Western Union

Vice President, Cyber Governance, Risk & Compliance and Deputy CISO

Texas · Hybrid · Posted yesterday

Opens westernunion.wd5.myworkdayjobs.com

Get a version of your resume written for this job.

Salary
Not listed
Job type
Full-time
Work mode
Hybrid
Source
Workday (employer's hiring system)

Skills mentioned

Cybersecurity, Incident Response, IAM, Cloud Security

About the role

We are seeking a seasoned Vice President of Cyber Governance, Risk & Compliance to lead the strategy, execution, and continuous maturation of our cybersecurity governance, risk, and compliance program. Reporting to the Chief Information Security Officer, this leader will oversee the frameworks, processes, and teams responsible for cyber risk governance, regulatory readiness, policy management, control assurance, third-party cyber risk oversight, and related GRC capabilities. 


In addition to leading Cyber GRC, this executive will serve as Deputy CISO for Western Union, supporting the CISO in the leadership and execution of the broader enterprise cybersecurity strategy. The Deputy CISO will represent the CISO in designated executive, Board, regulatory, business, and technology forums; help coordinate priorities across cybersecurity functions; provide leadership during significant cyber incidents; and assume delegated CISO responsibilities as required. 


The successful candidate will combine deep GRC and financial services expertise with the executive presence, business acumen, cybersecurity knowledge, and leadership capabilities necessary to operate across the full breadth of the cybersecurity organization. 


Role Responsibilities (GRC):

  • Lead the cyber GRC function and define strategic roadmap, operating model, and maturity targets. 
  • Maintain governance structures supporting cyber risk decision-making, escalation, and executive oversight. 
  • Drive cyber risk appetite, exception management, and risk acceptance processes. 
  • Oversee cyber and technology risk assessment methodologies and execution. 
  • Develop and maintain executive and Board-level cyber risk reporting and metrics. 
  • Lead preparation and coordination for regulatory exams, internal/external audits, and customer assessments related to cybersecurity. 
  • Oversee control framework management, evidence programs, and issue remediation governance. 
  • Own lifecycle management of security policies, standards, and governance documentation. 
  • Oversee cyber due diligence and ongoing risk monitoring for third-party vendors, partners, and strategic providers. 
  • Build, mentor, and scale a high-performing GRC team. 

Role Responsibilities (Deputy CISO):

  • Support the CISO in defining and executing the enterprise cybersecurity strategy. 
  • Serve as a strategic advisor to the CISO on cybersecurity risk, organizational priorities, investment decisions, regulatory matters, and emerging threats. 
  • Represent the CISO in designated executive, Board, business, technology, regulatory, risk, and governance forums. 
  • Help coordinate strategy, priorities, dependencies, and execution across cybersecurity functions. 
  • Promote integration among Security Operations, GRC, IAM, Security Engineering, Architecture, Application Security, Threat Intelligence, Incident Response, Fraud, and other relevant capabilities. 
  • Participate in cybersecurity strategic planning, budgeting, workforce planning, investment prioritization, and organizational design. 
  • Assist in preparing and delivering Board and executive-level cybersecurity reporting. 
  • Represent cybersecurity during significant regulatory examinations and interactions when delegated by the CISO. 
  • Identify cross-functional gaps and organizational risks and drive accountability for their resolution. 
  • Provide leadership continuity for the cybersecurity organization during periods when the CISO is unavailable. 
  • Assume additional CISO responsibilities and authorities when specifically delegated. 
  • Foster a culture of transparency, accountability, constructive challenge, collaboration, and continuous improvement. 
  • Build trusted relationships across Technology, Operations, Product, Legal, Compliance, Risk, Internal Audit, and business leadership 

Role Requirements:

