Risk & Controls Manager
Core
Runs the internal posture engine including the risk register, critical control monitoring, evidence management, and audit operations to keep risk state current for the Risk Committee.
Role type
Senior GRC Manager (Risk & Controls)
Builds
A defensible posture engine with automated evidence collection and audit readiness for a global self-custodial financial platform.
Domain
Cybersecurity / GRC / Web3 / Financial Infrastructure
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Risk register management, Control library maintenance, Audit cycle execution (ISO 27001/SOC 2), GRC platform proficiency, Stakeholder coordination, Technical writing
Preferred skills
CISA certification, ISO 27001 Lead Implementer/Auditor certification, Experience with Drata or equivalent GRC tools
Technologies
Drata, ISO 27001, SOC 2
Responsibilities
Operate the risk register from the Security Programme threat model; Run critical control monitoring and drift detection; Lead audit coordination and preparation (ISO 27001, SOC 2); Track residual risk and gap closure; Maintain the evidence file for internal and external audits.
Seniority
Senior, hands-on IC
