risk & controls manager в информационной безопасности
ориентир по рынку
вакансия
зп не указана
в среднем
190 804 ₽
мэтч
Загрузи резюме, чтобы видеть мэтчи с вакансией
подготовься к отклику
ai-инструменты
Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузи резюме
описание
MetaMask is a self-custodial financial platform with more than 100 million downloads, users in around 190 countries, and trillions in cumulative transaction volume. It is building an operating system for money that lets people hold, move, grow, and use what they own.
задачи
Operate the risk register based on the Security Programme threat model: populate it, track treatment, record acceptance decisions, follow up with owners, and run the exceptions register
Keep the ISMS and security policy library current for audit readiness; draft security standards when commissioned by the Lead
Run Drata as the control and evidence system, including the Statement of Applicability, framework crosswalk, and automation
Run critical control monitoring, including health check-ins, drift flags, and Drata automation; route drift to the SOC and maintain evidence for Lead assessments and independent internal audits
Feed threat-assessment findings into the register and confidence ratings; track which required assessments are current
Lead audit coordination and preparation for ISO 27001 and SOC 2, including logistics, ISMS readiness, team preparation, management-review packs, and customer due-diligence questionnaires
Coordinate the control register for external testing, including red team exercises, tabletop exercises, and pentests; run security awareness and weekly alerts
Track residual risk, exceptions, and gap closure against appetite; report expired exceptions while keeping underlying requirements in force
Report register state and evidence health so the Lead and Risk Committee can work from one view
Be accountable for a current, defensible posture engine covering the register, evidence, and audit operations
Ensure Drata collects evidence continuously, using automated evidence where coverage exists
требования
Hands-on experience running a risk register, control library and audit cycle (ISO 27001 and/or SOC 2)
Comfortable with GRC platforms (Drata or equivalent) and turning monitoring into evidence
Proven ability to coordinate audits and customer questionnaires with named control owners
Precise written work; register and Statement of Applicability quality matters
Strong stakeholder management with control owners and auditors
CISA, ISO 27001 Lead Implementer or Auditor, or equivalent professional certification
условия
Please note that we are unable to consider applications from candidates based in France, Italy, or Germany for this role
Compensation for candidates based outside the US, including Canada, EMEA, and LATAM, will be determined based on location, experience, and skills during the interview process, and may differ from the listed US range
US pay range (not including bonus, equity or other benefits): $150,000 — $206,000 USD