- Company Name
- Ripple
- Job Title
- Senior Manager, InfoSec GRC
- Job Description
-
Job Title: Senior Manager, InfoSec GRC
Role Summary
Lead the organization’s information security governance, risk, and compliance (GRC) function for banking license and regulatory engagements. Serve as primary advisor to regulators (OCC, NYDFS) and internal stakeholders, driving risk assessments, compliance audits, and crypto‑specific security controls across public cloud environments.
Expectations
- Manage all InfoSec GRC activities related to regulatory submissions, licensing, and audits.
- Mentor and coordinate with regulatory bodies, ensuring timely, accurate responses.
- Develop and maintain metrics, dashboards, and documentation that reflect risk posture and compliance status.
- Provide technical guidance on stablecoin reserves, financial reporting, and other crypto‑specific requirements.
Key Responsibilities
- Conduct enterprise‑wide risk assessments, identify and prioritize security risks, and validate controls through logs, screenshots, and audit reports.
- Maintain compliance with FFIEC, SOX, NYDFS, MAS, DORA, and SOC 2 frameworks, representing technical controls during internal and external audits.
- Lead end‑to‑end GRC initiatives, establishing clear objectives, deliverables, and performance metrics.
- Create and update dashboards, status reports, and technical documentation tailored to varied audiences.
- Mentor staff on technical compliance matters for stablecoin reserves and related financial reporting.
- Engage with regulators as a primary point of contact for InfoSec matters during bank license applications and ongoing compliance.
- Evaluate and manage security risks in public cloud (AWS) environments, understanding associated security implications.
Required Skills
- 10+ years of InfoSec risk management and compliance experience in heavily regulated industries (banking or financial services).
- Hands‑on technical background in security operations or architecture.
- Deep knowledge of U.S. regulatory frameworks (FFIEC, NYDFS) and experience working directly with financial regulators.
- Proficiency with SOX, SOC1, SOC2, ISO 27001, MAS, and DORA frameworks.
- Experience in charter banking, regulated financial institutions, or digital asset companies.
- Crypto and blockchain expertise, especially stablecoin reserves and financial reporting in regulated settings.
- Skill in developing clear, audience‑tailored technical documentation.
- Strong analytical, communication, and stakeholder‑management abilities.
Required Education & Certifications
- Bachelor’s degree in Information Security, Computer Science, Finance, or related field (or equivalent professional experience).
- Certifications such as CISSP, CISA, ISO 27001 Lead Implementer, and/or AWS Certified Security – Specialty or equivalent desirable.