368,657open jobs
9,442companies
50,883added this week
Browse all
Salary
$165k – $326k per year (Estimated)
Location
Remote (United States)
Seniority
Architect · 8+ years exp
Overview
Company
Impact
Profile match
Mercury is the fintech ambitious companies use for banking and all their financial workflows. With a powerful bank account at the center of their operations, companies can make better financial decisions and ensure that every dollar spent aligns with company priorities. That's why over 200K startups choose Mercury to confidently run all their financial operations with the precision, control, and focus they need to operate at their best.

The role:

You will be the operating second to the CISO and own the bank-entity scope of Mercury's 2LOD Information Security program. You'll be the person who keeps the program examiner-ready by default: coherent policy architecture, evidenced controls, a credible gap-remediation track record, and a tested incident response program with documented exercise history.

This is not a research or strategy role. It is a build-and-defend role. You will sit across the table from OCC examiners, FFIEC IT audit teams, our Chief Risk Officer, and the board's risk committee, and you will be expected to answer for every line in our policies and every status in our control inventory.

*Mercury is a fintech company, not an FDIC-insured bank. Banking services provided through Choice Financial Group and Column N.A., Members FDIC

What you'll own:

  • Bank-entity 2LOD InfoSec program. Governance, policy, risk, and oversight scoped to the chartered bank.
  • Examiner posture. OCC, FFIEC, FDIC and FRB examiner inquiries; ownership of the examiner-ready narrative; coordination of the evidence.
  • FFIEC control remediation. Lead remediation of identified FFIEC IT control deficiencies to charter readiness ahead of the OCC pre-opening examination
  • Policy architecture. Carry the bank-scoped policy stack (Policy / Standard / Procedure), including ratification cycles, MRCC memos, and board approvals.
  • BC/DR. Partner with the Chief Risk Officer on bank continuity, resilience, and recovery, including tabletop exercises and full-scale drills.
  • Audit and assurance. Manage relationships with internal audit (3LOD) and external assessors (SOC 2, FFIEC CAT, regulator-led IT examinations).
  • Third-party risk. Ensure TPRM evidence holds up to bank-grade scrutiny for critical service providers and material outsourcing arrangements.
  • Team development. Coach and grow the GRC sub-team; run a recurring training cadence; build the bench depth a national bank requires.

What we need:

  • 8+ years in Information Security, with 3+ years inside a regulated bank, trust bank, or de novo bank charter effort. Mercury is a startup chartering a national bank - this experience is non-negotiable.
  • Deep FFIEC and OCC fluency. You have deep working knowledge of the FFIEC CAT, the FFIEC IT Examination Handbook, BSA/AML IT supervisory expectations, and the OCC Heightened Standards.
  • Direct examiner-facing experience. You have defended a control to an OCC, FDIC, or Federal Reserve examiner. You know what good evidence looks like before it gets challenged.
  • Policy and standards craft. You can draft a board-ratifiable policy and the supporting standards stack that operationalizes intent, not just satisfies a checklist.
  • Operating discipline. You run cadences, write status that survives executive review, and maintain currency of controls, evidence, and risk registers.
  • 2LOD instinct. You understand the three-lines-of-defense model and have served in the oversight role.

What we'd love:

  • Prior Deputy CISO or equivalent senior 2LOD role at a national bank, trust bank, or large credit union.
  • Charter or de novo bank experience - if you've stood one up before, that is a meaningful advantage here.
  • Strong technical baseline,  you don't need to be an engineer, but you should be able to challenge an architecture review and read an incident timeline credibly.
  • CISSP, CISM, or CRISC

What success looks like:

  • At 30 days - You have developed working knowledge of Mercury’s FFIEC IT control inventory and roadmap, every in-flight policy draft, and met one-on-one with the GRC team. You can speak to the top ten risks in the bank-entity program by name.
  • At 90 days - You are running the weekly bank charter status cadence, leading examiner-readiness reviews, and personally accountable for at least three priority program tracks. The CISO is briefing the board and the MRCC with material you authored. 
  • At one year - The charter timeline is on track. The bank-entity Information Security program sustains supervisory-grade standards as a standing posture. You are the executive other functions consult to determine whether a security risk is material. 

Why this role:

We are building a security program designed to protect Mercury and enable the business. Chartering a national bank does not change that philosophy. It does mean we need a Deputy who can hold the bar to OCC standards without losing the operating tempo that has defined Mercury since inception.

If you've been waiting for a chance to build the bank-side security program you wish you'd inherited, this is it.

