Director, Governance

riot-platforms-careers

United States

On-site

USD 180,000 - 280,000

Full time

3 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Bonus
Equity grant
401(k) match
Health coverage
Gym membership
Pet insurance
Childcare discounts

Job summary

Riot Platforms is seeking a Director, Governance to build and scale a comprehensive GRC program across policy, compliance, and vendor risk. You will own the ISO 27001:2022 documentation framework, drive attestation programs, and shepherd governance through executive sponsorship.

You will coordinate with Legal, Procurement, HR, and Operations to map policies to SOC 2, ISO 27001, and NIST CSF, while enabling proactive risk management across critical infrastructure and digital assets.

Qualifications

  • 8–12+ years of progressive GRC, policy management, regulatory affairs, or governance program experience at a publicly traded or highly regulated company.
  • ISO 27001 Lead Implementer certification — required.
  • Demonstrated experience building a policy library from a minimal baseline — governance model design, framework mapping, attestation program rollout, and cross-functional adoption.
  • Experience standing up or operating a Contracts Management program with Legal co-ownership — contract risk review, DPA requirements, and GRC-Legal governance models.
  • Working knowledge of TPRM frameworks and vendor risk program design — tiering models, due diligence questionnaires, and ongoing monitoring processes.
  • Proven regulatory horizon scanning capability across critical infrastructure, digital assets, and data privacy (CISA, FinCEN, state privacy laws, DORA, NIS2 familiarity).
  • Experience mapping a policy library to multiple frameworks simultaneously (SOC 2, ISO 27001, NIST CSF) to support a unified audit and control program.
  • Strong cross-functional communication and influence: ability to drive policy adoption and contracts governance across Legal, Procurement, HR, and Operations without direct authority.
  • Preferred: CISM, CGEIT, CRISC, or CIPP/US certification; experience in critical infrastructure, energy, data center, or digital asset environments.

Responsibilities

  • Build and own the ISO 27001:2022 documentation framework: identify and produce all mandatory policies, procedures, and records required for certification, map them to Annex A controls, and drive adoption through executive sponsorship and attestation programs — this is the Year 1 priority with a contractually fixed delivery timeline.
  • Build and operate the Riot policy and standards library from near-zero baseline: establish the governance model (drafting, review routing, approval gates, versioning, renewal cadences), and extend scope beyond ISO 27001 to cover SOC 2, SOX, and enterprise policy requirements.
  • Own the regulatory horizon scanning program: monitor developments across critical infrastructure, digital assets, data privacy, and financial services; translate regulatory signals into GRC program actions; and deliver regular briefings to the Sr. Director and executive leadership.
  • Stand up the Contracts Management program in co-ownership with Legal: design the intake-to-repository workflow, establish GRC risk flagging criteria (data processing, liability, security, regulatory), and implement the Legal sign-off gate — Legal approves, GRC operates.
  • Own the Third-Party Risk Management (TPRM) and vendor risk program: build the vendor tiering model, define due diligence requirements by tier, partner with Procurement on intake integration, and establish ongoing monitoring cadences for critical and colocation vendors.
  • Manage the GRC framework lifecycle: maintain Riot's mapping of policies and controls to SOC 2 Trust Services Criteria, ISO 27001, NIST CSF, and applicable regulatory frameworks — keeping the library current as the regulatory and audit environment evolves.
  • Engage critical operations to ensure site-level operational policies, physical security standards, and environmental procedures are captured within the governance framework and aligned to enterprise GRC standards.

Job description

About Riot Platforms

Riot’s (NASDAQ: RIOT) vision is to be the world’s most trusted platform for powering and buildingdigital infrastructure.Riot’s mission is to empower the future of digital infrastructure by positivelyimpactingthe sectors, networks, and communities that we touch. We believe that the combination of an innovative spirit and strong community partnership allows us to achieve best-in-class execution and create successful outcomes.

Who we are

At Riot,we’rebuilding the future of digital infrastructure. Our team members have unparalleled opportunities to work on groundbreaking initiatives. Through technical excellence and strategic execution, Riot has positioned itself as a leader in the industry driving advancements that continue to set new benchmarks in digital infrastructure.

Weare trailblazers. Problem solvers. People who thrive in fast pacedenvironments,communicate clearly, and bring relentless focus to efficiency and execution.

About the role

The Director, Governance owns the foundational infrastructure every other GRC pillar depends on. Without a policy library, Compliance has nothing to test. Without regulatory horizon scanning, risk finds Riot before Riot finds risk. Without a contracts management program, vendor and third-party risk runs unchecked. Governance is the bedrock of this program — and this role builds it from near zero in Year 1.

This pillar is intentionally scoped to govern, not to test or audit. Governance owns the full lifecycle of policies and standards: drafting, approval routing, versioning, publication, and attestation tracking. Governance owns the ISO 27001:2022 documentation framework — all mandatory policy and procedure documents required for certification. Governance owns the regulatory radar, the Contracts Management program (in co-ownership with Legal), and the Third-Party Risk Management program (in partnership with Procurement).

You will report to the Senior Director, GRC and maintain a co-ownership relationship with the Chief Legal Officer on Contracts Management, where Legal holds final sign-off authority at every material decision gate. In critical operations, you will engage mining site and data center leadership to ensure site-level operational policies, physical security standards, and environmental procedures are captured within the enterprise governance framework.