  • Bachelor’s degree required; advanced degree preferred. 
  • 15+ years of experience in cybersecurity, technology risk, audit, compliance, or governance roles. 
  • 7+ years of people leadership experience with increasing organizational scope. 
  • Proven experience building, transforming, or materially uplifting cyber GRC programs in financial services or similarly regulated industries. 
  • Deep knowledge of cybersecurity governance, financial services regulatory expectations, security/control frameworks, audit/regulatory exams, and third-party cyber risk programs. 
  • Experience interacting directly with senior executives, Boards, regulators, auditors, and risk committees. 
  • Demonstrated understanding of cybersecurity beyond GRC, including security operations, identity, application security, cloud security, incident response, security engineering, architecture, and emerging technology risk. 
  • Demonstrated ability to translate cybersecurity and technology risks into business terms and actionable executive decisions. 
  • Possesses at least one of the following professional credentials (or other industry-related credential): CISSP, CRISC, CISM, CISA

  

The successful candidate will demonstrate: 

  • Executive presence and sound judgment 
  • Strategic and enterprise-level thinking 
  • Strong knowledge of cybersecurity and technology risk 
  • Regulatory fluency 
  • Transformation and change leadership 
  • Ability to influence across organizational boundaries 
  • Exceptional executive communication 
  • Strong people leadership and organizational development skills 
  • Ability to balance appropriate risk governance with business enablement 
  • Willingness and ability to challenge constructively while maintaining trusted relationships 

What Success Looks Like.  Within the first 12–18 months, this executive will: 

  • Complete a comprehensive assessment of Cyber GRC capabilities and maturity. 
  • Establish and begin executing a multi-year GRC transformation roadmap. 
  • Improve enterprise visibility into cybersecurity and technology risk. 
  • Strengthen executive and Board-level cybersecurity risk reporting. 
  • Improve regulatory and audit readiness and reduce recurring control issues. 
  • Mature policy governance, exception management, risk acceptance, and issue-management processes. 
  • Strengthen first-line accountability for cybersecurity risk. 
  • Improve integration among Cyber GRC and other cybersecurity functions. 
  • Become a trusted advisor and strategic partner to the CISO. 
  • Effectively represent the CISO with executives, regulators, and governance bodies when required. 
  • Demonstrate the leadership breadth necessary to provide continuity for the CISO function and assume broader cybersecurity responsibilities when delegated. 

Work Shift - HYBRID


Benefits

You will also have access to short-term incentives, multiple health insurance options, accident and life insurance, and access to best-in-class development platforms, to name a few. Please see the benefits below specific to your country. If applicable, additional role-specific benefits will be mentioned during your interview process or in an offer of employment.

Your United States specific benefits include:

  • Parental Leave
  • Family First Programs
  • Medical, Dental, and Life Insurance
  • Tuition Repayment Assistance Program

For residents of Colorado, California, Connecticut, Delaware, Minnesota, and Pennsylvania: Please do not respond to any questions on this initial application that may seek age-identifying information such as age, date of birth, or dates of school attendance or graduation. You may also redact this information from any materials you submit during the application process. You will not be penalized for redacting or removing this information.


Other Details

As part of the application process, all applicants are required to take assessments. Western Union has partnered with a 3rd party provider to administer these tests. Applicants will need to provide their name and email address in order to process the assessments. If you have any questions, you may reach out to careers@westernunion.com.


We are passionate about honoring our employee's identity and fostering a feeling of belonging. Our commitment is to provide an inclusive culture that celebrates the unique backgrounds and perspectives of our global teams while reflecting the communities we serve. We do not discriminate based on race, color, national origin, religion, political affiliation, sex (including pregnancy), sexual orientation, gender identity, age, disability, marital status, or veteran status. The company will provide accommodation to applicants, including those with disabilities, during the recruitment process, following applicable laws.

#LI-AM3

Estimated Job Posting End Date:

10-19-2026

This application window is a good-faith estimate of the time that this posting will remain open. This posting will be promptly updated if the deadline is extended or the role is filled.

Job ID wd-westernunion-wd5-westernunionjobs-vice-president--cyber-governance--risk---compliance-and-deputy-ciso_jr0132259 · Original posting ↗

Visa sponsorship history

  • 48 H-1B petitions approved for WESTERN UNION LLC in fiscal year 2023 (USCIS).

From public government data. It shows this employer has sponsored workers before, not that this job offers sponsorship: check the job ad or ask the employer. More visa-friendly jobs