Jobs and Careers
RI
Sr. Manager Governance, Risk, and Compliance
RippleIrelandfull_timeVerifiedPosted 17 Aug 2023
About the role
<p>At Ripple, we’re building a world where value moves like information does today. It’s big, it’s bold, and we’re already doing it. Through our crypto solutions for financial institutions, businesses, governments and developers, we are improving the global financial system and creating greater economic fairness and opportunity for more people, in more places around the world. And we get to do the best work of our career and grow our skills surrounded by colleagues who have our backs. </p>
<p>If you’re ready to see your impact and unlock incredible career growth opportunities, join us, and build real world value.</p>
<p><strong>THE WORK:</strong></p>
<p><strong>Through our blockchain technology and rapidly growing network of financial institutions, Ripple is improving the global financial system and increasing economic inclusion for more people, in more places around the world. Ripple is looking for passionate Information Security professionals to build a world class Information Security program. As part of the Information Security team, you will help us achieve this mission by actively working to protect our staff, company, and the larger crypto communities we engage with. </strong></p>
<p><strong>WHAT YOU’LL DO:</strong></p>
<ul>
<li>Act as primary point of contact for EU/UK regulators</li>
<li>Attend industry events and participate in industry discussions about regulation and frameworks</li>
<li>Contribute to periodic assessments of Ripple’s IT and Information security risks</li>
<li>Support and maintain security controls mapped to EU and UK information security and privacy compliance requirements in Ripple Unified Control Framework </li>
<li>Lead all aspects of outsourced IT services provided by related entities within the Ripple Group</li>
<li>Provide periodic updates to Ripple’s Irish and UK Board of Directors on the InfoSec program</li>
<li>Participate in Information Security and privacy-related audits and examinations conducted by external parties within the EU/UK region</li>
<li>Assist InfoSec Governance function to develop and maintain InfoSec Policies, Standards and Procedures relevant to InfoSec and privacy compliance </li>
<li>Work with the Governance team to prepare metrics and reports for UK/EU management and regulators on the status of InfoSec objectives</li>
<li>Support the GRC team in evaluating and responding to EU/UK customer/prospect questions and audits </li>
<li>Remain up to date on current security laws, regulations and standards</li>
<li>Assist the Sr InfoSec Risk Manager to develop effective remediation plans for control deficiencies relevant to regulations and compliance requirements; Perform control testing, document and communicate results in work papers and written reports for the successful certification on an ongoing basis</li>
<li>Perform security awareness training for employees</li>
<li>Support all GRC recurring tasks and control related activities within the UK/EU region</li>
<li>Work collaboratively with Finance, Compliance, Privacy and Legal teams to identify and manage data compliance requirements unique to the EU & UK markets. Make recommendations on improving compliance related processes and/or procedures</li>
<li>Support regional Security Assurance customer activities, such as assisting in drafting of region-specific security messaging, security due diligence responses, customer security contractual language, etc.</li>
</ul>
<p><strong>WHAT YOU'LL BRING: </strong></p>
<ul>
<li>Degree or equivalent in Computer Science or related field</li>
<li>10 years of experience in InfoSec with a specialization in one area of GRC </li>
<li>A broad understanding of security domains</li>
<li>Experience working with regulators and auditors</li>
<li>Experience with electronic money or payments regulatory standards and audits and ITGC Control audits</li>
<li>Previous approval from the Central Bank of Ireland as a PCF-49</li>
<li>Proficiency with common information security frameworks including PSD2, ISO 27001, GDPR, MiCA, SOC2, and NIST CSF</li>
<li>Demonstrated ability to collaborate across teams </li>
<li>Proven organizational, project management and documentation skills </li>
<li>Familiarity and experience with IT/Security/GRC toolset, such as : Jira, Confluence, and other GRC platforms etc.</li>
<li>Ability to analyze empirical evidence and technical reports, identify root causes, work with teams to determine solutions to remediate gaps. </li>
<li>Familiarly with different cloud concepts and tooling including AWS, GCP </li>
<li>Someone willing to adapt to change in a fast paced environment</li>
<li>Experience with cloud-native pre-IPO startup companies</li>
<li>Experience with AWS security services and tooling</li>
<li>Desirable certifications: CISSP, CISA, PMP</li>
</ul>
<p><strong>WHO WE ARE:</strong></p>
<p>Do Your Best Work</p>
<ul>
<li>The opportunity to build in a fast-paced start-up environment with experienced industry leaders</li>
<li>A learning environment where
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s