Risk & Controls Manager

Consensys · UNITED STATES - Remote, LATAM - Remote, EMEA - Remote · Operations

Posted 2026-09-24

Apply for this role →

About the role

This role runs the internal posture engine — the risk register, critical control monitoring, evidence, audit operations and GRC tooling. It keeps risk state current so the Lead and the Risk Committee decide from accurate data in the Risk Dashboard and reporting. Drata is the register of record. Named owners close gaps; this role keeps the register, evidence and audit operations current.

Responsibilities

Planning

Operate the risk register from the Security Programme threat model: populate, track treatment, record acceptance decisions, follow up owners, and run the exceptions register.

Keep the ISMS and security policy library current as part of audit readiness. Draft security standards when commissioned by the Lead.

Run Drata as the control and evidence system — Statement of Applicability, framework crosswalk and automation.

Execution

Run critical control monitoring: health check-ins, drift flags and Drata automation. Route drift to the SOC. Maintain the evidence file for Lead assessments and independent internal audit.

Feed threat-assessment findings into the register and confidence ratings. Track which required assessments are current.

Lead audit coordination and preparation: ISO 27001 and SOC 2 logistics, ISMS readiness, team prep, management-review pack, and customer due-diligence questionnaires.

Coordinate the control register for external testing (red team, tabletop, pentest). Run security awareness and weekly alerts.

Tracking and evaluating performance

Track residual risk, exceptions and gap-closure against appetite. Exceptions expire and are reported; the underlying requirement stays in force.

Report register state and evidence health so the Lead and Risk Committee work from one view.

Achieving overall defined performance

Be accountable for a current, defensible posture engine — register, evidence and audit operations.

Ensure Drata collects evidence continuously, with automated evidence where coverage exists.

Qualifications

Hands-on experience running a risk register, control library and audit cycle (ISO 27001 and/or SOC 2).

Comfortable with GRC platforms (Drata or equivalent) and turning monitoring into evidence.

Proven ability to coordinate audits and customer questionnaires with named control owners.

Precise written work; register and Statement of Applicability quality matters.

Strong stakeholder management with control owners and auditors.

CISA, ISO 27001 Lead Implementer or Auditor, or equivalent professional certification.

Don't meet all the requirements? Don't sweat it. We’re passionate about building a diverse team of humans and as such, if you think you've got what it takes for our chaotic-but-fun, remote-friendly, start-up environment—apply anyway, detailing your relevant transferable skills in your cover letter. While we have a pretty good idea of what we need, we're ready for you to challenge our thinking on who needs to be in this role.

The salary range listed for this role applies to US-based candidates only. Compensation for candidates based outside the US (including Canada, EMEA, and LATAM) will be determined based on location, experience, and skills during the interview process, and may differ from the listed US range.

US pay range (not including bonus, equity or other benefits)

$150,000—$206,000 USD

Apply for this role →

← Back to all jobs