Principal, Third Party Security Risk Management
KrakenAbout the role
Building the Future of Crypto
Our Krakenites are a world-class team with crypto conviction, united by our desire to discover and unlock the potential of crypto and blockchain technology.
What makes us different?
Kraken is a mission-focused company rooted in crypto values. As a Krakenite, you’ll join us on our mission to accelerate the global adoption of crypto, so that everyone can achieve financial freedom and inclusion. For over a decade, Kraken’s focus on our mission and crypto ethos has attracted many of the most talented crypto experts in the world.
Before you apply, please read the Kraken Culture page to learn more about our internal culture, values, and mission.
As a fully remote company, we have Krakenites in 60+ countries who speak over 50 languages. Krakenites are industry pioneers who develop premium crypto products for experienced traders, institutions, and newcomers to the space. Kraken is committed to industry-leading security, crypto education, and world-class client support through our products like Kraken Pro, Kraken NFT, and Kraken Futures.
Become a Krakenite and build the future of crypto!
Proof of Work
The Team
We are seeking a highly skilled and motivated security risk management professional to join our dynamic team. This role involves playing a key part in the evaluation, integration, and management of security and IT aspects during vendor engagements as well as merger and acquisition activities. The ideal candidate will have a strong background in information security and IT, along with experience in dealing with M&A processes.
The Opportunity
Due Diligence: Conduct thorough due diligence on the IT and security aspects of potential acquisitions, partnerships, and vendor engagements. Evaluate the cybersecurity posture, IT infrastructure, and technology stack of target companies
Risk Assessment: Identify and assess security risks and IT challenges associated with potential third party engagements. Provide recommendations to mitigate these risks
Integration Planning & Execution: Drive strategies for the integration of IT systems and security protocols for vendor engagements and acquisitions. Ensure seamless integration by coordinating cross-functional efforts while maintaining security standards
Controls Analysis: Evaluate performance to relevant IT & security regulations and standards in the context of third party engagements and acquisitions. Ensure that both the acquiring and acquired entities adhere to legal and regulatory requirements. This includes but is not limited to thorough review of audit reports for security-related deficiencies, required "user controls" and suggest remediation controls
Stakeholder Collaboration: Work closely with internal teams, external advisors, and contract counterparties including corporate development, engineering, legal, finance, and operations teams to ensure a holistic approach to third party management
Project Management: Manage projects related to IT and security aspects of M&A, ensuring timely and effective completion of tasks
Reporting: Prepare and present reports on IT and security findings and integration progress to senior management and relevant stakeholders
Post-Merger Integration Support: Provide ongoing support and guidance for the integration of IT and security systems post-merger or acquisition. Ensure internal teams do not lose sight of outstanding findings from earlier stages
Market Analysis: Stay abreast of market trends in cybersecurity, IT, and M&A to inform strategies and practices
Training and Development: Participate in relevant training and professional development opportunities to stay updated in th
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s