Director, Risk Management @Riot Platforms, Inc.
Compliance
Salary competitive sal..
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Employment Type full-time
Posted 1mth ago

[Hiring] Director, Risk Management @Riot Platforms, Inc.

1mth ago - Riot Platforms, Inc. is hiring a remote Director, Risk Management. πŸ’Έ Salary: competitive salary with bonus and equity πŸ“Location: USA

Role Description

The Director, Risk Management owns Riot's most time-critical GRC pillar. This role steps directly into that execution environment β€” timelines do not pause for onboarding.

This pillar is intentionally scoped: Risk Management owns the external auditor relationship, the evidence pipeline, the enterprise risk register, the POA&M lifecycle, and the ISO 27001 audit readiness and certification audit track. You own risk identification, risk quantification, audit execution, and the remediation lifecycle that closes gaps across all pillars.

You will report to the Senior Director, GRC and serve as Riot's primary relationship owner with external auditors across SOC 1, SOC 2, and ISO 27001. You will partner directly with the CFO on SOX obligations and with Internal Audit on shared ITGC methodology. In critical operations, you will engage mining site and data center leadership to ensure operational risks are captured, assessed, and reflected in the enterprise risk register.

What you'll do

  • Own end-to-end execution of SOC 1 and SOC 2 Type II audits: scoping, control walkthroughs, evidence collection, auditor liaison, management response drafting, and remediation tracking.
  • Lead the ISO 27001:2022 audit readiness and certification audit track β€” coordinating evidence, managing the certification audit relationship, and driving the program to on-schedule certification.
  • Serve as the primary liaison to Internal Audit for SOX ITGC coordination β€” establishing a shared control inventory, aligning testing methodologies, dividing walkthroughs to eliminate duplication, and maintaining a joint remediation cadence.
  • Build and operate the Riot enterprise risk register: define the risk taxonomy, conduct risk assessments across all business units, tier risks by likelihood and impact, and maintain a living register updated no less than quarterly.
  • Develop and maintain the KRI/KPI framework for executive and Board-level risk reporting β€” translating risk register outputs into leading indicators that give leadership actionable visibility into Riot's risk posture.
  • Run the POA&M (Plan of Action & Milestones) program: intake all audit findings and control gaps across all GRC pillars, assign ownership, track remediation progress, escalate stalled items, and report status to the Sr. Director on a defined cadence.
  • Build continuous audit-readiness infrastructure: design repeatable evidence pipelines, drive evidence collection automation where possible, and eliminate point-in-time audit scrambles by maintaining a year-round audit-ready posture.

Qualifications

  • 8–12+ years of progressive GRC, IT audit, or enterprise risk management experience, with direct, hands-on ownership of SOC 1 and/or SOC 2 Type II audits β€” required.
  • ISO 27001 Lead Implementer certification β€” required.
  • Working knowledge of SOX ITGC requirements at a publicly traded company, with demonstrated experience coordinating GRC work with an Internal Audit function.
  • Proven experience building or operating an enterprise risk register, risk taxonomy, and KRI/KPI reporting framework for executive audiences.
  • Experience owning the external auditor relationship β€” managing audit timelines, evidence requests, walkthrough coordination, and management response drafting across multiple concurrent audit programs.
  • Strong POA&M and remediation lifecycle management: tracking, escalating, and closing audit findings across cross-functional control owners.
  • Familiarity with at least one additional security framework beyond SOC 2 β€” ISO 27001, NIST CSF, or NIST 800-53.
  • Excellent written and verbal communication β€” ability to present risk posture and audit status in executive-ready formats for Board Audit Committee reporting.
  • Preferred: CISA or CRISC certification; experience in critical infrastructure, data center, energy, or digital asset environments; exposure to OT/ICS risk environments.

Benefits

  • Competitive Salary: Base range (commensurate with experience) + bonus + sign-on equity grant.
  • Long-Term Growth: Eligible to participate in Riot’s equity incentive programs and share in the success you help build.
  • 401(k) Retirement Plan: Includes a generous company match.
  • Comprehensive Health Coverage: Multiple medical plan options, including 100% company-paid plans.
  • Wellness & Lifestyle Perks: Enjoy free gym memberships, pet insurance, childcare discounts, and more to support your life both in and out of work.
Before You Apply
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Director, Risk Management @Riot Platforms, Inc.
Compliance
Salary competitive sal..
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Employment Type full-time
Posted 1mth ago
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
Γ—
Apply to the best remote jobs
before everyone else

Access 125,000+ vetted remote jobs and get daily alerts.

4.9 β˜…β˜…β˜…β˜…β˜… from 500+ reviews

⚑ 127,148+ remote jobs, refreshed hourly

πŸ”” Real-time alerts: Apply first, direct to employer

πŸ›‘οΈ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later