1

Cybersecurity Governance Risk Compliance Jobs in Delaware

... governance and compliance * Enables continuous, risk-based exposure management * Improves efficiency, control effectiveness, and compliance readiness * Drives alignment between cybersecurity ...

... governance and compliance * Enables continuous, risk-based exposure management * Improves efficiency, control effectiveness, and compliance readiness * Drives alignment between cybersecurity ...

Compliance Audit is responsible for executing and leading audit engagements based on established ... Banking industry audit experience with focus on Governance, Risk & Oversight Function preferred

$230 - $320/hr

... Risk, Compliance, Finance, Legal, Product, Data, Cybersecurity, and business teams to resolve ... Strengthens technology risk and governance visibility by tracking audit findings, regulatory ...

Showing results 41-60

Cybersecurity Governance Risk Compliance information

What is the difference between Cybersecurity Governance Risk Compliance vs Cybersecurity Analyst?

AspectCybersecurity Governance Risk ComplianceCybersecurity Analyst
CertificationsCISA, CISSP, CISMCompTIA Security+, CISSP, CEH
Work EnvironmentPolicy development, audits, compliance frameworksMonitoring security systems, incident response
Employer & Industry UsageOrganizations with compliance needs, regulatory bodiesIT security teams, cybersecurity firms

While Cybersecurity Governance Risk Compliance focuses on establishing policies, ensuring regulatory adherence, and managing risks, Cybersecurity Analysts primarily monitor security systems, analyze threats, and respond to incidents. Both roles are essential in a comprehensive cybersecurity strategy but differ in scope and daily responsibilities.

What are the key skills and qualifications needed to thrive as a cybersecurity governance, risk, and compliance (GRC) professional?

To thrive as a Cybersecurity GRC professional, you need a solid understanding of information security frameworks, risk management principles, and regulatory compliance, often supported by a degree in cybersecurity or related fields. Familiarity with tools like GRC platforms (e.g., Archer, ServiceNow), and certifications such as CISSP, CISM, or CRISC are highly valued. Strong analytical thinking, attention to detail, and effective communication skills help you interpret regulations and collaborate with stakeholders. These skills ensure organizations can manage cybersecurity risks proactively while meeting regulatory and industry standards.

What are some typical challenges faced by professionals in cybersecurity governance, risk, and compliance (GRC) roles?

Professionals in Cybersecurity GRC roles often navigate the challenge of keeping up with rapidly changing regulatory requirements while ensuring company policies align with both business objectives and security best practices. Balancing the need for robust security controls with operational efficiency, educating non-technical stakeholders about risk, and managing audits are common aspects of the job. Additionally, GRC professionals frequently collaborate with IT, legal, and business teams to ensure a cohesive approach to risk management and compliance. This dynamic environment requires strong communication skills, adaptability, and a commitment to continuous learning.

Is cybersecurity governance risk compliance a good career?

Cybersecurity Governance, Risk, and Compliance (GRC) is a growing field that offers opportunities in managing organizational security policies, risk assessments, and regulatory compliance. It requires knowledge of security frameworks, certifications like CISSP or CISM, and strong analytical skills. The role is in demand across various industries due to increasing cybersecurity threats and regulatory requirements.

Is cybersecurity governance risk compliance a good job?

Cybersecurity Governance, Risk, and Compliance (GRC) roles are in high demand due to increasing cybersecurity threats and regulatory requirements. These jobs typically require knowledge of security frameworks, risk management, and compliance standards, offering opportunities for career growth and specialization. They often involve collaboration across departments and may require certifications like CISSP or CISA.

What is cybersecurity governance, risk, and compliance (GRC)?

Cybersecurity Governance, Risk, and Compliance (GRC) refers to a framework used by organizations to align their IT and security strategies with business objectives, manage risks, and ensure compliance with laws and regulations. Governance involves setting policies and procedures, risk focuses on identifying and addressing threats, and compliance ensures adherence to required standards. Professionals in this field help organizations protect sensitive data, avoid regulatory penalties, and build trust with stakeholders. GRC is essential for maintaining effective cybersecurity and demonstrating due diligence.
What are popular job titles related to Cybersecurity Governance Risk Compliance jobs in Delaware? For Cybersecurity Governance Risk Compliance jobs in Delaware, the most frequently searched job titles are:
What job categories do people searching Cybersecurity Governance Risk Compliance jobs in Delaware look for? The top searched job categories for Cybersecurity Governance Risk Compliance jobs in Delaware are:
What cities in Delaware are hiring for Cybersecurity Governance Risk Compliance jobs? Cities in Delaware with the most Cybersecurity Governance Risk Compliance job openings:
Infographic showing various Cybersecurity Governance Risk Compliance job openings in Delaware as of August 2026, with employment types broken down into 76% Full Time, 8% Part Time, 8% Temporary, and 8% Contract. Highlights an 85% In-person, and 15% Hybrid job distribution.

