Risk & Controls Manager
New
M
MetaMaskFinancial Technology
Remote-first, global teamFull-TimeManager
Salary150,000 - 206,000 USD per year
Apply NowOpens the employer's application page
Job Details
- Required Skills
- Stakeholder managementRisk Management
Requirements
- Hands-on experience running a risk register, control library, and audit cycle (ISO 27001 and/or SOC 2).
- Comfortable with GRC platforms such as Drata or equivalent tools.
- Proven ability to coordinate audits and customer questionnaires with internal control owners.
- Precise written communication skills for maintaining registers and Statements of Applicability.
- Strong stakeholder management abilities to work with control owners and auditors.
- Professional certification such as CISA, ISO 27001 Lead Implementer, or ISO 27001 Auditor.
Responsibilities
- Operate the risk register from the Security Programme threat model by tracking treatments and recording acceptance decisions.
- Maintain the ISMS and security policy library to ensure audit readiness.
- Run the Drata GRC platform for Statement of Applicability, framework crosswalks, and automation.
- Perform critical control monitoring and route drift incidents to the SOC.
- Coordinate audit preparation for ISO 27001 and SOC 2, including management-review packs and customer due-diligence questionnaires.
- Track residual risk, exceptions, and gap-closure against risk appetite.
- Report register state and evidence health to the Lead and Risk Committee.
View Full Description & ApplyYou'll be redirected to the employer's site