Senior Manager, InfoSec GRC
Please note this is for New York, NY, United States. You only need to apply to one location if there are multiple listed for the job.
At Ripple, we’re building a world where value moves like information does today. It’s big, it’s bold, and we’re already doing it. Through our crypto solutions for financial institutions, businesses, governments and developers, we are improving the global financial system and creating greater economic fairness and opportunity for more people, in more places around the world. And we get to do the best work of our career and grow our skills surrounded by colleagues who have our backs.
If you’re ready to see your impact and unlock incredible career growth opportunities, join us, and build real world value.
WHAT YOU’LL DO:
- Regulatory Engagement and Leadership: You will be a key point of contact for all information security matters related to the bank license application. You'll represent the InfoSec GRC team by actively engaging with and providing mentorship to regulators like the OCC and NYDFS.
- Technical GRC and Risk Management: You will lead risk assessment processes and identify, assess, and prioritize information security risks across the organization. You'll have hands-on experience pulling technical evidence, such as logs, configuration screenshots, and audit reports, to validate the efficiency of our security controls.
- Compliance and Audits: You will maintain compliance with frameworks like FFIEC, SOX, NYDFS, MAS, DORA, and SOC 2. You will represent technical control operations during internal and external audits, including MAS financial audits and SOX/SOC1 audits, demonstrating a strong solid understanding of our infrastructure, applications, and security processes.
- Program Leadership: You will lead end-to-end GRC projects, establishing clear metrics and achievements. You will also develop and maintain dashboards to provide insight into compliance status, risk posture, and program efficiency.
- Crypto-Specific Expertise: You will provide technical mentorship on compliance related to stablecoin reserves and financial reporting, including preparing for the required attestation reports to meet regulatory requirements from agencies like the NYDFS.
WHAT YOU'LL BRING:
- A Bachelor's Degree in a relevant field or equivalent professional experience.
- 10+ years of experience in information security risk management and compliance within a highly regulated industry, with a strong background in the financial services or banking sector.
- A solid foundation in a hands-on technical information security role, with experience in areas like security operations or security architecture.
- Proven experience with U.S. regulatory frameworks like FFIEC and NYDFS, and a track record of directly working with financial regulators.
- Proficiency with common information security frameworks, including SOX, SOC1, ISO 27001, SOC 2, MAS, and DORA.
- Direct experience with charter banking or in a similar leadership role at a regulated financial institution or a digital asset company.
- Experience with crypto or blockchain technology, particularly in a highly regulated environment, including familiarity with stablecoin reserves and financial reporting requirements.
- Hands-on experience assessing and managing security risks in public cloud environments (preferably AWS) and a strong understanding of their security implications.
- Proven ability to create clear, audience-tailored technical documentation.
- Relevant certifications such as CISSP, CISA, or AWS Certified Security are highly desirable.
WHO WE ARE:
Do Your Best Work
- The opportunity to build in a fast-paced start-up environment with experienced industry leaders
- A learning environment where you can dive deep into the latest technologies and make an impact. A professional development budget to support other modes of learning.
- Thrive in an environment where no matter what race, ethnicity, gender, origin, or culture they identify with, every employee is a respected, valued, and empowered part of the team.
- In-office collaboration for moments that matter is important to our culture, and we give managers and teams the flexibility to decide which 10+ days a month they come in.
- Bi-weekly all-company meeting - business updates and ask me anything style discussion with our Leadership Team
- We come together for moments that matter which include team offsites, team bonding activities, happy hours and more!
Take Control of Your Finances
- Competitive salary, bonuses, and equity
- Competitive benefits that cover physical and mental healthcare, retirement, family forming, and family support
- Employee giving match
- Mobile phone stipend
Take Care of Yourself
- R&R days so you can rest and recharge
- Generous wellness reimbursement and weekly onsite & virtual programming
- Generous vacation policy - work with your manager to take time off when you need it
- Industry-leading parental leave policies. Family planning benefits.
- Catered lunches, fully-stocked kitchens with premium snacks/beverages, and plenty of fun events
Benefits listed above are for full-time employees.
Req ID: 25433