6 дней назад
Director, Compliance
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Director, Compliance (GRC and IT Controls): Building and operating Riot’s unified controls framework, testing program, remediation lifecycle, and GRC platform with an accent on ISO 27001, SOC 2, NIST CSF, and SOX ITGC alignment. Focus on administering the GRC platform, automating evidence collection, integrating AWS/Azure and operational systems, and ensuring audit-ready controls across IT, mining sites, and data centers.
Location: Remote - US
Company
builds digital infrastructure and focuses on powering and developing infrastructure for digital networks and communities.
What you will do
- Design and maintain a unified controls framework mapped to ISO 27001 Annex A, SOC 2 Trust Services Criteria, NIST CSF, and SOX ITGC.
- Own the ISO 27001:2022 controls implementation and evidence track.
- Execute control testing for design adequacy and operating effectiveness and maintain a continuous testing calendar.
- Select, implement, configure, integrate, and administer the GRC platform as the system of record for controls, risks, and evidence.
- Manage control issues, audit findings, remediation ownership, progress tracking, escalation, and closure validation.
- Automate evidence collection and monitoring while working with IT, Security Engineering, mining sites, and data center teams.
Requirements
- 8–12+ years of progressive GRC, IT audit, controls design, or compliance program experience.
- Hands-on GRC platform administration experience, including control library configuration, evidence mapping, workflows, and integrations.
- ISO 27001 Lead Implementer or Lead Auditor certification required.
- Experience designing multi-standard controls frameworks and executing audit-quality control testing.
- Experience managing POA&M issues and remediation lifecycles across cross-functional owners.
- Technical fluency with AWS and Azure security configurations, API-based integrations, and automated evidence pipelines; Python or SQL scripting is useful.
Nice to have
- CISA certification.
- Experience in critical infrastructure, data centers, or digital asset environments.
- Experience preparing SOC 2 evidence and facilitating auditor walkthroughs.
- AI-assisted automation experience.
Culture & Benefits
- Fast-paced environment focused on technical excellence, efficiency, and execution.
- Competitive base salary with a bonus and sign-on equity grant.
- Eligibility for equity incentive programs.
- 401(k) plan with a company match.
- Medical plan options, including 100% company-paid plans, plus gym memberships, pet insurance, and childcare discounts.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
6 дней назад
Sr. Staff Risk Management Analyst (Cybersecurity)
1 день назад
Principal Analyst, IT Compliance (Cybersecurity)
Sardine
7 дней назад
Security Compliance Lead (Fintech)
130 000 - 190 000$
2 дня назад
Senior Advisor, Cybersecurity
140 000 - 160 000$
5 дней назад
Client Assurance & TPRM Manager - Assistant Vice President (Cybersecurity Risk)
100 000 - 140 000$
6 дней назад
Governance, Risk & Compliance (GRC) Analyst (Defense)
120 000 - 150 000$