SVP, Head of Security Technology

Berkley

Wilmington, DE โ€ข Hybrid

Full-time

Re-posted 3 days ago


Job description

"Thoughtful Minds | Empowering Possibilities"
W. R. Berkley Corporation is comprised of 60+ businesses alongside Berkley Technology Services (BTS) and other shared services groups.
Here at Berkley Technology Services, the core of our success is our people. Our teams bring their own unique perspective and experiences which enables us to translate the needs of our business to deliver adaptable, secure solutions while providing an unmatched user-focused experience.
Our tagline "Thoughtful Minds | Empowering Possibilities" was crafted with our own teams in mind. At BTS, our teams thrive in Berkley's decentralized model - leveraging the power of being part of a long standing, heritage brand with extensive expertise while innovation and being entrepreneurial is encouraged.
Internally, we operate as a relatively flat organization valuing communication and feedback. We pride ourselves in an open-door policy where no one is treated differently based on title, fostering a culture of trust, transparency, and engagement.
Mission (what we stand for): We believe in the value of every voice, translate needs into capabilities, and secure the future of Berkley.
Vision (where we're going): Be the foundation of Berkley through adaptable solutions, resilient environments, and an unmatched experience.
Come join us as we push forward into the future of industry leading technological solutions.

The Company is an equal employment opportunity employer.


The SVP, Head of Security Technology, leads the modernization and delivery of the enterprise's core cybersecurity technology capabilities through an AI-enabled, automation-first, engineering-led model. This role reports to the CISO.

This role is accountable for evolving and integrating:

  • Security Architecture

  • Security Engineering

  • Identity and Access Management (IAM)

  • Continuous Threat and Exposure Management (CTEM)

The position transforms legacy, siloed security functions (e.g., vulnerability management, attack surface management, application security) into a scalable, intelligence-driven security ecosystem that:

  • Reduces enterprise risk through engineering and automation

  • Embeds security into enterprise architecture and technology platforms

  • Strengthens identity lifecycle governance and compliance

  • Enables continuous, risk-based exposure management

  • Improves efficiency, control effectiveness, and compliance readiness

  • Drives alignment between cybersecurity capabilities and business risk priorities, ensuring security investments directly support enterprise resilience, customer trust, and growth objectives

Responsibilities

Report to the CISO and lead the strategic execution across a team of security directors, managers, architects, engineers and analysts across multiple security technology disciplines.

Security Architecture

  • Define enterprise security architecture strategy, standards, and roadmaps

  • Embed secure-by-design principles across cloud, applications, data, and AI

  • Establish reusable design patterns and reduce exception-based approvals

  • Integrate security into transformation and modernization efforts

  • Lead Zero Trust security architecture strategy and adoption across identity, network, application, and data layers

  • Establish reference architectures for multi-cloud and hybrid environments, including CNAPP, CIEM, and data protection controls

Security Engineering

  • Lead engineering and lifecycle management of security platforms and controls

  • Establish automation-first operations (API, orchestration, policy-as-code)

  • Standardize tooling and reduce manual processes through automation

  • Improve platform resilience, telemetry, and service performance

  • Transition to a product and platform-based security engineering model with defined service ownership, SLAs, and performance metrics

  • Drive rationalization of security tools and vendors to reduce cost and complexity while improving capability coverage

Identity and Access Management (IAM) - User Administrative Lifecycle Scope

  • Lead and own overarching IAM strategy and lifecycle governance, including:

    • Provisioning (joiners), Access changes (movers), De-provisioning (leavers)

    • Enhance user access reviews and certifications

    • Implement, enhance and automate segregation of duties (SoD) monitoring and governance

    • Design and implement role and entitlement management capabilities

    • Enable access-related compliance and audit readiness in preparation for continuous control monitoring and assessment in alignment with Governance Risk and Control Function

  • Ensure least privilege, timely access removal, and reduction of orphaned accounts

