Ripple

Senior Director of Governance, Risk and Compliance

9.0/10

Ripple

$300,000 – $360,000 USD
Office / on-site
lead
1 day ago
cryptofintechweb3GovernanceRisk ManagementComplianceInformation SecurityAIAutomationBlockchainVendor SecurityThird-Party Risk Management

AI Summary

The vacancy is well-structured, providing clear expectations and compensation details, making it attractive for qualified applicants.

Check Match — Just drop your CV

See your fit for Senior Director of Governance, Risk and Compliance in seconds.

Description

Responsibilities

  • Define and lead Ripple's Governance, Risk & Compliance strategy.
  • Build a unified, engineering-first GRC function.
  • Set the strategic vision and multi-year roadmap for GRC.
  • Pioneer the use of AI and automation across the GRC function.
  • Lead, mentor, and grow a team of GRC Program Managers and Engineers.
  • Design and operate an integrated GRC program spanning ERM, Compliance, BCDR, and Internal Audit.
  • Own and advance Ripple's regulatory compliance posture across global jurisdictions.
  • Drive and maintain SOC 2 Type II and ISO 27001 certifications.
  • Build and operate a proactive risk management program.
  • Lead the Third-Party Risk Management program.
  • Own the Customer Security Assurance Program.
  • Drive a security-first culture through awareness and training programs.
  • Communicate risk posture, program maturity, and compliance status to the CISO, Board, and external regulators.

What We Offer

  • Competitive salary between $300,000 and $360,000 USD.
  • Opportunity to lead a high-impact GRC function in a growing company.
  • Work in a dynamic and innovative environment focused on improving the global financial system.

Requirements

Qualifications

  • 15+ years of experience in information security GRC.
  • 5+ years in a senior leadership role, preferably in crypto, blockchain, or FinTech.
  • Demonstrated success building and scaling GRC programs from the ground up.
  • Deep expertise in global regulatory frameworks (NYDFS, MAS, DFSA, DORA, GDPR, SOC 2, ISO 27001, NIST CSF, SOX/ITGC).
  • Proven experience leading cross-functional GRC programs with a data-driven mindset.
  • Strong track record of building automated, self-service evidence collection and audit readiness programs.
  • Experience operating a Third-Party Risk Management program at scale.
  • Hands-on knowledge of vendor security assessments and supply chain risk.
  • Executive-level communication skills.
  • Experience with crypto, digital asset, or stablecoin compliance is a strong plus.
  • Demonstrated ability to lead and develop geographically distributed teams.
Loading similar jobs...