Senior GRC Program Manager, Ripple Treasury
THE WORK:
As a Senior GRC Program Manager, you will support the customer security assurance program, helping Ripple Treasury customers and prospects understand and gain confidence in our security program. This role sits at the intersection of security, sales, and compliance, backing up the RFP team on security questionnaires, meeting directly with prospective customers, maintaining our security-related sales documentation, and supporting the management of customer focused DORA audits.
This is a strong fit for a GRC-minded security professional who translates technical controls into clear, customer-ready answers, owns documentation with rigor, and can handle multiple deadlines across concurrent customer engagements.
WHAT YOU’LL DO:
RFP & Security Questionnaire Support: Serve as backup to the RFP team, completing and reviewing security questionnaires (e.g., SIG, CAIQ, and custom customer questionnaires) accurately and on deadline, and maintaining a repository of reusable, approved responses.
Customer Engagement: Meet with prospective and existing customers to walk through the Ripple security program, respond to security and due diligence questions, and support security-related aspects of deals and renewals.
Security Sales Documentation: Create and maintain security-related sales collateral, security overviews, trust center content, certification and attestation summaries, control mappings, and architecture/data-flow references, ensuring materials stay current and accurately reflect the security program.
DORA Audit Support: Assist in managing customer-initiated DORA (Digital Operational Resilience Act) audits, including coordinating audit logistics, gathering and organizing evidence, and serving as a liaison between customers and internal control owners.
Evidence & Control Coordination: Partner with control owners across Information Security, Engineering, and IT to validate questionnaire responses and gather supporting evidence when needed.
Cross-Functional Collaboration: Work closely with Information Security, Legal, Sales, and Customer Success to ensure consistent, accurate, and contractually aligned representation of Ripple Treasury's security and compliance posture.
Continuous Improvement: Identify recurring customer questions and contribute to standardized responses, FAQs, and enablement materials to reduce manual effort and improve turnaround time.
Risk Judgment: Recognize customer requests that may introduce security, compliance, or contractual risk, and escalate appropriately.
WHAT YOU'LL BRING:
5+ years in GRC, customer security assurance, or a related security function, with hands-on experience responding to customer security questionnaires and due diligence requests.
Solid grounding in information security frameworks including SOC 2, ISO 27001, NIST, and SWIFT, with proven understanding of core security domains such as access control, encryption, vulnerability management, and vendor risk.
Familiarity with regulatory frameworks affecting financial services customers; direct exposure to DORA is a strong plus.
Strong written and verbal communication skills, with the ability to translate technical security concepts into clear, business-friendly language for non-technical audiences.
Comfort managing multiple concurrent customer engagements and deadlines with strong organizational discipline.
Experience with trust center or security assurance platforms (such as SafeBase,Vanta), questionnaire automation tooling, and GRC platforms (such as Drata or LogiGate).
Background working directly with financial services or FinTech customers, with familiarity with data protection and privacy frameworks including GDPR, CCPA, and DORA.
Relevant certifications such as CISA, CISM, CISSP, or Security+ are preferred.