  • Integrate IAM with HR, applications, and enterprise platforms

  • Enhance privileged access management and management of non-human identities in preparation for advanced agentic AI capabilities

  • Advance privileged access, machine identity, and non-human identity security in support of automation, cloud, and AI use cases

  • Implement identity-centric Zero Trust controls and continuous authentication models

Continuous Threat and Exposure Management (CTEM)

  • Transform vulnerability, attack surface, and application security into a unified CTEM function

  • Implement continuous, threat-informed prioritization of exposures

  • Align findings to asset criticality and business risk

  • Improve remediation effectiveness and reduce exploitable attack paths

  • Enhance asset visibility, ownership clarity, and dependency mapping

  • Partner with Security Operations and Security Incident and Response functions to coordinate a unified approach across teams

  • Establish attack path analysis and exploitability-based risk prioritization to reduce material exposure

  • Define measurable outcomes such as reduction in attack surface, time-to-remediation, and control effectiveness

AI and Automation Enablement

  • Deploy AI and analytics to improve prioritization and decision-making

  • Automate repetitive security processes and control validation

  • Enhance reporting, telemetry, and audit evidence generation

  • Partner with Head of Security AI to establish secure AI lifecycle practices, including model governance, data protection, prompt security, and third-party AI risk management

  • Partner with Head of Security Operations to leverage AI to enhance threat detection, anomaly identification, and predictive risk analytics

DevSecOps and Secure Development

  • Embed security into the software development lifecycle (SDLC), CI/CD pipelines, and developer workflows

  • Partner with engineering teams to implement scalable DevSecOps practices and developer-friendly security tooling

Operating Model, Leadership and Other Requirements

  • Establish a global operating model with clear accountability, service ownership, and capability maturity roadmaps

  • Develop business cases tied to measurable risk reduction, operational efficiency, and cost optimization

  • Partner with executive leadership and provide board-level reporting on security posture, risk trends, and investment impact

  • Technology first leader with very strong interpersonal skills with demonstrated ability to build and maintain strong relationships and partnerships vertically and horizontally across a mix of business, technology, legal, HR, risk and audit leaders and practitioners

  • Establish a product- and platform-based security technology operating model

  • Define core requirements that evidence demonstrable risk reduction and can be measured using KPIs/KRIs in conjunction with the metrics and analytics program

  • Drive roadmap, investment prioritization, and tool rationalization

  • Drive budgetary discipline through management of finances, including the build of defendable business cases

  • Lead and develop high-performing, multi-disciplinary teams in a positive and respectful capacity leading to high engagement across all disciplines

  • Organically improve the security posture of the organization by ensuring the incorporation of secure principles into every phase of the design, development, deployment, and operation of systems and solutions

  • Assess current environment and design a target state architecture with all accompanying diagrams and documentation as required by architecture teams

  • Provide top-level support as needed on security and operational related issues

  • Represent information security interests on various project teams and special assignments as directed

  • Active in a continuous improvement of the existing process, methodologies, technologies and practices

  • Provide top-level on-call support as required for this type of role, which is factored into the compensation for this role

Resilience and Risk Integration

  • Partner with Security Operations and Incident Response to improve cyber resilience, recovery readiness, and crisis response integration

  • Ensure alignment with enterprise risk management and regulatory expectations through continuous control monitoring


  • 15+ yearsโ€™ experience in a cybersecurity role with at least 5 as head of senior most security architect 
  • Previous and progressive experience in a technical security leadership position. 
  • Demonstrated experience modernizing security organizations (tool consolidation, automation, operating model redesign) 
  • Strong expertise in cloud-native security, Zero Trust, IAM, and CTEM practices 
  • Experience integrating cybersecurity with AI/ML technologies and governance frameworks 
  • Strong strategic thinking and decision-making capabilities 
  • Experience managing budgets, vendors, and large-scale programs 
  • Track record of delivering measurable improvements in risk reduction, efficiency, and security posture 
  • Disciplined thinker with structured approach to security architecture and strategic planning 
  • Inherent intellectual capability and curiosity to learn complex processes. 
  • Proven thought leadership, strategic thinking and decision-making. 
  • Must have strong analytical and problem-solving skills with the capability to identify solutions to unusual and complex problems. 
  • CISSP certification is strongly preferred 
  • Direct security related AI, networking, infrastructure, cloud, operating system, development, cloud, database experience is required  
  • Must be able to demonstrate proficiency in a wide range of security technologies, embedded security, and network platforms โ€“ in a global institution