Staff Manager, InfoSec GRC

Ripple

Ripple

IT
San Francisco, CA, USA · United States
USD 136k-170k / year + Equity
Posted on May 13, 2025

At Ripple, we’re building a world where value moves like information does today. It’s big, it’s bold, and we’re already doing it. Through our crypto solutions for financial institutions, businesses, governments and developers, we are improving the global financial system and creating greater economic fairness and opportunity for more people, in more places around the world. And we get to do the best work of our career and grow our skills surrounded by colleagues who have our backs.

If you’re ready to see your impact and unlock incredible career growth opportunities, join us, and build real world value.

THE WORK:

Through our blockchain technology and rapidly growing network of financial institutions, Ripple is improving the global financial system and increasing economic inclusion for more people, in more places around the world. Ripple is looking for passionate Information Security professionals to build a world-class Information Security program. In this critical role, you will be responsible for leading technical control testing and evidence collection across financial, security, customer, and regulatory audits in the fast-moving digital asset and stablecoin space, while also creating and delivering broader information security and GRC education materials to strengthen audit readiness and build security awareness across teams..

WHAT YOU’LL DO:

  • Map new regulatory and security frameworks (e.g., SOC 2, ISO 27001, DORA, GDPR) to the existing enterprise control library, identifying overlaps, gaps, and enhancement opportunities.
  • Scope, plan, and independently execute periodic technical control testing, validating the effectiveness of ITGC, Infosec, and regulatory controls across multiple environments (cloud, infrastructure, applications).
  • Gain direct system access and pull technical evidence (e.g., logs, system settings, access reports) for control testing, audits, and continuous compliance efforts.
  • Represent technical control operations during internal and external audits, financial audits, customer audits, and regulatory exams, demonstrating a strong working knowledge of infrastructure, application, and security processes.
  • Develop and maintain technical training materials and documentation for internal GRC processes, system workflows, and evidence collection procedures.
  • Deliver training to technical and non-technical audiences
  • Identify deficiencies or gaps during control testing and escalate to control owners, supporting them in understanding audit expectations without assuming direct remediation responsibilities.
  • Stay current on the organization's technical environment to effectively scope audit requests and assess risk implications.
  • Support continuous improvement initiatives such as enhanced evidence collection processes, audit readiness activities, and knowledge sharing across the GRC team.
  • Align policies, standards, and procedures with compliance objectives
  • Prepare metrics and reports for management on the status of Security GRC objectives
  • Evaluate and respond to customer/prospect questions and audits. Assist in aligning compliance reports and the public-facing Customer Trust Portal to reduce the overall number of customer requests
  • Remain up to date on current security laws, regulations, and standards
  • Represent the Security GRC team by actively engaging in projects and providing guidance, requirements, and documentation when requested
  • Partner with the wider Information Security team, Engineering, Compliance, Finance and Product, Legal, and Sales teams on security matters with the ability to have a direct impact on Ripple’s products' security and customer trust.
  • Create, evaluate, document, and maintain standards, processes, and procedures relative to security and privacy
  • Engage with management to identify possible resolutions to control weaknesses and opportunities for improvement

WHAT YOU'LL BRING:

  • Bachelor's Degree in relevant discipline or equivalent work experience
  • 5+ years of experience in information security risk management and compliance within a highly regulated industry
  • Solid understanding of IT general controls (ITGCs) within the context of financial audits, information security principles, cloud services (e.g., AWS, Azure), and technical systems (e.g., IAM, endpoint management, databases).
  • Hands-on experience pulling technical evidence such as system logs, configuration screenshots, audit reports, and database queries.
  • Strong analytical and documentation skills with an ability to translate technical processes into clear, structured training materials.
  • Experience with regulatory frameworks such as NYDFS, DORA, MAS, and CSSF and leading regulatory examinations and interfacing with regulators.
  • Comfortable working independently in technical environments, quickly learning new systems and processes.
  • Proficiency with common information security frameworks, including SOC2, NIST, CSA Cloud Controls Matrix (CCM), and ISO 27001
  • Ability to create clear, audience-tailored technical documentation, SOPs, and training content.
  • Experience developing and delivering training workshops or informal learning sessions on technical processes or compliance practices.
  • Familiarity with capability maturity frameworks
  • Ability to collaborate effectively across cross-functional teams of engineers, product managers, security and compliance experts
  • Demonstrated organizational, project management, and documentation skills
  • Familiarity and experience with IT/Security tooling such as Jira, Confluence, JupiterOne, Okta, AWS, integrated GRC platforms, etc
  • Ability to analyze empirical evidence and technical reports, identify root causes, and work with teams to identify solutions to remediate gaps
  • Experience in a distributed environment, a fast-moving environment
  • Experience with cloud-native pre-IPO startup companies
  • Desirable certifications: CISSP, CISA, AWS Certified Security, PMP
For positions that will be based in CA, the annual salary range for this position is below. Actual salaries may vary based on numerous factors including, among other things, an individual applicant’s experience and qualifications for the position. This range does not include equity or additional compensation, such as bonuses or commissions.
CA Annual Base Salary Range
$136,000$170,000 USD

WHO WE ARE:

Do Your Best Work

  • The opportunity to build in a fast-paced start-up environment with experienced industry leaders
  • A learning environment where you can dive deep into the latest technologies and make an impact. A professional development budget to support other modes of learning.
  • Thrive in an environment where no matter what race, ethnicity, gender, origin, or culture they identify with, every employee is a respected, valued, and empowered part of the team.
  • In-office collaboration for moments that matter is important to our culture, and we give managers and teams the flexibility to decide which 10+ days a month they come in.
  • Bi-weekly all-company meeting - business updates and ask me anything style discussion with our Leadership Team
  • We come together for moments that matter which include team offsites, team bonding activities, happy hours and more!

Take Control of Your Finances

  • Competitive salary, bonuses, and equity
  • Competitive benefits that cover physical and mental healthcare, retirement, family forming, and family support
  • Employee giving match
  • Mobile phone stipend

Take Care of Yourself

  • R&R days so you can rest and recharge
  • Generous wellness reimbursement and weekly onsite & virtual programming
  • Generous vacation policy - work with your manager to take time off when you need it
  • Industry-leading parental leave policies. Family planning benefits.
  • Catered lunches, fully-stocked kitchens with premium snacks/beverages, and plenty of fun events

Benefits listed above are for full-time employees.


Ripple is an Equal Opportunity Employer. We’re committed to building a diverse and inclusive team. We do not discriminate against qualified employees or applicants because of race, color, religion, gender identity, sex, sexual identity, pregnancy, national origin, ancestry, citizenship, age, marital status, physical disability, mental disability, medical condition, military status, or any other characteristic protected by local law or ordinance.