & Compliance Specialist in New York, NY.

The position duties are as follows: Lead strategic cybersecurity vendor risk management initiatives to enhance the firm's vendor risk posture and regulatory compliance framework. Day-to-day job duties include:

Architect and implement comprehensive cybersecurity vendor risk governance frameworks that align with regulatory requirements and establish enterprise-wide vendor risk tolerance thresholds.

Provide strategic leadership in vendor security risk analysis, mentoring junior team members, and establishing standardized methodologies for vendor due diligence, security assessments, and ongoing monitoring that integrate into the organization's overall enterprise risk management strategy.

Partner with procurement, legal, and business stakeholders to lead vendor assessments across the vendor lifecycle—from initial due diligence and onboarding through periodic reassessments, continuous monitoring, incident response coordination, and offboarding—designing risk mitigation solutions that balance business enablement with regulatory compliance.

Oversee vendor incident management and breach response protocols, establishing clear escalation procedures and coordinating with vendors during security events to ensure timely remediation and appropriate stakeholder communication.

Lead operational efficiency initiatives by implementing automated vendor compliance monitoring solutions, transforming manual assessment processes into scalable governance workflows, and establishing key risk indicators and dashboards that enable proactive risk management and decision-making. 

The position requires a 3 or 4 year Bachelor's degree in Finance, Engineering, Computer Science, or a related scientific or quantitative field or foreign equivalent plus three (3) years of progressively responsible experience as a cybersecurity GRC analyst, or similar occupation at a financial services or technology firm. Experience must include: 

Two (2) years of experience applying knowledge of vendor-related regulatory requirements related to global regulatory bodies - including FCA, DORA, SEBI, SEC, and Finra - to the vendor assessment and onboarding process;

One (1) year of experience managing vendor risk governance programs, including stakeholder management across technical and business teams;

One (1) year of experience developing vendor risk frameworks and conducting risk assessments of third-party integrations;

One (1) year of experience leading vendor security assessments and determining appropriate evaluation scope based on factors such as data sensitivity, system criticality, and operational dependencies; and

One (1) year of experience conducting vendor assessments for a trading environment built primarily in OCaml and Python.

All technical requirements for this role may be subject to employer conducted testing to assess minimum proficiency.

Part time telecommuting may be permitted with manager approval.

Ref. SCGRCS26

Source: Jane Street careers

Similar roles