What you'll do
  • Build and own the ISO 27001:2022 documentation framework: identify and produce all mandatory policies, procedures, and records required for certification, map them to Annex A controls, and drive adoption through executive sponsorship and attestation programs — this is the Year 1 priority with a contractually fixed delivery timeline.
  • Build and operate the Riot policy and standards library from near-zero baseline: establish the governance model (drafting, review routing, approval gates, versioning, renewal cadences), and extend scope beyond ISO 27001 to cover SOC 2, SOX, and enterprise policy requirements.
  • Own the regulatory horizon scanning program: monitor developments across critical infrastructure, digital assets, data privacy, and financial services; translate regulatory signals into GRC program actions; and deliver regular briefings to the Sr. Director and executive leadership.
  • Stand up the Contracts Management program in co-ownership with Legal: design the intake-to-repository workflow, establish GRC risk flagging criteria (data processing, liability, security, regulatory), and implement the Legal sign-off gate — Legal approves, GRC operates.
  • Own the Third-Party Risk Management (TPRM) and vendor risk program: build the vendor tiering model, define due diligence requirements by tier, partner with Procurement on intake integration, and establish ongoing monitoring cadences for critical and colocation vendors.
  • Manage the GRC framework lifecycle: maintain Riot's mapping of policies and controls to SOC 2 Trust Services Criteria, ISO 27001, NIST CSF, and applicable regulatory frameworks — keeping the library current as the regulatory and audit environment evolves.
  • Engage critical operations to ensure site-level operational policies, physical security standards, and environmental procedures are captured within the governance framework and aligned to enterprise GRC standards.
What you'll bring
  • 8–12+ years of progressive GRC, policy management, regulatory affairs, or governance program experience at a publicly traded or highly regulated company.
  • ISO 27001 Lead Implementer certification — required. The Director, Governance is the primary owner of ISO 27001:2022 policy and documentation implementation. Riot has an active, contractually required certification obligation; this credential is a baseline requirement, not a differentiator.
  • Demonstrated experience building a policy library from a minimal baseline — governance model design, framework mapping, attestation program rollout, and cross-functional adoption.
  • Experience standing up or operating a Contracts Management program with Legal co-ownership — contract risk review, DPA requirements, and GRC-Legal governance models.
  • Working knowledge of TPRM frameworks and vendor risk program design — tiering models, due diligence questionnaires, and ongoing monitoring processes.
  • Proven regulatory horizon scanning capability across critical infrastructure, digital assets, and data privacy (CISA, FinCEN, state privacy laws, DORA, NIS2 familiarity).
  • Experience mapping a policy library to multiple frameworks simultaneously (SOC 2, ISO 27001, NIST CSF) to support a unified audit and control program.
  • Strong cross-functional communication and influence: ability to drive policy adoption and contracts governance across Legal, Procurement, HR, and Operations without direct authority.
  • Preferred: CISM, CGEIT, CRISC, or CIPP/US certification; experience in critical infrastructure, energy, data center, or digital asset environments.
Compensation and Benefits
  • Competitive Salary: Base range (commensuratewith experience) + bonus + sign-on equity grant.
  • Long-Term Growth: Eligible to participate in Riot’s equity incentive programs and share in the success you help build.
  • 401(k) Retirement Plan: Incudes a generous company match.
  • Comprehensive Health Coverage: Multiple medical plan options, including 100% company-paid plans.
  • Wellness & Lifestyle Perks: Enjoy free gymmemberships, pet insurance, childcare discounts, and more to support your life both in and out of work.

Riot is an equal opportunity employer. We are committed to creating an inclusive environment for all employees.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Director, Risk Management
Director, Risk Management

riot-platforms-careers • United States

On-site
USD 150,000 - 190,000
Bonus and equity grant
Equity incentive programs
401(k) match
+1
Director, Risk Management
Director, Risk Management

Riot Platforms, Inc. • United States

On-site
USD 180,000 - 280,000
401(k) match
Equity grant
Health coverage
+2
Technical Program Manager - Standards and Governance
Technical Program Manager - Standards and Governance

riot-platforms-careers • Austin (TX)

On-site
USD 120,000 - 170,000
Equity grant
401(k) match
Health coverage
+3
Director, Investor Relations
Director, Investor Relations

Riot Platforms, Inc. • Irvine (CA)

On-site
USD 185,000 - 205,000
401(k) retirement plan
Comprehensive health coverage
Wellness & lifestyle perks
+1
Director, Investor Relations
Director, Investor Relations

Riot Platforms, Inc. • Denver (CO)

On-site
USD 185,000 - 205,000
Free gym memberships
Pet insurance
Childcare discounts
Senior Manager, Enterprise Engineering & Process Excellence
Senior Manager, Enterprise Engineering & Process Excellence

Riot Games • Los Angeles (CA)

On-site
USD 229,000 - 320,000
Medical, dental, vision insurance
Director, Investor Relations
Director, Investor Relations

Riot Platforms, Inc. • Northern (KY), New York (NY)

Hybrid
USD 185,000 - 205,000
Equity incentive programs
Sign-on equity grant
401(k) retirement plan with company-mc
+2
SVP, Engineering
SVP, Engineering

Riot Platforms, Inc. • United States

On-site
USD 310,000 - 340,000
Bonus programs
Equity incentive programs
Company health coverage
+2
Data Center Asset Manager - Reliability Management & Operational Readiness
Data Center Asset Manager - Reliability Management & Operational Readiness

riot-platforms-careers • United States

Hybrid
USD 155,000 - 170,000
People Operations Manager, Strategic Initiatives
People Operations Manager, Strategic Initiatives

riot-platforms-careers • Austin (TX)

On-site
USD 90,000 - 140,000
Competitive base salary
Bonus and equity opportunities
401(k) retirement plan with match
+2