Director, GRC & Privacy Security

Polymarket
2 months
New York, Hybrid
Security Fintech Risk Management Privacy Senior Hybrid Full time Policy Development Financial Services Cryptocurrency Prediction Markets AWS Cloud ISO 27001 NIST CSF GDPR GRC FinCEN Director Prediction Market Vanta Drata Governance Risk and Compliance Privacy Security Information Security Compliance SOC 2 Type II PCI-DSS v4.0 CCPA CISM CRISC CISSP CIPP/E CIPP/US CIS Controls Compliance Programs Audit Management Third-Party Risk Management Data Privacy Program Security Control Framework External Auditor Management Money Transmitter Licensing Tugboat Logic ServiceNow GRC Executive Communication
Polymarket is the world's largest prediction market platform, enabling individuals to express views on real-world events by trading on outcomes across politics, economics, sports, culture, and current affairs. Built as a peer-to-peer marketplace with no centralized 'house,' Polymarket aggregates diverse opinions into transparent, market-based probabilities that reflect collective expectations about the future. The company is growing fast, with $21B traded in 2025, and aims to become a ubiquitous beacon of truth in global media. Polymarket is hiring a Director of GRC & Privacy to build and lead the governance, risk, and compliance function within its security organization. As a high-growth fintech operating across multiple jurisdictions with several subsidiary entities, the company carries compliance obligations spanning PCI-DSS, SOC 2 Type II, data privacy regulations, and financial services requirements. This role will establish the GRC program from scratch. This is a senior, high-visibility role reporting directly to the CISO, responsible for hiring and developing a team of three and serving as the primary interface between security, legal, finance, and external auditors and regulators. The position requires equal fluency in regulatory requirements, risk management frameworks, and executive communication. Responsibilities include: building and owning the enterprise security risk management program (risk register, risk appetite framework, risk scoring methodology, and regular reporting); establishing and maintaining the security control framework, mapping controls to applicable standards (SOC 2 TSCs, PCI-DSS, CIS Controls); driving security policy development and lifecycle management; leading the company's security committee and governance forums; owning the end-to-end compliance program for SOC 2 Type II and PCI-DSS, focusing on continuous audit readiness and automation; managing relationships with external auditors, certification bodies, and regulators; owning the third-party risk management program; overseeing the data privacy program in partnership with Legal to ensure compliance with GDPR, CCPA, and applicable regulations; embedding privacy-by-design in product development; and managing data subject rights obligations and privacy incident response.