Mercury values diversity & belonging and is proud to be an Equal Employment Opportunity employer. All individuals seeking employment at Mercury are considered without regard to race, color, religion, national origin, age, sex, marital status, ancestry, physical or mental disability, veteran status, gender identity, sexual orientation, or any other legally protected characteristic. We are committed to providing reasonable accommodations throughout the recruitment process for applicants with disabilities or special needs. If you need assistance, or an accommodation, please let your recruiter know once you are contacted about a role.

Total Rewards

The total rewards package at Mercury includes base salary, equity (stock options/RSUs), and benefits.

Our salary and equity ranges are highly competitive within the SaaS and fintech industry and are updated regularly using the most reliable compensation survey data for our industry. New hire offers are made based on a candidate’s experience, expertise, geographic location, and internal pay equity relative to peers.

Our target new hire base salary ranges for this role are the following :

US employees in New York City, Los Angeles, Seattle, or the San Francisco Bay Area:

$269,700—$353,950 USD

US employees outside of New York City, Los Angeles, Seattle, or the San Francisco Bay Area:

$242,700—$318,550 USD

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,657 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
San Francisco
$42k – $49k per year (net) • In office • Full-Time • Bachelor's Degree • Moscow
Go
Python
Rust
TypeScript
DevOps
CI/CD
AWS
Kubernetes
IAM
Cybersecurity
CVE
ISO 27001
PCI DSS
SOC 2
Threat Modeling
Web3
Smart Contracts
Apply
Head of DevSecOps 2 days ago
$43k – $108k per year (Estimated) • In office • 10+ years exp • Bengaluru
DevOps
GCP
IAM
Cybersecurity
HIPAA
SOC 2
Apply
$17k – $44k per year (Estimated) • In office • Full-Time • 3+ years exp • Moscow
PowerShell
Python
JavaScript
Cybersecurity
PCI DSS
SOC 2
Apply
$200k – $240k per year • Equity • Remote/Hybrid • Full-Time • 3+ years exp • PhD • Chicago
AI/ML
AI Agents
DevOps
AWS
CI/CD
CircleCI
Terraform
Cybersecurity
Snyk
SOC 2
Least Privilege
Apply
IT Support Engineer 3 days ago
$83k – $117k per year • Remote
DevOps
AWS
Datadog
Terraform
GitLab
Cybersecurity
HIPAA
Okta
SOC 2
Management
Google Workspace
Jira
Slack
Apply
$170k – $283k per year (Estimated) • Remote • 10+ years exp • San Francisco
Haskell
Apply
Senior IT Auditor 10 days ago
$120k – $223k per year (Estimated) • Remote • San Francisco
AI/ML
ChatGPT
Claude
DevOps
AWS
Cybersecurity
ISO 27001
Apply
$166k – $258k per year (Estimated) • Remote • 10+ years exp • San Francisco
Apply
$163k – $301k per year (Estimated) • Remote • 10+ years exp • San Francisco
Apply
$131k – $224k per year (Estimated) • Remote • Contractor • 8+ years exp • San Francisco
Apply
$170k – $220k per year • Equity 1–2.8% • In office • Full-Time • 3+ years exp • San Francisco
Python
SQL
Python
Django
AI/ML
AI Agents
Context Engineering
LLM
LLM Evaluation
RAG
Apply
$173k – $314k per year • In office • Full-Time • 12+ years exp • Bachelor's Degree • San Francisco
Apex
JavaScript
Node JS
Python
SQL
TypeScript
Apex
Lightning Web Components
AI/ML
Agentforce
AI Agents
Claude
Claude Code
Copilot
Cursor
LLM
RAG
DevOps
AWS
Azure
CI/CD
Docker
GCP
GitHub
Grafana
gRPC
Kubernetes
New Relic
Prometheus
Splunk
Marketing
Salesforce
QA
Cypress
JMeter
k6
Locust
Playwright
Postman
Rest-Assured
Selenium
Apply
Senior ML Engineer 1 hour ago
$149k – $224k per year • In office • Full-Time • 5+ years exp • Master's Degree • San Francisco • Washington • Palo Alto
Python
Python
pySpark
Databases
Apache Kafka
AI/ML
AI Agents
Agentforce
Airflow
Anomaly Detection
Feature Store
Flink
Ray
Red Teaming
Spark
DevOps
CI/CD
Docker
Kubernetes
Cybersecurity
MITRE ATT&CK
Marketing
Salesforce
Apply
In office • Internship • 1+ year exp • Bachelor's Degree • San Francisco
Go
JavaScript
Ruby
Scala
Apply
$360k – $530k per year • In office • Full-Time • Bachelor's Degree • San Francisco
MATLAB
Python
MATLAB
Simulink
AI/ML
OpenAI
Robotics
Digital Twin
Apply
See all jobs
This is one of many
368,657 more open roles from verified company boards, updated every day.