Lead, Security GRC

Posted Feb 5

Empower the Individual Through Crypto

Gemini is a global crypto and Web3 platform founded by Cameron and Tyler Winklevoss in 2014. Gemini offers a wide range of crypto products and services for individuals and institutions in over 70 countries.

Crypto is about giving you greater choice, independence, and opportunity. We are here to help you on your journey. We build crypto products that are simple, elegant, and secure. Whether you are an individual or an institution, we want to help you buy, sell, and store your bitcoin and cryptocurrency. Crypto is not just a technology, it's a movement.

At Gemini, our mission is to empower the individual and that includes giving our employees flexibility of choice — our Office Optional Policy allows employees to choose to work from one of our physical locations or from home.

The Department: Security Governance, Risk & Compliance

The Role: Lead, Security GRC (Global Compliance & Client Engagement)

Gemini has an exciting opportunity for a Security GRC Lead. The company seeks to identify a highly proactive and technical individual with proven talent in security process development, policy creation, security standard navigation, risk and control framework mapping capabilities, and strategic evidence collection/curation insight. The successful candidate will work alongside the rest of the GRC team to ensure policies, procedures, and guidelines align with regulatory requirements and security frameworks; assess internal and external risks; and ensure compliance with security regulations. This individual will work with other internal teams to align security goals and objectives with business stakeholders. This position is full-time and will report to the Associate Director of Security GRC.

Responsibilities:

  • Support Gemini’s response to Regulators, Auditors, Client inquiries, and Due Diligence Questionnaires.
  • Lead Gemini’s efforts to maintain SOC 2 Type 2, ISO27001, PCI DSS, and other security certifications. 
  • Lead Gemini security compliance to NYSDFS Reg. 500, CBI, UK FCA and other regulators. 
  • Automate the responses to questions from external parties related to Gemini security governance.
  • Develop tooling to track the organization’s cybersecurity risk and compliance status.
  • Lead Gemini’s compliance automation efforts focused on maintaining and validating controls and associated evidence.
  • Research, implementation, and maintenance of compliance related tools: evidence collection automation and control monitoring
  • Collaborate with multiple stakeholders including HR, Legal, Operations, Engineering for maintaining GRC programs. 
  • Translate the regulatory requirements into implementable and software driven controls.
  • Orchestrate the enterprise wide business continuity planning and testing with technology teams. 
  • Develop and implement strategies to audit internal security/cybersecurity controls. 
  • Advise Gemini’s security team and leadership on additional security governance measures.
  • Understand, automate, and regulate internal identity, access, permissions, and entitlements, as it relates to full-time employees as well as contingent workers / contractors / consultants. 
  • Serve as a primary point of contact for security issues that require prompt remediation.

Minimum Qualifications:

  • BA/BS degree or equivalent practical experience.
  • 5 years of experience in the cyber security field developing and/or updating cyber security related documentation, policies, procedures and standards.
  • Strong analytical and creative problem solving skills.
  • Strong interpersonal skills to interact with customers, senior level personnel, auditors, and team members.
  • Strong organization skills to prioritize work and balance complex projects.
  • Ability to work independently and as part of a broader team.

Preferred Qualifications:

  • Former/Current ISO lead auditor certification.
  • Former/Current PCI Qualified Security Assessor (QSA).
  • Experience with automation of GRC initiatives and priorities.
  • Understanding of endpoint security, networking, and application-layer gateway technologies.
  • Operational knowledge of systems, databases, and network security best practices.
  • Experience with IDS, DLP, and SIEM tooling.
  • Experience with cloud-native environments.

It Pays to Work Here

The compensation & benefits package for this role includes:

  • Competitive starting salary
  • A discretionary annual bonus
  • Long-term incentive in the form of a new hire equity grant
  • Comprehensive health plans
  • 401K with company matching
  • Annual Learning & Development stipend
  • Paid Parental Leave
  • Flexible time off

Salary Range: The base salary range for this role is between $122,000 - $170,000 in the State of New York, the State of California and the State of Washington. This range is not inclusive of our discretionary bonus or equity package. When determining a candidate’s compensation, we consider a number of factors including skillset, experience, job scope, and current market data.

At Gemini, we strive to build diverse teams that reflect the people we want to empower through our products, and we are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity, or Veteran status. Equal Opportunity is the Law, and Gemini is proud to be an equal opportunity workplace. If you have a specific need that requires accommodation, please let a member of the People Team know.

#LI-REMOTE

#LI-AH1